Chinese Hackers May Be Behind Attacks Targeting Eastern Europe and Afghanistan
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11882 | Memory Corruption RCE in Microsoft Office via Legacy Equation Editor CVE-2017-11882 is a memory corruption vulnerability (CWE-119) in Microsoft Office, residing in the legacy Microsoft Equation Editor component (EQNEDT32.EXE), that allows remote code execution in the context of the current user. Attackers trigger it by persuading a user to open a crafted document, most commonly an RTF file or other Office document carrying a malicious embedded equation object, which overflows a buffer while the equation content is parsed. Successful exploitation lets the attacker run arbitrary code with the privileges of the signed-in user, a typical foothold for malware delivery and, per CISA, for ransomware operations. Any environment running affected Microsoft Office builds is exposed; the source data does not enumerate specific affected version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and holds a 99.9% EPSS score (percentile 100), though the source data lists no public PoC. Do: Apply Microsoft's Office security updates (November 2017 or later) across all endpoints, prioritizing this KEV-listed flaw given its known ransomware use. On systems that cannot yet be patched, disable or unregister the legacy Equation Editor (EQNEDT32.EXE) and consider blocking or warning on RTF attachments as interim mitigations. Check for indicators of abuse such as EQNEDT32.EXE spawning unexpected child processes after document opens. | 7.8 | 100% | KEV ransomware PoC ×10 |
| masshundreds of millions of users/installations (Office is near-ubiquitous on Windows and in enterprises; the share still unpatched is unknown) |
Full article365 words · extracted from infosecurity-magazine.com · click to collapse
A new analysis by Kaspersky unveiled a wave of targeted attacks on military-industrial complex enterprises and public institutions in Belarus, Russia, Ukraine and Afghanistan.
The cybersecurity company made the announcement in an advisory published on Monday, which claims the attackers were able to penetrate several enterprises and hijack the IT infrastructure of some of them.
Kaspersky did not name these entities but said they included industrial plants, design bureaus and research institutes, government agencies, ministries and departments.
In terms of how the threat actors (TA) infiltrated these entities, Kaspersky said the initial vector was phishing emails, some of which contained information specific to the organization under attack (and not publicly available).
“This could indicate that the attackers did preparatory work in advance,” the advisory read.
According to the report, the phishing emails contained Microsoft Word documents that exploited the CVE-2017-11882 vulnerability, a flaw enabling attackers to execute arbitrary code without any additional user activity.
Kaspersky further explained that in the attacks analyzed, the main module responsible was the PortDoor malware, a tool that collects general information on the infected system and sends it to the malware command-and-control (CnC) server.
“In cases where an infected system is of interest to the attackers, they use the PortDoor functionality to control the system remotely and install additional malware,” said the advisory.
The analysis of the campaign also showed the use of five additional backdoors at the same time: nccTrojan, Logtu, Cotx, DNSep and a fifth, unnamed one.
In terms of attribution, Kaspersky said significant overlaps in tactics, techniques, and procedures (TTP) have been observed with APT TA428, a Chinese threat group allegedly behind campaigns targeting government IT in Eastern Asia in 2019.
“The findings of our research show that spear phishing remains one of the most relevant threats to industrial enterprises and public institutions,” read the advisory’s conclusion.
“Given that the attackers have had some success, we believe it is highly likely that similar attacks will occur again in the future. Industrial enterprises and public institutions should do a great deal of work to successfully thwart such attacks.”
Technical details of the attacks, recommendations and indicators of compromise are available in the advisory’s full public version.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/china-behind-attacks-eastern/