Romania-linked ‘Rubycarp’ hackers look for cryptomining, phishing DDoS opportunities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-3129 | Unauthenticated RCE in Laravel Ignition error-page package (facade/ignition) Laravel Ignition, the default error-page package bundled with Laravel applications, uses file_get_contents() and file_put_contents() insecurely in its solution-execution feature, allowing unauthenticated remote attackers to read and write arbitrary files on the server. The flaw is triggered by sending a crafted, unauthenticated HTTP request to Ignition's execute-solution endpoint, which is reachable whenever the application runs with debug mode enabled. Attackers can chain the arbitrary file write to execute arbitrary code in the context of the web application, leading to server compromise and, per CISA, ransomware deployment. Any internet-facing Laravel application running a vulnerable version of the Ignition package with debug mode enabled is affected. The vulnerability is known to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-18 with ransomware use confirmed, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile). Do: Upgrade facade/ignition to 2.5.2 or later on all Laravel applications, or update to a current Laravel release that bundles the fixed package. Ensure production environments run with debug mode disabled and block or restrict the /_ignition/execute-solution endpoint from untrusted access as an interim mitigation. Given confirmed ransomware use, hunt for signs of compromise such as modified environment files, unexpected scheduled tasks, or webshells, and apply the CISA-required mitigations or discontinue use of the product if patching is not possible. | 9.8 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-facing Laravel apps with debug mode enabled, out of an installed base of hundreds of thousands of Laravel sites |
Full article565 words · extracted from therecord.media · click to collapse
A suspected Romanian cybercrime group remains active after more than a decade of operation and currently specializes in cryptomining, phishing campaigns and DDoS attacks, according to cybersecurity researchers. The group, labeled Rubycarp, may be related to another alleged Romanian threat actor with similar activities called Outlaw, said analysts from the Sysdig Threat Research Team. Overlaps with other groups are possible, according to the report. In addition to financial operations, the groups are also involved in the development and sale of cyberweapons, "which isn’t very common,” the researchers said. “Many of these threat actors are fighting it out over the same target space, making it difficult to attribute attacks,” Sysdig said. The researchers said Rubycarp mostly targets known vulnerabilities and conducts brute force attacks, where an attacker tries to gain access to a victim’s system by trying all possible combinations of usernames or passwords until they find the correct one. What makes the group dangerous, according to researchers, are its post-exploitation tools and “the breadth of its capabilities.” Rubycarp’s infrastructure includes many internet domains that are regularly rotated and often replaced and emptied of malicious content as soon as any potential research activity is detected, according to the report. The group’s latest campaigns include targeting and exploiting the Laravel framework, which developers use to build web applications, via a vulnerability tracked as CVE-2021-3129. That kind of activity was associated with a different operation, Androxgh0st, that was the subject of an alert by the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) earlier this year. The analysts also recently discovered evidence of attacks on WordPress sites, using previously available dumps of compromised usernames and passwords. Rubycarp currently operates a botnet, which has compromised over 600 servers. Once hackers obtain access to the targeted network, they infect it with a Perl Shellbot backdoor and connect the victim’s server to a command-and-control server so it can join the larger botnet. For illicit cryptomining — when attackers quietly use an infected system to mine for cryptocurrency — Rubycarp uses several types of miners and and sends the proceeds quietly to various digital wallets. Some miners, such as NanoMiner and XMrig, are well-known, while others, such as the one researchers named C3Bash, are custom-made. During its phishing operations, Rubycarp steals financially valuable assets such as credit card numbers. The hackers are likely using this money to fund their infrastructure or possibly to sell on darknet forums, researchers said. In a December 2023 hack, the group targeted Danish users and impersonated the Danish logistics company Bring. Researchers have identified 36 text files containing hundreds of Danish email addresses that were potentially targeted with phishing. Other Rubycarp phishing targets include European entities such as Swish Bank and Nets Bank, Sysdig said. Another interesting aspect of the group, according to the researchers, is that Rubycarp helps mentor people who are new to the cybercrime scene. “This does provide some financial benefits to the group since it can then sell them the toolset that it has made,” researchers said.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/romania-linked-rubycarp-cryptomining-phishing