CVE-2013-3906
published 2013-11-06CVE-2013-3906: GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010…
PriorityP187high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-08-15
Exploited in the wild
EPSS
84.97%
99.7th percentile
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | lync | — | — |
| microsoft | lync | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | powerpoint_viewer | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →A YARA rule for CVE-2013-3906 exploits was developed by CrowdStrike when Microsoft first announced the vulnerability, and it successfully detected malicious Word documents exploiting this CVE. ↗
- →CVE-2013-3906 is exploited via crafted TIFF images embedded in Word documents; hunt for Word documents containing anomalous TIFF streams delivered via spearphishing email. ↗
- →PlugX DLL side-loading via CVE-2013-3906-linked campaigns drops files to %TEMP%\RunHelp.exe, %TEMP%\ssMUIDLL.dll, and %TEMP%\ssMUIDLL.dll.conf; detect creation of these files in the TEMP directory. ↗
- →ModifiedElephant used CVE-2013-3906 in lure documents with fake double extensions (filename.pdf.exe) in mid-2013; detect executables with double extensions delivered via email. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7mhx-7529-p5jc: GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010
ghsa_unreviewed·2022-05-14
CVE-2013-3906 [HIGH] CWE-94 GHSA-7mhx-7529-p5jc: GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.
VulnCheck
Microsoft Graphics Component Memory Corruption Vulnerability
vulncheck·2013·CVSS 7.8
CVE-2013-3906 [HIGH] CWE-94 Microsoft Graphics Component Memory Corruption Vulnerability
Microsoft Graphics Component Memory Corruption Vulnerability
Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
Affected: Microsoft Graphics Component
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2013-3906; https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2013/ms13-096?redirectedfrom=MSDN; https://cyberwarzone.com/wp-content/uploads/2014/06/CrowdStrike_Global_Threat_Report_2013.pdf; https://web.archive.org/web/20160503234007/https://www.isightpartners.com/2014/10/cve-2014-4114/; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf; https://www.group-ib.com/brochures/gib-buhtrap-rep
CISA
Microsoft Graphics Component Memory Corruption Vulnerability
cisa·2022-02-15·CVSS 7.8
CVE-2013-3906 [HIGH] CWE-94 Microsoft Graphics Component Memory Corruption Vulnerability
Vulnerability: Microsoft Graphics Component Memory Corruption Vulnerability
Affected: Microsoft Graphics Component
Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-3906
Remediation Due Date: 2022-08-15
Suricata
ET MALWARE PlugX Checkin
suricata·2013-11-14
CVE-2013-3906 ET MALWARE PlugX Checkin
ET MALWARE PlugX Checkin
Rule: alert http1 $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE PlugX Checkin"; flow:established,to_server; http.method; content:"POST"; http.uri; pcre:"/^\/[A-F0-9]{24}$/"; http.header; content:"Accept|3a 20 2a 2f 2a 0d 0a|"; startswith; pcre:"/^[A-Z]{4}/R"; content:"1|3a 20|0|0d 0a|"; fast_pattern; within:6; http.header_names; content:!"Referer"; reference:url,fireeye.com/blog/technical/cyber-exploits/2013/11/exploit-proliferation-additional-threat-groups-acquire-cve-2013-3906.html; reference:md5,17f9f999e1814b99601446f8ce7eb816; classtype:command-and-control; sid:2017714; rev:11; metadata:created_at 2013_11_14, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_14;)
Suricata
ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1
suricata·2013-11-07
CVE-2013-3906 ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1
ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1"; flow:established,to_server; http.uri; content:"/rssfeed.php?a="; fast_pattern; pcre:"/^[^&]+?&\d+$/R"; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,botnetlegalnotice.com/citadel/files/Patel_Decl_Ex20.pdf; reference:url,www.fireeye.com/blog/technical/cyber-exploits/2013/11/the-dual-use-exploit-cve-2013-3906-used-in-both-targeted-attacks-and-crimeware-campaigns.html; classtype:command-and-control; sid:2017690; rev:4; metadata:attack_target Client_Endpoint, created_at 2013_11_07, deployment Perimeter, signature_severity Major, tag c2, updated_at 2024_04_20, mitre_tactic_id TA0010, mitre_tactic_name Exfi
Suricata
ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2
suricata·2013-11-07
CVE-2013-3906 ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2
ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2"; flow:established,to_server; http.uri; content:"/psp.php?p="; content:"&g="; content:"&s="; content:"&t="; content:"&r="; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,botnetlegalnotice.com/citadel/files/Patel_Decl_Ex20.pdf; reference:url,www.fireeye.com/blog/technical/cyber-exploits/2013/11/the-dual-use-exploit-cve-2013-3906-used-in-both-targeted-attacks-and-crimeware-campaigns.html; classtype:command-and-control; sid:2017691; rev:4; metadata:attack_target Client_Endpoint, created_at 2013_11_07, deployment Perimeter, signature_severity Major, tag c2, updated_at 2024_04_20, mitre_tactic_id TA0010, mitr
Exploit-DB
Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
exploitdb·2013-12-03
CVE-2013-3906 Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
---
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
require 'rex/zip'
require 'nokogiri'
