ZeroHour
Security Affairspublished ()ingested @securityaffairs

Whitehole Exploit Kit in the wild

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2011-3544
Remote Code Execution in Oracle Java SE JRE Applet Rhino Script Engine

CVE-2011-3544 is an access control flaw in the Rhino JavaScript Script Engine component used by Java applets in Oracle's Java Runtime Environment. It is triggered when a user's browser loads a malicious Java applet, allowing script executed through the Rhino engine to bypass Java's access restrictions. An attacker who successfully exploits it gains the ability to run arbitrary code on the victim's machine with the privileges of the logged-in user, typically via drive-by download from a compromised or attacker-controlled website. Any system with a vulnerable Oracle Java SE JDK or JRE and an enabled Java browser plugin is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-03-03, carries a 96.7% EPSS probability of exploitation within 30 days, and contemporary reports show it weaponized in the BlackHole/Whitehole exploit kits and used in mass OS X exploitation.

Do: Apply updated Oracle Java SE builds per Oracle's vendor instructions, prioritizing internet-facing and end-user systems listed in the KEV guidance. Where patching is delayed, disable the Java browser plugin or block Java applets at the web gateway, since the attack vector is malicious applets served over the web. Review endpoints for signs of exploit-kit drive-by compromise, especially legacy Windows and OS X machines with outdated Java.

97% KEV
  • Oracle Java SE JDK and JRE
masshundreds of millions of desktops and servers with a Java runtime installed; exact count unknown
CVE-2012-1723
Remote Arbitrary Code Execution in Oracle Java SE (Hotspot Component)

Oracle Java SE's Java Runtime Environment contains an unspecified flaw in its Hotspot component that allows remote attackers to affect confidentiality, integrity, and availability — characterized by CISA as arbitrary code execution. The available data does not document the exact trigger beyond 'unknown vectors related to Hotspot,' but flaws in the JVM's execution engine of this type are typically reached remotely by having the runtime process malicious Java content. A successful attacker gains code execution in the context of the process running the JVM, taking control of the affected host. Any deployment running affected, unpatched Oracle Java SE — particularly legacy JRE installs — is affected. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use and a 93.7% EPSS probability of exploitation in the next 30 days, confirming active in-the-wild exploitation, though the reviewed data lists no public PoC.

Do: Per CISA's required action, apply updates per vendor instructions: upgrade every Oracle Java SE installation to a currently supported patched release and inventory for legacy JRE builds that predate the 2012 Hotspot fix. Disable or restrict the Java browser plugin where it is not needed, and given known ransomware use, prioritize legacy Java systems for patching and threat-hunting.

94% KEV ransomware
  • Oracle Java SE (Java Runtime Environment, JRE)
mass≈ millions of endpoints running legacy, unpatched Java (exact count unknown)
CVE-2012-4681
Remote Code Execution in Oracle Java SE Runtime Environment (JRE)

A vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE allows arbitrary code execution remotely. It is triggered when the JRE processes attacker-controlled input, letting the attacker run arbitrary code in the context of the affected Java process. Any system running an affected Oracle Java SE build is exposed, including desktops and servers where Java is installed or used. Exploitation is confirmed in the wild: the flaw was weaponized by exploit kits in 2012 (e.g., the Whitehole Exploit Kit, whose use in the wild coincided with this CVE's coverage), was added to CISA's KEV on 2022-03-03 with known ransomware use, and EPSS currently assigns a 98.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in this data, but the flaw should be treated as actively exploited and urgent to patch.

Do: Inventory all systems running Oracle Java SE and apply updates per vendor instructions, as CISA's required action specifies. Where immediate patching is not possible, disable or restrict the Java browser plug-in and limit Java execution to trusted sites, since the flaw was historically exploited via drive-by exploit kits. Given the KEV listing and 98.5% EPSS score, prioritize patching internet-exposed and ransomware-relevant systems.

99% KEV ransomware
  • Oracle Java SE (JRE component)
massOrder of hundreds of millions of installations/endpoints (well above 1M); precise current count unknown from this data
CVE-2012-5076
Java Sandbox Bypass in Oracle Java SE

CVE-2012-5076 is a Java sandbox bypass caused by the default Java security properties configuration, which failed to restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. The flaw is triggered when an untrusted Java application or applet is run and abuses access to these packages to escape the Java sandbox. An attacker who successfully exploits it gains the ability to execute code with elevated privileges beyond the sandbox restrictions that are supposed to contain untrusted Java code. Any environment running affected Oracle Java SE and executing untrusted Java code — most notably browsers with the Java plugin loading applets — is exposed, and CISA lists Oracle Java SE as the affected product. CISA added this vulnerability to the KEV catalog on 2022-03-28, indicating known exploitation in the wild; no public proof-of-concept is known, and ransomware use is unknown.

