CVE-2015-1641
published 2015-04-14CVE-2015-1641: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation…
PriorityP189high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
96.79%
99.9th percentile
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | outlook | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
Detection & IOCsextracted from sources · hover to see the quote
registryHKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs - %APPDATA%\Intel\ResN32.dll↗
- →Post-exploitation shellcode reads the last four bytes of the RTF file as payload size, then decrypts and writes payload to a temp file executed via WinExec; detect WinExec calls from Office processes writing to %TEMP%. ↗
- →T9000 malware drops files into %APPDATA%\Intel directory; presence of hjwe.dat, tyeu.dat, vnkd.dat, qhnj.dat, dtl.dat, glp.uin, igfxtray.exe, hccutils.dll, ResN32.dll in that path is a strong indicator of compromise. ↗
- →T9000 uses AppInit_DLLs persistence pointing to ResN32.dll; alert on writes to HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs by non-system processes. ↗
- →DragonOK CVE-2015-1641 RTF exploit uses a unique shellcode; IPS signatures 14365, 14588, 13574, 13359 cover IsSpace and related C2 traffic. ↗
- →ModifiedElephant used CVE-2015-1641 exploits in .doc lure files; monitor for Office processes injecting into explorer.exe without writing to its memory (process hollowing variant). ↗
- →T9000 debug PDB path 'D:\WORK\T9000\hccutils_M4\Release\hccutils.pdb' embedded in hccutils.dll; scan memory/files for this string as a high-confidence T9000 indicator. ↗
- →T9000 debug PDB path 'D:\WORK\T9000\ResN_M2\Release\ResN32.pdb' embedded in ResN32.dll; scan for this string as a high-confidence T9000 indicator. ↗
- →T9000 BypassUAC component identified by PDB string 'H:\WORK\PROJECT\InfInstallBypassUAC\Release\BypassUAC.pdb' in QQMgr.dll; scan for this string. ↗
- ·The gtoimage[.]com and trend.gogolekr[.]com sysget C2 domains share the same registrant and resolve to the same netblock 104.202.173.0/24; blocking the netblock may affect other hosted services. ↗
- ·The Securelist source partially redacts the malicious hosting domain as 'files[.]maintr**plus[.]com'; the exact domain should be confirmed before blocking to avoid false positives. ↗
- ·The T9000 mutex value contains 'xx' placeholders (820C90CxxA1B084495866C6D95B2595xx1C3), suggesting the exact characters were redacted; the full mutex string must be confirmed from a live sample before using as a detection rule. ↗
- ·igfxtray.exe used by T9000 for DLL sideloading is a legitimate Microsoft executable; blocking or alerting on it alone will produce false positives — detection should focus on the presence of hccutils.dll in the same directory. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7p4q-fv59-h67q: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Autom
ghsa_unreviewed·2022-05-14
CVE-2015-1641 [HIGH] CWE-787 GHSA-7p4q-fv59-h67q: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Autom
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."
