SandWorm hacking team exploited 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2013-3906 | Memory Corruption RCE in Microsoft Graphics Component (Actively Exploited) Microsoft's Graphics Component contains a memory corruption vulnerability that can allow remote code execution when the component processes maliciously crafted graphics content, typically delivered inside documents or other rendered content. An attacker who successfully triggers the flaw gains the ability to execute arbitrary code on the target system in the context of the current user, inheriting that user's privileges. Any Microsoft Windows system running an affected version of the Graphics Component is exposed, since the component is part of the Windows platform and is reachable through normal document and image rendering. The flaw was exploited as a zero-day in targeted attacks — notably by the Sandworm threat group against Ukrainian government and NATO-related targets, per iSight Partners reporting — and was addressed in Microsoft's December 2013 security updates. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-15, and EPSS currently assigns an 85% probability of exploitation within 30 days (100th percentile). Do: Apply the vendor's December 2013 security updates covering the Graphics Component (MS13-098) to all Windows systems, prioritizing legacy machines that may have never received the patch, and verify KEV remediation compliance if you are a federal agency. Because exploitation vectors historically involved malicious document rendering, reinforce email filtering and Office attack-surface reduction (e.g., blocking untrusted embedded graphics/objects) on any systems that remain unpatched. | — | 85% | KEV |
| mass≈1 billion+ Windows installations carried the component at the time of disclosure; residual exposure is limited to systems never patched with the December 2013… | |
| CVE-2014-4114 | Remote Code Execution in Microsoft Windows OLE via Crafted Files CVE-2014-4114 is a flaw in the Windows Object Linking & Embedding (OLE) component, categorized as improper input validation (CWE-20), that permits remote code execution when a user opens a file containing a specially crafted OLE object. It is triggered entirely through user interaction — opening a malicious document such as an Office/PowerPoint file with an embedded OLE object — with no prior authentication or network service exposed. A successful attacker gains code execution in the context of the logged-on user, enabling follow-on actions such as downloading payloads or moving laterally within an enterprise. All affected Windows releases are exposed; Microsoft addressed the flaw in its November 2014 security updates. Exploitation was observed in the wild by the Sandworm threat group using weaponized PowerPoint files, and the flaw carries a very high likelihood of exploitation (EPSS 81.6%, 100th percentile) and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03. Do: Apply Microsoft's Windows OLE security update from the November 2014 release to all affected Windows hosts, per the CISA KEV required action; the CVSS score is not yet published, so treat this as high priority given the RCE impact. As interim mitigation, limit opening of untrusted Office files containing embedded OLE objects and consider restricting OLE object activation for files from the internet zone. For detection, check endpoints for suspicious outbound SMB connections initiated shortly after a user opens a PowerPoint/Office document, a pattern associated with Sandworm exploitation of this flaw. | — | 82% | KEV |
| masshundreds of millions of Windows desktops and servers (OLE is a core Windows component present on effectively every affected Windows installation) |
Full article613 words · extracted from securityaffairs.com · click to collapse

iSIGHT Partners firm uncovered a Russian hacking team dubbed Sandworm that was running a cyber espionage campaign on NATO and other Government entities.
According to a new report issued by the cyber security firm iSIGHT Partners a group of Russian hackers has been exploiting a previously unknown flaw in Microsoft’s Windows operating system to spy on NATO, the Ukrainian government, a U.S. university researcher and many other entities. The researchers at ISight dubbed the hacking group SandWorm because of references discovered in its code to the science-fiction novel “Dune.”
The experts at iSIGHT Partners have worked in close collaboration with Microsoft during the investigation, the company announced the discovery of a zero-day vulnerability affecting all supported versions of Microsoft Windows and Windows Server 2008 and 2012. The vulnerability has been classified with the code CVE-2014-4114, and according the revelation made by iSIGHT is has been exploited in cyber espionage operation on a large scale by a Russia hacking team, the nature of the target and the tactics, techniques, and procedures (TTP) adopted lead the experts to believe that this is the work of state-sponsored hackers.
“This is consistent with espionage activity,” said iSight Senior Director Stephen Ward. “All indicators from a targeting and lures perspective would indicate espionage with Russian national interests.”
Microsoft is already working on a security update for the CVE-2014-4114 that will be available in the next patch updates on the October 14th.
According to the report issued by iSIGHT, the APT has been active since at least 2009, Its targets in the recent campaign also included a Polish energy firm, a Western European government agency and also a French telecommunications firm.
The experts began the investigation in late 2013 when the NATO alliance was targeted by the SandWorm hacking team with exploits other than the zero-day, but they discovered the critical zero-day in August, when the group targeted the Ukrainian government, in the lead-up to the NATO summit in Wales.
“In late August, while tracking the Sandworm Team, iSIGHT discovered a spear-phishing campaign targeting the Ukrainian government and at least one United States organization. Notably, these spear-phishing attacks coincided with the NATO summit on Ukraine held in Wales.” states the report published by iSIGHT.
Security experts speculated that the intensification of the cyber dispute between Russian and Ukraine could have increased the likelihood to discover operations that went under the radar for so long.
Below chronological details provided by the researchers on the Sandworm activity:
- The NATO alliance was targeted as early as December 2013 with exploits other than the zero-day
- GlobSec attendees were targeted in May of 2014 with exploits other than the zero-day
- June 2014
- Broad targeting against a specific Western European government
- Targeting of a Polish energy firm using CVE-2013-3906
- Targeting of a French telecommunications firm using a BlackEnergy variant configured with a Base64-encoded reference to the firm
The SandWorm hacking team sent spear-phishing emails with a malicious attachments to compromise the victim’s machine, the threat actors mentioned a global security forum on Russia and a purported list of Russian terrorists.
Another element that suggests Russia is responsible for the cyber espionage campaign are codes discovered on the C&C server, located in Germany, that had not been properly secured and that contains Russian-language computer files that had been uploaded by the hackers.
“They could have closed it off, and they didn’t,” he said of the server. “It was poor operational security.”
The investigators noticed that SandWorm apparently re-engineered malware previously by other APT probably to masquerade its campaigns.
Read the full post for further information.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – Sandworm, cyber espionage)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/29230/security/sandworm-0day-cyberespionage.html