ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hezbollah Hacker Group Targeted Telecoms, Hosting, ISPs Worldwide

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2012-3152
Remote vulnerability in Oracle Fusion Middleware Reports Developer exploited in the wild

CVE-2012-3152 is an unspecified remote vulnerability in the Reports Developer component of Oracle Fusion Middleware that allows attackers to affect the confidentiality and integrity of affected systems. An attacker who can reach the reporting service over the network can send crafted requests to read sensitive data or tamper with information handled by that component; the precise trigger mechanism and authentication requirements are not detailed in available data. Any organization running Oracle Fusion Middleware with the Reports Developer component deployed is potentially affected, with telecoms, ISPs, and hosting providers among the environments observed to be targeted. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and is associated with the Lebanese Cedar APT's intrusions into telecoms, ISPs, and hosting firms worldwide. EPSS rates the 30-day exploitation probability at 98.8% (100th percentile), making prompt patching a high priority.

Do: Apply vendor-supplied updates to Oracle Fusion Middleware per CISA's required action (apply updates per vendor instructions). Inventory your environment to determine whether the Reports Developer/Oracle Reports component is deployed and whether it is internet-exposed, and restrict network access to it where patching is not immediately possible. Because the flaw has been used in the wild by the Lebanese Cedar APT, especially in telecom, ISP, and hosting environments, also hunt for signs of compromise such as unexpected processes, webshells, or unusual outbound connections.

99% KEV
  • Oracle Fusion Middleware (Reports Developer component)
largetens of thousands of deployments worldwide (enterprise middleware installed base); exact count unknown
CVE-2019-11581
Unauthenticated SSTI RCE in Atlassian Jira Server and Data Center

Atlassian Jira Server and Data Center contain a server-side template injection (CWE-74) in the ContactAdministrators and SendBulkMail actions, rated critical at CVSS 9.8. The flaw is triggered by sending crafted, template-syntax input to these mail-related actions over the network; because the vulnerability requires no authentication or user interaction per the CVSS vector, any attacker who can reach the Jira web interface can trigger it. Successful exploitation yields unauthenticated remote code execution on the server hosting Jira, with high impact on confidentiality, integrity, and availability. Organizations running any Jira Server or Data Center release in the 4.4–7.6, 7.7–7.13, 8.0, 8.1, or 8.2 lines prior to the listed fixed versions are affected, and the exposure is concentrated among instances reachable from the internet. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 with a required action to apply vendor updates, and EPSS places it in the 100th percentile (~84.6% probability of exploitation within 30 days).

Do: Apply the vendor updates per Atlassian/CISA instructions — upgrade to Jira 7.6.14, 7.13.5, 8.0.3, 8.1.2, or 8.2.3 (or later) as applicable, since this is a KEV item with a required patching action. As an interim mitigation, disable the 'Allow users to contact administrators' option in Jira's General Configuration to close the ContactAdministrators path and restrict SendBulkMail access, and limit exposure of the Jira web interface to the internet. Review access logs for requests hitting ContactAdministrators/SendBulkMail endpoints containing template injection payloads and hunt for signs of post-exploitation code execution on affected servers.

9.885% KEV
  • Atlassian Jira Server All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3
  • Atlassian Jira Data Center All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3
largetens of thousands of internet-exposed Jira Server/Data Center instances
CVE-2019-3396
Server-Side Template Injection RCE in Atlassian Confluence Server and Data Center

Atlassian Confluence Server and Data Center contain a server-side template injection flaw (CWE-22) in which attacker-supplied template content is processed by the server, enabling path traversal and ultimately remote code execution. An attacker triggers it by submitting crafted template syntax in a request to a vulnerable instance, and can run arbitrary commands or code on the underlying server. Successful compromise could allow data theft, deployment of webshells, or ransomware; CISA notes known ransomware use of this vulnerability. Organizations running self-hosted Confluence Server or Data Center are affected, particularly instances exposed to the internet. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and EPSS assigns a 99.9% probability of exploitation, placing it in the top percentile.

Do: Apply updates per vendor instructions by upgrading Confluence Server and Data Center to Atlassian's fixed releases, and prioritize internet-facing instances. Until patched, restrict network exposure of Confluence and monitor for signs of compromise such as webshells, unexpected processes, or ransomware activity, since ransomware operators are known to exploit this flaw.

9.8100% KEV ransomware PoC ×4
  • Atlassian Confluence Server and Data Center
largetens of thousands of internet-exposed Confluence Server/Data Center instances, with an installed base plausibly in the hundreds of thousands of servers across…
Full article533 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 29, 2021

A "persistent attacker group" with alleged ties to Hezbollah has retooled its malware arsenal with a new version of a remote access Trojan (RAT) to break into companies worldwide and extract valuable information.

In a new report published by the ClearSky research team on Thursday, the Israeli cybersecurity firm said it identified at least 250 public-facing web servers since early 2020 that have been hacked by the threat actor to gather intelligence and steal the company's databases.

The orchestrated intrusions hit a slew of companies located in the U.S., the U.K., Egypt, Jordan, Lebanon, Saudi Arabia, Israel, and the Palestinian Authority, with a majority of the victims representing telecom operators (Etisalat, Mobily, Vodafone Egypt), internet service providers (SaudiNet, TE Data), and hosting and infrastructure service providers (Secured Servers LLC, iomart).

First documented in 2015, Volatile Cedar (or Lebanese Cedar) has been known to penetrate a large number of targets using various attack techniques, including a custom-made malware implant codenamed Explosive.

Volatile Cedar has been previously suspected of Lebanese origins — specifically Hezbollah's cyber unit — in connection with a cyberespionage campaign in 2015 that targeted military suppliers, telecom companies, media outlets, and universities.

The 2020 attacks were no different. The hacking activity uncovered by ClearSky matched operations attributed to Hezbollah based on code overlaps between the 2015 and 2020 variants of the Explosive RAT, which is deployed onto victims' networks by exploiting known 1-day vulnerabilities in unpatched Oracle and Atlassian web servers.

Using the three flaws in the servers (CVE-2019-3396, CVE-2019-11581, and CVE-2012-3152) as an attack vector to gain an initial foothold, the attackers then injected a web shell and a JSP file browser, both of which were used to move laterally across the network, fetch additional malware, and download the Explosive RAT, which comes with capabilities to record keystrokes, capture screenshots, and execute arbitrary commands.

"The web shell is used to carry out various espionage operations over the attacked web server, including potential asset location for further attacks, file installation server configuration and more," the researchers noted, but not before obtaining escalated privileges to carry out the tasks and transmit the results to a command-and-control (C2) server.

In the five years since the Explosive RAT was first seen, ClearSky said new anti-debugging features were added to the implant in its latest iteration (V4), with the communications between the compromised machine and the C2 server now encrypted.

While it's not surprising for threat actors to keep a low profile, the fact that Lebanese Cedar managed to stay hidden since 2015 without attracting any attention whatsoever implies the group may have ceased operations for prolonged periods in between to avoid detection.

ClearSky noted that the group's use of web shell as its primary hacking tool could have been instrumental in leading researchers to a "dead-end in terms of attribution."

"Lebanese Cedar has shifted its focus significantly. Initially they attacked computers as an initial point of access, then progressed to the victim's network then further progressing (sic) to targeting vulnerable, public facing web servers," the researchers added.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/01/hezbollah-hacker-group-targeted.html