Do: Apply Oracle's updates per vendor instructions, as required by the CISA KEV listing — upgrade all Java SE deployments to the current patched release and verify no systems remain on unpatched builds. As mitigation, disable the Java browser plugin or block untrusted applets and applications where full patching is not yet possible, and monitor for exploitation activity consistent with exploit kit delivery.

91% KEV
  • Oracle Java SE
masshundreds of millions of installations (Java runtime is ubiquitous; Oracle has historically cited over a billion Java-enabled devices)
CVE-2013-0422
Java Applet Permission-Restriction Flaw Enables Remote Code Execution in Oracle JRE

CVE-2013-0422 is a flaw in how Oracle's Java Runtime Environment restricts the permissions of Java applets (CWE-264), allowing an applet to run with privileges beyond its intended security sandbox. It is triggered when a user loads a web page that delivers a malicious Java applet, such as via a drive-by visit or a phishing link pointing to an attacker-controlled site. Successful exploitation lets the attacker execute commands in the context of the current user on the client system, which in the 2013 campaigns was used to deliver malware families tracked in exploit kits and APT activity (e.g., Whitehole, Miniduke, Icefog) and is recorded by CISA as being used in ransomware. Any system with Oracle JRE installed—especially workstations and browsers with the Java applet plug-in enabled—is affected. Exploitation is confirmed in the wild: the flaw was mass-exploited by exploit kits at the time of disclosure, it carries a 97.6% EPSS probability of exploitation (100th percentile), and it was added to CISA KEV on 2022-05-25, so patching remains an active requirement.

Do: Apply Oracle's Java updates per vendor instructions — at disclosure this meant the emergency Java 7 Update 11 or later, and today the current supported Java release. As interim mitigation, disable the Java browser plug-in (or Java in browsers) and uninstall JRE where it is no longer needed. Given known in-the-wild use by exploit kits and ransomware, prioritize KEV remediation and check endpoints for drive-by web-borne infections delivered via malicious applets.

98% KEV ransomware
  • Oracle Java Runtime Environment (JRE)
masshundreds of millions of Java installs (Java was near-ubiquitous on enterprise desktops and servers in 2013)
Full article469 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 09, 2013

Exploit kit, a name which has become depressingly familiar, crimaware kit that contains malicious code to exploit principal vulnerabilities in large consume product such as browsers, last news is that a new kit named Whitehole has emerged on the underground market. Generally the exploit kits are malicious Web-based applications designed to install malware on computers by exploiting known vulnerabilities in outdated browser and browsers plug-ins.

“The downloaded files are detected as BKDR_ZACCESS.NTW and TROJ_RANSOM.NTW respectively.ZACCESS/SIRIEF variants are known bootkit malware that download other malware and push fake applications. This specific ZACCESS variant connects to certain websites to send and receive information as well as terminates certain processes. It also downloads additional malicious files onto already infected systems. On the other hand, ransomware typically locks systems until users pay a sum of money via specific payment modes. Senior threat researcher David Sancho wrote a detailed report on how this threat is evolving at a fast pace in his paper, Police Ransomware Update.”

According to security firm Trend Micro the cybercrime has a new weapon to compromise computers using a malware diffused over the internet. Whitehole is very similar to most popular exploit kit Blackhole, but it has some particular differences, Whitehole only contains exploits for known Java vulnerabilities (CVE-2011-3544, CVE-2012-1723, CVE-2012-4681, CVE-2012-5076 and CVE-2013-0422).

The Whitehole appears as an ongoing project and currently is sold as a test release, however, its creators are already renting it in the underground for prices between US$200 and $1,800, depending on their traffic volume.

“Given Whiteholes current state, we may be seeing more noteworthy changes to the exploit kit these coming months. Thus, we are continuously monitoring this threat for any developments,”

The schema is quite simple, a well-known technique dubbed drive-by downloads is implemented for malware diffusion, users generally get redirected to drive-by download attack pages visiting a compromised website.

Another interesting feature implemented for Whitehole exploit is the antivirus detection evasion technique that is able to prevent Google Safe Browsing from detecting and blocking it and load up to 20 malicious files at once.

The monitoring of underground forums is a fundamental activity for cybercrime prevention, it is necessary to detect in time the growing the cyber threats. Sometimes in the underground are also proposed very dangerous exploit kit containing code for exploit of zero-day vulnerabilities, in these case, there is no other defense that intercepts as soon as possible to malicious code to reverse it.

Anyway, it is strongly suggested to keep always updated the software we regularly use, including browser plug-ins limiting their use to a minimum, completely disable components that are not frequently used.

Create damage infecting millions of machines has never been so easy and cheap!

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Whitehole, hacking)  

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/12249/cyber-crime/whitehole-exploit-kit-in-the-wild.html