CVE-2012-0158
published 2012-04-10CVE-2012-0158: The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2…
PriorityP196high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.97%
100.0th percentile
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | biztalk_server | — | — |
| microsoft | commerce_server | — | — |
| microsoft | commerce_server | — | — |
| microsoft | commerce_server_2009 | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_web_components | — | — |
| microsoft | sql_server_2008 | — | — |
| microsoft | visual_basic | — | — |
| microsoft | visual_foxpro | — | — |
| microsoft | visual_foxpro | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandcmd.exe /c dir /s %windir%\system32\*.sys&&taskkill /im winword.exe /f&dir /a /s %windir%\system32\*.msc && DOCUME~1\ADMINI~1\LOCALS~1\Temp\~.doc↗
- →RTF exploit documents targeting CVE-2012-0158 can be detected by checking for invalid `listoverridecount` values in RTF; the only legal values are 0, 1, or 9 — other values indicate exploitation. ↗
- →Snort rules 24974 and 24975 (referencing `listoverridecount`) provide coverage for RTF-based exploitation of this vulnerability family. ↗
- →HOMEKit-generated malicious Word documents (OLE format) share consistent metadata: Author=User, Last Modified By=User, Company=HOME, Code Page=Windows Simplified Chinese, Create Date=2006:09:28 17:06:00, Modify Date=2006:09:28 17:09:00. ↗
- →HOMEKit shellcode decryption stub uses ROR 3 combined with XOR key 0xAF on each ciphertext byte; this can be used as a static signature for HOMEKit shellcode. ↗
- →Cookle Trojan uses a misspelled 'Cookie' HTTP header field in its C2 beacon containing the same value as its mutex (LDE_160425); hunt for HTTP requests with malformed Cookie headers matching this pattern. ↗
- →Cookle Trojan uses a modified base64 encoding that swaps uppercase and lowercase letters in the base64 alphabet; this non-standard encoding can be used to fingerprint the malware's network traffic or strings. ↗
- →Asruex variant drops and executes the infector as rundll32.exe from the Word document exploit; monitor for rundll32.exe being dropped to temp/working directories by Office processes. ↗
- →Asruex anti-debugging check looks for avast! Sandbox path; presence of this check can be used to identify the malware family in memory or static analysis. ↗
- ·The Asruex variant only infects files within a specific size range; files outside this range are not targeted, which may limit detection coverage based on file size alone. ↗
- ·Cookle Trojan sleeps for 20 minutes before generating C2 beacons, which may cause sandbox analysis to miss network activity if analysis timeout is shorter than this delay. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xc3w-wqx5-qrf9: The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL
ghsa_unreviewed·2022-05-04
CVE-2012-0158 [HIGH] CWE-94 GHSA-xc3w-wqx5-qrf9: The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."
VulnCheck
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
vulncheck·2012·CVSS 8.8
CVE-2012-0158 [HIGH] CWE-94 Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.
Affected: Microsoft MSCOMCTL.OCX
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://web.archive.org/web/20120907091804/http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_the_taidoor_campaign.pdf; https://www.cve.org/CVERecord?id=CVE-2012-0158; https://cybersecurity.att.com/blogs/labs-research/msupdater-trojan-found-using-cve-2012-0158-space-and-missile-defense-conference; https://securelist.com/red-october-diplomati
CISA
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2012-0158 [HIGH] CWE-94 Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Vulnerability: Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Affected: Microsoft MSCOMCTL.OCX
Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-0158
Remediation Due Date: 2022-05-03
Suricata
ET MALWARE EvilGrab/Vidgrab Checkin
suricata·2013-09-04
CVE-2012-0158 ET MALWARE EvilGrab/Vidgrab Checkin
ET MALWARE EvilGrab/Vidgrab Checkin
Rule: alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE EvilGrab/Vidgrab Checkin"; flow:established,to_server; content:"|7c 28|"; pcre:"/^\d{1,3}\x2e\d{1,3}\x2e\d{1,3}\x2e\d{1,3}/R"; content:"|29 7c|"; within:2; pcre:"/^\d{1,5}/R"; content:"|7c|Win"; within:4; reference:url,contagiodump.blogspot.com.br/2013/09/sandbox-miming-cve-2012-0158-in-mhtml.html; classtype:command-and-control; sid:2017413; rev:4; metadata:created_at 2013_09_04, signature_severity Major, updated_at 2024_03_06;)
YARA
CVE_2012_0158_KeyBoy
yara·CVSS 8.8
CVE-2012-0158 [HIGH] CVE_2012_0158_KeyBoy
rule CVE_2012_0158_KeyBoy {
meta:
author = "Etienne Maynier "
description = "CVE-2012-0158 variant"
file = "8307e444cad98b1b59568ad2eba5f201"
strings:
$a = "d0cf11e0a1b11ae1000000000000000000000000000000003e000300feff09000600000000000000000000000100000001" nocase // OLE header
$b = "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" nocase // junk data
$c = /5(\{\\b0\}|)[ ]*2006F00(\{\\b0\}|)[ ]*6F007(\{\\b0\}|)[ ]*400200045(\{\\b0\}|)[ ]*006(\{\\b0\}|)[ ]*E007(\{\\b0\}|)[ ]*400720079/ nocase
$d = "MSComctlLib.ListViewCtrl.2"
$e = "ac38c874503c307405347aaaebf2ac2c31ebf6e8e3" nocase //decod
Exploit-DB
Microsoft Windows - MSCOMCTL ActiveX Buffer Overflow (MS12-027) (Metasploit)
exploitdb·2012-04-25
CVE-2012-0158 Microsoft Windows - MSCOMCTL ActiveX Buffer Overflow (MS12-027) (Metasploit)
Microsoft Windows - MSCOMCTL ActiveX Buffer Overflow (MS12-027) (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
class Metasploit3 'MS12-027 MSCOMCTL ActiveX Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in MSCOMCTL.OCX. It uses a malicious
RTF to embed the specially crafted MSComctlLib.ListViewCtrl.2 Control as exploited
in the wild on April 2012.
This module targets Office 2007 and Office 2010 targets. The DEP/ASLR bypass on Office
2010 is done with the Ikazuchi ROP chain proposed by Abysssec. This chain uses
"msgr3en.dll", wh
Metasploit
MS12-027 MSCOMCTL ActiveX Buffer Overflow
metasploit
MS12-027 MSCOMCTL ActiveX Buffer Overflow
MS12-027 MSCOMCTL ActiveX Buffer Overflow
This module exploits a stack buffer overflow in MSCOMCTL.OCX. It uses a malicious RTF to embed the specially crafted MSComctlLib.ListViewCtrl.2 Control as exploited in the wild on April 2012. This module targets Office 2007 and Office 2010 targets. The DEP/ASLR bypass on Office 2010 is done with the Ikazuchi ROP chain proposed by Abysssec. This chain uses "msgr3en.dll", which will load after office got load, so the malicious file must be loaded through "File / Open" to achieve exploitation.
Checkpoint
10 Years of DLL Hijacking, and What We Can Do to Prevent 10 More
blogs_checkpoint·2024-09-25
CVE-2012-0158 10 Years of DLL Hijacking, and What We Can Do to Prevent 10 More
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## 10 Years of DLL Hijacking, and What We Can Do to Prevent 10 More
## Introduction
DLL Hijacking — a technique for forcing legitimate applications to run malicious code — has been in use f
Qualys
Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
#### Table of Contents
- Stats on the Top 20 Vulnerable Vendors & By-Products
- Top Twenty Most Targeted by Attackers
- TruRisk Dashboard
- Key Insights & Takeaways
- References
- Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the curre
Qualys
Qualys Top 20 Most Exploited Vulnerabilities
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Qualys Top 20 Most Exploited Vulnerabilities
## Table of Contents
Stats on the Top 20 Vulnerable Vendors & By-Products
Top Twenty Most Targeted by Attackers
TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the current year.
Qualys
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
blogs_qualys·2023-07-18
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
## Table of Contents
Top Ten Vulnerabilities Exploited by Threat Actors
Top Ten Highly Active Threat Actors
Top Ten Most Exploited Vulnerabilities by Malware
Top Ten Most Active Malware
Top Ten Vulnerabilities Exploited by Ransomware
Prioritizing Exploited Vulnerabilities with TheQualys VMDR and TruRisk
Assess Your Organizations Exposure to Risk / TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributor
The previous blog from this three-part series showcased an overview of the vulnerability threat landscape. To summarize quickly, it illustrated the popular methods of exploiting vulnerabilities and the tactical techniques employed by threat actors, malware, and ransomware groups. Perhaps more crucially, we stated that commonly used solutions (CISA KEV/EPSS) of
Sentinelone
Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
blogs_sentinelone·2022-06-09
Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
## Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
## Executive Summary
Aoqin Dragon, a threat actor SentinelLABS has been extensively tracking, has operated since 2013 targeting government, education, and telecommunication organizations in Southeast Asia and Australia.
Aoqin Dragon seeks initial access primarily through document exploits and the use of fake removable devices.
Other techniques the attacker has been observed using include DLL hijacking, Themida-packed files, and DNS tunneling to evade post-compromise detection.
Based on our analysis of the targets, infrastructure and malware structure of Aoqin Dragon campaigns, we assess with moderate confidence the threat actor is a small Chinese-speaking team with potential ass
Sentinelone
Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
blogs_sentinelone·2022-06-09
Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
## Executive Summary
- Aoqin Dragon, a threat actor SentinelLABS has been extensively tracking, has operated since 2013 targeting government, education, and telecommunication organizations in Southeast Asia and Australia.
- Aoqin Dragon seeks initial access primarily through document exploits and the use of fake removable devices.
- Other techniques the attacker has been observed using include DLL hijacking, Themida-packed files, and DNS tunneling to evade post-compromise detection.
- Based on our analysis of the targets, infrastructure and malware structure of Aoqin Dragon campaigns, we assess with moderate confidence the threat actor is a small Chinese-speaking team with potential association to UNC94 (Mandiant).
