CVE-2018-8120
published 2018-05-09CVE-2018-8120: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of…
PriorityP187high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-05
Exploited in the wild
EPSS
73.72%
99.4th percentile
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →PurpleFox exploit chain exploiting CVE-2018-8120 delivers payloads via WPAD abuse; monitor for DNS/HTTP requests to wpad.id and subsequent MSI/PowerShell staging activity. ↗
- →ScarCruft (APT group) uses CVE-2018-8120 to bypass Windows UAC and execute next-stage payloads with elevated privileges, delivered via spear-phishing and known exploits. ↗
- →PowerGhost miner uses CVE-2018-8120 (32- or 64-bit exploit) for privilege escalation alongside MS16-032 and MS15-051; spreads via WMI and EternalBlue. ↗
- ·The Falcon Sandbox analysis of the CVE-2018-8120 exploit was performed specifically on Windows 7 32-bit SP1 Build 7601 with Adobe Acrobat Reader DC Continuous Release 2018.009.20044; results may differ on other OS/Reader versions. ↗
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v82r-2hh9-72g8: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
ghsa_unreviewed·2022-05-13·CVSS 7.0
CVE-2018-8120 [HIGH] CWE-404 GHSA-v82r-2hh9-72g8: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
GHSA
GHSA-p8cj-jc4x-6vj2: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
ghsa_unreviewed·2022-05-13·CVSS 7.0
CVE-2018-8164 [HIGH] CWE-404 GHSA-p8cj-jc4x-6vj2: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8120, CVE-2018-8124, CVE-2018-8166.
GHSA
GHSA-x52j-3x33-rx5c: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
ghsa_unreviewed·2022-05-13·CVSS 7.0
CVE-2018-8166 [HIGH] CWE-404 GHSA-x52j-3x33-rx5c: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8120, CVE-2018-8124, CVE-2018-8164.
GHSA
GHSA-f6m6-xgx3-fg98: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
ghsa_unreviewed·2022-05-13·CVSS 7.0
CVE-2018-8124 [HIGH] CWE-404 GHSA-f6m6-xgx3-fg98: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8120, CVE-2018-8164, CVE-2018-8166.
VulnCheck
Microsoft Win32k Privilege Escalation Vulnerability
vulncheck·2018·CVSS 7.0
CVE-2018-8120 [HIGH] CWE-404 Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k Privilege Escalation Vulnerability
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Affected: Microsoft Win32k
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2018-May; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rapidly-evolving-ransomware-gandcrab-version-5-partners-with-crypter-service-for-obfuscation/; https://securelist.com/scarcruft-continues-to-evolve-introduces-bluetooth-harvester/90729/; https://web.archive.org/web/20220227045141/https://risksense.com/wp-content/uploads/201
CISA
Microsoft Win32k Privilege Escalation Vulnerability
cisa·2022-03-15·CVSS 7.0
CVE-2018-8120 [HIGH] CWE-404 Microsoft Win32k Privilege Escalation Vulnerability
Vulnerability: Microsoft Win32k Privilege Escalation Vulnerability
Affected: Microsoft Win32k
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8120
Remediation Due Date: 2022-04-05
Microsoft
Win32k Elevation of Privilege Vulnerability
vendor_msrc·2018-05-08·CVSS 7.0
CVE-2018-8120 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how Win32k handles objects in memory.
Microsoft Graphics Component: Microsoft Graphics Component
Impact: Elevation of Pri
No detection rules found.
Exploit-DB
Microsoft Windows - SetImeInfoEx Win32k NULL Pointer Dereference (Metasploit)
exploitdb·2018-10-22·CVSS 7.0
CVE-2018-8120 [HIGH] Microsoft Windows - SetImeInfoEx Win32k NULL Pointer Dereference (Metasploit)
Microsoft Windows - SetImeInfoEx Win32k NULL Pointer Dereference (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Windows SetImeInfoEx Win32k NULL Pointer Dereference',
'Description' => %q{
This module exploits elevation of privilege vulnerability that exists in Windows 7 and 2008 R2
when the Win32k component fails to properly handle objects in memory. An attacker who
successfully exploited this vulnerability could run arbitrary code in kernel mode. An
attacker could then install programs; view, change, or delete data; or create new
accounts with full user rights.