VulnCheck
Microsoft Office Memory Corruption Vulnerability
vulncheck·2015·CVSS 7.8
CVE-2015-1641 [HIGH] CWE-399 Microsoft Office Memory Corruption Vulnerability
Microsoft Office Memory Corruption Vulnerability
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
Affected: Microsoft Office
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.sekoia.fr/blog/ms-office-exploit-analysis-cve-2015-1641/; https://unit42.paloaltonetworks.com/unit42-new-sofacy-attacks-against-us-government-agency/; https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=09308982
CISA
Microsoft Office Memory Corruption Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2015-1641 [HIGH] CWE-399 Microsoft Office Memory Corruption Vulnerability
Vulnerability: Microsoft Office Memory Corruption Vulnerability
Affected: Microsoft Office
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1641
Remediation Due Date: 2022-05-03
Suricata
ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)
suricata·2025-01-27·CVSS 7.8
CVE-2015-1641 [HIGH] ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)
ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)
Rule: alert tcp any any -> $HOME_NET any (msg:"ET HUNTING Microsoft Office Memory Corruption (CVE-2015-1641)"; flow:established,to_client; file.data; content:"|7b 5c|rtf"; content:"|7b 5c 2a 5c|objdata|20|0105000002000000"; content:"6f746b6c6f6164722e5752417373656d626c792e3100"; fast_pattern; nocase; distance:8; content:"d0cf11e0a1b11ae1"; nocase; distance:0; content:"|7c 34 24 04|"; reference:url,degsew.wordpress.com/2016/03/28/new-microst-office-word-2007-2013-exploit-cve-2015-1641-analysis/; reference:cve,2015-1641; classtype:bad-unknown; sid:2059680; rev:1; metadata:attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2025_01_27, cve CVE_2015_1641, deployment Perimeter, deployment SSLDecrypt, confidence Medium, s
No public exploits indexed.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-10
ModifiedElephant APT and a Decade of Fabricating Evidence
## ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure o
Sentinelone
ModifiedElephant APT and a Decade of Fabricating Evidence
blogs_sentinelone·2022-02-09
ModifiedElephant APT and a Decade of Fabricating Evidence
## Executive Summary
- Our research attributes a decade of activity to a threat actor we call ModifiedElephant.
- ModifiedElephant is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
- ModifiedElephant has been operating since at least 2012, and has repeatedly targeted specific individuals.
- ModifiedElephant operates through the use of commercially available remote access trojans (RATs) and has potential ties to the commercial surveillance industry.
- The threat actor uses spearphishing with malicious documents to deliver malware, such as NetWire, DarkComet, and simple keyloggers with infrastructure overlaps that allow us to connect long periods of previou
Trendmicro
Deciphering Confucius’ Cyberespionage Operations
blogs_trendmicro·2018-02-13
Deciphering Confucius’ Cyberespionage Operations
APT und gezielte Angriffe
## Deciphering Confucius’ Cyberespionage Operations
Online romance scams are not uncommon; many catfishers toy with and manipulate victims’ to cash in on their bank accounts. However, it is unusual to see it used as a vector for cyberespionage.
By: Daniel Lunghi, Jaromir Horejsi Feb 13, 2018 Read time: ( words)
Save to Folio
In today’s online chat and dating scene, romance scams are not uncommon, what with catfishers and West African cybercriminals potently toying with their victims’ emotions to cash in on their bank accounts. It’s quite odd (and probably underreported), however, to see it used as a vector for cyberespionage.
We stumbled upon the Confucius hacking group while delving into Patchwork’s cyberespionage operations , and found a number of similari
Trendmicro
Deciphering Confucius’ Cyberespionage Operations
blogs_trendmicro·2018-02-13
Deciphering Confucius’ Cyberespionage Operations
APT & Targeted Attacks
# Deciphering Confucius’ Cyberespionage Operations
Online romance scams are not uncommon; many catfishers toy with and manipulate victims’ to cash in on their bank accounts. However, it is unusual to see it used as a vector for cyberespionage.
By: Daniel Lunghi, Jaromir Horejsi
2018/02/13
Read time: ( words)
Save to Folio
In today’s online chat and dating scene, romance scams are not uncommon, what with catfishers and West African cybercriminals potently toying with their victims’ emotions to cash in on their bank accounts. It’s quite odd (and probably underreported), however, to see it used as a vector for cyberespionage.
We stumbled upon the Confucius hacking group while delving into Patchwork’s cyberespionage operations, and found a number of similarities.
Trendmicro
Deciphering Confucius’ Cyberespionage Operations
blogs_trendmicro·2018-02-13
Deciphering Confucius’ Cyberespionage Operations
APT & Targeted Attacks
## Deciphering Confucius’ Cyberespionage Operations
Online romance scams are not uncommon; many catfishers toy with and manipulate victims’ to cash in on their bank accounts. However, it is unusual to see it used as a vector for cyberespionage.