## Overview
SentinelLABS has uncovered a cluster of activity beginning a
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-10
ModifiedElephant APT and a Decade of Fabricating Evidence
## ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure o
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-09
ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
- Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
- ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
- ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
- ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
- The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure overlaps that allow us to connect long periods of previou
Fortinet
Wiper Malware Riding the 2021 Tokyo Olympic Games | FortiGuard Labs
blogs_fortinet·2021-07-26·CVSS 8.8
[HIGH] Wiper Malware Riding the 2021 Tokyo Olympic Games | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Wiper Malware Riding the 2021 Tokyo Olympic Games
By Shunichi Imano and Fred Gutierrez | July 26, 2021
FortiGuard Labs Threat Research Report
As society becomes increasingly reliant on technology, and as the world is more connected than ever, attacks by threat actors are not only more prevalent but also more disruptive. Because of the variety of agendas held by different malicious entities including—cybercriminals, hacktivists, nation states, etc.—attacks and disruptions targeted at high profile events are easy targets for sowing chaos, distributing malware, capturing or exfiltrating data, or even shutting down an event altogether. But regardless of the purpose, mass disruption and fear almost always occurs whether that was the intended goal of the attack
Checkpoint
14th June – Threat Intelligence Report
blogs_checkpoint·2021-06-14
CVE-2021-21220 14th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Audi and Volkswagen have experienced data breaches that affected 3.3 million customers. Between August 2019 and May 2021, unsecured data was left exposed on the internet by a mutual vendor. During that time, an unauthorized threat actor accesses the data.
Researchers have observed a new wave of DDoS extortion by Fancy Lazarus,
Unit42
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
blogs_unit42·2020-08-26
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
Threat Research Center
Threat Research
Vulnerabilities
## The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
Jay Chen
Published: August 26, 2020
Threat Research
Vulnerabilities
Exploit
## Executive Summary
With the ever-increasing number of new vulnerabilities, vulnerability management becomes one of the most critical processes in ensuring continuous business operation. While it is clear that timely patching is essential, it’s also important to know quantitatively how a delay could increase risk. What is the chance that attackers breach my organization using a CVE just disclosed or using an unknown (zero-day) vulnerability? To understand the state of vulnerability disclosure and exploit development, Unit 42 researchers analyzed 45,450 publicly availabl
Unit42
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
blogs_unit42·2020-08-26
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
## Executive Summary
With the ever-increasing number of new vulnerabilities, vulnerability management becomes one of the most critical processes in ensuring continuous business operation. While it is clear that timely patching is essential, it’s also important to know quantitatively how a delay could increase risk. What is the chance that attackers breach my organization using a CVE just disclosed or using an unknown (zero-day) vulnerability? To understand the state of vulnerability disclosure and exploit development, Unit 42 researchers analyzed 45,450 publicly available exploits in Exploit Database at the time of this writing. The research correlated the exploit data with vulnerability and patch information to study exploit development in multiple facets.
The research reveals that:
-
Securelist
Cycldek: Bridging the (air) gap
blogs_securelist·2020-06-03
Cycldek: Bridging the (air) gap
Table of Contents
Key findings
Background
Two implants, two clusters
Info stealing and lateral movement toolset
Formerly Unreported Malware: USBCulprit
Conclusion
Appendix – IOCs
Authors
GReAT
Mark Lechtik
Giampaolo Dedola
## Key findings
While investigating attacks related to a group named Cycldek post 2018, we were able to uncover various pieces of information on its activities that were not known thus far. In this blog post we aim to bridge the knowledge gap on this group and provide a more thorough insight into its latest activities and modus operandi. Here are some key insights that will be described in this publication:
Cycldek (also known as Goblin Panda and Conimes) has been active in the past two years, conducting targeted operations against governments in Southeast
Securelist
Cycldek: Bridging the (air) gap
blogs_securelist·2020-06-03
Cycldek: Bridging the (air) gap
Table of Contents
- Key findings
- Background
- Two implants, two clusters
- Info stealing and lateral movement toolset
- Formerly Unreported Malware: USBCulprit
- Conclusion
- Appendix – IOCs
Authors
- GReAT
- Mark Lechtik
- Giampaolo Dedola
## Key findings
While investigating attacks related to a group named Cycldek post 2018, we were able to uncover various pieces of information on its activities that were not known thus far. In this blog post we aim to bridge the knowledge gap on this group and provide a more thorough insight into its latest activities and modus operandi. Here are some key insights that will be described in this publication:
- Cycldek (also known as Goblin Panda and Conimes) has been active in the past two years, conducting targeted operations against governmen
Unit42
COVID-19 Themed Malware Within Cloud Environments
blogs_unit42·2020-05-11
COVID-19 Themed Malware Within Cloud Environments
## Executive Summary
Unit 42 researchers found that public cloud infrastructure has communicated with domains known to distribute COVID-19 themed malware. On March 24, 2020, Unit 42 published a blog discussing attack patterns used by malicious actors in relation to the novel Coronavirus (COVID-19). Taking these findings a step further, researchers attempted to uncover if there are malicious COVID-19 related events taking place within public cloud infrastructure. If indications of this activity were found, how could organizations protect themselves?
Researchers identified 300+ COVID-19 themed malware samples that communicated with 20 unique IP addresses and domain indicators of compromise (IOCs). After querying Prisma Cloud for network connections to these 20 suspicious IOCs between March
Unit42
COVID-19 Themed Malware Within Cloud Environments
blogs_unit42·2020-05-11
COVID-19 Themed Malware Within Cloud Environments
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## COVID-19 Themed Malware Within Cloud Environments
Nathaniel Quist
Published: May 11, 2020
Cloud Cybersecurity Research
Malware
Threat Research
COVID
NetFlow
## Executive Summary
Unit 42 researchers found that public cloud infrastructure has communicated with domains known to distribute COVID-19 themed malware. On March 24, 2020, Unit 42 published a blog discussing attack patterns used by malicious actors in relation to the novel Coronavirus (COVID-19). Taking these findings a step further, researchers attempted to uncover if there are malicious COVID-19 related events taking place within public cloud infrastructure. If indications of this activity were found, how could organizations protect themselves?
Tenable
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
blogs_tenable·2020-04-30
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Malicious Attackers Target Government and Medical Organizations With COVID-19 Themed Phishing Campaigns
blogs_unit42·2020-04-14
Malicious Attackers Target Government and Medical Organizations With COVID-19 Themed Phishing Campaigns
## Executive Summary
Despite prior reporting by various sources indicating that some cyber threat attacker activity may subside in some respects during the COVID-19 pandemic, Unit 42 has observed quite the opposite with regard to COVID-19 themed threats, particularly in the realm of phishing attacks.
While the various COVID-19 themed phishing campaigns observed by Unit 42 are numerous, this blog seeks to provide a thorough picture and solid technical analysis of the cross-section between the various types of COVID-19 themed threats organizations may be facing during the ongoing pandemic. Specifically, we address a ransomware variant (EDA2) observed in attacks on a Canadian government healthcare organization and a Canadian medical research university, as well as an infostealer variant (Ag
Unit42
Malicious Attackers Target Government and Medical Organizations With COVID-19 Themed Phishing Campaigns
blogs_unit42·2020-04-14
Malicious Attackers Target Government and Medical Organizations With COVID-19 Themed Phishing Campaigns
Threat Research Center
Threat Research
Ransomware
## Malicious Attackers Target Government and Medical Organizations With COVID-19 Themed Phishing Campaigns
Adrian McCabe
Vicky Ray
Juan Cortes
Published: April 14, 2020
Ransomware
Threat Research
COVID
Infostealer
Phishing
## Executive Summary
Despite prior reporting by various sources indicating that some cyber threat attacker activity may subside in some respects during the COVID-19 pandemic, Unit 42 has observed quite the opposite with regard to COVID-19 themed threats, particularly in the realm of phishing attacks.
While the various COVID-19 themed phishing campaigns observed by Unit 42 are numerous , this blog seeks to provide a thorough picture and solid technical analysis of the cross-section between the various ty
Unit42
Don’t Panic: COVID-19 Cyber Threats
blogs_unit42·2020-03-24
Don’t Panic: COVID-19 Cyber Threats
Threat Research Center
Threat Research
Malware
## Don’t Panic: COVID-19 Cyber Threats
Ryan Olson
Published: March 24, 2020
Malware
Threat Research
COVID Phishing
Secure Remote Workforce
## Executive Summary
When people ask me what Unit 42 does, the most concise answer I can normally give is “we research bad guys doing bad things.” With the onset of the COVID-19 pandemic spreading around the world, many of us have had to adapt our lives to accommodate the new reality. Bad guys are no different. They’ve also adapted and are taking advantage of this pandemic to launch cyber attacks.
The biggest opportunity for cyber attackers with this outbreak has nothing to do with technology, but with how humans change their behavior and patterns in response to the crisis.
The purpose of t
Unit42
Don’t Panic: COVID-19 Cyber Threats
blogs_unit42·2020-03-24
Don’t Panic: COVID-19 Cyber Threats
## Executive Summary
When people ask me what Unit 42 does, the most concise answer I can normally give is “we research bad guys doing bad things.” With the onset of the COVID-19 pandemic spreading around the world, many of us have had to adapt our lives to accommodate the new reality. Bad guys are no different. They’ve also adapted and are taking advantage of this pandemic to launch cyber attacks.
The biggest opportunity for cyber attackers with this outbreak has nothing to do with technology, but with how humans change their behavior and patterns in response to the crisis.
