ZeroHour
CyberScooppublished ()ingested @AJVicens

Previously unreported Lebanon-based hacking group targeting Israel, Microsoft says

criticalExploit / PoC exploited in the wildimportance 60CVE-2018-13379

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-13379
Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN

CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors.

Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible.

9.8100% KEV ransomware
  • Fortinet FortiOS
mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices)
Full article920 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The new group is suspected of collaborating with "multiple" Iranian-linked hacking efforts.

The flag of Iran is seen in front of the building of the International Atomic Energy Agency (IAEA) on May 24, 2021 in Vienna, Austria. (Photo by Michael Gruber/Getty Images)

A previously unreported Lebanon-based hacking group with likely ties to Iranian intelligence has targeted more than 20 Israeli organizations since February, Microsoft’s Threat Intelligence Center and Digital Security Unit reported Thursday.

The group, which Microsoft dubbed “Polonium,” targeted or compromised more than 20 organizations in Israel and one unnamed intergovernmental organization with operations in Lebanon “with a focus on critical manafacturing, IT, and Israel’s defense industry,” the researchers wrote. In one case a cloud services provider “was used to target a downstream aviation company and law firm in a supply chain attack.”

The group created legitimate Microsoft OneDrive accounts and then utilized those accounts to execute part of its attack. The observed activity was not related to any security issues or vulnerabilities within OneDrive, the researchers wrote.

It’s still unclear how the attackers gained initial access to their victims’ networks. But roughly 80% of them were running Fortinet appliances, which “suggests, but does not definitively prove” that the Polonium compromised the Fortinet appliances using a three-year-old vulnerability identified as CVE-2018-13379.

Polonium is likely an “operational group based in Lebanon” that may be coordinating with Iran’s Ministry of Intelligence and Security (MOIS), the researchers wrote.

“Such collaboration or direction from Tehran would align with a string of revelations since late 2020 that the Government of Iran is using third parties to carry out cyber operations on their behalf, likely to enhance Iran’s plausible deniability,” the Microsoft researchers wrote.

The researchers assessed with “moderate confidence” that Polonium is coordinating with multiple Iranian-linked hacking groups based on common targeting, evidence of possible “hand-off” operations, the use of Microsoft OneDrive for command and control functions and the use of AirVPN, which is common among the groups.

The U.S. government formally linked one of those groups — widely known as “MuddyWater” but tracked by Microsoft as “Mercury” — to the MOIS in January.

The ongoing exploitation of this particular vulnerability shows “how a single vulnerable appliance can effect a whole country for a long time.”

Omri Segev Moyal, PROFERO CYBER SECURITY

Omri Segev Moyal, a co-founder of Israeli incident response firm Profero Cyber Security, told CyberScoop in an online chat Thursday that Microsoft’s research is “once again showing the devastating vulnerability of Fortinet (CVE-2018-13379 aka fortifuck),” referring to a nickname for the vulnerability.

The ongoing exploitation of this particular vulnerability shows “how a single vulnerable appliance can effect a whole country for a long time,” he said, noting that his company’s statistics, as well as those of the Israeli CERT, show that it’s perhaps the most exploited by threat actors targeting Israel.

He also said that Microsoft’s research shows “the sticky connection between [Hezbollah] and MOIS when it comes to [targeting] Israeli cyberspace.”

Microsoft did not tie Polonium to Hezbollah, a Lebanese-based group with deep ties to Iran that the U.S. government designated as a foreign terrorist organization in 1997 and blamed for multiple attacks on U.S. and Israeli targets over the years.

But Segev Moyal noted the documented history of collaboration and coordination between Hezbollah and Iran’s MOIS, which includes “intelligence collection and cyber and disinformation operations across the region,” according to a 2021 report from the U.S. based Middle East Institute.

More Scoops

This picture taken from Rafah shows smoke billowing following Israeli bombardments over Khan Yunis in the southern Gaza Strip on February 13, 2024, amid the ongoing conflict between Israel and the Palestinian Hamas militant group. (Photo by SAID KHATIB / AFP)

Google: Iranian, regional hacking operations that target Israel remain opportunistic but focused

Objectives from the hacking groups include espionage, information operations or destructive activities, researchers say.

People wait at a gas station in Tehran on December 18, 2023 after a cyberattack disrupted fuel distribution. (Photo by ATTA KENARE / AFP)

Israel-linked hacking group claims attack on Iranian gas pumps

A picture taken on November 23, 2023, shows an Israeli flag near the Dome of the Rock shrine, Islam’s third holiest site, in Jerusalem’s Old City. (Photo by AHMAD GHARABLI/AFP via Getty Images)

Shadowy hacking group targeting Israel shows outsized capabilities

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/lebanon-polonium-israel-hacking-cyber/