module ::Nokogiri
module XML
class Builder
#
# Some XML documents don't declare the namespace before referencing, but Nokogiri requires one.
# So here's our hack to get around that by adding a new custom method to the Builder class
#
def custom_root(ns)
e = @parent.create_element(ns)
e.add_namespace_definition(ns, "href")
@ns = e.namespace_definitions.find { |x| x.prefix == ns.to_s }
return self
end
end
end
end
class Metasploit3 "Microsoft Tagged Image File Format (TIFF) Integer Overflow",
'Description' => %q{
This mo
Metasploit
MS13-096 Microsoft Tagged Image File Format (TIFF) Integer Overflow
metasploit
MS13-096 Microsoft Tagged Image File Format (TIFF) Integer Overflow
MS13-096 Microsoft Tagged Image File Format (TIFF) Integer Overflow
This module exploits a vulnerability found in Microsoft's Tagged Image File Format. It was originally discovered in the wild, targeting Windows XP and Windows Server 2003 users running Microsoft Office, specifically in the Middle East and South Asia region. The flaw is due to a DWORD value extracted from the TIFF file that is embedded as a drawing in Microsoft Office, and how it gets calculated with user-controlled inputs, and stored in the EAX register. The 32-bit register will run out of storage space to represent the large value, which ends up being 0, but it still gets pushed as a dwBytes argument (size) for a HeapAlloc call. The HeapAlloc function will allocate a chunk anyway with size 0, and the address of this chun
Tenable
Sandworm APT Deploys New SwiftSlicer Wiper Using Active Directory Group Policy
blogs_tenable·2023-01-27
Sandworm APT Deploys New SwiftSlicer Wiper Using Active Directory Group Policy
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-10
ModifiedElephant APT and a Decade of Fabricating Evidence
## ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure o
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-09
ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
- Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
- ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
- ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
- ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
- The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure overlaps that allow us to connect long periods of previou
Talos
Modified Zyklon and plugins from India
blogs_talos·2017-05-23·CVSS 8.8
[HIGH] Modified Zyklon and plugins from India
### Introduction Streams of malicious emails Talos inspects every day usually consist of active spamming campaigns for various ransomware families, phishing campaigns and the common malware family suspects such as banking Trojans and bots.. It is however often more interesting to analyze campaigns smaller in volume as they might contain more interesting malware. A few weeks ago I became interested in just such a campaign with a smaller number of circulating email messages. The email, first of them submitted from Middle East, purports to be coming from a Turkish trading company, which might further indicate the geographic area where the attacks were active. Analyzing malware is often like solving a puzzle, you have to do it piece by piece to reach the final image. In this case I spent more
Securelist
How Security Products are Tested – Part 1
blogs_securelist·2017-02-27
How Security Products are Tested – Part 1
Table of Contents
- Basic testing methodologies
- Specialized tests
- Types of tests
- Market players
- How to win tests
Authors
- Vyacheslav Zakorzhevsky
## Methodologies and the main players
The demand for tests appeared almost simultaneously with the development of the first antivirus programs – in the mid-to-late 1990s. Demand created supply: test labs at computer magazines started to measure the effectiveness of security solutions with the help of self-made methodologies, and later an industry of specialized companies emerged with a more comprehensive approach to testing methods.
The first primitive tests scanning huge collections of malicious and supposedly malicious files taken from everywhere were rightfully criticized first and foremost by the vendors. Such tests were chara
Unit42
PlugX Uses Legitimate Samsung Application for DLL Side-Loading
blogs_unit42·2015-05-01·CVSS 8.8
[HIGH] PlugX Uses Legitimate Samsung Application for DLL Side-Loading
### Summary
While threat actors using the PlugX Trojan typically leverage legitimate executables to load their malicious DLLs through a technique called DLL side-loading, Unit 42 has observed a new executable in use for this purpose. Threat actors are now using this previously unseen executable, created by Samsung, to load variants of the PlugX Trojan.
Using our AutoFocus threat intelligence service, we have flagged these variants to help users identify related attacks.
### Malware Details
This story starts with the analysis of a malicious Word document named 雨傘達動後教會生 態.doc (which translates to “Church ecology after the Umbrella Movement”) that was created with the infamous “Tran Duy Linh” exploit kit. This malicious document exploits CVE-2012-0158 to open a decoy document and execute
Unit42
PlugX Uses Legitimate Samsung Application for DLL Side-Loading
blogs_unit42·2015-05-01·CVSS 8.8
[HIGH] PlugX Uses Legitimate Samsung Application for DLL Side-Loading
## PlugX Uses Legitimate Samsung Application for DLL Side-Loading
Robert Falcone
Published: May 1, 2015
Malware
Threat Research
PlugX
Samsung
Trojan
## Summary
While threat actors using the PlugX Trojan typically leverage legitimate executables to load their malicious DLLs through a technique called DLL side-loading, Unit 42 has observed a new executable in use for this purpose. Threat actors are now using this previously unseen executable, created by Samsung, to load variants of the PlugX Trojan.
Using our AutoFocus threat intelligence service, we have flagged these variants to help users identify related attacks.