The purpose of this report is not to contribute to the fear and anxiety many of us are already experiencing, but to help you be informed about what is happening and how to protect yourself and your organization. We w
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
CVE-2018-
Unit42
PKPLUG: Chinese Cyber Espionage Group Attacking Southeast Asia
blogs_unit42·2019-10-03
PKPLUG: Chinese Cyber Espionage Group Attacking Southeast Asia
Threat Research Center
Threat Actor Groups
Nation-State Cyberattacks
## PKPLUG: Chinese Cyber Espionage Group Attacking Southeast Asia
Alex Hinchliffe
Published: October 3, 2019
Malware
Nation-State Cyberattacks
Threat Actor Groups
China
Cyber espionage
Farseer
HenBox
PKPLUG
## Executive Summary
For three years, Unit 42 has tracked a set of cyber espionage attack campaigns across Asia, which used a mix of publicly available and custom malware. Unit 42 created the moniker “PKPLUG” for the threat actor group, or groups, behind these and other documented attacks referenced later in this report. We say group or groups as our current visibility doesn’t allow us to determine with high confidence if this is the work of one group, or more than one group which uses the same tools
Unit42
PKPLUG: Chinese Cyber Espionage Group Attacking Southeast Asia
blogs_unit42·2019-10-03
PKPLUG: Chinese Cyber Espionage Group Attacking Southeast Asia
# Executive Summary
For three years, Unit 42 has tracked a set of cyber espionage attack campaigns across Asia, which used a mix of publicly available and custom malware. Unit 42 created the moniker “PKPLUG” for the threat actor group, or groups, behind these and other documented attacks referenced later in this report. We say group or groups as our current visibility doesn’t allow us to determine with high confidence if this is the work of one group, or more than one group which uses the same tools and has the same tasking. The name comes from the tactic of delivering PlugX malware inside ZIP archive files as part of a DLL side-loading package. The ZIP file format contains the ASCII magic-bytes “PK” in its header, hence PKPLUG.
While tracking these attackers, Unit 42 discovered addition
Trendmicro
Backdoor-Variante infiziert Word-Dokumente und PDFs
blogs_trendmicro·2019-08-26·CVSS 7.3
[HIGH] Backdoor-Variante infiziert Word-Dokumente und PDFs
Malware
## Backdoor-Variante infiziert Word-Dokumente und PDFs
Sicherheitsforscher stießen auf Asruex in einer PDF-Datei und stellten fest, dass eine Variante der Malware auch als Infector fungieren kann, insbesondere durch die Ausnutzung alter Schwachstellen.
By: Trend Micro Aug 26, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Ian Mercado and Mhica Romero
Asruex wurde 2015 zum ersten Mal gesichtet und ist bekannt für seine Backdoor-Funktionen und die Verbindung zur Spyware DarkHotel. Nun stießen die Sicherheitsforscher auf Asruex in einer PDF-Datei und stellten fest, dass eine Variante der Malware auch als Infector fungieren kann, insbesondere durch die Ausnutzung alter Schwachstellen wie CVE-2012-0158 und CVE-2010-2883, die Code in Word- bzw. PDF-Dateien injizieren.
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Cyber Threats
# Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero
2019/08/22
Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities cou
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Cyber Threats
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero 2019/08/22 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities co
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Cyberbedrohungen
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabiliti
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Cyber Threats
# Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero
Aug 22, 2019
Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities c
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Ciberamenazas
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Cyber Threats
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Minacce cyber
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities
Fortinet
CTA Adversary Playbook: Goblin Panda
blogs_fortinet·2018-11-01·CVSS 8.8
[HIGH] CTA Adversary Playbook: Goblin Panda
FORTIGUARD LABS THREAT RESEARCH
CTA Adversary Playbook: Goblin Panda
By FortiGuard SE Team | November 01, 2018
Adversary Playbook: The FortiGuard SE Team is releasing this new playbook on the threat actor group known as Goblin Panda as part of its role in the Cyber Threat Alliance. For more information regarding this series of adversary playbooks being created by CTA members, please visit the Cyber Threat Alliance Playbook Whitepaper.
Active since 2014, Goblin Panda is a threat actor that is focused on interests in Southeast Asia. Goblin Panda has been documented by various organizations, including Fortinet, over the past several years. Due to non-standardized naming conventions within the industry, Goblin Panda is also known as APT 27, Hellsing, Cycledek, and perhaps 1937CN. Goblin Pan
Unit42
Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository
blogs_unit42·2017-10-27·CVSS 8.8
CVE-2012-0158 [HIGH] Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository
## Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository
Unit 42
Published: October 27, 2017
Malware
Threat Research
Vulnerabilities
CVE-2012-0158
Downloader
Phishing
QuasarRAT
Subaat
In mid-July, Palo Alto Networks Unit 42 identified a small targeted phishing campaign aimed at a government organization. While tracking the activities of this campaign, we identified a repository of additional malware, including a web server that was used to host the payloads used for both this attack as well as others. We’ll discuss how we discovered it, as well as possible attribution towards the individual behind these attacks.
The Initial Attack
Beginning on July 16, 2017, Unit 42 observed a small wave of phishing emails targeting a US-based government organization. W
Unit42
Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository
blogs_unit42·2017-10-27·CVSS 8.8
[HIGH] Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository
In mid-July, Palo Alto Networks Unit 42 identified a small targeted phishing campaign aimed at a government organization. While tracking the activities of this campaign, we identified a repository of additional malware, including a web server that was used to host the payloads used for both this attack as well as others. We’ll discuss how we discovered it, as well as possible attribution towards the individual behind these attacks.
The Initial Attack
Beginning on July 16, 2017, Unit 42 observed a small wave of phishing emails targeting a US-based government organization. We observed a total of 43 emails with the following subject lines:
- Invention
- Invention Event
Within the 43 emails we observed, we found that three unique files were delivered, which consisted of two RTFs and a Micr
Unit42
BadPatch
blogs_unit42·2017-10-20
BadPatch
## BadPatch
Tomer Bar
Simon Conant
Published: October 20, 2017
Malware
Threat Research
BadPatch
KASPERAGENT
MICROPSIA
## Introduction
In April 2017, in collaboration with Clearsky, Palo Alto Networks Unit 42 published an article about our research into targeted attacks in the Middle East. In that research we discussed two new malware families we named KASPERAGENT and MICROPSIA.
Since then, we have continued our research into the Command and Control (C2) infrastructure associated with KASPERAGENT and MICROPSIA. This ongoing research lead us to a new Middle Eastern campaign. Our findings from this new campaign include C2 infrastructure, new attack methods, four types of malware (including Android malware), a system for management of stolen victim data and some detail of the act
Unit42
BadPatch
blogs_unit42·2017-10-20
BadPatch
## Introduction
In April 2017, in collaboration with Clearsky, Palo Alto Networks Unit 42 published an article about our research into targeted attacks in the Middle East. In that research we discussed two new malware families we named KASPERAGENT and MICROPSIA.
Since then, we have continued our research into the Command and Control (C2) infrastructure associated with KASPERAGENT and MICROPSIA. This ongoing research lead us to a new Middle Eastern campaign. Our findings from this new campaign include C2 infrastructure, new attack methods, four types of malware (including Android malware), a system for management of stolen victim data and some detail of the actors.
It is notable that our research has shown that this newly-identified attack campaign dates back to at least June 2012, over
Fortinet
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
blogs_fortinet·2017-09-05·CVSS 8.8
CVE-2012-0158 [HIGH] Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
FORTIGUARD LABS THREAT RESEARCH
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
By Jasper Manuel and Artem Semenchenko | September 05, 2017
Recently, FortiGuard Labs came across several malicious documents that exploit the vulnerability CVE-2012-0158. To evade suspicion from the victim, these RTF files drop decoy documents containing politically themed texts about a variety of Vietnamese government-related information. It was believed in a recent report that the hacking campaign where these documents were used was led by the Chinese hacking group 1937CN. The link to the group was found through malicious domains used as command and control servers by the attacker. In this blog, we will delve into the malware used in this campaign and will try to provide more clues as to
Talos
When combining exploits for added effect goes wrong
blogs_talos·2017-08-14·CVSS 8.8
CVE-2017-0199 [HIGH] When combining exploits for added effect goes wrong
### IntroductionSince public disclosure in April 2017,CVE-2017-0199has been frequently used within malicious Office documents. The vulnerability allows attackers to include Ole2Link objects within RTF documents to launch remote code when HTA applications are opened and parsed by Microsoft Word.
In this recent campaign, attackers combined CVE-2017-0199 exploitation with an earlier exploit, CVE-2012-0158, possibly in an attempt to evade user prompts by Word, or to arrive at code execution via a different mechanism. Potentially, this was just a test run in order to test a new concept. In any case, the attackers made mistakes which caused the attack to be a lot less effective than it could have been.
Analysis of the payload highlights the potential for the Ole2Link exploit to launch other do
Talos
When combining exploits for added effect goes wrong
blogs_talos·2017-08-14·CVSS 8.8
CVE-2017-0199 [HIGH] When combining exploits for added effect goes wrong
## When combining exploits for added effect goes wrong
## Introduction Since public disclosure in April 2017, CVE-2017-0199 has been frequently used within malicious Office documents. The vulnerability allows attackers to include Ole2Link objects within RTF documents to launch remote code when HTA applications are opened and parsed by Microsoft Word.
In this recent campaign, attackers combined CVE-2017-0199 exploitation with an earlier exploit, CVE-2012-0158 , possibly in an attempt to evade user prompts by Word, or to arrive at code execution via a different mechanism. Potentially, this was just a test run in order to test a new concept. In any case, the attackers made mistakes which caused the attack to be a lot less effective than it could have been.
Analysis of the payload highlight
Trendmicro
The Trail of BlackTech’s Cyber Espionage Campaigns
blogs_trendmicro·2017-06-22·CVSS 9.8
[CRITICAL] The Trail of BlackTech’s Cyber Espionage Campaigns
# The Trail of BlackTech’s Cyber Espionage Campaigns
Following the activities and evolving tactics of cyberespionage group BlackTech helped us uncover the proverbial red string of fate that connected three seemingly disparate campaigns: PLEAD, Shrouded Crossbow, and of late, Waterbear.
By: Lenart Bermejo, Razor Huang, CH Lei
2017/06/22
Read time: ( words)
Save to Folio
BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes and domain names of some of their C&C servers, BlackTech’s campaigns are likely designed to steal their target’s technology.
Following their activities and evolving tactics and techniques helped us uncover the proverbial red string of fate that connected three see
Securelist
InPage zero-day exploit used to attack financial institutions in Asia
blogs_securelist·2016-11-23·CVSS 8.8
[HIGH] InPage zero-day exploit used to attack financial institutions in Asia
Table of Contents
Discovery and analysis
Technical details
Inside weaponized documents
Victims
Conclusions
Indicators of compromise:
Hashes
C&Cs used in the samples dropped by the weaponized InPage documents:
Authors
Denis Legezo
In September 2016, while researching a new wave of attacks, we found an interesting target which appeared to constantly receive spearphishes, a practice we commonly describe as a “magnet of threats”. Among all the attacks received by this magnet of threats, which included various older Office exploits such as CVE-2012-0158, one of them attracted our attention. This file, which was also uploaded to a multiscanner service in September 2016, had an extension that we were unfamiliar with – “.inp”. Further investigation revealed this was an InPage document.