This module is tested against windows 7 x86, windows 7 x64 and windows server 2008 R2 standard
Metasploit
Windows SetImeInfoEx Win32k NULL Pointer Dereference
metasploit
Windows SetImeInfoEx Win32k NULL Pointer Dereference
Windows SetImeInfoEx Win32k NULL Pointer Dereference
This module exploits elevation of privilege vulnerability that exists in Windows 7 and 2008 R2 when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This module is tested against windows 7 x86, windows 7 x64 and windows server 2008 R2 standard x64.
Unit42
Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor
blogs_unit42·2023-06-28·CVSS 9.1
CVE-2021-26855 [CRITICAL] Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor
Threat Research Center
High Profile Threats
Malware
## Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor
Daniel Frank
Published: June 28, 2023
High Profile Threats
Malware
Cryptocurrency
Cryptojacking
CVE-2021-26855
CVE-2021-33766
CVE-2021-34473
CVE-2022-41040
Manic Menagerie
Microsoft Exchange Server
Persistence method
ProxyNotShell
Webshell
## Executive Summary
Unit 42 researchers discovered an active campaign that targeted several web hosting and IT providers in the United States and European Union from late 2020 to late 2022. Unit 42 tracks the activity associated with this campaign as CL-CRI-0021 and believes it stems from the same threat actor responsible for the previous campaign known as Manic Menagerie .
The threat actor deployed coin m
Unit42
Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor
blogs_unit42·2023-06-28
Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor
## Executive Summary
Unit 42 researchers discovered an active campaign that targeted several web hosting and IT providers in the United States and European Union from late 2020 to late 2022. Unit 42 tracks the activity associated with this campaign as CL-CRI-0021 and believes it stems from the same threat actor responsible for the previous campaign known as Manic Menagerie.
The threat actor deployed coin miners on hijacked machines to abuse the compromised servers’ resources. They have further deepened their foothold in victims’ environments by mass deployment of web shells, which granted them sustained access, as well as access to internal resources of the compromised websites.
In doing so, the attackers could potentially have turned the hijacked legitimate websites – hosted by the tar
Tenable
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
blogs_tenable·2022-03-24
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro 2021/07/01 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has b
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Minacce cyber
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Ciberamenazas
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
# PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro
2021/07/01
Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has b
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyberbedrohungen
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
2019/11/05
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously de
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
Nov 05, 2019
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously
Trendmicro
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
blogs_trendmicro·2019-09-09
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
Cyber Threats
# ‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
This new iteration of Purple Fox that we came across, delivered by Rig, has a few new tricks up its sleeve. It retains its rootkit component by abusing publicly available code. It also abuses PowerShell making it capable of fileless infection.
By: Johnlery Triunfante, Earle Maui Earnshaw, Michael Jhon Ofiaza
Sep 09, 2019
Read time: ( words)
Save to Folio
Exploit kits may no longer be as prolific as it was back when their activities were detected in the millions, but their recurring activities in the first half of 2019 indicate that they won’t be going away any time soon. The Rig exploit kit, for instance, is known for delivering various payloads — such as downloader trojans, ransomware, cryptocurrency-mining malwar
Trendmicro
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
blogs_trendmicro·2019-09-09
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
Cyber Threats
# ‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
This new iteration of Purple Fox that we came across, delivered by Rig, has a few new tricks up its sleeve. It retains its rootkit component by abusing publicly available code. It also abuses PowerShell making it capable of fileless infection.
By: Johnlery Triunfante, Earle Maui Earnshaw, Michael Jhon Ofiaza
2019/09/09
Read time: ( words)
Save to Folio
Exploit kits may no longer be as prolific as it was back when their activities were detected in the millions, but their recurring activities in the first half of 2019 indicate that they won’t be going away any time soon. The Rig exploit kit, for instance, is known for delivering various payloads — such as downloader trojans, ransomware, cryptocurrency-mining malware,
Securelist
IT threat evolution Q2 2019
blogs_securelist·2019-08-19
IT threat evolution Q2 2019
Table of Contents
- Targeted attacks and malware campaigns
- Other security news
Authors
- David Emm
## Targeted attacks and malware campaigns
### More about ShadowHammer
In March, we published the results of our investigation into a sophisticated supply-chain attack involving the ASUS Live Update Utility, used to deliver BIOS, UEFI and software updates to ASUS laptops and desktops. The attackers added a backdoor to the utility and then distributed it to users through official channels.
