ZeroHour
The Recordpublished ()ingested

German government warns of APT27 activity targeting local companies

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26855
+3 in the same advisory: …27065 …26857 …26858
Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon)

CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing.

Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use.

9.1
group max
100% KEV ransomware PoC ×4
  • Microsoft Exchange Server On-premises Exchange Server editions supported in the vendor's March 2021 guidance (Exchange Server 2013, 2016, and 2019), prior to the March 2021 security upda
masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers
CVE-2021-40539
Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus

CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities.

Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances.

9.899% KEV ransomware PoC
  • Zoho (zohocorp) ManageEngine ADSelfService Plus 6113 and prior
largetens of thousands of enterprise server installations (unknown precise count)
Full article442 words · extracted from therecord.media · click to collapse

The German government said on Tuesday that a Chinese cyberespionage group known as APT27 has repeatedly attacked German companies over the past few months using vulnerabilities in software like Microsoft Exchange and Zoho SelfService.

The attacks, which have been taking place since at least March 2021, have aimed to install a version of the HyperBro malware inside corporate networks for the purpose of intelligence collection from infected hosts, the Federal Office for the Protection of the Constitution (BfV) said in a press release.

"It cannot be ruled out that the actors, in addition to stealing business secrets and intellectual property, are also trying to infiltrate the networks of (corporate) customers or service providers (supply chain attack)," the BfV added.

APT27 leveraged Microsoft Exchange and Zoho bugs

According to the agency, APT27, also known as Emissary Panda, has used the following exploits as a way to get a foothold inside companies that failed to patch their internet-exposed servers:

All of the above are well-known vulnerabilities previously exploited by other Chinese hacking groups. For example, the four Exchange bugs, also known as ProxyLogon, were also used by a group known as Hafnium, according to Microsoft.

The Zoho vulnerability is also the exact same one that was used to breach the Port of Houston authority last year and which was also heavily abused through the fall and winter, according to CISA.

In the case of the attacks against German companies, the BfV said that the final payload was HyperBro, a malware strain seen in attacks as far back as 2018, typically used by APT27, and which can grant the group full control over infected systems.

The BfV reports [PDF, TXT] contains indicators of compromise that both German and non-German organizations and their security teams could use to set up protective measures.

The recent report fits in a general trend that has been shaping up in recent years, where Chinese hackers have often targeted large German companies, from where they are believed to have stolen intellectual property and other business information.

Past victims include software company TeamViewer, steel producer ThyssenKrupp, pharmaceutical giant Bayer, and many others.

German authorities have warned the local business sector about Chinese cyber-espionage since at least 2018.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/german-government-warns-of-apt27-activity-targeting-local-companies