ZeroHour
Security Affairspublished ()ingested @securityaffairs

Lebanese Cedar APT group broke into telco and ISPs worldwide

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2012-3152
Remote vulnerability in Oracle Fusion Middleware Reports Developer exploited in the wild

CVE-2012-3152 is an unspecified remote vulnerability in the Reports Developer component of Oracle Fusion Middleware that allows attackers to affect the confidentiality and integrity of affected systems. An attacker who can reach the reporting service over the network can send crafted requests to read sensitive data or tamper with information handled by that component; the precise trigger mechanism and authentication requirements are not detailed in available data. Any organization running Oracle Fusion Middleware with the Reports Developer component deployed is potentially affected, with telecoms, ISPs, and hosting providers among the environments observed to be targeted. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and is associated with the Lebanese Cedar APT's intrusions into telecoms, ISPs, and hosting firms worldwide. EPSS rates the 30-day exploitation probability at 98.8% (100th percentile), making prompt patching a high priority.

Do: Apply vendor-supplied updates to Oracle Fusion Middleware per CISA's required action (apply updates per vendor instructions). Inventory your environment to determine whether the Reports Developer/Oracle Reports component is deployed and whether it is internet-exposed, and restrict network access to it where patching is not immediately possible. Because the flaw has been used in the wild by the Lebanese Cedar APT, especially in telecom, ISP, and hosting environments, also hunt for signs of compromise such as unexpected processes, webshells, or unusual outbound connections.

99% KEV
  • Oracle Fusion Middleware (Reports Developer component)
largetens of thousands of deployments worldwide (enterprise middleware installed base); exact count unknown
CVE-2019-11581
Unauthenticated SSTI RCE in Atlassian Jira Server and Data Center

Atlassian Jira Server and Data Center contain a server-side template injection (CWE-74) in the ContactAdministrators and SendBulkMail actions, rated critical at CVSS 9.8. The flaw is triggered by sending crafted, template-syntax input to these mail-related actions over the network; because the vulnerability requires no authentication or user interaction per the CVSS vector, any attacker who can reach the Jira web interface can trigger it. Successful exploitation yields unauthenticated remote code execution on the server hosting Jira, with high impact on confidentiality, integrity, and availability. Organizations running any Jira Server or Data Center release in the 4.4–7.6, 7.7–7.13, 8.0, 8.1, or 8.2 lines prior to the listed fixed versions are affected, and the exposure is concentrated among instances reachable from the internet. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 with a required action to apply vendor updates, and EPSS places it in the 100th percentile (~84.6% probability of exploitation within 30 days).

Do: Apply the vendor updates per Atlassian/CISA instructions — upgrade to Jira 7.6.14, 7.13.5, 8.0.3, 8.1.2, or 8.2.3 (or later) as applicable, since this is a KEV item with a required patching action. As an interim mitigation, disable the 'Allow users to contact administrators' option in Jira's General Configuration to close the ContactAdministrators path and restrict SendBulkMail access, and limit exposure of the Jira web interface to the internet. Review access logs for requests hitting ContactAdministrators/SendBulkMail endpoints containing template injection payloads and hunt for signs of post-exploitation code execution on affected servers.

9.885% KEV
  • Atlassian Jira Server All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3
  • Atlassian Jira Data Center All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3
largetens of thousands of internet-exposed Jira Server/Data Center instances
CVE-2019-3396
Server-Side Template Injection RCE in Atlassian Confluence Server and Data Center

Atlassian Confluence Server and Data Center contain a server-side template injection flaw (CWE-22) in which attacker-supplied template content is processed by the server, enabling path traversal and ultimately remote code execution. An attacker triggers it by submitting crafted template syntax in a request to a vulnerable instance, and can run arbitrary commands or code on the underlying server. Successful compromise could allow data theft, deployment of webshells, or ransomware; CISA notes known ransomware use of this vulnerability. Organizations running self-hosted Confluence Server or Data Center are affected, particularly instances exposed to the internet. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and EPSS assigns a 99.9% probability of exploitation, placing it in the top percentile.

Do: Apply updates per vendor instructions by upgrading Confluence Server and Data Center to Atlassian's fixed releases, and prioritize internet-facing instances. Until patched, restrict network exposure of Confluence and monitor for signs of compromise such as webshells, unexpected processes, or ransomware activity, since ransomware operators are known to exploit this flaw.

9.8100% KEV ransomware PoC ×4
  • Atlassian Confluence Server and Data Center
largetens of thousands of internet-exposed Confluence Server/Data Center instances, with an installed base plausibly in the hundreds of thousands of servers across…
Full article490 words · extracted from securityaffairs.com · click to collapse

Clearsky researchers linked the Lebanese Cedar APT group to a cyber espionage campaign that targeted companies around the world.

Clearsky researchers linked the Lebanese Cedar group (aka Volatile Cedar) to a cyber espionage campaign that targeted companies around the world.

The APT group has been active since 2012, experts linked the group to the Hezbollah militant group.

The activities of the group were first spotted by Check-Point and Kaspersky labs in 2015.

ClearSky experts linked the Lebanese Cedar group to intrusions at telco companies, internet service providers, hosting providers, and managed hosting and applications companies.

The attacks began in early 2020 and threat actors breached internet service providers in the US, the UK, Egypt, Israel, Lebanon, Jordan, the Palestinian Authority, Saudi Arabia, and the UAE.

“Based on a modified JSP file browser with a unique string that the adversary used to deploy ‘Explosive RAT’ into the victims’ network, we found some 250 servers that were apparently breached by Lebanese Cedar” reads the report published by the ClearSky. “We assess that there are many more companies that have been hacked and that valuable information was stolen from these companies over periods of months and years.”

Threat actors focus on intelligence gathering and the theft of sensitive data from targeted companies.

The Lebanese Cedar hackers used open-source hacking tools to scan the internet for unpatched Atlassian and Oracle servers, then they used exploits to gain access to the server and deploy a web shell to gain a foothold in the target system.

“The group’s main attack vector is intrusion into Oracle and Atlassian WEB servers. We assess that the intrusion into these systems was done by exploiting known vulnerabilities in systems that were not patched and detecting loopholes using open-source hacking tools.” continues the report.

The attackers made regular use of critical 1-day vulnerabilities based on the vulnerable versions of the services in the compromised servers. The 1-day vulnerabilities exploited by the hackers are:

• Atlassian Confluence Server (CVE-2019-3396)
• Atlassian Jira Server or Data Center (CVE-2019-11581)
• Oracle 10g 11.1.2.0 (CVE-2012-3152)

Lebanese Cedar APT

Once breached the targeted systems, the hackers used multiple web shells, such as ASPXSpy, Caterpillar 2, Mamad Warning, to conduct multiple tasks. They also used a modified version of the open-source tool named JSP file browser to get web-based access and manipulate files stored on a remote server.

Once inside the target networks, the attackers deployed the Explosive remote access trojan (RAT), a malware exclusively used by the Lebanese Cedar group in past attacks.

The experts identified 254 infected servers worldwide, “135 of them shared the same hash as the files we identified in victim’ network during our investigation.”

Additional details about the campaigns are included in the analysis published by ClearSky, including Indicators of Compromise.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, APT)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/113975/apt/lebanese-cedar-apt-attacks.html