Securelist
InPage zero-day exploit used to attack financial institutions in Asia
blogs_securelist·2016-11-23·CVSS 8.8
CVE-2012-0158 [HIGH] InPage zero-day exploit used to attack financial institutions in Asia
Table of Contents
- Discovery and analysis
- Technical details
- Inside weaponized documents
- Victims
- Conclusions
- Indicators of compromise:
Authors
- Denis Legezo
In September 2016, while researching a new wave of attacks, we found an interesting target which appeared to constantly receive spearphishes, a practice we commonly describe as a “magnet of threats”. Among all the attacks received by this magnet of threats, which included various older Office exploits such as CVE-2012-0158, one of them attracted our attention. This file, which was also uploaded to a multiscanner service in September 2016, had an extension that we were unfamiliar with – “.inp”. Further investigation revealed this was an InPage document. InPage, in case you are wondering, is publishing and text processing
Unit42
Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy
blogs_unit42·2016-11-22·CVSS 8.8
[HIGH] Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy
Taiwan has been a regular target of cyber espionage threat actors for a number of years. Reasons for Taiwan being targeted range from being one of the sovereign states of the disputed South China Sea region to its emerging economy and growth with Taiwan being one of the most innovative countries in the High-Tech industry in Asia.
In early August, Unit 42 identified two attacks using similar techniques. The more interesting one was a targeted attack towards the Secretary General of Taiwan's Government office – Executive Yuan. The Executive Yuan has several individual boards which are formed to enforce different executing functions of the government. The Executive Yuan Council evaluates statutory and budgetary bills and bills concerning martial law, amnesty, declaration of war, conclusion o
Unit42
Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy
blogs_unit42·2016-11-22
Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy
Threat Research Center
Threat Research
Malware
## Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy
Vicky Ray
Robert Falcone
Jen Miller-Osborn
Tom Lancaster
Published: November 22, 2016
Malware
Threat Research
APAC
Poison Ivy
Spear Phishing
Taiwan
Threat research
Tropic Trooper
Taiwan has been a regular target of cyber espionage threat actors for a number of years. Reasons for Taiwan being targeted range from being one of the sovereign states of the disputed South China Sea region to its emerging economy and growth with Taiwan being one of the most innovative countries in the High-Tech industry in Asia.
In early August, Unit 42 identified two attacks using similar techniques. The more interesting one was a targeted attack towards the S
Securelist
IT threat evolution Q3 2016
blogs_securelist·2016-11-03·CVSS 8.8
[HIGH] IT threat evolution Q3 2016
Table of Contents
Overview
Targeted attacks and malware campaigns
Dropping Elephant
ProjectSauron
ShadowBrokers
Operation Ghoul
Malware stories
Lurk
Ransomware
Data breaches
Authors
David Emm
Statistics
Download the full report (PDF)
## Overview
## Targeted attacks and malware campaigns
## Dropping Elephant
Targeted attack campaigns don’t need to be technically advanced in order to be successful. In July 2016 we reported on a group called Dropping Elephant (also known as ‘Chinastrats’ and ‘Patchwork’). Using a combination of social engineering, old exploit code and some PowerShell-based malware this group was able to steal sensitive data from its victims.
This group, which has been active since November 2015, targets high profile diplomatic and economic organizations lin
Securelist
IT threat evolution Q3 2016
blogs_securelist·2016-11-03·CVSS 8.8
[HIGH] IT threat evolution Q3 2016
Table of Contents
- Overview
Authors
- David Emm
Statistics
Download the full report (PDF)
## Overview
### Targeted attacks and malware campaigns
#### Dropping Elephant
Targeted attack campaigns don’t need to be technically advanced in order to be successful. In July 2016 we reported on a group called Dropping Elephant (also known as ‘Chinastrats’ and ‘Patchwork’). Using a combination of social engineering, old exploit code and some PowerShell-based malware this group was able to steal sensitive data from its victims.
This group, which has been active since November 2015, targets high profile diplomatic and economic organizations linked to China’s foreign relations – an interest that is evident from the themes the attackers use to trap their victims.
The attackers use a combinat
Unit42
PSA: Conference Invite used as a Lure by Operation Lotus Blossom Actors
blogs_unit42·2016-10-28·CVSS 8.8
[HIGH] PSA: Conference Invite used as a Lure by Operation Lotus Blossom Actors
Threat Research Center
Threat Research
Malware
## PSA: Conference Invite used as a Lure by Operation Lotus Blossom Actors
Robert Falcone
Published: October 28, 2016
Malware
Threat Research
Cybersecurity Summit Jakarta
Emissary Trojan
Operation Lotus Blossom
Threat research
Actors related to the Operation Lotus Blossom campaign continue their attack campaigns in the Asia Pacific region. It appears that these threat actors have begun using Palo Alto Networks upcoming Cyber Security Summit hosted on November 3, 2016 in Jakarta, Indonesia as a lure to compromise targeted individuals. The payload installed in attacks using this lure is a variant of the Emissary Trojan that we have analyzed in the past, which has direct links to threat actors associated with Operation Lotus Blossom
Unit42
PSA: Conference Invite used as a Lure by Operation Lotus Blossom Actors
blogs_unit42·2016-10-28·CVSS 8.8
[HIGH] PSA: Conference Invite used as a Lure by Operation Lotus Blossom Actors
Actors related to the Operation Lotus Blossom campaign continue their attack campaigns in the Asia Pacific region. It appears that these threat actors have begun using Palo Alto Networks upcoming Cyber Security Summit hosted on November 3, 2016 in Jakarta, Indonesia as a lure to compromise targeted individuals. The payload installed in attacks using this lure is a variant of the Emissary Trojan that we have analyzed in the past, which has direct links to threat actors associated with Operation Lotus Blossom.
As our readers and customers in Indonesia are likely recipients of this phishing e-mail, we want to release some key facts to clarify the situation.
1. The malicious email will have an attachment named “[FREE INVITATIONS] CyberSecurity Summit.doc” that if opened will exploit CVE-2012
Unit42
Fresh Baked HOMEKit-made Cookles – With a DarkHotel Overlap
blogs_unit42·2016-08-12·CVSS 8.8
CVE-2012-0158 [HIGH] Fresh Baked HOMEKit-made Cookles – With a DarkHotel Overlap
Threat actors tend to reuse certain tools, a trend we observed during recent Unit 42 research published on MNKit. In this post, we will discuss a fresh toolkit, which on the surface, appeared similar to MNKit, but functionally was found to be quite different.
This toolkit, which we named “HOMEKit”, is similar to MNKit in that it is also designed to generate weaponized Microsoft Word documents containing an exploit for CVE-2012-0158, but it uses OLE instead of MHTML files. In addition, we have been able to track the use of HOMEKit by its operators since 2013 across a variety of campaigns, using several different variants of the toolkit. For this post, we will be focusing on the most recent example of the HOMEKit toolkit, in addition to an interesting overlap we discovered with the well-kno
Unit42
Fresh Baked HOMEKit-made Cookles – With a DarkHotel Overlap
blogs_unit42·2016-08-12·CVSS 8.8
[HIGH] Fresh Baked HOMEKit-made Cookles – With a DarkHotel Overlap
Threat Research Center
Threat Research
Malware
## Fresh Baked HOMEKit-made Cookles – With a DarkHotel Overlap
Bryan Lee
Robert Falcone
Published: August 12, 2016
Malware
Threat Research
Cookle
DarkHotel
HOMEKit
Microsoft
Phishing
Trojan
Threat actors tend to reuse certain tools, a trend we observed during recent Unit 42 research published on MNKit . In this post, we will discuss a fresh toolkit, which on the surface, appeared similar to MNKit, but functionally was found to be quite different.
This toolkit, which we named “HOMEKit”, is similar to MNKit in that it is also designed to generate weaponized Microsoft Word documents containing an exploit for CVE-2012-0158, but it uses OLE instead of MHTML files. In addition, we have been able to track the use of HOMEKit by its o
Unit42
Recent MNKit Exploit Activity Reveals Some Common Threads
blogs_unit42·2016-06-30·CVSS 8.8
CVE-2012-0158 [HIGH] Recent MNKit Exploit Activity Reveals Some Common Threads
Threat Research Center
Threat Research
Malware
## Recent MNKit Exploit Activity Reveals Some Common Threads
Anthony Kasza
Published: June 30, 2016
Malware
Threat Research
Vulnerabilities
CVE-2012-0158
LURKo Ghost
MNKit
NetTraveler
Payload
Saker
Unit 42 recently identified a variant of MNKit-weaponized documents being used to deliver LURK0 Gh0st, NetTraveler, and Saker payloads. The documents were delivered to targets involved with universities, NGOs, and political/human rights groups concerning Islam and South Asia. Reuse of this MNKit variant, sender email addresses, email subject lines, attachment filenames, command and control domains, XOR keys, and targeted recipients show a connection between the different payload families delivered.
MNKit is the name given to a buil
Unit42
Recent MNKit Exploit Activity Reveals Some Common Threads
blogs_unit42·2016-06-30·CVSS 8.8
[HIGH] Recent MNKit Exploit Activity Reveals Some Common Threads
Unit 42 recently identified a variant of MNKit-weaponized documents being used to deliver LURK0 Gh0st, NetTraveler, and Saker payloads. The documents were delivered to targets involved with universities, NGOs, and political/human rights groups concerning Islam and South Asia. Reuse of this MNKit variant, sender email addresses, email subject lines, attachment filenames, command and control domains, XOR keys, and targeted recipients show a connection between the different payload families delivered.
MNKit is the name given to a builder that generates CVE-2012-0158 exploit documents. The documents are in MHTML format and install a malicious payload on the compromised host. We believe MNKit is privately shared between multiple attack groups, but is not widely available.
Information about pr
Unit42
ProjectM: Link Found Between Pakistani Actor and Operation Transparent Tribe
blogs_unit42·2016-03-25·CVSS 7.8
[HIGH] ProjectM: Link Found Between Pakistani Actor and Operation Transparent Tribe
Be the first to receive the latest news, cyber threat intelligence and research from Unit 42. Subscribe Now.
