New Capoae Malware Infiltrates WordPress Sites and Installs Backdoored Plugin
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-20062 | Unauthenticated Remote Code Execution in ThinkPHP-based noneCms 1.3 NoneCms V1.3, an open-source Chinese CMS built on the ThinkPHP 5.0.x framework, is vulnerable to unauthenticated remote code execution through the framework's URL dispatcher in thinkphp/library/think/App.php. Because the framework's 's' routing parameter can invoke arbitrary framework classes and methods, an attacker can pass a crafted 'filter' value (e.g., s=index/\think\Request/input&filter=phpinfo&data=1) that is applied to the 'data' argument as a callable, executing attacker-chosen PHP functions or code. Successful exploitation gives full code execution on the web server under the application's privileges, enabling web shells, botnet implants, and ransomware staging without any credentials or user interaction. Any internet-facing deployment of noneCms V1.3 — and, more broadly, applications running the affected ThinkPHP 5.0.x framework (the public PoC references 5.0.23) — is exposed. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), EPSS assigns a 99.5% probability of exploitation within 30 days, and headlines note botnets such as Enemybot and Chinese threat actors chaining ThinkPHP RCEs against CMS servers. Do: Apply updates per vendor instructions: upgrade noneCms to the latest release and update the bundled ThinkPHP 5.0.x framework to a patched build. Inspect web server and WAF logs for requests using the s=index/\think\Request/input&filter=... pattern and other ThinkPHP route-invocation payloads, and hunt for web shells or post-exploitation artifacts. Until patched, block or strictly validate the 's' and 'filter' query parameters at a WAF/reverse proxy and limit internet exposure of the application. | 9.8 | 100% | KEV PoC ×2 |
| nicheunknown exact count; plausibly on the order of hundreds to a few thousand self-hosted sites, with at least some internet-exposed instances | |
| CVE-2019-1003029 | Sandbox Bypass Enables RCE in Jenkins Script Security Plugin 1.53 and Earlier CVE-2019-1003029 is a sandbox bypass in the Jenkins Script Security Plugin (versions 1.53 and earlier) in GroovySandbox.java and SecureGroovyScript.java, allowing Groovy scripts that are supposed to be restricted by the sandbox to escape its protections. A remote attacker who has Overall/Read permission on a Jenkins instance can trigger the flaw and execute arbitrary code in the Jenkins master JVM, gaining high-impact access to the controller and, per the CVSS scope change, to resources it manages. Any Jenkins deployment running the affected plugin versions is exposed, including the Jenkins components bundled with Red Hat OpenShift Container Platform. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-25, and EPSS estimates a 73.9% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Upgrade the Script Security Plugin to version 1.54 or later (the first release after the affected 1.53), and apply the corresponding Jenkins updates in Red Hat OpenShift Container Platform per Red Hat's instructions. As interim mitigation, restrict Overall/Read access to untrusted users and limit who can submit or define sandboxed Groovy scripts. Confirm the update on any Jenkins instance in your environment, prioritizing internet-exposed controllers, since the flaw is on CISA's KEV list. | 9.9 | 74% | KEV |
| largetens of thousands of internet-exposed Jenkins controllers; hundreds of thousands of plugin installations overall | |
| CVE-2019-1003030 | Sandbox Bypass Enables RCE in Jenkins Pipeline: Groovy Plugin A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier, in the CpsGroovyShell.java component, allowing Groovy scripts to escape the plugin's intended script sandbox. It is triggered when a Jenkins controller executes a pipeline script that an attacker can control — for example, a low-privileged authenticated user with permission to define or edit a job's pipeline definition. Successful exploitation yields arbitrary code execution in the Jenkins master JVM, giving the attacker full control of the controller and, per the CVSS scope change, impact that extends to the wider Jenkins environment including connected build agents. Affected deployments include Jenkins controllers running the vulnerable plugin — CISA's KEV entry names the Matrix Project Plugin — as well as Jenkins distributed through Red Hat OpenShift Container Platform. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), confirming in-the-wild exploitation, and EPSS of ~96.9% (100th percentile) indicates an extremely high probability of near-term exploitation. Do: Apply updates per vendor instructions (the CISA KEV required action), upgrading the Pipeline: Groovy Plugin to a version later than 2.63 and deploying updated Jenkins images where applicable (including Red Hat OpenShift Container Platform). Restrict which users can create or edit pipeline scripts, and audit job configurations for attacker-controlled or recently modified pipeline definitions. Because the flaw is KEV-listed and actively exploited, check controllers for signs of compromise, such as unexpected processes or build activity in the master JVM. | 9.9 | 97% | KEV PoC |