By: Daniel Lunghi, Jaromir Horejsi 2018/02/13 Read time: ( words)
Save to Folio
In today’s online chat and dating scene, romance scams are not uncommon, what with catfishers and West African cybercriminals potently toying with their victims’ emotions to cash in on their bank accounts. It’s quite odd (and probably underreported), however, to see it used as a vector for cyberespionage.
We stumbled upon the Confucius hacking group while delving into Patchwork’s cyberespionage operations , and found a number of similarities.
Trendmicro
Deciphering Confucius’ Cyberespionage Operations
blogs_trendmicro·2018-02-13
Deciphering Confucius’ Cyberespionage Operations
APT & Targeted Attacks
## Deciphering Confucius’ Cyberespionage Operations
Online romance scams are not uncommon; many catfishers toy with and manipulate victims’ to cash in on their bank accounts. However, it is unusual to see it used as a vector for cyberespionage.
By: Daniel Lunghi, Jaromir Horejsi Feb 13, 2018 Read time: ( words)
Save to Folio
In today’s online chat and dating scene, romance scams are not uncommon, what with catfishers and West African cybercriminals potently toying with their victims’ emotions to cash in on their bank accounts. It’s quite odd (and probably underreported), however, to see it used as a vector for cyberespionage.
We stumbled upon the Confucius hacking group while delving into Patchwork’s cyberespionage operations , and found a number of similaritie
Trendmicro
Deciphering Confucius’ Cyberespionage Operations
blogs_trendmicro·2018-02-13
Deciphering Confucius’ Cyberespionage Operations
APT y ataques dirigidos
## Deciphering Confucius’ Cyberespionage Operations
Online romance scams are not uncommon; many catfishers toy with and manipulate victims’ to cash in on their bank accounts. However, it is unusual to see it used as a vector for cyberespionage.
By: Daniel Lunghi, Jaromir Horejsi Feb 13, 2018 Read time: ( words)
Save to Folio
In today’s online chat and dating scene, romance scams are not uncommon, what with catfishers and West African cybercriminals potently toying with their victims’ emotions to cash in on their bank accounts. It’s quite odd (and probably underreported), however, to see it used as a vector for cyberespionage.
We stumbled upon the Confucius hacking group while delving into Patchwork’s cyberespionage operations , and found a number of similariti
Trendmicro
Untangling the Patchwork Cyberespionage Group
blogs_trendmicro·2017-12-11
Untangling the Patchwork Cyberespionage Group
Cyber Crime
# Untangling the Patchwork Cyberespionage Group
Patchwork (also known as Dropping Elephant) is a cyberespionage group known for targeting diplomatic and government agencies that has since added businesses to their list of targets.
By: Daniel Lunghi, Jaromir Horejsi, Cedric Pernet
2017/12/11
Read time: ( words)
Save to Folio
Updated as of October 9, 2018, 7:24PM PDT to remove Socksbot and update the appendix and technical brief; hat tip to Michael Yip of Accenture Security for an earlier research on Socksbot.
Patchwork (also known as Dropping Elephant) is a cyberespionage group known for targeting diplomatic and government agencies that has since added businesses to their list of targets. Patchwork’s moniker is from its notoriety for rehashing off-the-rack tools and malwa
Unit42
Threat Actors Target Government of Belarus Using CMSTAR Trojan
blogs_unit42·2017-09-28
Threat Actors Target Government of Belarus Using CMSTAR Trojan
Palo Alto Networks Unit 42 has identified a series of phishing emails containing updated versions of the previously discussed CMSTAR malware family targeting various government entities in the country of Belarus.
We first reported on CMSTAR in spear phishing attacks in spring of 2015 and later in 2016.
In this latest campaign, we observed a total of 20 unique emails between June and August of this year that included two new variants of the CMSTAR Downloader. We also discovered two previously unknown payloads. These payloads contained backdoors that we have named BYEBY and PYLOT respectively.