## Malware Details
This story starts with the analysis of a malicious Word document named 雨傘達動後教會生 態.doc (which translates to “Church ecology after the Umbrella
Unit42
Super Tuesday: A Patch Tuesday We Won’t Forget
blogs_unit42·2014-10-15·CVSS 7.8
[HIGH] Super Tuesday: A Patch Tuesday We Won’t Forget
Sometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities, Adobe issued updates for Flash and ColdFusion, and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that three of the Microsoft vulnerabilities were being exploited in targeted attack campaigns.
### Sandworm
The first to drop was the Sandworm Campaign, a report from iSight partners, which described attacks on European and American targets in the month of August using new versions of the BlackEnergy bot, but the group behind the attacks has been operating since at least 2009. The biggest news here was the group’s exploitation of a “new” vulnerability in Windows, CV
Unit42
Super Tuesday: A Patch Tuesday We Won’t Forget
blogs_unit42·2014-10-15·CVSS 7.8
[HIGH] Super Tuesday: A Patch Tuesday We Won’t Forget
## Super Tuesday: A Patch Tuesday We Won’t Forget
Ryan Olson
Published: October 15, 2014
Threat Research
Vulnerabilities
BlackEnergy
ISight
Microsoft
Microsoft Security Bulletin
Patch Tuesday
PowerShell Empire
Sandworm
Sometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities , Adobe issued updates for Flash and ColdFusion , and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that three of the Microsoft vulnerabilities were being exploited in targeted attack campaigns.
## Sandworm
The first to drop was the Sandworm Campaign , a report from iSight partners, which described attacks on European and American t
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes
blogs_talos·2013-12-10·CVSS 5.5
CVE-2013-5045 [MEDIUM] Microsoft Update Tuesday: December 2013, some 0-day fixes
## Microsoft Update Tuesday: December 2013, some 0-day fixes
Microsoft’s final update for the year brings us 11 bulletins covering 24 CVE issues.
As is customary, there is the critical IE bulletin, MS13-097 . This time it covers 7 CVE issues. As in other months, this includes a number of use-after-free issues that we’ve come to expect in IE. However this month we also get 2 escalation of privilege vulnerabilities ( CVE-2013-5045 and CVE-2013-5046 ), where an attacker could break out of the low integrity sandbox. This assumes of course that the attacker has first gained remote code execution through another vulnerability and then uses one of these vulnerabilities to execute arbitrary programs.
There is also a critical update for GDI+, MS13-096 . This one fixes the 0-day vulnerability ( C
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes
blogs_talos·2013-12-10·CVSS 5.5
CVE-2013-5045 [MEDIUM] Microsoft Update Tuesday: December 2013, some 0-day fixes
Microsoft’s final update for the year brings us 11 bulletins covering 24 CVE issues.
As is customary, there is the critical IE bulletin, MS13-097. This time it covers 7 CVE issues. As in other months, this includes a number of use-after-free issues that we’ve come to expect in IE. However this month we also get 2 escalation of privilege vulnerabilities (CVE-2013-5045 and CVE-2013-5046), where an attacker could break out of the low integrity sandbox. This assumes of course that the attacker has first gained remote code execution through another vulnerability and then uses one of these vulnerabilities to execute arbitrary programs.
There is also a critical update for GDI+, MS13-096. This one fixes the 0-day vulnerability (CVE-2013-3906) that is being exploited in the wild. The vulnerabilit
Crowdstrike
Analysis of a CVE-2013-3906 Exploit
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] Analysis of a CVE-2013-3906 Exploit
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Zscaler
Zscaler found Multiple Security Vulnerabilities | 11-05-2013
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Multiple Security Vulnerabilities | 11-05-2013
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
Analysis of a CVE-2013-3906 Exploit
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] Analysis of a CVE-2013-3906 Exploit
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Threat Intel
Sandworm Team (Sandworm Team, ELECTRUM, Telebots)
threat_intel
Sandworm Team (Sandworm Team, ELECTRUM, Telebots)
# Threat Actor Profile: Sandworm Team
ATT&CK ID: G0034
Also known as: Sandworm Team, ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44
Suspected origin: Russia
## Overview
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020)
In October 2020, the US indicted six GRU Unit 74455 of
http://blogs.mcafee.com/mcafee-labs/mcafee-labs-detects-zero-day-exploit-targeting-microsoft-office-2http://blogs.technet.com/b/srd/archive/2013/11/05/cve-2013-3906-a-graphics-vulnerability-exploited-through-word-documents.aspxhttp://technet.microsoft.com/security/advisory/2896666http://www.exploit-db.com/exploits/30011https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-096http://blogs.mcafee.com/mcafee-labs/mcafee-labs-detects-zero-day-exploit-targeting-microsoft-office-2http://blogs.technet.com/b/srd/archive/2013/11/05/cve-2013-3906-a-graphics-vulnerability-exploited-through-word-documents.aspxhttp://technet.microsoft.com/security/advisory/2896666http://www.exploit-db.com/exploits/30011https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-096https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3906
2013-11-06
Published
2022-02-15
Added to CISA KEV
Exploited in the wild