Magnet Goblin Exploits 1
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-21887 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). NVD description · AI analysis pending | 4.9 | 43% |
| — | ||
| CVE-2023-46805 | Authentication Bypass in Ivanti Connect Secure and Policy Secure Web Component Ivanti Connect Secure (ICS, formerly Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass (CWE-287) in the web component that allows an attacker to access restricted resources by bypassing control checks without valid credentials. The flaw is triggered through the exposed web interface of the gateway, and it is most dangerous when chained with CVE-2024-21887, a command injection vulnerability in the same component, which turns the bypass into unauthenticated arbitrary command execution on the appliance. An attacker gains access to protected resources and, via the chained command injection, the ability to run commands on the gateway — the pattern observed in the January 2024 exploitation wave that led to follow-on compromise, including known ransomware use. Affected organizations are those running Ivanti Connect Secure or Policy Secure gateways, which are typically deployed as internet-facing VPN concentrators at the network edge. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-01-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile); no CVSS score is available yet and no public PoC is known. Do: Apply Ivanti's mitigations or patched builds per the vendor's instructions immediately, or discontinue use of the product if mitigations are unavailable, as CISA's KEV required action states, and remediate the companion command injection flaw CVE-2024-21887 on the same gateways. Because exploitation is confirmed in the wild with known ransomware use, treat any long-running appliance as potentially compromised: check it for signs of compromise per vendor guidance and rotate credentials, sessions, and any secrets stored on or reachable through the VPN. | 8.2 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed gateways (public internet-wide scans around the January 2024 disclosure found on the order of 20,000-30,000 exposed… |
Full article306 words · extracted from infosecurity-magazine.com · click to collapse
Security researchers have uncovered a trend involving the exploitation of 1-day vulnerabilities, including two in Ivanti Connect Secure VPN.
The flaws, identified as CVE-2023-46805 and CVE-2023-21887, were quickly exploited by multiple threat actors, leading to various malicious activities. Tracking these exploits, the Check Point Research (CPR) team said it encountered a cluster of activities attributed to a threat actor dubbed Magnet Goblin.
The actor has been observed methodically leveraging 1-day vulnerabilities, particularly targeting edge devices like the Ivanti Connect Secure VPN. Magnet Goblin uses custom Linux malware to pursue financial gain.
These exploits involve the deployment of malware via a range of methods, including the exploitation of vulnerabilities in Magento, Qlik Sense and potentially Apache ActiveMQ.
Detailed in an advisory published on Friday, the researchers’ investigation revealed a sophisticated infrastructure behind Magnet Goblin’s operations. They found evidence of the deployment of payloads such as WARPWIRE JavaScript credential stealers and Ligolo tunneling tools.
Read more on similar attacks: Two Ivanti Zero-Days Actively Exploited in the Wild
Furthermore, the threat actor’s activities extended beyond Linux environments, with some instances targeting Windows systems using tools like ScreenConnect and AnyDesk, suggesting a wide-ranging and adaptable approach.
CPR said the analysis of NerbianRAT variants sheds light on the intricacies of the malware’s operation. From initialization to command-and-control, the malware exhibits a sophisticated design, allowing for flexibility in executing various actions on infected machines. Additionally, MiniNerbian, a simplified version of NerbianRAT, further showcases the threat actor’s adaptability and stealthy tactics.
“Magnet Goblin, whose campaigns appear to be financially motivated, has been quick to adopt 1-day vulnerabilities to deliver their custom Linux malware, NerbianRAT and MiniNerbian,” warned CPR.
“Those tools have operated under the radar as they mostly reside on edge devices. This is part of an ongoing trend for threat actors to target areas which until now have been left unprotected.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/magnet-goblin-exploits-ivanti-flaws/