ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Russian APT Hackers Used COVID

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-36934
Local Privilege Escalation (SeriousSAM/HiveNightmare) in Microsoft Windows 10

CVE-2021-36934 is an elevation of privilege vulnerability in Windows caused by overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. A local attacker who already has the ability to execute low-privileged code on a victim system can leverage the misconfigured ACLs to gain arbitrary code execution with SYSTEM privileges, then install programs, view, change or delete data, or create new accounts with full user rights. Affected products per the CPE data are Windows 10 versions 1809, 1909, 2004, 20H2 and 21H1, with related coverage noting the bug impacts all Windows 10 versions released in the past 2.5 years and also references Windows 11. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-02-10, confirming in-the-wild exploitation, and EPSS assigns a 67.3% probability of exploitation within 30 days (99th percentile). Mitigation is two-step: installing the security update alone is not sufficient — administrators must also manually delete all shadow copies of system files, including the SAM database, per KB5005357.

Do: Apply Microsoft's security update per vendor instructions, then follow KB5005357 to manually delete all shadow copies of system files (including the SAM database), because the update alone does not fully mitigate the vulnerability. Restrict or verify ACLs on the System32 config directory and shadow-copy access if shadow-copy deletion cannot be done immediately, and prioritize patching given the flaw's listing in CISA's Known Exploited Vulnerabilities Catalog.

7.867% KEV
  • microsoft Windows 10 1809
  • microsoft Windows 10 1909
  • microsoft Windows 10 2004
  • +3 more
masshundreds of millions of Windows 10 devices (every supported feature update from mid-2018 through mid-2021 is in scope)
Full article457 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 09, 2022

The Russia-linked threat actor known as APT29 targeted European diplomatic missions and Ministries of Foreign Affairs as part of a series of spear-phishing campaigns mounted in October and November 2021.

According to ESET's T3 2021 Threat Report shared with The Hacker News, the intrusions paved the way for the deployment of Cobalt Strike Beacon on compromised systems, followed by leveraging the foothold to drop additional malware for gathering information about the hosts and other machines in the same network.

Also tracked under the names The Dukes, Cozy Bear, and Nobelium, the advanced persistent threat group is an infamous cyber-espionage group that has been active for more than a decade, with its attacks targeting Europe and the U.S., before it gained widespread attention for the supply‐chain compromise of SolarWinds, leading to further infections in several downstream entities, including U.S. government agencies in 2020.

The spear-phishing attacks commenced with a COVID-19-themed phishing email impersonating the Iranian Ministry of Foreign Affairs and containing an HTML attachment that, when opened, prompts the recipients to open or save what appears to be an ISO disk image file ("Covid.iso").

Should the victim opt to open or download the file, "a small piece of JavaScript decodes the ISO file, which is embedded directly in the HTML attachment." The disk image file, in turn, includes an HTML application that's executed using mshta.exe to run a piece of PowerShell code that ultimately loads the Cobalt Strike Beacon onto the infected system.

ESET also characterized APT29's reliance on HTML and ISO disk images (or VHDX files) as an evasion technique orchestrated specifically to evade Mark of the Web (MOTW) protections, a security feature introduced by Microsoft to determine the origin of a file.

"An ISO disk image doesn't propagate the so-called Mark of the Web to the files inside the disk image," the researchers said. "As such, and even if the ISO were downloaded from the internet, no warning would be displayed to the victim when the HTA is opened."

Upon successfully gaining initial access, the threat actor delivered a variety of off-the-shelf tools to query the target's Active Directory (AdFind), execute commands on a remote machine using SMB protocol (Sharp-SMBExec), carry out reconnaissance (SharpView), and even an exploit for a Windows privilege escalation flaw (CVE-2021-36934) to carry out follow-on attacks.

"Recent months have shown that The Dukes are a serious threat to western organizations, especially in the diplomatic sector," the researchers noted. "They are very persistent, have good operational security, and they know how to create convincing phishing messages."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/02/russian-apt-hackers-used-covid-19-lures.html