ASUS was not the only company used by the attackers. Other targets included several gaming companies, a conglomerate holding company and a pharmaceutical company – all located in South Korea. Either the attackers had access to the source code of the victims’ projects or they injected malware at the t
Securelist
IT threat evolution Q2 2019
blogs_securelist·2019-08-19
IT threat evolution Q2 2019
Table of Contents
Targeted attacks and malware campaigns
More about ShadowHammer
The ongoing activities of Roaming Mantis
The muddy waters of Middle East APTs
ScarCruft continues to evolve
The Zebrocy multi-language malware salad
Platinum returns
The Gaza Cybergang SneakyPastes campaign
TajMahal: a sophisticated new APT framework
FIN7 cybercrime operations continue
Zero-day vulnerability in win32k.sys
Plurox: a modular backdoor
Other security news
Digital doppelgangers
Potential problems with third-party plugins
Game of threats
Large-scale SIM-swap fraud
The problems with legal spyware
The WhatsApp call that opens up a device to surveillance
High severity bugs in VLC media player
Smart speakers listeners
Privacy matters
Authors
David Emm
## Targeted attacks and mal
Securelist
ScarCruft continues to evolve, introduces Bluetooth harvester
blogs_securelist·2019-05-13·CVSS 7.0
[HIGH] ScarCruft continues to evolve, introduces Bluetooth harvester
Authors
GReAT
## Executive summary
After publishing our initial series of blogposts back in 2016, we have continued to track the ScarCruft threat actor. ScarCruft is a Korean-speaking and allegedly state-sponsored threat actor that usually targets organizations and companies with links to the Korean peninsula. The threat actor is highly skilled and, by all appearances, quite resourceful.
We recently discovered some interesting telemetry on this actor, and decided to dig deeper into ScarCruft’s recent activity. This shows that the actor is still very active and constantly trying to elaborate its attack tools. Based on our telemetry, we can reassemble ScarCruft’s binary infection procedure. It used a multi-stage binary infection to update each module effectively and evade detection. In a
Securelist
ScarCruft continues to evolve, introduces Bluetooth harvester
blogs_securelist·2019-05-13·CVSS 7.0
[HIGH] ScarCruft continues to evolve, introduces Bluetooth harvester
Authors
- GReAT
## Executive summary
After publishing our initial series of blogposts back in 2016, we have continued to track the ScarCruft threat actor. ScarCruft is a Korean-speaking and allegedly state-sponsored threat actor that usually targets organizations and companies with links to the Korean peninsula. The threat actor is highly skilled and, by all appearances, quite resourceful.
We recently discovered some interesting telemetry on this actor, and decided to dig deeper into ScarCruft’s recent activity. This shows that the actor is still very active and constantly trying to elaborate its attack tools. Based on our telemetry, we can reassemble ScarCruft’s binary infection procedure. It used a multi-stage binary infection to update each module effectively and evade detection. In
Securelist
IT threat evolution Q2 2018. Statistics
blogs_securelist·2018-08-06
IT threat evolution Q2 2018. Statistics
Table of Contents
- Q2 figures
- Mobile threats
- Attacks on IoT devices
- Online threats in the financial sector
- Vulnerable apps used by cybercriminals
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Alexander Liskin
- Oleg Kupreev
## Q2 figures
According to KSN:
- Kaspersky Lab solutions blocked 962,947,023 attacks launched from online resources located in 187 countries across the globe.
- 351,913,075 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to bank accounts were logged on the computers of 215,762 users.
- Ransomware attacks were registered on the computers of 158,921 unique users.
