Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell) Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×9 |
| masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services |
Full article319 words · extracted from infosecurity-magazine.com · click to collapse
The Remcos Trojan has returned to the top ten list (in eighth position) of most wanted malware by Check Point Software for the first time since December 2022.
According to the latest report published by the company earlier today, threat actors used Remcos extensively in February to target Ukrainian government entities through phishing attacks.
The research document also clarifies that, overall, weekly attacks targeting Ukraine have decreased by 44% between October 2022 and February 2023.
“While there has been a decrease in the number of politically motivated attacks on Ukraine, they remain a battleground for cyber-criminals,” explained Maya Horowitz, VP of research at Check Point Software, commenting on the report’s findings.
“Hacktivism has typically been high on the agenda for threat actors since the Russo-Ukrainian war began, and most have favored disruptive attack methods such as DDoS to garner the most publicity.”
Horowitz added that recent attacks against Ukrainian targets used a more traditional attack route, such as phishing scams, to obtain information and extract data.
“It’s important that all organizations and government bodies follow safe security practices when receiving and opening emails. Do not download attachments without scanning the properties first. Avoid clicking on links within the body of the email, and check the sender address for any abnormalities such as additional characters or misspellings.”
Qbot retained its leading position in the list, followed by the Formbook infostealer and the infamous Emotet trojan – both of which climbed ranks compared to Check Point’s January report.
Banking trojan Anubis also retained its position as top mobile malware, followed by Hiddad (a malware tool designed to repackage apps with extra ads) and the AhMyth RAT.
The vulnerability most exploited in the wild in February was the web server malicious URL directory traversal, replacing the web server flaw that exposed GitHub repository information in October 2022. The Apache Log4j remote code execution vulnerability (CVE-2021-44228) took the third spot.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/remcos-returns-wanted-malware-list/