Unit 42 is currently researching an attack campaign that targets government and military personnel of India. This attack appears to overlap with the Operation Transparent Tribe and Operation C-Major campaigns that targeted Indian embassies in Saudi Arabia and Kazakhstan, as well as the Indian military.
We are tracking the group of actors involved in this campaign as ‘ProjectM.’ During our research, we found a linkage between the infrastructure used by ProjectM and an individual from Pakistan. We cannot definitively confirm this individual is involved with this attack campaign, but the evidence that we will discuss in this blog post suggests that it is highly likely that this indiv
Unit42
ProjectM: Link Found Between Pakistani Actor and Operation Transparent Tribe
blogs_unit42·2016-03-25·CVSS 7.8
[HIGH] ProjectM: Link Found Between Pakistani Actor and Operation Transparent Tribe
## ProjectM: Link Found Between Pakistani Actor and Operation Transparent Tribe
Robert Falcone
Simon Conant
Published: March 25, 2016
Malware
Threat Actor Groups
Threat Research
Operation C-Major
Operation Transparent Tribe
ProjectM
Trojan
Be the first to receive the latest news, cyber threat intelligence and research from Unit 42. Subscribe Now .
Unit 42 is currently researching an attack campaign that targets government and military personnel of India. This attack appears to overlap with the Operation Transparent Tribe and Operation C-Major campaigns that targeted Indian embassies in Saudi Arabia and Kazakhstan, as well as the Indian military.
We are tracking the group of actors involved in this campaign as ‘ProjectM.’ During our research, we found a linkage between the inf
Unit42
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
blogs_unit42·2016-03-14
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
Unit 42 has collected multiple spear phishing emails, weaponized document files, and payloads that targeted various offices of the Mongolian government during the time period of August 2015 and February 2016. The phishing emails and document files leveraged a variety of geopolitically sensitive subject matters as attractive lures, such as events in Beijing, the Dalai Lama, North Korea relations, the Zika virus, and various legitimate appearing announcements. As we began to analyze and tear down the various samples we collected, we found significant overlaps with previously reported and documented adversary groups, attack campaigns, and their toolsets, exemplifying the concept of the Digital Quartermaster.
The concept of the Digital Quartermaster is not a particularly new one; it is the id
Unit42
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
blogs_unit42·2016-03-14
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
Threat Research Center
Threat Research
Malware
## Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government
Josh Grunzweig
Robert Falcone
Bryan Lee
Published: March 14, 2016
Malware
Threat Research
BBSRAT
Cmstar
Digital Quartermaster
Mongolia
Unit 42 has collected multiple spear phishing emails, weaponized document files, and payloads that targeted various offices of the Mongolian government during the time period of August 2015 and February 2016 . The phishing emails and document files leveraged a variety of geopolitically sensitive subject matters as attractive lures, such as events in Beijing, the Dalai Lama, North Korea relations, the Zika virus, and various legitimate appearing announcements. As we began to analyze and tear down the variou
Unit42
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
blogs_unit42·2016-01-24
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
Threat Research Center
Threat Research
Malware
## Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
Robert Falcone
Jen Miller-Osborn
Published: January 24, 2016
Malware
Threat Research
Android
Apple
BrutishCommand
CallMe
Cyber espionage
Cyber Threat Alliance
Cybersecurity
Espionage
FakeM
Mac OS X
Microsoft
MobileOrder
Psylo
Scarlet Mimic
SkiBoot Loader
SubtractThis
Trojans
## Executive Summary
Over the past seven months, Unit 42 has been investigating a series of attacks we attribute to a group we have code named “Scarlet Mimic.” The attacks began over four years ago and their targeting pattern suggests that this adversary’s primary mission is to gather information about minority rights activists. We do not have evidence directly linking
Unit42
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
blogs_unit42·2016-01-24
Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists
## Executive Summary
Over the past seven months, Unit 42 has been investigating a series of attacks we attribute to a group we have code named “Scarlet Mimic.” The attacks began over four years ago and their targeting pattern suggests that this adversary’s primary mission is to gather information about minority rights activists. We do not have evidence directly linking these attacks to a government source, but the information derived from these activities supports an assessment that a group or groups with motivations similar to the stated position of the Chinese government in relation to these targets is involved.
The goal of this report is to expose the tools, tactics and infrastructure deployed by Scarlet Mimic in order to increase awareness of this threat and decrease its operational
Unit42
NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
blogs_unit42·2016-01-21·CVSS 8.8
CVE-2012-0158 [HIGH] NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
Unit 42 recently identified a targeted attack against an individual working for the Foreign Ministry of Uzbekistan in China. A spear-phishing email was sent to a diplomat of the Embassy of Uzbekistan who is likely based in Beijing, China. In this report, we’ll review how the actors attempted to exploit CVE-2012-0158 to install the NetTraveler Trojan.
On December 12, 2015, a spear-phishing email was sent to a diplomat of the Embassy of Uzbekistan. The body and subject of the email suggests that the email was spoofed to look like it was sent by the Russian Foreign Ministry and the attachment may contain an official annual report on CHS (Council of Heads of Member States), who form the SCO (Shanghai Cooperation Organization).
Filename: “2015.12.11_сроки СГГ 2015 в Уфе.doc.doc” (translated t
Unit42
NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
blogs_unit42·2016-01-21·CVSS 8.8
[HIGH] NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
## NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistan
Vicky Ray
Robert Falcone
Published: January 21, 2016
Malware
Threat Research
NetTraveler
Spear Phishing
Trojan
Ufa
Ufe
Uzbekistan
Unit 42 recently identified a targeted attack against an individual working for the Foreign Ministry of Uzbekistan in China. A spear-phishing email was sent to a diplomat of the Embassy of Uzbekistan who is likely based in Beijing, China. In this report, we’ll review how the actors attempted to exploit CVE-2012-0158 to install the NetTraveler Trojan.
On December 12, 2015, a spear-phishing email was sent to a diplomat of the Embassy of Uzbekistan. The body and subject of the email suggests that the email was spoofed to look like it was sent by the Russian Foreign Ministry and the att
Unit42
As Usual, Attackers Were Busy Over the Holiday Season
blogs_unit42·2016-01-13
As Usual, Attackers Were Busy Over the Holiday Season
## As Usual, Attackers Were Busy Over the Holiday Season
Bryan Lee
Published: January 13, 2016
Malware
Ransomware
Threat Research
Festivus
Lotus Blossom
The holiday season is a time for friends and family, as well as for heightened levels of consumer shopping. It’s also a time of year when threat actors get especially opportunistic, and the 2015 holiday season was no different.
Let’s take a closer look at recent holiday season-themed attacks.
## Happy Festivus!
Unit 42 examined the time period from November 25, 2015 through December 29, 2015 and identified nearly 4 million phishing attacks containing malicious attachments using AutoFocus. Out of these phishing email messages, we then searched specifically for holiday-themes, using keywords such as “Christmas,” “holiday,” “San
Unit42
As Usual, Attackers Were Busy Over the Holiday Season
blogs_unit42·2016-01-13
As Usual, Attackers Were Busy Over the Holiday Season
The holiday season is a time for friends and family, as well as for heightened levels of consumer shopping. It’s also a time of year when threat actors get especially opportunistic, and the 2015 holiday season was no different.
Let’s take a closer look at recent holiday season-themed attacks.
### Happy Festivus!
Unit 42 examined the time period from November 25, 2015 through December 29, 2015 and identified nearly 4 million phishing attacks containing malicious attachments using AutoFocus. Out of these phishing email messages, we then searched specifically for holiday-themes, using keywords such as “Christmas,” “holiday,” “Santa,” etc. Amongst the results, 92 percent of the attacks identified to be holiday themed were already found to have a Unit 42 tag associated with it, providing add
Unit42
BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger
blogs_unit42·2015-12-22·CVSS 8.8
[HIGH] BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger
In late 2014, ESET presented an attack campaign that had been observed over a period of time targeting Russia and other Russian speaking nations, dubbed “Roaming Tiger”. The attack was found to heavily rely on RTF exploits and at the time, thought to make use of the PlugX malware family.
ESET did not attribute the attacks to a particular attack group, but noted that the objective of the campaign was espionage and general information stealing. Based on data collected from Palo Alto Networks AutoFocus threat intelligence, we discovered continued operations of activity very similar to the Roaming Tiger attack campaign that began in the August 2015 timeframe, with a concentration of attacks in late October and continuing into December.
The adversaries behind these attacks continued to target
Unit42
BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger
blogs_unit42·2015-12-22·CVSS 8.8
[HIGH] BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger
## BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger
Bryan Lee
Josh Grunzweig
Published: December 22, 2015
Malware
Threat Research
BBSRAT
Microsoft Office
PlugX
Roaming Tiger
In late 2014, ESET presented an attack campaign that had been observed over a period of time targeting Russia and other Russian speaking nations, dubbed “Roaming Tiger”. The attack was found to heavily rely on RTF exploits and at the time, thought to make use of the PlugX malware family.
ESET did not attribute the attacks to a particular attack group, but noted that the objective of the campaign was espionage and general information stealing. Based on data collected from Palo Alto Networks AutoFocus threat intelligence, we discovered continued operations of activity very similar to the
Unit42
Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media
blogs_unit42·2015-09-23·CVSS 8.8
[HIGH] Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media
## Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media
Robert Falcone
Jen Miller-Osborn
Published: September 23, 2015
Malware
Threat Research
3102
9002
Evilgrab
Trojan
On May 6 and May 11, 2015, Unit 42 observed two targeted attacks, the first against the U.S. government and the second on a European media company. Threat actors delivered the same document via spear-phishing emails to both organizations. The actors weaponized the delivery document to install a variant of the ‘9002’ Trojan called ‘3102’ that heavily relies on plugins to provide functionality needed by the actors to carry out on their objectives.