- Our File Anti-Virus logged 192,053,
Securelist
IT threat evolution Q2 2018. Statistics
blogs_securelist·2018-08-06
IT threat evolution Q2 2018. Statistics
Table of Contents
Q2 figures
Mobile threats
General statistics
Distribution of detected mobile apps by type
TOP 20 mobile malware
Geography of mobile threats
Mobile banking Trojans
Mobile ransomware Trojans
Attacks on IoT devices
Telnet attacks
TOP 10 countries by shares of IoT devices infected via Telnet
TOP 10 malware downloaded to infected IoT devices in successful Telnet attacks
SSH attacks
TOP 10 countries by shares of IoT devices attacked via SSH
Online threats in the financial sector
Q2 events
New banking Trojan DanaBot
The peculiar BackSwap technique
Carbanak gang leader detained
Ransomware Trojan uses Doppelgänging technique
General statistics on financial threats
Geography of attacks
TOP 10 countries by percentage of attacked users
TOP 10 banking malware f
Tenable
July Vulnerability of the Month: Two Zero-Days Caught in Development
blogs_tenable·2018-07-31·CVSS 8.8
[HIGH] July Vulnerability of the Month: Two Zero-Days Caught in Development
Blog / Research
Subscribe
# July Vulnerability of the Month: Two Zero-Days Caught in Development
Tenable Research
July 31, 2018
3 Min Read
An Adobe Reader double free vulnerability on Windows and macOS systems earns the nod for its interesting discovery and patch story.
Novelty, sophistication or just plain weirdness are some of the potential criteria we use to select the Tenable vulnerability of the month. We collect nominations from our 70+ research team members, shortlist the finalists and give the entire team the chance to vote -- combining the total experience and knowledge of Tenable Research to identify the vulnerability of the month.
## Background
This month, Tenable Research highlights CVE-2018-4990, an Adobe Reader double free vulnerability on Windows and macOS systems. C
Tenable
July Vulnerability of the Month: Two Zero-Days Caught in Development
blogs_tenable·2018-07-31
July Vulnerability of the Month: Two Zero-Days Caught in Development
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
A mining multitool
blogs_securelist·2018-07-26
A mining multitool
Authors
Vladas Bulavas
Anatoly Kazantsev
## Symbiosis of PowerShell and EternalBlue for cryptocurrency mining
Recently, an interesting miner implementation appeared on Kaspersky Lab’s radar. The malware, which we dubbed PowerGhost, is capable of stealthily establishing itself in a system and spreading across large corporate networks infecting both workstations and servers. This type of hidden consolidation is typical of miners: the more machines that get infected and the longer they remain that way, the greater the attacker’s profits. Therefore, it’s not uncommon to see clean software being infected with a miner ; the popularity of the legitimate software serves to promote the malware’s proliferation. The creators of PowerGhost, however, went further and started using fileless techniqu
Securelist
A mining multitool
blogs_securelist·2018-07-26
A mining multitool
Authors
- Vladas Bulavas
- Anatoly Kazantsev
## Symbiosis of PowerShell and EternalBlue for cryptocurrency mining
Recently, an interesting miner implementation appeared on Kaspersky Lab’s radar. The malware, which we dubbed PowerGhost, is capable of stealthily establishing itself in a system and spreading across large corporate networks infecting both workstations and servers. This type of hidden consolidation is typical of miners: the more machines that get infected and the longer they remain that way, the greater the attacker’s profits. Therefore, it’s not uncommon to see clean software being infected with a miner; the popularity of the legitimate software serves to promote the malware’s proliferation. The creators of PowerGhost, however, went further and started using fileless techni
Sentinelone
SentinelOne Detects New Malicious PDF File
blogs_sentinelone·2018-06-11·CVSS 8.8
[HIGH] SentinelOne Detects New Malicious PDF File
Documents have always been a popular attack vector. Documents, unlike executables, have been traditionally considered less suspicious and harmful. This concept made it easier for attackers using them to circumvent traditional security solutions. But, over time and with the growing scripting and macro capabilities, documents became much more similar to executables, in a sense that they could run code, create processes and more. Recently, a new malicious PDF file was identified by ESET and Microsoft. Though it was not observed in the wild yet, it’s pretty dangerous as it exploits two previous zero day vulnerabilities: Remote code execution in Adobe Reader (CVE-2018-4990) and Privilege Escalation in Microsoft Windows (CVE-2018-8120).
