Chemical sector targeted by North Korea
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-0609 | Use-After-Free in Google Chromium Animation Component (Chrome, Edge, Opera) CVE-2022-0609 is a use-after-free vulnerability (CWE-416) in the Animation component of Google's Chromium browser engine that can corrupt heap memory. A remote attacker triggers it by persuading a user to load a crafted HTML page (for example via a malicious or compromised website), with no authentication required beyond opening the page. Successful exploitation can lead to heap corruption and potentially arbitrary code execution in the context of the affected browser. Any browser or application built on Chromium is potentially affected, including Google Chrome, Microsoft Edge, and Opera. The flaw is actively exploited: CISA added it to the KEV catalog on 2022-02-15 with a required action to apply vendor updates, Google confirmed in-the-wild exploitation at disclosure, no public PoC is known, ransomware use is unknown, and EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile). Do: Apply the vendor updates immediately: Google fixed this in Chrome 98.0.4758.102 (February 2022), so update Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers or Chromium-embedded applications to releases containing that Chromium fix, and inventory browser versions across your fleet to catch machines lagging on the update. Until fully patched, treat unsolicited links to web pages as an exploitation vector given confirmed in-the-wild use, and comply with CISA's KEV required action to apply updates per vendor instructions. | 8.8 | 23% | KEV |
| mass≈3 billion+ browser users (Chrome alone has an installed base exceeding 3 billion; Chromium also underlies Edge, Opera, and other Chromium-based browsers) |
Full article518 words · extracted from therecord.media · click to collapse
An espionage campaign from North Korea’s Lazarus Group that was previously uncovered by Google researchers has now turned its attention to chemical sector organizations in South Korea, according to a report from cybersecurity company Symantec. Google released a report in March identifying two North Korean government hacking campaigns that exploited Google Chrome 0-day CVE-2022-0609. One of them – Operation Dream Job – had been running since at least August 2020 and most recently targeted over 250 individuals working for 10 different news media, domain registrars, web hosting providers and software vendors. The campaign saw hackers send emails claiming to come from recruiters at Disney, Google and Oracle with fake potential job opportunities. The emails contained links spoofing legitimate job hunting websites like Indeed and ZipRecruiter, according to Google Threat Analysis Group’s Adam Weidemann. The Threat Hunter Team at Symantec said Operation Dream Job has now been expanded to target chemical and IT sector organizations in South Korea. They were able to tie the activity to Operation Dream Job based on file hashes, file names, and tools that were observed in previous Dream Job campaigns. “The Lazarus group is likely targeting organizations in the chemical sector to obtain intellectual property to further North Korea’s own pursuits in this area,” Symantec explained. “The group’s continuation of Operation Dream Job, as witnessed by Symantec and others, suggests that the operation is sufficiently successful.” The company noted that the typical attack starts with a malicious link in an email and kicks off a chain of events that eventually allows the hackers to get into a system and move laterally within a network using Windows Management Instrumentation (WMI). “In some instances, the attackers were spotted dumping credentials from the registry, installing a BAT file in a likely effort to gain persistence, and using a scheduled task configured to run as a specific user. The attackers were also observed deploying post-compromise tools, including a tool used to take screenshots of web pages viewed on the compromised machine at set intervals (SiteShoter),” Symantec said. “They were also seen using an IP logging tool (IP Logger), a protocol used to turn computers on remotely (WakeOnLAN), a file and directory copier (FastCopy), and the File Transfer Protocol (FTP) executed under the MagicLine process.” They provided a detailed case study of one intrusion that ran from January 17 to January 20. On Thursday, the US Treasury’s Office of Foreign Assets Control (OFAC) attributed one of the largest decentralized finance (DeFi) hacks ever to the Lazarus Group and sanctioned the group. Chainalysis, a company that tracks illegal blockchain transactions, said in a January report that hackers working for the North Korean government and the Lazarus Group are believed to have stolen almost $400 million worth of cryptocurrency from seven hacked companies throughout 2021.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chemical-sector-targeted-by-north-korea-linked-hacking-group-researchers-say