| largetens of thousands of internet-exposed Jenkins controllers, out of hundreds of thousands of total installations running the bundled Pipeline: Groovy plugin | |
| CVE-2020-14882 | Remote Code Execution in Oracle WebLogic Server CVE-2020-14882 is a remote code execution vulnerability in Oracle WebLogic Server; its relationship to CVE-2020-14750 (a WebLogic administration console flaw) indicates it is reachable over the network, likely without authentication. An attacker who can reach a vulnerable WebLogic instance can trigger the flaw and execute arbitrary code in the context of the server. Successful exploitation can yield full control of the affected host, enabling data theft, lateral movement, and potentially ransomware deployment (ransomware use is currently unknown). Any organization running Oracle WebLogic Server is affected; WebLogic is widely deployed as a Java application server in large enterprises and government networks, and instances are frequently exposed to the internet. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a maximum EPSS score of 100%, indicating confirmed in-the-wild exploitation. Do: Apply Oracle's WebLogic Server updates per vendor instructions immediately, as this is a required action under the CISA KEV listing. Inventory environments for WebLogic deployments (commonly listening on ports 7001/7002), prioritize patching internet-facing instances, and restrict or firewall access to the WebLogic administration console until patched. Review access logs for signs of exploitation, and treat unpatched, externally reachable WebLogic servers as high risk given the 100% EPSS score and confirmed in-the-wild exploitation. | 9.8 | 100% | KEV PoC ×3 |
| large≈50,000–100,000 internet-exposed WebLogic systems (public internet-wide scan counts around 2020); many more deployed internally in enterprise networks |
Full article408 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 21, 2021
A recently discovered wave of malware attacks has been spotted using a variety of tactics to enslave susceptible machines with easy-to-guess administrative credentials to co-opt them into a network with the goal of illegally mining cryptocurrency.
"The malware's primary tactic is to spread by taking advantage of vulnerable systems and weak administrative credentials. Once they've been infected, these systems are then used to mine cryptocurrency," Akamai security researcher Larry Cashdollar said in a write-up published last week.
The PHP malware — codenamed "Capoae" (short for "Сканирование," the Russian word for "Scanning") — is said to be delivered to the hosts via a backdoored addition to a WordPress plugin called "download-monitor," which gets installed after successfully brute-forcing WordPress admin credentials. The attacks also involve the deployment of a Golang binary with decryption functionality, with the obfuscated payloads retrieved by leveraging the trojanized plugin to make a GET request from an actor-controlled domain.
Also included is a feature to decrypted and execute additional payloads, while the Golang binary takes advantage of exploits for multiple remote code execution flaws in Oracle WebLogic Server (CVE-2020-14882), NoneCms (CVE-2018-20062), and Jenkins (CVE-2019-1003029 and CVE-2019-1003030) to brute force its way into systems running SSH and ultimately launch the XMRig mining software.
What's more, the attack chain stands out for its persistence tricks, which includes choosing a legitimate-looking system path on the disk where system binaries are likely to be found as well as generating a random six-character filename that's then subsequently used to copy itself into the new location on the system before deleting the malware upon execution.
"The Capoae campaign's use of multiple vulnerabilities and tactics highlights just how intent these operators are on getting a foothold on as many machines as possible," Cashdollar said. "The good news is, the same techniques we recommend for most organizations to keep systems and networks secure still apply here."
"Don't use weak or default credentials for servers or deployed applications," Cashdollar added. "Ensure you're keeping those deployed applications up to date with the latest security patches and check in on them from time to time. Keeping an eye out for higher than normal system resource consumption, odd/unexpected running processes, suspicious artifacts and suspicious access log entries, etc., will help you potentially identify compromised machines."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/09/new-capoae-malware-infiltrates.html