Figure 1 Diagram of the attack sequence
## Phishing Emails
Between June and August of this year, we observed a total of 20 unique emails being sent to the following email addresses:
Email Address
Unit42
Threat Actors Target Government of Belarus Using CMSTAR Trojan
blogs_unit42·2017-09-28
Threat Actors Target Government of Belarus Using CMSTAR Trojan
## Threat Actors Target Government of Belarus Using CMSTAR Trojan
Josh Grunzweig
Robert Falcone
Published: September 28, 2017
Malware
Threat Research
BYEBY
Cmstar
Phishing
PYLOT
Palo Alto Networks Unit 42 has identified a series of phishing emails containing updated versions of the previously discussed CMSTAR malware family targeting various government entities in the country of Belarus.
We first reported on CMSTAR in spear phishing attacks in spring of 2015 and later in 2016 .
In this latest campaign, we observed a total of 20 unique emails between June and August of this year that included two new variants of the CMSTAR Downloader. We also discovered two previously unknown payloads. These payloads contained backdoors that we have named BYEBY and PYLOT respectively.
Figure 1
Securelist
A simple example of a complex cyberattack
blogs_securelist·2017-09-25·CVSS 7.8
[HIGH] A simple example of a complex cyberattack
Authors
Vasily Berdnikov
Dmitry Karasovsky
Alexey Shulmin
## How cyberspies achieve their goals by using cheap tools and careful aiming
We’re already used to the fact that complex cyberattacks use 0-day vulnerabilities, bypassing digital signature checks, virtual file systems, non-standard encryption algorithms and other tricks. Sometimes, however, all of this may be done in much simpler ways, as was the case in the malicious campaign that we detected a while ago – we named it ‘Microcin’ after microini, one of the malicious components used in it.
We detected a suspicious RTF file. The document contained an exploit to the previously known and patched vulnerability CVE-2015-1641 ; however, its code had been modified considerably. Remarkably, the malicious document was delivered via web
Securelist
A simple example of a complex cyberattack
blogs_securelist·2017-09-25·CVSS 7.8
[HIGH] A simple example of a complex cyberattack
Authors
- Vasily Berdnikov
- Dmitry Karasovsky
- Alexey Shulmin
## How cyberspies achieve their goals by using cheap tools and careful aiming
We’re already used to the fact that complex cyberattacks use 0-day vulnerabilities, bypassing digital signature checks, virtual file systems, non-standard encryption algorithms and other tricks. Sometimes, however, all of this may be done in much simpler ways, as was the case in the malicious campaign that we detected a while ago – we named it ‘Microcin’ after microini, one of the malicious components used in it.
We detected a suspicious RTF file. The document contained an exploit to the previously known and patched vulnerability CVE-2015-1641; however, its code had been modified considerably. Remarkably, the malicious document was delivered via
Securelist
Nigerian phishing: Industrial companies under attack
blogs_securelist·2017-06-15
Nigerian phishing: Industrial companies under attack
Table of Contents
- Targeted Attack
- The Emails
- Nigerian Fishing
- P.S. The Hidden Threat
- Protection Measures
Authors
- Kaspersky ICS CERT
In late 2016, the Kaspersky Lab Industrial Control Systems Cyber Emergency Response Team (Kaspersky Lab ICS CERT) reported on phishing attacks that were primarily targeting industrial companies from the metallurgy, electric power, construction, engineering and other sectors. As further research demonstrated, this was just part of a bigger story that began much earlier and is unlikely to end any time soon.
## Targeted Attack
In October 2016, Kaspersky Lab products detected a surge in malware infection attempts on the computers of our customers who had industrial control systems installed. The malware used in these attacks was a specific modif
Securelist
Nigerian phishing: Industrial companies under attack
blogs_securelist·2017-06-15
Nigerian phishing: Industrial companies under attack
Table of Contents
Targeted Attack
The Emails
Malicious Files
Domains Used by the Attackers
Attack Scenario
Nigerian Fishing
Hunting the Big Phish
Potential Losses
P.S. The Hidden Threat
Protection Measures
Authors
Kaspersky ICS CERT
In late 2016, the Kaspersky Lab Industrial Control Systems Cyber Emergency Response Team ( Kaspersky Lab ICS CERT ) reported on phishing attacks that were primarily targeting industrial companies from the metallurgy, electric power, construction, engineering and other sectors. As further research demonstrated, this was just part of a bigger story that began much earlier and is unlikely to end any time soon.