The 3102 payload used in this attack also appears to be related to the Evilgrab payload delivered in the watering hole attack hosted on the Preside
Unit42
Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media
blogs_unit42·2015-09-23·CVSS 8.8
[HIGH] Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media
On May 6 and May 11, 2015, Unit 42 observed two targeted attacks, the first against the U.S. government and the second on a European media company. Threat actors delivered the same document via spear-phishing emails to both organizations. The actors weaponized the delivery document to install a variant of the ‘9002’ Trojan called ‘3102’ that heavily relies on plugins to provide functionality needed by the actors to carry out on their objectives.
The 3102 payload used in this attack also appears to be related to the Evilgrab payload delivered in the watering hole attack hosted on the President of Myanmar’s website in May 2015. Additionally, we uncovered ties between the C2 infrastructure and individuals in China active in online hacking forums that claim to work in Trojan development.
Pal
Unit42
Evilgrab Delivered by Watering Hole Attack on President of Myanmar’s Website
blogs_unit42·2015-06-11
Evilgrab Delivered by Watering Hole Attack on President of Myanmar’s Website
## Evilgrab Delivered by Watering Hole Attack on President of Myanmar’s Website
Robert Falcone
Published: June 11, 2015
Malware
Threat Research
Evilgrab
IFRAME
JavaScript
Myanmar
Trojan
Vidgrab
Watering Hole Attack
On May 12, 2015, Unit 42 observed an apparent watering hole attack, also known as a strategic website compromise (SWC), involving the President of Myanmar's website. Visiting the main page hosted at "www.president-office.gov[.]mm" triggered the malicious content, as the threat actors injected an inline frame (IFRAME) into a JavaScript file used by Drupal for the site's theme.
Unit 42 believes threat actors chose this website to set up a watering hole in order to target and gather information on individuals in Myanmar, individuals involved in political relations wit
Unit42
Evilgrab Delivered by Watering Hole Attack on President of Myanmar’s Website
blogs_unit42·2015-06-11
Evilgrab Delivered by Watering Hole Attack on President of Myanmar’s Website
On May 12, 2015, Unit 42 observed an apparent watering hole attack, also known as a strategic website compromise (SWC), involving the President of Myanmar's website. Visiting the main page hosted at "www.president-office.gov[.]mm" triggered the malicious content, as the threat actors injected an inline frame (IFRAME) into a JavaScript file used by Drupal for the site's theme.
Unit 42 believes threat actors chose this website to set up a watering hole in order to target and gather information on individuals in Myanmar, individuals involved in political relations with the country and/or organizations doing business in Myanmar. Unit 42 has evidence to suggest the threat actors have had access to the website since November 2014 if not earlier.
Shortly after we reported the infection to the o
Unit42
Cmstar Downloader: Lurid and Enfal's New Cousin
blogs_unit42·2015-05-18·CVSS 8.8
CVE-2012-0158 [HIGH] Cmstar Downloader: Lurid and Enfal's New Cousin
In recent weeks, Unit 42 has been analyzing delivery documents used in spear-phishing attacks that drop a custom downloader used in cyber espionage attacks. This specific downloader, Cmstar, is associated with the Lurid downloader also known as ‘Enfal’. Cmstar was named for the log message ‘CM**’ used by the downloader.
Unit 42 is aware of threat actors using two toolkits - MNKit and the Tran Duy Linh toolkit - to produce malicious documents that exploit CVE-2012-0158 in order to implant Cmstar. The Cmstar downloader itself has several unique and interesting features, as well as substantial infrastructure overlap with other tools worth discussing.
### Manual Building of Import Address Table
The Cmstar downloader starts by manually building its import address table (IAT), much like shell
Unit42
Cmstar Downloader: Lurid and Enfal's New Cousin
blogs_unit42·2015-05-18·CVSS 8.8
[HIGH] Cmstar Downloader: Lurid and Enfal's New Cousin
## Cmstar Downloader: Lurid and Enfal's New Cousin
Robert Falcone
Published: May 18, 2015
Malware
Threat Research
Cmstar
Enfal
Lurid
Spear Phishing
In recent weeks, Unit 42 has been analyzing delivery documents used in spear-phishing attacks that drop a custom downloader used in cyber espionage attacks. This specific downloader, Cmstar, is associated with the Lurid downloader also known as ‘Enfal’. Cmstar was named for the log message ‘CM**’ used by the downloader.
Unit 42 is aware of threat actors using two toolkits - MNKit and the Tran Duy Linh toolkit - to produce malicious documents that exploit CVE-2012-0158 in order to implant Cmstar. The Cmstar downloader itself has several unique and interesting features, as well as substantial infrastructure overlap with other tools wor
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
- Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
- Internet Explorer: MS14-021 for CVE-2014-1776, Qualys ID: 100191
- MS14-012 for CVE-201
Unit42
PlugX Uses Legitimate Samsung Application for DLL Side-Loading
blogs_unit42·2015-05-01·CVSS 8.8
[HIGH] PlugX Uses Legitimate Samsung Application for DLL Side-Loading
### Summary
While threat actors using the PlugX Trojan typically leverage legitimate executables to load their malicious DLLs through a technique called DLL side-loading, Unit 42 has observed a new executable in use for this purpose. Threat actors are now using this previously unseen executable, created by Samsung, to load variants of the PlugX Trojan.
Using our AutoFocus threat intelligence service, we have flagged these variants to help users identify related attacks.
### Malware Details
This story starts with the analysis of a malicious Word document named 雨傘達動後教會生 態.doc (which translates to “Church ecology after the Umbrella Movement”) that was created with the infamous “Tran Duy Linh” exploit kit. This malicious document exploits CVE-2012-0158 to open a decoy document and execute
Unit42
PlugX Uses Legitimate Samsung Application for DLL Side-Loading
blogs_unit42·2015-05-01·CVSS 8.8
[HIGH] PlugX Uses Legitimate Samsung Application for DLL Side-Loading
## PlugX Uses Legitimate Samsung Application for DLL Side-Loading
Robert Falcone
Published: May 1, 2015
Malware
Threat Research
PlugX
Samsung
Trojan
## Summary
While threat actors using the PlugX Trojan typically leverage legitimate executables to load their malicious DLLs through a technique called DLL side-loading, Unit 42 has observed a new executable in use for this purpose. Threat actors are now using this previously unseen executable, created by Samsung, to load variants of the PlugX Trojan.
Using our AutoFocus threat intelligence service, we have flagged these variants to help users identify related attacks.
## Malware Details
This story starts with the analysis of a malicious Word document named 雨傘達動後教會生 態.doc (which translates to “Church ecology after the Umbrella
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
MS14-012 for CVE-2014-0322
MS13-038 for CVE-2013-1347
MS13-008 for CVE-2012-4792
MS10-01
Unit42
Super Tuesday: A Patch Tuesday We Won’t Forget
blogs_unit42·2014-10-15·CVSS 7.8
[HIGH] Super Tuesday: A Patch Tuesday We Won’t Forget
Sometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities, Adobe issued updates for Flash and ColdFusion, and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that three of the Microsoft vulnerabilities were being exploited in targeted attack campaigns.
### Sandworm
The first to drop was the Sandworm Campaign, a report from iSight partners, which described attacks on European and American targets in the month of August using new versions of the BlackEnergy bot, but the group behind the attacks has been operating since at least 2009. The biggest news here was the group’s exploitation of a “new” vulnerability in Windows, CV
Unit42
Super Tuesday: A Patch Tuesday We Won’t Forget
blogs_unit42·2014-10-15·CVSS 7.8
[HIGH] Super Tuesday: A Patch Tuesday We Won’t Forget
## Super Tuesday: A Patch Tuesday We Won’t Forget
Ryan Olson
Published: October 15, 2014
Threat Research
Vulnerabilities
BlackEnergy
ISight
Microsoft
Microsoft Security Bulletin
Patch Tuesday
PowerShell Empire
Sandworm
Sometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities , Adobe issued updates for Flash and ColdFusion , and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that three of the Microsoft vulnerabilities were being exploited in targeted attack campaigns.
## Sandworm
The first to drop was the Sandworm Campaign , a report from iSight partners, which described attacks on European and American t
Talos
CVE-2014-1761, Oh did you mean CVE-2012-2539?
blogs_talos·2014-04-08·CVSS 8.8
CVE-2014-1761 [HIGH] CVE-2014-1761, Oh did you mean CVE-2012-2539?
When the VRT first received word of a new Microsoft Word 0-day I anxiously awaited details and the ever important hash of the in-the-wild exploit to be able to research it and provide coverage through Snort, ClamAV and the FireAmp suite of products. I was especially interested when word came that it was an RTF vulnerability, as I have spent a lot of time looking at high profile RTF vulnerabilities such as the ever popular CVE-2012-0158.
When the in the wild sample finally arrived I thought someone was playing an early April Fool's joke on us: I knew this vulnerability already. More than that, I had written the coverage for this almost a year and half ago! The vulnerability appeared to be CVE-2012-2539, which was released December 11th 2012 as Microsoft Security Bulletin MS12-079. I checke
Talos
CVE-2014-1761, Oh did you mean CVE-2012-2539?
blogs_talos·2014-04-08·CVSS 8.8
CVE-2014-1761 [HIGH] CVE-2014-1761, Oh did you mean CVE-2012-2539?
## CVE-2014-1761, Oh did you mean CVE-2012-2539?
When the VRT first received word of a new Microsoft Word 0-day I anxiously awaited details and the ever important hash of the in-the-wild exploit to be able to research it and provide coverage through Snort, ClamAV and the FireAmp suite of products. I was especially interested when word came that it was an RTF vulnerability, as I have spent a lot of time looking at high profile RTF vulnerabilities such as the ever popular CVE-2012-0158.
When the in the wild sample finally arrived I thought someone was playing an early April Fool's joke on us: I knew this vulnerability already. More than that, I had written the coverage for this almost a year and half ago! The vulnerability appeared to be CVE-2012-2539, which was released December 11th 2012
Trendmicro
EvilGrab Malware Family Used In Targeted Attacks
blogs_trendmicro·2013-09-19·CVSS 8.8
[HIGH] EvilGrab Malware Family Used In Targeted Attacks
APT & Targeted Attacks
# EvilGrab Malware Family Used In Targeted Attacks
Recently, we spotted a new malware family that was being used in targeted attacks – the EvilGrab malware family. It is called EvilGrab due to its behavior of grabbing audio, video, and screenshots from affected machines.
