ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

New APT Group XDSpy Targets Belarus and Russian

highThreat actorimportance 60CVE-2020-0968

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0968
Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CVE-2020-0968 is a memory corruption vulnerability (CWE-787, out-of-bounds write) in Microsoft Internet Explorer's scripting engine, where the engine mishandles objects in memory in a way that can be leveraged for remote code execution. It is typically triggered when a user views a specially crafted webpage in Internet Explorer or in an application that hosts the IE rendering components; successful exploitation gives the attacker code execution in the context of the current user. Any Windows environment where Internet Explorer and its scripting engine are present is affected, which spans most enterprise and consumer Windows estates. Exploitation is confirmed in the wild: the flaw is listed in CISA's KEV catalog (added 2021-11-03) with known ransomware use, and EPSS assigns a 30.7% probability of exploitation within 30 days (98th percentile). No public proof-of-concept is known, indicating attackers are not dependent on public PoC code.

Do: Apply the Microsoft security updates that fix CVE-2020-0968 (released in the March 2020 Patch Tuesday batch) across all Windows systems with Internet Explorer, prioritizing user workstations and remote desktop/terminal servers per CISA's required action to apply vendor updates. Since the exploit path runs through web content, verify whether legacy web apps or desktop applications still invoke the IE engine and reduce reliance on IE as a default renderer. Confirm remediation by checking for the corresponding cumulative Windows/IE update rather than relying on a single KB lookup.

7.531% KEV ransomware
  • Microsoft Internet Explorer
masshundreds of millions of Windows endpoints (IE is a built-in OS component)
Full article322 words · extracted from infosecurity-magazine.com · click to collapse

Security researchers have discovered a new APT group that has been stealing sensitive information from Eastern European governments and businesses for over nine years.

Dubbed “XDSpy,” the group shares no similarities of malicious code, network infrastructure or regional targets with any known APT outfit, according to ESET.

It operates largely in a GMT+2 or +3 time zone, the same as its targets, and operatives work only Monday-Friday.

It focuses exclusively on spearphishing to compromise targets, although emails could contain malicious RAR or ZIP attachments or links.

Interestingly, the group’s technical proficiency seems to vary, according to ESET.

On the one hand it has used the same malware architecture for nine years, with the main XDDown malware component downloaded to a victim computer from a C&C server. This installs additional plugins to gather basic info, crawl the C drive, exfiltrate local files, gather browser passwords and more.

However, on the other hand, it was recently spotted exploiting CVE-2020-0968. “At the time it was exploited by XDSpy, no proof-of-concept and very little information about this specific vulnerability was available online,” explained ESET. “We think that XDSpy either bought this exploit from a broker or developed a 1-day exploit themselves by looking at previous exploits for inspiration.”

The security vendor refused to speculate on who could be behind XDSpy. It is most interested in stealing information from government targets in Eastern Europe and the Balkans, including a February campaign against Belarussian institutions in February and Russian-speaking targets in September this year.

Moldova, Serbia, Russia and Ukraine have also come under attack since 2011.

“The group has attracted very little public attention so far, with the exception of an advisory from the Belarusian CERT in February 2020,” said Mathieu Faou, ESET researcher. ““Since we did not find any code similarities with other malware families, and we did not observe any overlap in the network infrastructure, we conclude that XDSpy is a previously undocumented group.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apt-group-xdspy-targets-belarus/