## Targeted Attack
In October 2016, Kaspersky Lab products detected a surge in malware infection attempts on the computers of our customers w
Fortinet
In-Depth Look at New Variant of MONSOON APT Backdoor, Part 1
blogs_fortinet·2017-04-05·CVSS 7.8
CVE-2015-1641 [HIGH] In-Depth Look at New Variant of MONSOON APT Backdoor, Part 1
FORTIGUARD LABS THREAT RESEARCH
In-Depth Look at New Variant of MONSOON APT Backdoor, Part 1
By Jasper Manuel and Artem Semenchenko | April 05, 2017
Three weeks ago, FortiGuard Labs, along with @_ddoxer (Roland de la Paz), using VirusTotal Intelligence queries, spotted a document with the politically themed file name “Senate_panel.doc”. This malicious RTF file takes advantage of the vulnerability CVE-2015-1641. Upon successful exploitation, it drops a malware in the %appdata%\Microsoft directory. To evade suspicion by the victim, it also drops a decoy document which shows the symbol of the Ministry of Foreign Affairs of Pakistan on the first page, but on the next pages shows an article about the Senate of Pakistan.
Decoy document
As we were unable to identify which malware family the d
Fortinet
In-Depth Look at New Variant of MONSOON APT Backdoor, Part 2
blogs_fortinet·2017-04-05·CVSS 7.8
[HIGH] In-Depth Look at New Variant of MONSOON APT Backdoor, Part 2
FORTIGUARD LABS THREAT RESEARCH
In-Depth Look at New Variant of MONSOON APT Backdoor, Part 2
By Jasper Manuel and Artem Semenchenko | April 05, 2017
In part 1 of FortiGuard Labs’ analysis of a new variant of the BADNEWS backdoor, which is actively being used in the MONSOON APT campaign, we did a deep technical analysis of what this backdoor of capable of and how the bad guys control it using the command and control server. In this part of the analysis, we will try to discover who might be behind the distribution of these files.
Who’s Behind these Malicious Files
In part 1, we discussed that the BADNEWS backdoor is being dropped by a malicious RTF exploiting CVE-2015-1641. Interestingly, these RTF exploits contain an INCLUDEPICTURE field to insert a picture into the document which point
Unit42
DragonOK Updates Toolset and Targets Multiple Geographic Regions
blogs_unit42·2017-01-05·CVSS 7.8
[HIGH] DragonOK Updates Toolset and Targets Multiple Geographic Regions
Threat Research Center
Threat Research
Malware
## DragonOK Updates Toolset and Targets Multiple Geographic Regions
Josh Grunzweig
Published: January 5, 2017
Malware
Threat Research
DragonOK
Japan
Threat intelligence
The DragonOK group has been actively launching attacks for years. We first discussed them in April 2015 when we witnessed them targeting a number of organizations in Japan . In recent months, Unit 42 has observed a number of attacks that we attribute to this group. Multiple new variants of the previously discussed sysget malware family have been observed in use by DragonOK. Sysget malware was delivered both directly via phishing emails, as well as in Rich Text Format (RTF) documents exploiting the CVE-2015-1641 vulnerability (patched in MS15-033 ) that in turn leve
Unit42
DragonOK Updates Toolset and Targets Multiple Geographic Regions
blogs_unit42·2017-01-05·CVSS 7.8
[HIGH] DragonOK Updates Toolset and Targets Multiple Geographic Regions
The DragonOK group has been actively launching attacks for years. We first discussed them in April 2015 when we witnessed them targeting a number of organizations in Japan. In recent months, Unit 42 has observed a number of attacks that we attribute to this group. Multiple new variants of the previously discussed sysget malware family have been observed in use by DragonOK. Sysget malware was delivered both directly via phishing emails, as well as in Rich Text Format (RTF) documents exploiting the CVE-2015-1641 vulnerability (patched in MS15-033) that in turn leveraged a very unique shellcode. Additionally, we have observed instances of the IsSpace and TidePool malware families being delivered via the same techniques. While Japan is still the most heavily targeted geographic region by this
Unit42
New Sofacy Attacks Against US Government Agency
blogs_unit42·2016-06-14·CVSS 7.8
[HIGH] New Sofacy Attacks Against US Government Agency
The Sofacy group, also known as APT28, is a well-known threat group that frequently conducts cyber espionage campaigns. Recently, Unit 42 identified a spear phishing e-mail from the Sofacy group that targeted the United States government. The e-mail was sent from a potentially compromised account belonging to the Ministry of Foreign Affairs of another government entity and carried the Carberp variant of the Sofacy Trojan. The developer implemented a clever persistence mechanism in the Trojan, one which had not been observed in previous attacks. The focus of this blog will be on the attacks and the infrastructure associated with Sofacy using the new persistence mechanism as a correlation point.
