Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-24919 | Information Disclosure in Internet-Facing Check Point Quantum Security Gateways Check Point Quantum Security Gateways contain an information disclosure flaw (CWE-200) that can expose information stored on the appliance to unauthorized parties. It is triggered when an attacker targets a gateway connected to the internet with IPSec VPN, Remote Access VPN, or Mobile Access enabled, sending crafted requests to the exposed VPN services. A successful attacker gains unauthorized access to information on the gateway, and CISA notes known use of this flaw in ransomware campaigns. The issue spans multiple Check Point product lines: CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-05-30 with ransomware use listed, and EPSS assigns a 100% probability of exploitation within 30 days, though no public proof-of-concept is known. Do: Apply the hotfix Check Point distributes per its advisory (SK170863) to all internet-facing gateways running IPSec VPN, Remote Access VPN, or Mobile Access; this is also the CISA KEV required action. Where the hotfix cannot be applied immediately, restrict or disable the Remote Access VPN and Mobile Access software blades as an interim mitigation. Review gateway and VPN logs for signs of exploitation and prioritize remediation given confirmed ransomware use. | 8.6 | 100% | KEV ransomware |
| largetens of thousands of internet-exposed VPN gateways (10k-100k systems) |
Full article488 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 09, 2024Cyber Espionage / Malware
The China-linked advanced persistent threat (APT) group known as Mustang Panda has been observed weaponizing Visual Studio Code software as part of espionage operations targeting government entities in Southeast Asia.
"This threat actor used Visual Studio Code's embedded reverse shell feature to gain a foothold in target networks," Palo Alto Networks Unit 42 researcher Tom Fakterman said in a report, describing it as a "relatively new technique" that was first demonstrated in September 2023 by Truvis Thornton.
The campaign is assessed to be a continuation of a previously documented attack activity aimed at an unnamed Southeast Asian government entity in late September 2023.
Mustang Panda, also known by the names BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta, Red Lich, and Stately Taurus, has been operational since 2012, routinely conducting cyber espionage campaigns targeting government and religious entities across Europe and Asia, particularly those located in South China Sea countries.
The latest observed attack sequence is notable for its abuse of Visual Studio Code's reverse shell to execute arbitrary code and deliver additional payloads.
"To abuse Visual Studio Code for malicious purposes, an attacker can use the portable version of code.exe (the executable file for Visual Studio Code), or an already installed version of the software," Fakterman noted. "By running the command code.exe tunnel, an attacker receives a link that requires them to log into GitHub with their own account."
Once this step is complete, the attacker is redirected to a Visual Studio Code web environment that's connected to the infected machine, allowing them to run commands or create new files.
It's worth pointing out that the malicious use of this technique was previously highlighted by Dutch cybersecurity firm mnemonic in connection with zero-day exploitation of a now-patched vulnerability in Check Point's Network Security gateway products (CVE-2024-24919, CVSS score: 8.6) earlier this year.
Unit 42 said the Mustang Panda actor leveraged the mechanism to deliver malware, perform reconnaissance, and exfiltrate sensitive data. Furthermore, the attacker is said to have used OpenSSH to execute commands, transfer files, and spread across the network.
That's not all. A closer analysis of the infected environment has revealed a second cluster of activity "occurring simultaneously and at times even on the same endpoints" that utilized the ShadowPad malware, a modular backdoor widely shared by Chinese espionage groups.
It's currently unclear if these two intrusion sets are related to one another, or if two different groups are "piggybacking on each other's access."
"Based on the forensic evidence and timeline, one could conclude that these two clusters originated from the same threat actor (Stately Taurus)," Fakterman said. "However, there could be other possible explanations that can account for this connection, such as a collaborative effort between two Chinese APT threat actors."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/09/chinese-hackers-exploit-visual-studio.html