Previously unreported Lebanon-based hacking group targeting Israel, Microsoft says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-13379 | Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors. Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible. | 9.8 | 100% | KEV ransomware |
| mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices) |
Full article920 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The new group is suspected of collaborating with "multiple" Iranian-linked hacking efforts.
A previously unreported Lebanon-based hacking group with likely ties to Iranian intelligence has targeted more than 20 Israeli organizations since February, Microsoft’s Threat Intelligence Center and Digital Security Unit reported Thursday.
The group, which Microsoft dubbed “Polonium,” targeted or compromised more than 20 organizations in Israel and one unnamed intergovernmental organization with operations in Lebanon “with a focus on critical manafacturing, IT, and Israel’s defense industry,” the researchers wrote. In one case a cloud services provider “was used to target a downstream aviation company and law firm in a supply chain attack.”
The group created legitimate Microsoft OneDrive accounts and then utilized those accounts to execute part of its attack. The observed activity was not related to any security issues or vulnerabilities within OneDrive, the researchers wrote.
It’s still unclear how the attackers gained initial access to their victims’ networks. But roughly 80% of them were running Fortinet appliances, which “suggests, but does not definitively prove” that the Polonium compromised the Fortinet appliances using a three-year-old vulnerability identified as CVE-2018-13379.
Polonium is likely an “operational group based in Lebanon” that may be coordinating with Iran’s Ministry of Intelligence and Security (MOIS), the researchers wrote.
“Such collaboration or direction from Tehran would align with a string of revelations since late 2020 that the Government of Iran is using third parties to carry out cyber operations on their behalf, likely to enhance Iran’s plausible deniability,” the Microsoft researchers wrote.
The researchers assessed with “moderate confidence” that Polonium is coordinating with multiple Iranian-linked hacking groups based on common targeting, evidence of possible “hand-off” operations, the use of Microsoft OneDrive for command and control functions and the use of AirVPN, which is common among the groups.
The U.S. government formally linked one of those groups — widely known as “MuddyWater” but tracked by Microsoft as “Mercury” — to the MOIS in January.
The ongoing exploitation of this particular vulnerability shows “how a single vulnerable appliance can effect a whole country for a long time.”
Omri Segev Moyal, PROFERO CYBER SECURITY
Omri Segev Moyal, a co-founder of Israeli incident response firm Profero Cyber Security, told CyberScoop in an online chat Thursday that Microsoft’s research is “once again showing the devastating vulnerability of Fortinet (CVE-2018-13379 aka fortifuck),” referring to a nickname for the vulnerability.
The ongoing exploitation of this particular vulnerability shows “how a single vulnerable appliance can effect a whole country for a long time,” he said, noting that his company’s statistics, as well as those of the Israeli CERT, show that it’s perhaps the most exploited by threat actors targeting Israel.
He also said that Microsoft’s research shows “the sticky connection between [Hezbollah] and MOIS when it comes to [targeting] Israeli cyberspace.”
Microsoft did not tie Polonium to Hezbollah, a Lebanese-based group with deep ties to Iran that the U.S. government designated as a foreign terrorist organization in 1997 and blamed for multiple attacks on U.S. and Israeli targets over the years.
But Segev Moyal noted the documented history of collaboration and coordination between Hezbollah and Iran’s MOIS, which includes “intelligence collection and cyber and disinformation operations across the region,” according to a 2021 report from the U.S. based Middle East Institute.
More Scoops
Google: Iranian, regional hacking operations that target Israel remain opportunistic but focused
Objectives from the hacking groups include espionage, information operations or destructive activities, researchers say.
Israel-linked hacking group claims attack on Iranian gas pumps
Shadowy hacking group targeting Israel shows outsized capabilities
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/lebanon-polonium-israel-hacking-cyber/