### The Delivery
On May 28, 2016, attackers sent a spear-phishing e-mail to a U.S. government e
Unit42
New Sofacy Attacks Against US Government Agency
blogs_unit42·2016-06-14
New Sofacy Attacks Against US Government Agency
Threat Research Center
Threat Research
Malware
## New Sofacy Attacks Against US Government Agency
Robert Falcone
Bryan Lee
Published: June 14, 2016
Malware
Threat Actor Groups
Threat Research
APT28
Carberp
Fighting Ursa
Ministry of Foreign Affairs
Sofacy
Trojan
The Sofacy group, also known as APT28, is a well-known threat group that frequently conducts cyber espionage campaigns. Recently, Unit 42 identified a spear phishing e-mail from the Sofacy group that targeted the United States government. The e-mail was sent from a potentially compromised account belonging to the Ministry of Foreign Affairs of another government entity and carried the Carberp variant of the Sofacy Trojan. The developer implemented a clever persistence mechanism in the Trojan, one which had not been
Unit42
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
blogs_unit42·2016-02-04
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
Most custom backdoors used by advanced attackers have limited functionality. They evade detection by keeping their code simple and flying under the radar. But during a recent investigation we found a backdoor that takes a very different approach. We refer to this backdoor as T9000, which is a newer variant of the T5000 malware family, also known as Plat1.
In addition to the basic functionality all backdoors provide, T9000 allows the attacker to capture encrypted data, take screenshots of specific applications and specifically target Skype users. The malware goes to great lengths to identify a total of 24 potential security products that may be running on a system and customizes its installation mechanism to specifically evade those that are installed. It uses a multi-stage installation pr
Unit42
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
blogs_unit42·2016-02-04
T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
## T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques
Josh Grunzweig
Jen Miller-Osborn
Published: February 4, 2016
Malware
Threat Research
Skype
T5000
T9000
Trojans
Most custom backdoors used by advanced attackers have limited functionality. They evade detection by keeping their code simple and flying under the radar. But during a recent investigation we found a backdoor that takes a very different approach. We refer to this backdoor as T9000, which is a newer variant of the T5000 malware family, also known as Plat1.
In addition to the basic functionality all backdoors provide, T9000 allows the attacker to capture encrypted data, take screenshots of specific applications and specifically target Skype users. The malware goes to great lengths to identify a tot
Talos
Microsoft Patch Tuesday for April 2015: 11 Bulletins Released
blogs_talos·2015-04-14·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for April 2015: 11 Bulletins Released
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 11 bulletins being released which address 26 CVEs. The first 4 bulletins are rated Critical and address vulnerabilities within Internet Explorer, Office, IIS, and Graphics Component. The remaining 7 bulletins are rated Important and cover vulnerabilities within SharePoint, Task Scheduler, Windows, XML Core Services, Active Directory, .NET, and Hyper-V.
