ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Lazarus Targets Internet Infrastructure and Healthcare with QuiteRAT

criticalMalwareimportance 60CVE-2022-47966

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-47966
Unauthenticated SAML RCE in Zoho ManageEngine On-Premise Products

CVE-2022-47966 is a critical (CVSS 9.8), unauthenticated remote code execution flaw in roughly two dozen Zoho ManageEngine on-premise products caused by their bundled Apache Santuario xmlsec (XML Security for Java) 1.4.1 library, in which the XSLT features leave security protections to the application and ManageEngine did not provide them. An attacker triggers the flaw by sending a crafted SAML response containing a malicious XSLT transform to the SAML single sign-on (SSO) endpoint; exploitation is only possible if SAML SSO has ever been configured for the product (for some products, SAML SSO must be currently active). Successful exploitation yields arbitrary code execution in the context of the affected ManageEngine application, typically full compromise of the server and a foothold into the wider enterprise network. Any organization running an affected product version with SAML SSO enabled is affected, with internet-exposed ITSM/identity-management servers the most likely targets. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, Rapid7 reported broad attacker interest, North Korea's Lazarus Group used it to deploy QuiteRAT, and Iranian government-backed actors have targeted U.S. energy and transit-sector organizations.

Do: Apply vendor updates immediately, upgrading each installed product to at least the fixed version listed (e.g., ServiceDesk Plus 14004+, ADSelfService Plus 6211+, Endpoint Central/Endpoint Central MSP 10.1.2228.11+, Password Manager Pro 12124+, ServiceDesk Plus MSP 13001+, ADAudit Plus 7081+, ADManager Plus 7162+, AD360 4310+); this is a CISA KEV required action. As an interim mitigation, disable or restrict SAML SSO (or limit access to the product's SSO endpoints), since SAML SSO must have been configured for exploitation. Prioritize patching internet-exposed instances and review those servers for signs of compromise, given documented use by Lazarus Group, ransomware operators, and Iranian nation-state actors.

9.8100% KEV ransomware PoC ×6
  • zohocorp ManageEngine Access Manager Plus before 4308
  • zohocorp ManageEngine Active Directory 360 (AD360) before 4310
  • zohocorp ManageEngine ADAudit Plus before 7081
  • +9 more
largetens of thousands of installations plausibly affected (thousands of instances internet-exposed), out of ManageEngine's very large on-prem install base
Full article393 words · extracted from infosecurity-magazine.com · click to collapse

The North Korean state-sponsored actor Lazarus Group recently started a new campaign targeting internet backbone infrastructure and healthcare entities in Europe and the US, security researchers from Cisco Talos have found.

The researchers said that the attackers began exploiting a ManageEngine ServiceDesk vulnerability (CVE-2022-47966) in January 2023, only five days after it was disclosed.

This vulnerability is highly critical, with a CVSS score of 9.8/10 and a Kenna risk score of 100/100.

The threat actors used the exploit to gain initial access. The successful exploitation triggered the immediate download and execution of a malicious binary via the Java runtime process, activating the implant on the infected server. This binary is a variant of their MagicRAT malware that Cisco Talos named QuiteRAT.

First discovered in February by WithSecure, QuiteRAT has stayed under the radar until now. Like MagicRAT, QuiteRAT is built from the Qt framework, a free, open source, and cross-platform framework designed for building applications, and includes capabilities such as arbitrary command execution.

Its file size, however, is much smaller at 4 to 5MB compared with 18MB.

“This substantial difference in size is due to Lazarus Group incorporating only a handful of required Qt libraries into QuiteRAT, as opposed to MagicRAT, in which they embedded the entire Qt framework,” reads the analysis, published on August 24, 2023.

Once the implant starts running, it sends out preliminary system information to its command and control (C&C) servers. Then, it waits for the C&C to respond with a command code or an actual Windows command to execute on the endpoint via a child cmd.exe process.

“While MagicRAT consists of persistence mechanisms implemented in it via the ability to set up scheduled tasks, QuiteRAT does not have a persistence capability and needs to be issued one by the C&C server to achieve continued operation on the infected endpoint,” the researchers added.

This is the third documented campaign attributed to the Lazarus Group since the beginning of 2023, with the actor reusing the same infrastructure throughout these operations.

Read more: Lazarus Group's DeathNote Campaign Reveals Shift in Targets

The exploited vulnerability, affecting multiple products of Zoho-owned ManageEngine, is now awaiting reanalysis.

The same day Cisco Talos’ analysis was published, the FBI warned cryptocurrency firms about a surge in blockchain activity linked to the theft of hundreds of millions in digital currency attributed to the Lazarus Group.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/lazarus-internet-healthcare/