ZeroHour
The Recordpublished ()ingested

Rare new Windows rootkit spotted in Chinese APT attacks

highMalwareimportance 47CVE-2017-7269

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-7269
Buffer Overflow in Microsoft IIS 6.0 via WebDAV PROPFIND Header

CVE-2017-7269 is a buffer overflow (CWE-119) in Internet Information Services (IIS) 6.0, the web server shipped with Microsoft Windows Server 2003 R2. A remote attacker triggers it by sending a WebDAV PROPFIND request whose overly long header begins with 'If: <http://', overflowing a buffer during header parsing. Successful exploitation allows remote code execution on the affected web server, giving the attacker control of the host at the web service's privilege level. Only organizations still running IIS 6.0 on Windows Server 2003 R2 are affected, typically legacy web servers, since that OS reached end of support in July 2015. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a 99.8% EPSS score (100th percentile), indicating active in-the-wild exploitation; no public PoC is recorded in this data and, because the OS is out of support, no generally distributed patch exists.

Do: Inventory internet-facing systems still running IIS 6.0 on Windows Server 2003 R2 and prioritize migration to a supported Windows/IIS version, since no general patch was released for this out-of-support product (custom-support customers may be able to obtain a hotfix from Microsoft). As interim mitigation, disable WebDAV if it is not needed, or block or limit PROPFIND requests and long 'If' headers via IIS request filtering, a reverse proxy, or a WAF. Per the KEV entry, apply updates per vendor instructions; ransomware association is currently unknown.

9.8100% KEV PoC ×5
  • Microsoft Windows Server 2003 R2 with Internet Information Services (IIS) 6.0 IIS 6.0 (as shipped with Windows Server 2003 R2)
largetens of thousands of internet-exposed IIS 6.0 servers today (hundreds of thousands at the 2017 disclosure)
Full article516 words · extracted from therecord.media · click to collapse

Ever since Microsoft bolstered security features with the release of Windows 10, rootkits have become a rarity on the malware scene, as developing and then successfully installing one without getting detected or blocked has become significantly more difficult than in previous years.

But in a report published today, security firm Kaspersky said it discovered a rare new Windows rootkit that has remained undetected since at least 2018 and has been deployed in some highly targeted attacks.

Rootkit was linked to suspected Chinese APT activity

Kaspersky said the rootkit, which it named Moriya, was developed by a mysterious threat actor that bears all the signs of being a Chinese cyber-espionage group (also known as an APT).

"Unfortunately, we are not able to attribute the attack to any particular known actor, but based on the TTPs used throughout the campaign, we suppose it is a Chinese-speaking one," the Kaspersky GReAT team said today.

"We base this on the fact that the targeted entities were attacked in the past by Chinese-speaking actors, and are generally located in countries that are usually targeted by such an actor profile. Moreover, the tools leveraged by the attackers, such as China Chopper, BOUNCER, Termite and Earthworm, are an additional indicator supporting our hypothesis as they have previously been used in campaigns attributed to well-known Chinese-speaking groups," the company added.

Kaspersky said that based on its telemetry, the attacks were highly targeted, and the group delivered the Moriya rootkit to less than ten victims across the world.

"The most prominent victims are two large regional diplomatic organizations in South-East Asia and Africa, while all the others were victims in South Asia," it added.

Moriya used a clever design to avoid detection

The Russian security firm said the threat actor remained undetected because of Moriya's design, which besides borrowing tried-and-tested techniques used by the rootkits of other APTs (such as Turla, Lamberts, and Equation Group), also used its own trickery.

This included interposing itself between the Windows TCP/IP network stack and incoming network traffic, and then intercepting data packets before they reached the operating system and any locally installed antivirus.

Moriya would parse these incoming network data to look for a so-called "magic value" in TCP packets which would activate the rootkit's functions and instruct the malware to carry out various operations.

As to how Moriya was installed inside organizations, Kaspersky said that the entry point was usually outdated IIS web servers. One confirmed entry point, according to the security firm, was a server that was not patched for a vulnerability tracked as CVE-2017-7269, which the attackers abused to install a web shell on the victim's server and then use it to deploy Moriya.

Despite known incidents of Moriya deployments being so rare, Kaspersky has published indicators of compromise to allow companies to scan servers and workstations for Moriya artifacts.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/rare-new-windows-rootkit-spotted-in-chinese-apt-attacks