### Bulletins Rated CriticalMS15-032, MS15-033, MS15-034, and MS15-035 are rated Critical.
MS15-032 is this month’s Internet Explorer security bulletin with vulnerabilities in versions 6 through 11 being addressed. This month, 10 CVEs were addressed with the majority
Talos
Microsoft Patch Tuesday for April 2015: 11 Bulletins Released
blogs_talos·2015-04-14·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for April 2015: 11 Bulletins Released
## Microsoft Patch Tuesday for April 2015: 11 Bulletins Released
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release sees a total of 11 bulletins being released which address 26 CVEs. The first 4 bulletins are rated Critical and address vulnerabilities within Internet Explorer, Office, IIS, and Graphics Component. The remaining 7 bulletins are rated Important and cover vulnerabilities within SharePoint, Task Scheduler, Windows, XML Core Services, Active Directory, .NET, and Hyper-V.
## Bulletins Rated Critical MS15-032, MS15-033, MS15-034, and MS15-035 are rated Critical.
MS15-032 is this month’s Internet Explorer security bulletin with vulnerabilities in versions 6 through 11 bein
Qualys
Patch Tuesday April 2015 | Qualys
blogs_qualys·2015-04-14·CVSS 7.8
[HIGH] Patch Tuesday April 2015 | Qualys
April’s Patch Tuesday continues the 2015 trend of high volume patches. This month we have a full set of 11 patches from Microsoft addressing 26 vulnerabilities.The vulnerabilities affect Windows and Office on both servers and workstations. In addition, Oracle is publishing their quarterly Critical Patch Update fixing 98 vulnerabilities in over 25 software categories, including Java, Oracle RDBMS and MySQL.
Add to that the fixes in Adobe, Mozilla and Google Chrome software that were initiated by the results of the PWN2OWN competition in Vancouver, and every defensive IT security professional will have their work doubled this month.
Let’s start with Microsoft: 11 bulletins from MS15-032 to MS15-042 with four of them critical. But priorities are clear this month:
Number one is MS15-033, th
Qualys
Patch Tuesday April 2015 | Qualys
blogs_qualys·2015-04-14·CVSS 7.8
[HIGH] Patch Tuesday April 2015 | Qualys
April’s Patch Tuesday continues the 2015 trend of high volume patches. This month we have a full set of 11 patches from Microsoft addressing 26 vulnerabilities.The vulnerabilities affect Windows and Office on both servers and workstations. In addition, Oracle is publishing their quarterly Critical Patch Update fixing 98 vulnerabilities in over 25 software categories, including Java, Oracle RDBMS and MySQL.
Add to that the fixes in Adobe, Mozilla and Google Chrome software that were initiated by the results of the PWN2OWN competition in Vancouver, and every defensive IT security professional will have their work doubled this month.
