CVE-2018-8174
published 2018-05-09CVE-2018-8174: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution…
PriorityP191high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-08-15
Exploited in the wild
EPSS
87.64%
99.7th percentile
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The Fallout Exploit Kit landing page uses HTML tags (span, h3, p) to hide obfuscated VBScript exploit code for CVE-2018-8174; look for heavily obfuscated tag content in landing pages redirecting to findmyname[.]pw. ↗
- →Azorult payload uses process hollowing: creates a suspended copy of itself, injects decrypted payload, then resumes execution. Detect suspended self-process creation followed by cross-process memory writes. ↗
- →Microsoft rates CVE-2018-8174 as 'Exploitation Detected' at time of patch release; treat any unpatched system running Internet Explorer or VBScript as actively at risk. ↗
- ·CVE-2018-8174 affects VBScript in Internet Explorer; Internet Explorer 11 on Windows 10 RS3 is NOT vulnerable because VBScript is disabled by default in that configuration. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_msrc7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5cv8-848m-hmm2: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code E
ghsa_unreviewed·2022-05-13
CVE-2018-8174 [HIGH] CWE-787 GHSA-5cv8-848m-hmm2: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code E
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Project0
On VBScript - Project Zero
project_zero·2018-12-01·CVSS 7.5
CVE-2018-8174 [HIGH] On VBScript - Project Zero
Posted by Ivan Fratric, Google Project Zero
Introduction
Vulnerabilities in the VBScript scripting engine are a well known way to attack Microsoft Windows. In order to reduce this attack surface, in Windows 10 Fall Creators Update, Microsoft disabled VBScript execution in Internet Explorer in the Internet Zone and the Restricted Sites Zone by default. Yet this did not deter attackers from using it - in 2018 alone, there have been at least two instances of 0day attacks using vulnerabilities in VBScript: CVE-2018-8174 and CVE-2018-8373. In both of these cases, the delivery method for the exploit were Microsoft Office files with an embedded object which caused malicious VBScript code to be processed using the Internet Explorer engine. For a more detailed analysis of the techniques used in
VulnCheck
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
vulncheck·2018·CVSS 7.5
CVE-2018-8174 [HIGH] CWE-787 Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2018-May; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.trendmicro.com/en_us/research/18/g/a-look-into-recent-exploit-kit-activities.html; https://blog.talosintelligence.com/2018/07/multiple-cobalt-personality-disorder.html; https://www.group-ib.com/resources/threat-research/silence_moving-into-the-darkside.pdf; https
CISA
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
cisa·2022-02-15·CVSS 7.5
CVE-2018-8174 [HIGH] CWE-787 Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Vulnerability: Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Affected: Microsoft Windows
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8174
Remediation Due Date: 2022-08-15
Microsoft
Windows VBScript Engine Remote Code Execution Vulnerability
vendor_msrc·2018-05-08·CVSS 7.5
CVE-2018-8174 [HIGH] Windows VBScript Engine Remote Code Execution Vulnerability
Windows VBScript Engine Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website that is
Suricata
ET EXPLOIT CVE-2018-8174 Common Construct B64 M2
suricata·2019-03-11·CVSS 7.5
CVE-2018-8174 [HIGH] ET EXPLOIT CVE-2018-8174 Common Construct B64 M2
ET EXPLOIT CVE-2018-8174 Common Construct B64 M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2018-8174 Common Construct B64 M2"; flow:established,to_client; file.data; content:"|68546147567362474e765a4756425a475279554746795957|"; classtype:attempted-user; sid:2027070; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_03_11, cve CVE_2018_8174, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT CVE-2018-8174 Common Construct B64 M3
suricata·2019-03-11·CVSS 7.5
CVE-2018-8174 [HIGH] ET EXPLOIT CVE-2018-8174 Common Construct B64 M3
