ZeroHour
Security Affairspublished ()ingested @securityaffairs

TAC-040 group used previously undetected Ljl Backdoor

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22965
Unauthenticated RCE in VMware Spring Framework (Spring4Shell) - JDK 9+ Tomcat WARs

CVE-2022-22965 ('Spring4Shell') is a critical (CVSS 9.8) remote code execution flaw in VMware's Spring Framework, caused by insecure data binding that lets unauthenticated attackers overwrite internal class and module properties through crafted request parameters (CWE-94, code injection). It affects Spring MVC and Spring WebFlux applications running on JDK 9 or later; the demonstrated exploit path requires a Tomcat WAR deployment, while applications packaged as Spring Boot executable jars are not exploitable that way, though the underlying issue may be reachable via other routes. A successful attack yields full remote code execution with the privileges of the application server, with no authentication or user interaction required. VMware Spring Framework 5.3.0-5.3.17 and 5.2.0-5.2.19 (plus older releases) are affected, and the flaw also impacts bundled products from Cisco, Oracle, Siemens and Veritas, including multiple Oracle Communications Cloud Native Core components. It is being actively exploited in the wild: added to CISA's KEV on 2022-04-04, EPSS puts 30-day exploitation probability at 99.6% (100th percentile), a public PoC is available, and mass scanning of vulnerable servers has been observed.

Do: Upgrade Spring Framework to 5.3.18, 5.2.20 or later (or apply vendor-supplied fixes for bundled products, e.g., via Oracle's patch release and Cisco's advisory), prioritizing internet-facing Tomcat WAR deployments on JDK 9+; this is a CISA KEV entry, so treat patching as urgent. If patching must wait, mitigate by running on JDK 8, deploying as a Spring Boot executable jar rather than a WAR on Tomcat, and applying the vendor-documented workaround that disallows 'class.*', 'Class.*' and 'module.*' fields in data binding. Inventory exposed Tomcat/Spring services and hunt for signs of exploitation given confirmed in-the-wild use.

9.8100% KEV PoC
  • vmware Spring Framework 5.3.0-5.3.17 and 5.2.0-5.2.19, plus older/unsupported releases; exploitable via Spring MVC/WebFlux data binding on JDK 9+ (demonstrated path: Tomcat WAR deploym
  • Cisco CX Cloud Agent
  • Oracle Communications Cloud Native Core Automated Test Suite
  • +9 more
massmass - on the order of 1M+ Spring-based Java deployments overall, with at least ~100,000 internet-exposed Tomcat servers on JDK 9+ plausibly meeting the…
CVE-2022-26134
Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center

Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target.

Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections.

9.8100% KEV ransomware PoC ×2
  • Atlassian Confluence Server
  • Atlassian Confluence Data Center
largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022…
Full article546 words · extracted from securityaffairs.com · click to collapse

A threat actor, tracked as TAC-040, exploited Atlassian Confluence flaw CVE-2022-26134 to deploy previously undetected Ljl Backdoor.

Cybersecurity firm Deepwatch reported that a threat actor, tracked as TAC-040, has likely exploited the CVE-2022-26134 flaw in Atlassian Confluence servers to deploy a previously undetected backdoor dubbed Ljl Backdoor. The attackers exploited the flaw in an attack against an unnamed organization in the research and technical services sector.

The attack took place in May and lasted seven days, the analysis of the network logs suggests TAC-040 exfiltrated around 700MBs of data from the victim system.

“ATI’s thorough analysis determined that the attack occurred during the end of May over a seven day period. TAC-040 highly likely exploited a vulnerability in an Atlassian Confluence server. The evidence indicates that the threat actor executed malicious commands with a parent process of tomcat9.exe in Atlassian’s Confluence directory.” reads the analysis published by Deepwatch.

Experts also speculated attackers could have alternatively exploited the Spring4Shell vulnerability (CVE-2022-22965) to gain initial access to the Confluence web application.

After the initial compromise, the attackers ran multiple commands to enumerate the local system, network, and Active Directory environment.

The researchers discovered the presence of an XMRig crypto-miner on the compromised system. 

“The threat actor likely utilized a memory-based webshell or opted to run commands directly through the
exploit, as no dropper commands or forensic records of an on-disk webshell were recovered. Several opensource reports detail similar defense/detection avoidance techniques concerning the exploitation of CVE2022-26134, but technical details on these techniques are sparse.” continues the report.

The Deepwatch Threat Intel Team confirmed that the ljl Backdoor is a never-before-seen and persistent backdoor which implements the following capabilities:

  • Reverse Proxy.
  • Query whether the victim is active or idle.
  • Exfiltrate files/directories.
  • Load arbitrary and remotely downloaded .NET assemblies as “plugins.”
  • Get user accounts.
  • Get the foreground window and window text.
  • Get victim system information, such as CPU name, GPU name, hardware id, bios manufacturer,
  • Mainboard name, total physical memory, LAN IP address, and mac address.
  • Get victim geographic information, such as ASN, ISP, country name, country code, region name, region code, city, postal code, continent name, continent code, latitude, longitude, metro code, time zone, and date and time.

Once TAC-040 achieved persistence on the target systems, it employed various publicly available open-source tools cloned from GitHub including:

  • Open-source tools cloned from GitHub:
  • NetRipper
  • PowerSploit
  • Invoke-Vnc
  • CME-PowerShell-Scripts
  • CrackMapExec: attack framework with multiple tools
  • Invoke-Obfuscation
  • SessionGopher
  • mimipenguin
  • mimikittenz
  • RID_Hijacking
  • RandomPS-Scripts

At this time, it is unclear who is behind the TAC-040, experts only speculate that it operates to gather intelligence despite the discovery of XMRig crypto miner on the system suggests it could be financially motivated.

The Monero address managed by the group threat actors has netted at least 652 XMR (more than $100K).

“Regarding this activity cluster, there are still a few unanswered questions. First and foremost, we cannot be certain of TAC040’s intentions and goals due to visibility gaps. However, it is likely that TAC-040’s goal was espionage-related. However, we can not completely rule out that they were financially motivated. The Threat Intel Team needs additional evidence to build confidence in this hypothesis.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Ljl Backdoor)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/134033/hacking/tac-040-ljl-backdoor.html