By: Trend Micro
Sep 19, 2013
Read time: ( words)
Save to Folio
Recently, we spotted a new malware family that was being used in targeted attacks - the EvilGrab malware family. It is called EvilGrab due to its behavior of grabbing audio, video, and screenshots from affected machines. We detect EvilGrab under the following malware families:
- BKDR_HGDER
- BKDR_EVILOGE
- BKDR_NVICM
Looking into the feedback provided by the Smart Protection Network, EvilGrab is most prevalent in the Asia-Pacific
Trendmicro
EvilGrab Malware Family Used In Targeted Attacks
blogs_trendmicro·2013-09-19·CVSS 8.8
[HIGH] EvilGrab Malware Family Used In Targeted Attacks
APT & Targeted Attacks
# EvilGrab Malware Family Used In Targeted Attacks
Recently, we spotted a new malware family that was being used in targeted attacks – the EvilGrab malware family. It is called EvilGrab due to its behavior of grabbing audio, video, and screenshots from affected machines.
By: Trend Micro
2013/09/19
Read time: ( words)
Save to Folio
Recently, we spotted a new malware family that was being used in targeted attacks - the EvilGrab malware family. It is called EvilGrab due to its behavior of grabbing audio, video, and screenshots from affected machines. We detect EvilGrab under the following malware families:
- BKDR_HGDER
- BKDR_EVILOGE
- BKDR_NVICM
Looking into the feedback provided by the Smart Protection Network, EvilGrab is most prevalent in the Asia-Pacific re
Talos
It's not the Dalai Lama's birthday, oh and you got owned
blogs_talos·2012-07-11·CVSS 8.8
CVE-2012-0158 [HIGH] It's not the Dalai Lama's birthday, oh and you got owned
## It's not the Dalai Lama's birthday, oh and you got owned
A number of recent targeted attack campaigns have centered around the Dalai Lama, including purported plans for his birthday and calls to action for democracy in Tibet. These attacks use several popular exploits and even include attacks on Mac OS X. While investigating samples of these attacks, Alain Zidouemba and I discovered a few that were using CVE-2012-0158, which exploits a bug in the Mscomctl activex control. Observed in the wild embedded within RTF, DOC or XLS documents, RTFs are the weapon of choice for most of these attacks.
While the vulnerability was originally patched in April, attacks in the wild have evolved since then. Originally, detection consisted of identifying the following elements:
1. The magic code for a
Talos
It's not the Dalai Lama's birthday, oh and you got owned
blogs_talos·2012-07-11·CVSS 8.8
CVE-2012-0158 [HIGH] It's not the Dalai Lama's birthday, oh and you got owned
A number of recent targeted attack campaigns have centered around the Dalai Lama, including purported plans for his birthday and calls to action for democracy in Tibet. These attacks use several popular exploits and even include attacks on Mac OS X. While investigating samples of these attacks, Alain Zidouemba and I discovered a few that were using CVE-2012-0158, which exploits a bug in the Mscomctl activex control. Observed in the wild embedded within RTF, DOC or XLS documents, RTFs are the weapon of choice for most of these attacks.
While the vulnerability was originally patched in April, attacks in the wild have evolved since then. Originally, detection consisted of identifying the following elements:
1. The magic code for a stream header
2. The magic codes for either listview or tre
Krebs
Adobe, Microsoft Issue Critical Updates
blogs_krebs·2012-04-10
Adobe, Microsoft Issue Critical Updates
Adobe and Microsoft today each issued critical updates to plug security holes in their products. The patch batch from Microsoft fixes at least 11 flaws in Windows and Windows software. Adobe’s update tackles four vulnerabilities that are present in current versions of Adobe Acrobat and Reader.
Seven of the 11 bugs Microsoft fixed with today’s release earned its most serious “critical” rating, which Microsoft assigns to flaws that it believes attackers or malware could leverage to break into systems without any help from users. In its security bulletin summary for April 2012, Microsoft says it expects miscreants to quickly develop reliable exploits capable of leveraging at least four of the vulnerabilities.
Among those is an interesting weakness (MS12-024) in the way that Windows handles
Krebs
Adobe, Microsoft Issue Critical Updates – Krebs on Security
blogs_krebs·2012-04-01
Adobe, Microsoft Issue Critical Updates – Krebs on Security
Adobe and Microsoft today each issued critical updates to plug security holes in their products. The patch batch from Microsoft fixes at least 11 flaws in Windows and Windows software. Adobe’s update tackles four vulnerabilities that are present in current versions of Adobe Acrobat and Reader .
Seven of the 11 bugs Microsoft fixed with today’s release earned its most serious “critical” rating, which Microsoft assigns to flaws that it believes attackers or malware could leverage to break into systems without any help from users. In its security bulletin summary for April 2012, Microsoft says it expects miscreants to quickly develop reliable exploits capable of leveraging at least four of the vulnerabilities.
Among those is an interesting weakness ( MS12-024 ) in the way that Windows handl
Threat Intel
admin@338 (admin@338)
threat_intel·CVSS 8.8
[HIGH] admin@338 (admin@338)
# Threat Actor Profile: admin@338
ATT&CK ID: G0018
Also known as: admin@338
Suspected origin: China
## Overview
admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors. (Citation: FireEye admin@338)
## Techniques (TTPs)
### Initial Access
- T1566.001 Spearphishing Attachment
Usage: admin@338 has sent emails with malicious Microsoft Office documents attached.(Citation: FireEye admin@338)
### Execution
- T1203 Exploitation for Client Execution
Usage: admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word C
Recorded Future
Top Exploited Vulnerabilities in 2020 Affect Citrix, Microsoft Products
blogs_recorded_future
Top Exploited Vulnerabilities in 2020 Affect Citrix, Microsoft Products
## Top Exploited Vulnerabilities in 2020 Affect Citrix, Microsoft Products
This analysis focuses on ransomware, exploit kit, phishing attack, or remote access trojan co-occurrences with vulnerabilities from January 1 to December 31, 2020. We analyzed thousands of sources, including code repositories, underground forum postings, and dark web sites. This is a follow-up to our 2019 report , and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
## Executive Summary
This report highlights the top, most weaponized vulnerabilities in 2020 based on exploitation across all industries and associations with multiple types of malware. For the first time since this report’s inception in 2015, no vulnerabilities in Adobe pro
Threat Intel
APT41 (APT41, Wicked Panda, Brass Typhoon)
threat_intel
APT41 (APT41, Wicked Panda, Brass Typhoon)
# Threat Actor Profile: APT41
ATT&CK ID: G0096
Also known as: APT41, Wicked Panda, Brass Typhoon, BARIUM
Suspected origin: China
## Overview
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.(Citation: FireEye APT41 Aug 2019)(Citation: Group IB APT 41 June 202
Threat Intel
BITTER (BITTER, T-APT-17)
threat_intel·CVSS 8.8
[HIGH] BITTER (BITTER, T-APT-17)
# Threat Actor Profile: BITTER
ATT&CK ID: G1002
Also known as: BITTER, T-APT-17
Suspected origin: China
## Overview
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.(Citation: Cisco Talos Bitter Bangladesh May 2022)(Citation: Forcepoint BITTER Pakistan Oct 2016)
## Techniques (TTPs)
### Resource Development
- T1588.002 Tool
Usage: BITTER has obtained tools such as PuTTY for use in their operations.(Citation: Forcepoint BITTER Pakistan Oct 2016)
- T1608.001 Upload Malware
Usage: BITTER has registered domains to stage payloads.(Citation: Forcepoint BITTER Pakistan Oct 2016)
- T1583.001 Domains
Usage: BITTER has regis
Zscaler
Zscaler Protects against Microsoft's Patch Cycle | Round 10
blogs_zscaler·CVSS 9.3
[CRITICAL] Zscaler Protects against Microsoft's Patch Cycle | Round 10
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
# Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report, and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
### Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to shed
Recorded Future
Top Exploited Vulnerabilities in 2020 Affect Citrix, Microsoft Products
blogs_recorded_future
Top Exploited Vulnerabilities in 2020 Affect Citrix, Microsoft Products
# Top Exploited Vulnerabilities in 2020 Affect Citrix, Microsoft Products
Editor’s Note*: The following post is an excerpt of a full report. To read the entire analysis,*
to download the report as a PDF.