ET EXPLOIT CVE-2018-8174 Common Construct B64 M3
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2018-8174 Common Construct B64 M3"; flow:established,to_client; file.data; content:"|6f5532686c6247786a6232526c5157526b636c4268636d4674|"; classtype:attempted-user; sid:2027071; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_03_11, cve CVE_2018_8174, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT CVE-2018-8174 Common Construct B64 M1
suricata·2019-03-11·CVSS 7.5
CVE-2018-8174 [HIGH] ET EXPLOIT CVE-2018-8174 Common Construct B64 M1
ET EXPLOIT CVE-2018-8174 Common Construct B64 M1
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2018-8174 Common Construct B64 M1"; flow:established,to_client; file.data; content:"|4b464e6f5a5778735932396b5a55466b5a484a5159584a6862|"; classtype:attempted-user; sid:2027069; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_03_11, cve CVE_2018_8174, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Qualys
Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
#### Table of Contents
- Stats on the Top 20 Vulnerable Vendors & By-Products
- Top Twenty Most Targeted by Attackers
- TruRisk Dashboard
- Key Insights & Takeaways
- References
- Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the curre
Qualys
Qualys Top 20 Most Exploited Vulnerabilities
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Qualys Top 20 Most Exploited Vulnerabilities
## Table of Contents
Stats on the Top 20 Vulnerable Vendors & By-Products
Top Twenty Most Targeted by Attackers
TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the current year.
Trendmicro
Magniber unter der Lupe
blogs_trendmicro·2023-02-02·CVSS 7.5
[HIGH] Magniber unter der Lupe
Ransomware
## Magniber unter der Lupe
Magniber-Ransomware nutzt verschiedene Schwachstellen aus, aber obwohl sie im Vergleich zu den neueren Ransomware-Kampagnen mit doppelter Erpressung eine einfachere Kill Chain verwendet, ist sie nicht weniger effektiv. Die Analyse zeigt, was zu tun ist.
By: Trend Micro Feb 02, 2023 Read time: ( words)
Save to Folio
Die Ransomware wurde bereits vor sechs Jahren entdeckt, dennoch verwenden Angreifer die Malware immer noch. Im Oktober 2022 gab es Berichte über Phishing-Attacken, über die Magniber-Ransomware verteilt wurde. Sie nutzten Standalone JavaScript-Dateien, die mit einem manipulierten Schlüssel digital signiert waren, und missbrauchten die Zero Day-Lücke CVE-2022-44698 , um Mark-of-the-Web (MOTW)-Sicherheitswarnungen zu umgehen. So konnten bö
Sentinelone
Maze
blogs_sentinelone·2022-11-30
Maze
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Tenable
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
blogs_tenable·2021-01-21
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
blogs_sentinelone·2020-11-26·CVSS 7.8
[HIGH] Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
## Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone
## Overview
Egregor ransomware is an offshoot of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by compromising organizations, stealing sensitive user data, encrypting said data, and demanding a ransom to exchange encrypted documents. Egregor is ransomware associated with the cyberattacks against GEFCO and Barnes & Noble, Ubisoft, and numerous others.
Multiple intelligence and security companies believe that there are ties between past, now defunct, Maze affiliates and Egregor. There have been reports of ties to Sekhmet , ProLock , and LockBit as well (both of which have also been tied to Maze). With regard to Sekhmet, there are deep similarities in the configuration form
Sentinelone
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone - SentinelLabs
blogs_sentinelone·2020-11-25·CVSS 7.8
[HIGH] Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone - SentinelLabs
## Overview
Egregor ransomware is an offshoot of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by compromising organizations, stealing sensitive user data, encrypting said data, and demanding a ransom to exchange encrypted documents. Egregor is ransomware associated with the cyberattacks against GEFCO and Barnes & Noble, Ubisoft, and numerous others.
