ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Democratic Party of Hong Kong Website Compromised and Serving Spyware

highMalwareimportance 47CVE-2011-0611

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2011-0611
Remote Code Execution in Adobe Flash Player via Crafted Flash Content

Adobe Flash Player contains a flaw tracked as CWE-843 that allows remote attackers to execute arbitrary code or crash the application (denial of service) by inducing it to load specially crafted Flash content. Exploitation requires only that a victim's Flash runtime process a malicious SWF file — for example embedded in a document or served by a website — with no authentication involved; related reporting from this era describes waterhole attacks in which compromised websites served Flash exploits to targeted users. A successful attack yields code execution with the privileges of the user running Flash, which for browser-plugin deployments typically means the logged-in desktop user. Anyone running affected Adobe Flash Player is affected; CISA's listing does not enumerate specific vulnerable versions, and the product line is end-of-life. Exploitation is confirmed: the flaw was added to CISA's KEV catalog on 2022-03-03, EPSS assigns a 99.4% 30-day exploitation probability (100th percentile), and no public proof-of-concept is known.

Do: Because Flash Player is end-of-life and receives no security updates, remove or uninstall it entirely — including browser plugins, standalone runtimes, and any embedded copies — which is also CISA's required action for impacted systems. If removal must be deferred, disconnect affected systems or block untrusted Flash content and audit logs for exploitation, given the confirmed in-the-wild status and ~99% exploitation probability; whether ransomware operators have used this flaw is unknown.

99% KEV
  • Adobe Flash Player
mass≈1B+ historical installs (near-universal browser plugin); current remaining installs unknown

Indicators of compromiseAll →

TypeIndicatorContext
domainloveusa.dyndns-blog.comemory and phones collected information off of the system to loveusa.dyndns-blog.com. The drop server is not active at this point. Because so ma
Full article491 words · extracted from securelist.com · click to collapse

Incidents

Incidents

30 May 2011

minute read

The Democratic Party of Hong Kong’s website was compromised and malware uploaded to the web server. Interestingly, the server was distributing malicious flash and spyware nearly identical to the compromised UK Amnesty International servers at the beginning of this month. The server is being cleaned up.

The english version of the website did not include injected iframe links pointing to the exploit.html page, which in turn delivers three different version-appropriate malicious variants of flash detected by Kaspersky as “Exploit.SWF.CVE-2011-0611”. The malicious flash was 0day at the beginning of this month, and will be effective on unpatched systems.

While it’s interesting that the security team researching the previous incident thought that the technique for delivering the payload to the hard drive is deserving a new term “drive-by caching”, it’s also incorrect to think that security products are given a higher bar to hurdle in preventing the attack because of the minor tweak – Kaspersky’s detection and prevention for the 0day flash files was released weeks before the Adobe patches. In other words, the attacks are being stopped just the same by Kaspersky products.

If one of the malicious flash is successful in downloading and executing the newsvine.jp2 file hosted on the server, it immediately drops a couple of files, pe.dll and srvlic.dll. These files are loaded and the delphi component decrypts its more sensitive information in-memory and phones collected information off of the system to loveusa.dyndns-blog.com. The drop server is not active at this point.

Because so many individuals run vulnerable versions of Adobe Flash and infrequently update their software, and because CVE-2011-0611 was just patched this month, the attackers had a pretty good chance of hitting their targets. Political groups continue to be an active target of cyberattacks this year.

UPDATE: we had a few final links to clean up from the standard suckerfish.js script on the server’s home page. These same malicious links leading to a 3rd party server at thesaj(dot)com hosting malicious flash, detected by Kaspersky as Exploit.SWF.CVE-2011-0611.u and Exploit.SWF.CVE-2011-0611.v, were injected and cleaned from “The Taiwan Brain Trust” web site a couple of weeks ago. The “Trust” is a group in Taiwan that “…provides policy analysis and recommendations to decision-makers in government, multinational corporations, private enterprises and civil society”, making it another compromised high value political target.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/democratic-party-of-hong-kong-website-compromised-and-serving-spyware/30644/