China-linked hackers exploit Fortinet zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-41328 | Path Traversal in Fortinet FortiOS Exploited in Targeted Attacks CVE-2022-41328 is a path traversal flaw (CWE-22) in Fortinet FortiOS in which the system fails to properly limit file paths, allowing crafted CLI commands to escape the restricted directory. A privileged attacker — one who already has CLI access to the device — can issue these crafted commands to read and write arbitrary files on the underlying Linux system, effectively breaking out of the FortiOS CLI sandbox. That post-compromise capability is valuable for stealth and persistence, since changes to system files on the underlying OS may not be visible through normal FortiOS administration. Organizations running FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.9, or any release before 6.4.11 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-14, carries a high EPSS score (10.7% probability of exploitation within 30 days, 96th percentile), and public reporting describes its use in targeted cyberattacks on government entities attributed to the espionage group tracked as UNC3886, though no public proof-of-concept code is known. Do: Upgrade all affected FortiGate/FortiOS devices to a fixed release beyond the affected ranges — 7.2.4 or later, 7.0.10 or later, or 6.4.11 or later — per Fortinet's advisory, as required by the CISA KEV entry. Restrict privileged CLI access (admin accounts, trusted-host/local-in policies) and review CLI logs plus the underlying Linux filesystem for unexpected file changes as signs of compromise, particularly on government or otherwise high-value networks given UNC3886 targeting. | 7.1 | 11% | KEV |
| masshundreds of thousands of FortiGate deployments (well over 100,000 internet-facing FortiGates appear in public scans) |
Full article587 words · extracted from therecord.media · click to collapse
A suspected state-sponsored hacking group based in China has exploited zero-day vulnerabilities and deployed custom malware to spy on defense, government, tech, and telecom organizations, according to a new report. Cybersecurity firm Mandiant said it investigated “dozens of intrusions” in recent years where China-linked groups have used these techniques to steal user credentials and maintain long-term access to the victims’ devices. One group — tracked by Mandiant as UNC3886 — was observed in several attacks in mid-2022 targeting network security systems, firewalls, and virtualization technologies that enable computers to run multiple operating systems and applications simultaneously. The group used backdoors on Fortinet and VMware systems to attack victims’ devices. Mandiant’s Chief Technical Officer Charles Carmakal told The Record that researchers have identified nearly 10 victims across the defense, technology, and telecom industries in the U.S., Europe, and Asia that were impacted by the attacks. According to a joint investigation from Mandiant and Fortinet, hackers deployed their malware across multiple Fortinet systems. The hacking group initially accessed Fortinet’s centralized management device, FortiManager – which is accessible from the internet – before exploiting the CVE-2022-41328 zero-day vulnerability. The high-severity bug was discovered and patched by Fortinet earlier in March, and allows hackers to execute malicious code and deploy malware payloads on unpatched FortiGate firewall devices. Researchers traced the attack to China based on victim selection and the use of techniques and malware previously employed by China-affiliated hackers. The UNC3886 group is associated with a novel malware framework, which was disclosed by Mandiant in September 2022. This malware impacted network devices such as VMware ESXi, Linux vCenter servers, and Windows virtual machines. This is the second Fortinet bug suspected to be exploited by China-linked hackers that the company has jointly discovered with Mandiant. In January, Mandiant warned of another attack targeting Fortinet’s firewall software, which it attributed to a Chinese group unrelated to UNC3886. Mandiant called UNC3886 “an advanced cyber espionage group with unique capabilities.” In the recent attack, the group employed various techniques to avoid detection, according to Brad Slaybaugh, Mandiant's principal consultant. For example, they tampered with a genuine system file to disable digital signature verification checks during system startup. They also turned off logging services and history files and selectively erased log entries linked to their activity, Slaybaugh told The Record. Their recent activity highlights the vulnerability of internet-exposed systems such as firewalls, smart devices and VPN technologies that do not support endpoint detection and response (EDR) security software to cyberattacks, the company said. “As EDR solutions improve malware detection efficacy on Windows systems, certain state-sponsored threat actors have shifted to developing and deploying malware on systems that do not generally support EDR,” Mandiant wrote in its September report. Such incidents are harder to investigate, according to Mandiant, because many network devices don't have tools to detect changes made to the operating system while it's running. To get evidence, investigators may need to ask the manufacturer for help collecting images of the system. While the technique used by UNC3886 "requires a deeper level of understanding" of how network devices operate, Mandiant predicted that other threat actors will try to build similar tools for future attacks.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/china-linked-hackers-exploit-fortinet-zero-day