Multiple intelligence and security companies believe that there are ties between past, now defunct, Maze affiliates and Egregor. There have been reports of ties to Sekhmet, ProLock, and LockBit as well (both of which have also been tied to Maze). With regard to Sekhmet, there are deep similarities in the configuration format and obfuscation style. SentinelOne-affiliated security researcher
Securelist
IT threat evolution Q2 2020
blogs_securelist·2020-09-03
IT threat evolution Q2 2020
Table of Contents
Targeted attacks
PhantomLance: hiding in plain sight
Naikon’s Aria
COMpfun authors spoof visa application with HTTP status-based Trojan
Mind the [air] gap
Looking at big threats using code similarity
SixLittleMonkeys
Other malware
Loncom packer: from backdoors to Cobalt Strike
xHelper: the Trojan matryoshka
Spike in RDP brute-force attacks
Gaming during the COVID-19 pandemic
Rovnix bootkit back in business
Web skimming with Google Analytics
The Magnitude Exploit Kit
Authors
David Emm
IT threat evolution Q2 2020. PC statistics
IT threat evolution Q2 2020. Mobile statistics
## Targeted attacks
## PhantomLance: hiding in plain sight
In April, we reported the results of our investigation into a mobile spyware campaign that we call ‘PhantomLance’ . The cam
Securelist
CactusPete APT group’s updated Bisonal backdoor
blogs_securelist·2020-08-13
CactusPete APT group’s updated Bisonal backdoor
Table of Contents
What are they looking for?
CactusPete activity
In the end…
IoCs
Authors
Konstantin Zykov
## The backdoor was used to target financial and military organizations in Eastern Europe
CactusPete (also known as Karma Panda or Tonto Team) is an APT group that has been publicly known since at least 2013. Some of the group’s activities have been previously described in public by multiple sources. We have been investigating and privately reporting on this group’s activity for years as well. Historically, their activity has been focused on military, diplomatic and infrastructure targets in Asia and Eastern Europe.
This is also true of the group’s latest activities.
A new CactusPete campaign, spotted at the end of February 2020 by Kaspersky, shows that the group’s favored t
Securelist
CactusPete APT group’s updated Bisonal backdoor
blogs_securelist·2020-08-13
CactusPete APT group’s updated Bisonal backdoor
Table of Contents
- What are they looking for?
- CactusPete activity
- In the end…
- IoCs
Authors
- Konstantin Zykov
## The backdoor was used to target financial and military organizations in Eastern Europe
CactusPete (also known as Karma Panda or Tonto Team) is an APT group that has been publicly known since at least 2013. Some of the group’s activities have been previously described in public by multiple sources. We have been investigating and privately reporting on this group’s activity for years as well. Historically, their activity has been focused on military, diplomatic and infrastructure targets in Asia and Eastern Europe.
This is also true of the group’s latest activities.
A new CactusPete campaign, spotted at the end of February 2020 by Kaspersky, shows that the group’s f
Securelist
Magnitude exploit kit – evolution
blogs_securelist·2020-06-24·CVSS 7.5
[HIGH] Magnitude exploit kit – evolution
Table of Contents
Introduction
Infection vector
Shellcode
Elevation of privilege exploit
Ransomware
Conclusions
Authors
Boris Larin
Exploit kits are not as widespread as they used to be. In the past, they relied on the use of already patched vulnerabilities. Newer and more secure web browsers with automatic updates simply do not allow known vulnerabilities to be exploited. It was very different back in the heyday of Adobe Flash because it’s just a plugin for a web browser, meaning that even if the user has an up-to-date browser, there’s a non-zero chance that Adobe Flash may still be vulnerable to 1-day exploits. Now that Adobe Flash is about to reach its end-of-life date at the end of this year, it is disabled by default in all web browser and has pretty much been replaced with o
Securelist
Magnitude exploit kit – evolution
blogs_securelist·2020-06-24·CVSS 7.5
[HIGH] Magnitude exploit kit – evolution
Table of Contents
- Introduction
- Shellcode
- Elevation of privilege exploit
- Ransomware
- Conclusions
Authors
- Boris Larin
Exploit kits are not as widespread as they used to be. In the past, they relied on the use of already patched vulnerabilities. Newer and more secure web browsers with automatic updates simply do not allow known vulnerabilities to be exploited. It was very different back in the heyday of Adobe Flash because it’s just a plugin for a web browser, meaning that even if the user has an up-to-date browser, there’s a non-zero chance that Adobe Flash may still be vulnerable to 1-day exploits. Now that Adobe Flash is about to reach its end-of-life date at the end of this year, it is disabled by default in all web browser and has pretty much been replaced with open stand
Unit42
Threat Brief: Maze Ransomware
blogs_unit42·2020-05-08·CVSS 7.8
[HIGH] Threat Brief: Maze Ransomware
## Executive Summary
Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the Unit 42 Playbook Viewer.
Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized Word or Excel attachments. However, it has also been distributed via exploit kits such as the Spelevo Exploit Kit, which has been used with Flash Player vulnerabilities CVE-2018-15982 and CVE-2018-4878. Ma
Unit42
Threat Brief: Maze Ransomware
blogs_unit42·2020-05-08·CVSS 7.8
[HIGH] Threat Brief: Maze Ransomware
Threat Research Center
High Profile Threats
Ransomware
## Threat Brief: Maze Ransomware
Brittany Barbehenn
Doel Santos
Published: May 8, 2020
High Profile Threats
Ransomware
Maze
SpelevoEK
## Executive Summary
Since the beginning of the calendar year, Palo Alto Networks has detected an uptick in Maze ransomware samples across multiple industries. As a result, we've created this general threat assessment post on the Maze ransomware activities and full visualization of these techniques can be viewed in the Unit 42 Playbook Viewer .
Maze ransomware, a variant of ChaCha ransomware, was first observed in May 2019 and has targeted organizations in North America, South America, Europe, Asia, and Australia. This ransomware is typically distributed via emails containing weaponized
Tenable
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
blogs_tenable·2020-04-13
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Trendmicro
Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit and Brand-New Cinobi Banking Trojan
blogs_trendmicro·2020-03-11
Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit and Brand-New Cinobi Banking Trojan
Malware
# Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit and Brand-New Cinobi Banking Trojan
We discovered a new campaign that we dubbed "Operation Overtrap" that mainly targets online users of various Japanese banks.
By: Jaromir Horejsi, Joseph C Chen
2020/03/11
Read time: ( words)
Save to Folio
We recently discovered a new campaign that we dubbed “Operation Overtrap” for the numerous ways it can infect or trap victims with its payload. The campaign mainly targets online users of various Japanese banks by stealing their banking credentials using a three-pronged attack. Based on our telemetry, Operation Overtrap has been active since April 2019 and has been solely targeting online banking users located in Japan. Our analysis found that this campaign u
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
CVE-2018-
Trendmicro
Capesand verwendet öffentliche Exploits und Tools
blogs_trendmicro·2019-11-07
Capesand verwendet öffentliche Exploits und Tools
Ausnutzung von Schwachstellen
## Capesand verwendet öffentliche Exploits und Tools
Die Sicherheitsforscher von Trend Micro haben kürzlich ein neues Exploit Kit namens Capesand entdeckt, das auf neuere Sicherheitslücken in Adobe Flash und Microsoft Internet Explorer (IE) zielt.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez Nov 07, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Elliot Cao, Joseph C. Chen, William Gamazo Sanchez
Die Sicherheitsforscher von Trend Micro haben kürzlich ein neues Exploit Kit namens Capesand entdeckt. Das Exploit Kit zielt auf neuere Sicherheitslücken in Adobe Flash und Microsoft Internet Explorer (IE). Die Recherche offenbarte auch den Missbrauch einer Sicherheitslücke für IE von 2015. Die kriminellen Hintermänner entwickeln das Kit stän
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
2019/11/05
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously de
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools
blogs_trendmicro·2019-11-05
New Capesand Exploit Kit Reuses Public Exploits, Tools
Malware
# New Capesand Exploit Kit Reuses Public Exploits, Tools
We found exploit kit Capesand abusing recently disclosed gaps in Adobe Flash and Internet Explorer (IE). Further investigation showed it also exploits a 2015 flaw in IE, appearing to reuse source code from a publicly shared exploit kit code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez
Nov 05, 2019
Read time: ( words)
Save to Folio
Updated as of 7:00 PM Eastern Standard Time to remove one included image.
