The leaked NSA hacking tools keep showing up in criminal schemes
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0144 | Remote Code Execution in Microsoft SMBv1 (EternalBlue) affecting Windows and Siemens devices CVE-2017-0144 is a remote code execution flaw in the SMBv1 server component of Microsoft Windows, commonly known as EternalBlue, and one of the SMB flaws fixed by Microsoft in the March 2017 MS17-010 bulletin. An attacker who can reach the SMB service over the network sends specially crafted packets that trigger memory corruption in the SMBv1 implementation, gaining the ability to execute arbitrary code on the target without user interaction. Successful exploitation yields full system compromise and has been heavily weaponized for wormable spread and ransomware delivery, notably via the leaked NSA exploit and in the WannaCry/NotPetya-era outbreaks, and the flaw has repeatedly been bundled into botnets and ransomware tooling since. Anyone running unpatched Windows Vista SP2 through Windows 10 1607 / Windows Server 2016 with SMBv1 enabled is affected, as are Siemens medical and laboratory devices (ACUSON ultrasound, syngo SC2000, Tissue Preparation System, VERSANT kPCR systems) whose firmware depends on SMBv1. Exploitation is actively ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with known ransomware use, carries a 99.2% EPSS exploitation probability (100th percentile), and multiple public exploits and PoCs are available. Do: Apply the Microsoft MS17-010 (March 2017) security updates on every listed Windows version and the corresponding Siemens firmware updates for ACUSON, syngo SC2000, Tissue Preparation System, and VERSANT kPCR devices, per CISA's required action to apply vendor updates. Where patching is not yet possible, disable SMBv1 or block inbound TCP 445 (and UDP 137/138) at network boundaries and isolate legacy/medical systems from the internet. Sweep exposed and legacy hosts for compromise indicators, including DOUBLEPULSAR implants delivered over SMB, as public tooling for detecting and neutralizing this implant is available. | 8.8 | 99% | KEV ransomware PoC ×6 |
| massorder of hundreds of thousands of internet-exposed SMB endpoints, and millions of unpatched Windows systems when internal enterprise and medical-device… |
Full article806 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
In practice, EternalBlue will allow a hacker to quickly compromise multiple computers on a shared network as long as they are all similarly running dated Microsoft software.
A hacking tool linked to the NSA continues to be used by cybercriminals in efforts to remotely steal money and confidential information from online banking users, according to research conducted by U.S. cybersecurity firm Proofpoint.
In a recent blogpost by company researchers, Proofpoint said it had discovered two different banking trojans in the wild with computer code taken from a now publicly available exploit known as “EternalBlue,” or CVE-2017-0144.
EternalBlue is believed to have been used by the NSA to gather intelligence. Originally leaked in April, the exploit works by targeting a dated vulnerability in Microsoft’s Server Message Block protocol. The vulnerability affects outdated versions of several different Microsoft operating systems.
Microsoft already released a patch to fix the issue.
In practice, EternalBlue will allow a hacker to quickly compromise multiple computers on a shared network as long as they are all similarly running dated software.
“Patching Windows can take a very long for many organizations – we routinely observe one or two-year-old (and sometimes older) exploits being used successfully in a variety of attacks,” explained Kevin Epstein, vice president of Threat Operations for Proofpoint. “As long as threat actors continue to find widespread, unpatched vulnerabilities, they will continue to leverage exploits like EternalBlue.”
The two trojans, Retefe and TrickBot, are relatively common and have been in use for several months as part of various email phishing campaigns against companies and individual users. The latest versions of these trojans are the ones that carry elements of EternalBlue.
The new variant of Retefe identified by Proofpoint was sent in an unsolicited email to a company. The email contained a malicious Microsoft Office document that was laden with embedded Package Shell Objects. When opened, a PowerShell command will launch a download for a .zip archive holding a obfuscated JavaScript installer hosted on a remote server. The eventual result is the installation of a virus that leverages EternalBlue to quickly spread inside an infected network.
Retefe has been largely used in attacks against banks in Austria, Sweden, Switzerland, Japan and the United Kingdom, according to researchers.
“While it has never reached the scale or notoriety of better-known banking Trojans such as Dridex or Zeus, [Retefe] is notable for its consistent regional focus, and interesting implementation,” a Proofpoint blog post notes.
More broadly, the use of EternalBlue in attacks doesn’t appear to be narrowly focused or aimed at one specific industry or region, experts say.
“There does not appear to be a common theme in terms of targeting for attacks leveraging EternalBlue,” said Epstein. “Rather, this approach seems to be evolving, giving attackers both destructive and disruptive potential as we saw with WannaCry’s rapid propagation via EternalBlue as well as more precise lateral movement after a successful infiltration through other vectors as we observed with Retefe.”
In the past, the EternalBlue exploits has been used tandem with ransomware to extort money from businesses. It’s not entirely clear who is behind Retefe or Trickbot, although a relatively small group is thought to be behind the spread of Retefe.
“Although this Retefe variant appears to be used exclusively by the so-called Retefe Gang, we don’t know who first developed the malware,” Epstein told CyberScoop. “We do not have sufficient information to attribute the Trickbot variant featuring EternalBlue to a particular author.”
The EternalBlue exploit first became publicly known and adoptable following the publication of a package of NSA documents by a group known as The Shadow Brokers.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/retefe-eternal-blue-nsa-proofpoint/