ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

BADNEWS! Patchwork APT Hackers Score Own Goal in Recent Malware Attacks

highMalwareimportance 47CVE-2017-0261

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0261
Use-After-Free RCE in Microsoft Office 2010/2013/2016

CVE-2017-0261 is a use-after-free (CWE-416) remote code execution flaw in Microsoft Office 2010 SP2, 2013 SP1, and 2016, caused by improper handling of objects in memory. It is triggered by convincing a user to open a malicious document or email attachment, which corrupts memory and lets the attacker run arbitrary code with the victim's privileges (high impact on confidentiality, integrity, and availability). Any user of the affected Office editions is exposed, and because the attack requires user interaction via a crafted file, email-borne targeting is the realistic attack path. The flaw was patched in Microsoft's May 2017 Patch Tuesday releases after being exploited as a zero day, with public reporting linking active exploitation to Russian APT groups. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), and its EPSS score of 78.1% (100th percentile) reflects a very high likelihood of exploitation.

Do: Apply Microsoft's May 2017 Patch Tuesday security updates to all installations of Office 2010 SP2, 2013 SP1, and 2016, following the vendor's instructions as required by the CISA KEV listing. Until patched, warn users against opening unsolicited or untrusted Office attachments and consider email filtering to block risky file types. Verify fleet compliance against the KEV required action (apply updates per vendor instructions) and prioritize endpoints of targeted or high-value users.

7.878% KEV
  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016 all versions prior to the May 2017 security updates
masstens to hundreds of millions of users (Office's global install base across the affected editions)
Full article565 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 10, 2022

Threat hunters have shed light on the tactics, techniques, and procedures embraced by an Indian-origin hacking group called Patchwork as part of a renewed campaign that commenced in late November 2021, targeting Pakistani government entities and individuals with a research focus on molecular medicine and biological science.

"Ironically, all the information we gathered was possible thanks to the threat actor infecting themselves with their own [remote access trojan], resulting in captured keystrokes and screenshots of their own computer and virtual machines," Malwarebytes Threat Intelligence Team said in a report published on Friday.

Prominent victims that were successfully infiltrated include Pakistan's Ministry of Defense, National Defence University of Islamabad, Faculty of Bio-Sciences at UVAS Lahore, International Center for Chemical and Biological Sciences (ICCBS), H.E.J. Research Institute of Chemistry, and the Salim Habib University (SBU).

Believed to have been active since 2015, Patchwork APT is also tracked by the wider cybersecurity community under the monikers Dropping Elephant, Chinastrats (Kaspersky), Quilted Tiger (CrowdStrike), Monsoon (Forcepoint), Zinc Emerson, TG-4410 (SecureWorks), and APT-C-09 (Qihoo 360).

The espionage group, primarily known for striking diplomatic and government agencies in Pakistan, China, U.S. think tanks, and other targets located in the Indian subcontinent via spear-phishing campaigns, gets its name from the fact that most of the code used for its malware tooling was copied and pasted from various sources publicly available on the web.

"The code used by this threat actor is copy-pasted from various online forums, in a way that reminds us of a patchwork quilt," researchers from the now-defunct Israeli cybersecurity startup Cymmetria noted in its findings published in July 2016.

Over the years, successive covert operations staged by the actor have attempted to drop and execute QuasarRAT as well as an implant named BADNEWS that acts as a backdoor for the attackers, providing them with full control over the victim machine. In January 2021, the threat group was also observed exploiting a remote code execution vulnerability in Microsoft Office (CVE-2017-0261) to deliver payloads on victim machines.

The latest campaign is no different in that the adversary lures potential targets with RTF documents impersonating Pakistani authorities that ultimately act as a conduit for deploying a new variant of the BADNEWS trojan called Ragnatela — meaning "spider web" in Italian — enabling the operators to execute arbitrary commands, capture keystrokes and screenshots, list and upload files, and download additional malware.

The new lures, which purport to be from the Pakistan Defence Officers Housing Authority (DHA) in Karachi, contains an exploit for Microsoft Equation Editor that's triggered to compromise the victim's computer and execute the Ragnatela payload.

But in what's a case of OpSec failure, the threat actor also ended up infecting their own development machine with the RAT, as Malwarebytes was able to unmask a number of its tactics, including the use of dual keyboard layouts (English and Indian) as well as the adoption of virtual machines and VPNs such as VPN Secure and CyberGhost to conceal their IP address.

"While they continue to use the same lures and RAT, the group has shown interest in a new kind of target," the researchers concluded. "Indeed, this is the first time we have observed Patchwork targeting molecular medicine and biological science researchers."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/01/badnews-patchwork-apt-hackers-score-own.html