F-Secure has discovered MiniDuke malware samples in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2013-0640 | Memory Corruption RCE in Adobe Reader and Acrobat (acroform.dll) CVE-2013-0640 is a memory corruption flaw (out-of-bounds write, CWE-787) in acroform.dll, the AcroForm PDF-forms component of Adobe Reader and Acrobat, which can be triggered by opening a specially crafted PDF. An attacker who tricks a user into opening a malicious PDF gains remote code execution with the privileges of the logged-on user; this was the vector used by the MiniDuke espionage campaign of February 2013, which delivered a small government-grade backdoor assembler backdoor via PDF 0-day exploits. Anyone running unpatched Adobe Reader or Acrobat is affected, and F-Secure's discovery of in-the-wild MiniDuke samples plus Uyghur- and Tibetan-themed PDF attacks confirm active targeted exploitation. The bug carries a very high likelihood of exploitation (EPSS 87%, 100th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03 with required action to apply vendor updates; no public PoC is catalogued, but in-the-wild exploitation is confirmed. Do: Apply updates per vendor instructions (the CISA KEV required action): bring all Adobe Reader and Acrobat installations to the latest patched release issued by Adobe in February 2013 or later. Inventory endpoints for outdated PDF readers, block or inspect PDFs from untrusted sources as an interim mitigation, and check government/NGO-type targeted machines for MiniDuke-style PDF-borne backdoor indicators. | — | 87% | KEV |
| masshundreds of millions of users (Adobe Reader/Acrobat is near-universal on desktops) |
Full article635 words · extracted from securityaffairs.com · click to collapse

Security Experts at F-Secure discovered a collection of pdf documents, that had references to Ukraine, containing MiniDuke malware samples.
MiniDuke is the name of a sophisticated cyber espionage campaign discovered more than one year ago by experts at Kaspersky Lab and Hungary’s Laboratory of Cryptography and System Security (CrySyS). The malicious code was used by unknown hackers to infect dozens of computers at government agencies across Europe exploiting a security flaw in Adobe software, the malicious Payload is dropped once the victim opens the malicious PDF file.
The malware was designed to steal sensitive information from government organizations and high profile entities, the level of sophistication and the nature of the chosen targets suggest that the attacks are part of a state-sponsored espionage campaign.
Authors of MiniDuke implemented many interesting features, it was a tiny malware (20KB) and the overall botnet was controlled by Twitter accounts used as Command & Control and located backup control channels via Google searches, in this way the attackers were able to make difficult the malware traffic detection. Another smart feature is represented by the way the attackers deploy an additional backdoor in the victim system with a GIF files that embedded the malware.
Exactly one year later security experts are still facing with MiniDuke, this time the attackers used a bogus PDF documents related to Ukraine to deceive the victims. Researchers at F-Secure made the disturbing discovery while they were analyzing a collection of document used by attackers from a large batch of potential MiniDuke Samples.
“To investigate similar cases, we have created a tool for extracting the payloads and the decoy documents from MiniDuke PDF files. With this tool we were able to process a large batch of potential MiniDuke samples last week. While browsing the set of extracted decoy documents, we noticed several ones that had references to Ukraine. This is interesting considering the current crisis in the area.” reported Mikko Hypponen, the CTO of security research firm F-Secure.
The documents explicitly refer political issues like the recent crisis in the Ukraine or NATO informative in the attempt to circumvent the victims, F-Secure reported, for example, the existence of a bogus document signed by Ruslan Demchenko, the First Deputy Minister for Foreign Affairs of Ukraine.
“The letter is addressed to the heads of foreign diplomatic institutions in Ukraine. When translated, it’s a note regarding the 100th year anniversary of the 1st World War.” states Hypponen.
The use of such kind of documents suggests that attackers have had access to the Ukrainian Ministry of Foreign Affairs, anyway they have no problem with the language used.
“We don’t know where the attacker got this decoy file from,” “We don’t know who was targeted by these attacks. We don’t know who’s behind these attacks. What we do know is that all these attacks used the CVE-2013-0640 vulnerability and dropped the same backdoor (compilation date 2013-02-21).”
Who is behind the attack?
It’s impossible to speculate on the real nature of the attackers, the problem of attribution is hard to approach, especially when the attackers demonstrate to be able to provide high level APT with sophisticated evasion techniques.
As remarked by Hypponen during the recent TrustyCon conference there is the risk that a Government-built malware and cyber weapons will run out of control, every government could be able to make a reverse engineering of source code of malware like Miniduke and could be used by state-sponsored hackers and cyber criminals, two categories separated by a thin line.
(Security Affairs – search engine, malware)
March 4th, 2014UPDATE : “These examples were found by mining old samples. The cases above are from 2013. So far, we haven’t found Ukraine-related Miniduke samples that would have been used in 2014.” reported F-Secure.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/23658/cyber-crime/f-secure-new-miniduke-atp.html