This analysis focuses on ransomware, exploit kit, phishing attack, or remote access trojan co-occurrences with vulnerabilities from January 1 to December 31, 2020. We analyzed thousands of sources, including code repositories, underground forum postings, and dark web sites. This is a follow-up to our 2019 report, and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
### Executive Summary
This report highlights the top, most weaponized vulnerabilities in 2020 based on exploitation across all industries and as
Threat Intel
Aoqin Dragon (Aoqin Dragon)
threat_intel·CVSS 7.8
[HIGH] Aoqin Dragon (Aoqin Dragon)
# Threat Actor Profile: Aoqin Dragon
ATT&CK ID: G1007
Also known as: Aoqin Dragon
Suspected origin: China
## Overview
Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.(Citation: SentinelOne Aoqin Dragon June 2022)
## Techniques (TTPs)
### Resource Development
- T1587.001 Malware
Usage: Aoqin Dragon has used custom malware, including Mongall and Heyoka Backdoor, in their operations.(Citation: SentinelOne Aoqin Dragon June 2022)
- T1588.002 Tool
Usage: A
Threat Intel
Tropic Trooper (Tropic Trooper, Pirate Panda, KeyBoy)
threat_intel
Tropic Trooper (Tropic Trooper, Pirate Panda, KeyBoy)
# Threat Actor Profile: Tropic Trooper
ATT&CK ID: G0081
Also known as: Tropic Trooper, Pirate Panda, KeyBoy
Suspected origin: China
## Overview
Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.(Citation: TrendMicro Tropic Trooper Mar 2018)(Citation: Unit 42 Tropic Trooper Nov 2016)(Citation: TrendMicro Tropic Trooper May 2020)
## Techniques (TTPs)
### Initial Access
- T1566.001 Spearphishing Attachment
Usage: Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments.(Citation: Unit 42 Tropic Trooper Nov 2016)(
Threat Intel
BlackTech (BlackTech, Palmerworm)
threat_intel·CVSS 9.8
[CRITICAL] BlackTech (BlackTech, Palmerworm)
# Threat Actor Profile: BlackTech
ATT&CK ID: G0098
Also known as: BlackTech, Palmerworm
Suspected origin: China
## Overview
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.(Citation: TrendMicro BlackTech June 2017)(Citation: Symantec Palmerworm Sep 2020)(Citation: Reuters Taiwan BlackTech August 2020)
## Techniques (TTPs)
### Resource Development
- T1588.003 Code Signing Certificates
Usage: BlackTech has used stolen code-signing certificates for its malicious pay
Threat Intel
APT12 (APT12, IXESHE, DynCalc)
threat_intel·CVSS 8.8
[HIGH] APT12 (APT12, IXESHE, DynCalc)
# Threat Actor Profile: APT12
ATT&CK ID: G0005
Also known as: APT12, IXESHE, DynCalc, Numbered Panda, DNSCALC
Suspected origin: China
## Overview
APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.(Citation: Meyers Numbered Panda)
## Techniques (TTPs)
### Initial Access
- T1566.001 Spearphishing Attachment
Usage: APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.(Citation: Moran 2014)(Citation: Trend Micro IXESHE 2012)
### Execution
- T1204.002 Malicious File
Usage: APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.(Citation: Moran 2014)(Citation: Trend Mi
Threat Intel
Inception (Inception, Inception Framework, Cloud Atlas)
threat_intel·CVSS 8.8
[HIGH] Inception (Inception, Inception Framework, Cloud Atlas)
# Threat Actor Profile: Inception
ATT&CK ID: G0100
Also known as: Inception, Inception Framework, Cloud Atlas
Suspected origin: Russia
## Overview
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)
## Techniques (TTPs)
### Resource Development
- T1588.002 Tool
Usage: Inception has obtained and used open-source tools such as LaZagne.(Citation: Kaspersky Cloud Atlas August 2019)
### Initial Access
- T1566.001 Spearphishing Attachment
Usage: Ince
Threat Intel
Transparent Tribe (Transparent Tribe, COPPER FIELDSTONE, APT36)
threat_intel
Transparent Tribe (Transparent Tribe, COPPER FIELDSTONE, APT36)
# Threat Actor Profile: Transparent Tribe
ATT&CK ID: G0134
Also known as: Transparent Tribe, COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM
Suspected origin: Pakistan
## Overview
Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint Operation Transparent Tribe March 2016)(Citation: Kaspersky Transparent Tribe August 2020)(Citation: Talos Transparent Tribe May 2021)
## Campaigns
- **C0011** (C0011) [2021-12-01T06:00:00.000Z to 2022-07-01T05:00:00.000Z]
C0011 was a suspected cyber espionage campaign conducted by Transparent Tribe that targeted students at universities and colleges in India. Security researchers noted this ca
arXiv
ThreatPilot: Attack-Driven Threat Intelligence Extraction
arxiv_fulltext·2025-12-21
ThreatPilot: Attack-Driven Threat Intelligence Extraction
: Attack-Driven Threat Intelligence Extraction
Ming Xu
National University of Singapore
Singapore
Singapore
[email protected]
Hongtai Wang
National University of Singapore
Singapore
Singapore
[email protected]
Jiahao Liu
National University of Singapore
Singapore
Singapore
[email protected]
Xinfeng Li
Nanyang Technological University
Singapore
Singapore
[email protected]
Zhengmin Yu
Fudan University
Shanghai
China
[email protected]
Weili Han
Fudan University
Shanghai
China
[email protected]
Hoon Wei Lim
Cyber Special Ops-R&D, NCS Group
Singapore
Singapore
[email protected]
Jin Song Dong
National University of Singapore
Singapore
Singapore
[email protected]
Jiaheng Zhang
National University of Singapore
Singapore
Singapore
[email protected]
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
arXiv
Software Updates Strategies: a Quantitative Evaluation against Advanced Persistent Threats
arxiv_fulltext·2022-05-25
Software Updates Strategies: a Quantitative Evaluation against Advanced Persistent Threats
Software Updates Strategies: a Quantitative Evaluation against Advanced Persistent Threats
Giorgio Di Tizio,
Michele Armellini,
Fabio Massacci
G. Di Tizio (corresponding author) is with University of Trento, Italy.
E-mail: [email protected]
M. Armellini is with University of Trento, Italy.
F. Massacci is with University of Trento, Italy and Vrije Universiteit Amsterdam, The Netherlands.
The final version of this paper appears in: IEEE Transactions on Software Engineering, 2022. DOI 10.1109/TSE.2022.3176674
## Abstract
Software updates reduce the opportunity for exploitation. However, since updates can also introduce breaking changes, enterprises face the problem of balancing the need to secure software with updates with the need to support operations. We propose a methodology t
arXiv
What are the attackers doing now? Automating cyber threat intelligence extraction from text on pace with the changing threat landscape: A survey
arxiv_fulltext·2021-09-14
What are the attackers doing now? Automating cyber threat intelligence extraction from text on pace with the changing threat landscape: A survey
What are the attackers doing now? Automating cyberthreat intelligence extraction from text on pace with the changing threat landscape: A survey
Md Rayhanur Rahman
[email protected]
Rezvan Mahdavi-Hezaveh
[email protected]
Laurie Williams
[email protected]
North Carolina State University
Raleigh
North Carolina
USA
Rahman et al.
## Abstract
Cyberattackers are continuously changing their strategies and techniques to bypass the security mechanisms deployed by the targeted organizations. To thwart these attackers, cyberthreat intelligence (CTI) can help organizations keep pace with ever-changing threat landscapes. Cybersecurity researchers have contributed to the automated extraction of CTI from textual sources, such as threat reports and online articles, where cyberattack strategies, proced
arXiv
Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
arxiv_fulltext·2021-02-10·CVSS 8.8
CVE-2017-11882 [HIGH] Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
Top 10 Most Exploited Vulnerabilities 2016-2019
(https://us-cert.cisa.gov/ncas/alerts/aa20-133a)
.83fcdec8a329824466f140a2e6cdfeec473a9ee2 .0
longtable[]@lllllll@
& CVSS Score & Number of Tactics & Number of Techniques &
Number of CAPECs & Number of CWEs & Number of CPEs
CVE-2017-11882 & 8.55 & 0 & 0 & 12 & 1 & 4
CVE-2017-0199 & 8.55 & 0 & 0 & 0 & 0 & 9
CVE-2017-5638 & 10.0 & 1 & 3 & 51 & 1 & 53
CVE-2012-0158 & 9.3 & 0 & 0 & 3 & 1 & 29
CVE-2019-0604 & 8.65 & 1 & 3 & 51 & 1 & 4
CVE-2017-0143 & 0.0 (not listed in BRON but NVD says high severity)
& 0 & 0 & 0 & 0 & 0
CVE-2018-4878 & 8.65 & 0 & 0 & 0 & 1 & 3
CVE-2017-8759 & 8.55 & 1 & 3 & 51 & 1 & 8
CVE-2015-1641 & 9.3 & 0 & 0 & 0 & 1 & 11
CVE-2018-7600 & 8.65 & 1 & 3 & 51 & 1 & 4
longtable
4 out of Top 10 Vulnerabilities share the follow
arXiv
An Analysis of Malware Trends in Enterprise Networks
arxiv_fulltext·2019-10-01
An Analysis of Malware Trends in Enterprise Networks
An Analysis of Malware Trends in Enterprise Networks
An Analysis of Malware Trends in Enterprise Networks
Abbas Acar1,
Long Lu 2,
A. Selcuk Uluagac 1,
Engin Kirda 2
A. Acar et al.
Florida International University
\aacar001,suluagac\@fiu.edu
Northeastern University
[email protected],[email protected]
## Abstract
We present an empirical and large-scale analysis of malware
samples captured from two different enterprises from 2017 to early 2018. Particularly, we perform threat vector, social-engineering, vulnerability and
time-series analysis on our dataset. Unlike existing malware studies, our
analysis is specifically focused on the recent enterprise malware samples. First
of all, based on our analysis on the combined datasets of two enterprises, our
results confirm the general consensu
arXiv
o-glasses: Visualizing x86 Code from Binary Using a 1d-CNN
arxiv_fulltext·2018-06-14
o-glasses: Visualizing x86 Code from Binary Using a 1d-CNN
o-glasses: Visualizing x86 Code from Binary Using a 1d-CNN
Yuhei Otsubo12
Akira Otsuka2
Mamoru Mimura32
Takeshi Sakaki4
Atsuhiro Goto2
National Police Agency, Tokyo, Japan
Institute of Information Security, Kanagawa, Japan
[email protected]
National Defense Academy, Kanagawa, Japan
The University of Tokyo, Tokyo, Japan
## Abstract
Malicious document files used in targeted attacks often contain a small program called shellcode.
It is often hard to prepare a runnable environment for dynamic analysis of these document files because they exploit specific vulnerabilities.
In these cases, it is necessary to identify the position of the shellcode in each document file to analyze it.
If the exploit code uses executable scripts such as JavaScript and Flash, it is not so hard to locate the s
http://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/http://www.securityfocus.com/bid/52911http://www.securitytracker.com/id?1026899http://www.securitytracker.com/id?1026900http://www.securitytracker.com/id?1026902http://www.securitytracker.com/id?1026903http://www.securitytracker.com/id?1026904http://www.securitytracker.com/id?1026905http://www.us-cert.gov/cas/techalerts/TA12-101A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027https://exchange.xforce.ibmcloud.com/vulnerabilities/74372https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462http://opensources.info/comment-on-the-curious-case-of-a-cve-2012-0158-exploit-by-chris-pierce/http://www.securityfocus.com/bid/52911http://www.securitytracker.com/id?1026899http://www.securitytracker.com/id?1026900http://www.securitytracker.com/id?1026902http://www.securitytracker.com/id?1026903http://www.securitytracker.com/id?1026904http://www.securitytracker.com/id?1026905http://www.us-cert.gov/cas/techalerts/TA12-101A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-027https://exchange.xforce.ibmcloud.com/vulnerabilities/74372https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15462https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0158
2012-04-10
Published
2021-11-03
Added to CISA KEV
Exploited in the wild