The attack is carried out in 2 phases. First, a JS code th
Sentinelone
SentinelOne Detects New Malicious PDF File
blogs_sentinelone·2018-06-11·CVSS 8.8
[HIGH] SentinelOne Detects New Malicious PDF File
Documents have always been a popular attack vector. Documents, unlike executables, have been traditionally considered less suspicious and harmful. This concept made it easier for attackers using them to circumvent traditional security solutions. But, over time and with the growing scripting and macro capabilities, documents became much more similar to executables, in a sense that they could run code, create processes and more. Recently, a new malicious PDF file was identified by ESET and Microsoft. Though it was not observed in the wild yet, it’s pretty dangerous as it exploits two previous zero day vulnerabilities: Remote code execution in Adobe Reader (CVE-2018-4990) and Privilege Escalation in Microsoft Windows (CVE-2018-8120).
The attack is carried out in 2 phases. First, a JS code th
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that cou
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits y vulnerabilidades
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that co
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Ausnutzung von Schwachstellen
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
# Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro
2018/05/09
Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174, which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that could
Tenable
Microsoft May Madness
blogs_tenable·2018-05-09
Microsoft May Madness
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro 2018/05/09 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that could
Tenable
Microsoft May Madness
blogs_tenable·2018-05-09·CVSS 9.8
[CRITICAL] Microsoft May Madness
Blog / Research
Subscribe
# Microsoft May Madness
Josef Weiss
May 9, 2018
4 Min Read
Patch Tuesday was anything but typical in the month of May. On May 8, Microsoft released security patches for a total of 67 vulnerabilities, addressing 21 critical vulnerabilities, 42 important and four low-severity, while Adobe addressed a critical flaw in Adobe Flash Player. This is a big push from Microsoft in securing Windows, coming right after the recent release of Windows 10, version 1803, which added several security improvements, among other feature updates.
However, what makes this update particularly important is that it addresses two zero-day vulnerabilities that are being actively exploited in the wild and a further two for which public exploits have been published.
The first critical v
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008, which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16.
### Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of these is notable and requires prompt attenti
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
## Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008 , which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16 .
## Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of thes
Tenable
Why Are You Still Using IE? Double Kill Is Just the Latest Issue
blogs_tenable·2018-04-27
Why Are You Still Using IE? Double Kill Is Just the Latest Issue
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Why Are You Still Using IE? Double Kill Is Just the Latest Issue
blogs_tenable·2018-04-27·CVSS 7.5
CVE-2018-8174 [HIGH] Why Are You Still Using IE? Double Kill Is Just the Latest Issue
Blog / Cyber Exposure Alerts
Subscribe
# Why Are You Still Using IE? Double Kill Is Just the Latest Issue
Steve Tilson
April 27, 2018
4 Min Read
[UPDATE] When we released this warning over a week ago, we suspected it might gain traction and become a bigger issue. As expected, Microsoft addressed this vulnerability on Patch Tuesday. Of the many items addressed in the patch, the most important fixes are around CVE-2018-8174. This CVE references a Windows VBScript engine remote code execution vulnerability – otherwise known as the Double Kill IE zero-day vulnerability.
Microsoft's legacy browser Internet Explorer (IE) has been used for almost three decades, but not without issues. IE has been so plagued with security problems that Microsoft built a new, more secure browser called Edge.
Crowdstrike
Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Zscaler
Zscaler protects against new vulnerabilities for Internet E
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler protects against new vulnerabilities for Internet E
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Leveraging Falcon Sandbox to Detect and Analyze Malicious PDFs Containing Zero-Day Exploits
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
http://www.securityfocus.com/bid/104034http://www.securitytracker.com/id/1040849https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8120https://www.exploit-db.com/exploits/45653/http://www.securityfocus.com/bid/104034http://www.securitytracker.com/id/1040849https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8120https://www.exploit-db.com/exploits/45653/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8120
2018-05-09
Published
2022-03-15
Added to CISA KEV
Exploited in the wild