New Findings Challenge Attribution in Denmark's Energy Sector Cyberattacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-9054 | Pre-Authentication OS Command Injection in Zyxel NAS Devices CVE-2020-9054 is a pre-authentication OS command injection flaw (CWE-78) in multiple Zyxel network-attached storage (NAS) devices. A remote, unauthenticated attacker can send crafted input to the devices' web interface to inject and execute arbitrary OS commands without logging in, resulting in remote code execution on the NAS. Successful exploitation gives the attacker control of the device, which can be used to access, alter or destroy stored data and to pivot into the network the NAS is attached to. Organizations and users running affected Zyxel NAS models are at risk, especially where the management web interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, confirming exploitation in the wild; EPSS assigns a 100% probability of exploitation within 30 days, while no public proof-of-concept is known and any ransomware use is unconfirmed. Do: Apply the firmware updates specified in Zyxel's advisory, per CISA's required action, prioritizing any NAS whose web interface is exposed to the internet. Until patched, restrict the NAS management interface to trusted networks or VPN access and do not expose the admin UI directly to the internet. Because exploitation is confirmed in the wild, check affected devices for indicators of compromise, such as unexpected accounts, scheduled jobs, or outbound connections. | 9.8 | 100% | KEV PoC |
| moderateplausibly tens of thousands of affected devices installed worldwide, with only a low-thousands subset directly internet-exposed | |
| CVE-2022-30525 | OS Command Injection in Zyxel Firewalls Enables Remote Command Execution CVE-2022-30525 is an OS command injection vulnerability (CWE-78) in the CGI program of certain Zyxel firewall firmware versions. By sending crafted requests to the vulnerable CGI program, an attacker can modify specific files on the appliance and inject and execute operating system commands. Successful exploitation yields command execution on the firewall itself, allowing an attacker to alter device files/configuration and potentially pivot into the protected network — the class of edge-device flaw commonly targeted by ransomware operators (ransomware use in this case is not yet confirmed). Organizations running affected Zyxel firewalls, particularly those with management interfaces reachable from the internet, are at risk. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-05-16, EPSS assigns a 99.9% 30-day exploitation probability (100th percentile), and no public PoC is catalogued yet. Do: Apply Zyxel's fixed firmware per the vendor's instructions immediately, as required by the CISA KEV listing. Until patched, restrict HTTP/HTTPS management access to the firewall to trusted source addresses only. Because exploitation is confirmed in the wild, prioritize internet-facing Zyxel firewalls and review devices for indicators of compromise such as modified configurations or unexpected administrative changes. | 9.8 | 100% | KEV PoC ×3 |
| large≈ tens of thousands of internet-exposed Zyxel firewall management interfaces (order of magnitude 10k–100k devices) | |
| CVE-2023-27881 | A user could use the “Upload Resource” functionality to upload files to any location on the disk. A user could use the “Upload Resource” functionality to upload files to any location on the disk. NVD description · AI analysis pending | 9.9 | <1% |
| — | ||
| CVE-2023-28771 | Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies. Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use. | 9.8 | 99% | KEV PoC |
| largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate |
Full article429 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 14, 2024Cyber Attack / Vulnerability
The cyber attacks targeting the energy sector in Denmark last year may not have had the involvement of the Russia-linked Sandworm hacking group, new findings from Forescout show.
The intrusions, which targeted around 22 Danish energy organizations in May 2023, occurred in two distinct waves, one which exploited a security flaw in Zyxel firewall (CVE-2023-28771) and a follow-on activity cluster that saw the attackers deploy Mirai botnet variants on infected hosts via an as-yet-unknown initial access vector.
The first wave took place on May 11, while the second wave lasted from May 22 to 31, 2023. In one such attack detected on May 24, it was observed that the compromised system was communicating with IP addresses (217.57.80[.]18 and 70.62.153[.]174) that were previously used as command-and-control (C2) for the now-dismantled Cyclops Blink botnet.
Forescout’s closer examination of the attack campaign, however, has revealed that not only were the two waves unrelated, but also unlikely the work of the state-sponsored group owing to the fact the second wave was part of a broader mass exploitation campaign against unpatched Zyxel firewalls. It’s currently not known who is behind the twin sets of attacks.
“The campaign described as the ‘second wave’ of attacks on Denmark, started before and continued after [the 10-day time period], targeting firewalls indiscriminately in a very similar manner, only changing staging servers periodically,” the company said in a report aptly titled “Clearing the Fog of War.”
There is evidence to suggest that the attacks may have started as early as February 16 using other known flaws Zyxel devices (CVE-2020-9054 and CVE-2022-30525) alongside CVE-2023-28771, and persisted as late as October 2023, with the activity singling out various entities across Europe and the U.S.
“This is further evidence that exploitation of CVE-2023-27881, rather than being limited to Danish critical infrastructure, is ongoing and targeting exposed devices, some of which just happen to be Zyxel firewalls safeguarding critical infrastructure organizations,” Forescout added.
When reached for comment, SektorCERT pointed to its November 2023 report, in which it noted that "whether Sandworm was involved in the attack cannot be said with certainty. Individual indicators of this have been observed, but we have no opportunity to neither confirm nor deny it."
The non-profit also reiterated that cyber attacks are difficult to attribute to a specific threat actor and that it doesn't have any concrete evidence to accuse Russia of being involved in the attack.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/01/new-findings-challenge-attribution-in.html