Let’s start with Microsoft: 11 bulletins from MS15-032 to MS15-042 with four of them critical. But priorities are clear this month:
Number one is MS15-033, th
Threat Intel
Confucius (Confucius, Confucius APT)
threat_intel·CVSS 7.8
[HIGH] Confucius (Confucius, Confucius APT)
# Threat Actor Profile: Confucius
ATT&CK ID: G0142
Also known as: Confucius, Confucius APT
## Overview
Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.(Citation: TrendMicro Confucius APT Feb 2018)(Citation: TrendMicro Confucius APT Aug 2021)(Citation: Uptycs Confucius APT Jan 2021)
## Techniques (TTPs)
### Resource Development
- T1583.006 Web Services
Usage: Confucius has obtained cloud storage service accounts to host stolen data.(Citation: TrendMicro Confucius APT Feb 2018)
### Initial Access
- T156
Threat Intel
APT41 (APT41, Wicked Panda, Brass Typhoon)
threat_intel
APT41 (APT41, Wicked Panda, Brass Typhoon)
# Threat Actor Profile: APT41
ATT&CK ID: G0096
Also known as: APT41, Wicked Panda, Brass Typhoon, BARIUM
Suspected origin: China
## Overview
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.(Citation: FireEye APT41 Aug 2019)(Citation: Group IB APT 41 June 202
Crowdstrike
Arrests Put New Focus on CARBON SPIDER Adversary Group
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Arrests Put New Focus on CARBON SPIDER Adversary Group
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Zscaler
Zscaler found Multiple Security Vulnerabilities | 04-14-2015
blogs_zscaler·CVSS 9.3
[CRITICAL] Zscaler found Multiple Security Vulnerabilities | 04-14-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Threat Intel
Patchwork (Patchwork, Hangover Group, Dropping Elephant)
threat_intel
Patchwork (Patchwork, Hangover Group, Dropping Elephant)
# Threat Actor Profile: Patchwork
ATT&CK ID: G0040
Also known as: Patchwork, Hangover Group, Dropping Elephant, Chinastrats, MONSOON, Operation Hangover
Suspected origin: China
## Overview
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.(Citation: Cymmetria Patchwork) (Citation: Symantec Patchwork)(Citation: TrendMicro Patchwork Dec 2017)(Cita
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
arXiv
Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
arxiv_fulltext·2021-02-10·CVSS 8.8
CVE-2017-11882 [HIGH] Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
Top 10 Most Exploited Vulnerabilities 2016-2019
(https://us-cert.cisa.gov/ncas/alerts/aa20-133a)
.83fcdec8a329824466f140a2e6cdfeec473a9ee2 .0
longtable[]@lllllll@
& CVSS Score & Number of Tactics & Number of Techniques &
Number of CAPECs & Number of CWEs & Number of CPEs
CVE-2017-11882 & 8.55 & 0 & 0 & 12 & 1 & 4
CVE-2017-0199 & 8.55 & 0 & 0 & 0 & 0 & 9
CVE-2017-5638 & 10.0 & 1 & 3 & 51 & 1 & 53
CVE-2012-0158 & 9.3 & 0 & 0 & 3 & 1 & 29
CVE-2019-0604 & 8.65 & 1 & 3 & 51 & 1 & 4
CVE-2017-0143 & 0.0 (not listed in BRON but NVD says high severity)
& 0 & 0 & 0 & 0 & 0
CVE-2018-4878 & 8.65 & 0 & 0 & 0 & 1 & 3
CVE-2017-8759 & 8.55 & 1 & 3 & 51 & 1 & 8
CVE-2015-1641 & 9.3 & 0 & 0 & 0 & 1 & 11
CVE-2018-7600 & 8.65 & 1 & 3 & 51 & 1 & 4
longtable
4 out of Top 10 Vulnerabilities share the follow
arXiv
On the Effectiveness of Type-based Control Flow Integrity
arxiv_fulltext·2020-02-14
On the Effectiveness of Type-based Control Flow Integrity
2018
2018
acmcopyright
[ACSAC '18]2018 Annual Computer Security Applications ConferenceDecember 3--7, 2018San Juan, PR, USA
2018 Annual Computer Security Applications Conference (ACSAC '18), December 3--7, 2018, San Juan, PR, USA
15.00
10.1145/3274694.3274739
978-1-4503-6569-7/18/12
On the Effectiveness of Type-based Control Flow Integrity
Reza Mirzazade farkhani
Northeastern University
[email protected]
Saman Jafari
Northeastern University
[email protected]
Sajjad Arshad
Northeastern University
[email protected]
William Robertson
Northeastern University
[email protected]
Engin Kirda
Northeastern University
[email protected]
Hamed Okhravi
MIT Lincoln Laboratory
[email protected]
## Abstract
Control flow integrity (CFI) has received significant attention in the community
http://www.securityfocus.com/bid/73995http://www.securitytracker.com/id/1032104https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-033http://www.securityfocus.com/bid/73995http://www.securitytracker.com/id/1032104https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-033https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1641
2015-04-14
Published
2021-11-03
Added to CISA KEV
Exploited in the wild