We discovered a new exploit kit named Capesand in October 2019. Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE). Based on our investigation, it also exploits a 2015 vulnerability for IE. It seems the cybercriminals behind the exploit kit are continuously
Unit42
Web-Based Threats: First Half 2019
blogs_unit42·2019-11-01
Web-Based Threats: First Half 2019
Threat Research Center
Trend Reports
Malware
## Web-Based Threats: First Half 2019
Fang Liu
Tao Yan
Jin Chen
Rongbo Shao
Zhanglin He
Bo Qu
Published: November 1, 2019
Malware
Trend Reports
Vulnerabilities
ELink
Exploit Kits
Malicious Domains
Malicious URL
Phishing
## Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system . In examining the data we collect, which includes URLs extracted from emails or submitted by API, we can identify patterns and trends which helps us discern prevalent web threats. This blog is the fifth installment in a series of posts tracking web-based threats over time, specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.
Unit42
Web-Based Threats: First Half 2019
blogs_unit42·2019-11-01
Web-Based Threats: First Half 2019
# Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system. In examining the data we collect, which includes URLs extracted from emails or submitted by API, we can identify patterns and trends which helps us discern prevalent web threats. This blog is the fifth installment in a series of posts tracking web-based threats over time, specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.
We observed a significant decrease in the activity of the Fallout exploit kit in the first quarter of 2019 while at the same time observing an increase in activity of the Kaixin exploit kit in the second quarter. Kaixin is primarily observed hosted in China and with the increased popularit
Sentinelone
From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
blogs_sentinelone·2019-10-11·CVSS 7.8
CVE-2018-8174 [HIGH] From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
Platform
- Platform Overview
- Singularity Platform
Welcome to IntegratedEnterprise Security
- AI Security Portfolio
Leading the Way in AI-Powered Security Solutions
- How It Works
The Singularity XDR Difference
- Singularity Marketplace
One-Click Integrations to Unlock the Power of XDR
- Pricing & Packaging
Comparisons and Guidance at a Glance
- Data & AI
- Purple AI
Accelerate SecOps with Generative AI
- Singularity Hyperautomation
Easily Automate Security Processes
- AI-SIEM
The AI SIEM for the Autonomous SOC
- Singularity Data Lake
AI-Powered, Unified Data Lake
- Singularity Data Lake for Log Analytics
Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
- Endpoint Security
- Singularity Endpoint
Autonomous Prevention, Detection, and Response
- Singularity XDR
Native &
Sentinelone
From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
blogs_sentinelone·2019-10-11·CVSS 7.8
[HIGH] From Zero to Hero, Chapter 3: RIG Exploit Kit - VBScript CVE-2018-8174 & Flash CVE-2018-4878 Exploit
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Fortinet
Exploring a Recent Magnitude Exploit Kit Sample | FortiGuard Labs
blogs_fortinet·2019-10-09·CVSS 7.5
[HIGH] Exploring a Recent Magnitude Exploit Kit Sample | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Exploring a Recent Magnitude Exploit Kit Sample
By Jessie Leung | October 09, 2019
As Internet Explorer's (IE) share of the browser pie continues to shrink, exploit kits — frameworks hosted by malicious actors to target browser vulnerabilities, particularly for IE — are much less active than before. However, some of them now target geographic regions where IE owns a more sizable part of the market. Magnitude Exploit Kit is one that continues to target South Korea.
Examining a Magnitude Exploit Kit Sample
At FortiGuard Labs, we discovered a sample of the Magnitude Exploit Kit that was using a specific technique with VBScript to load the .NET assembly from memory.
The flow for this sample was as follows:
Ad network 302 redirection
Magnitude EK 'gate' co
Sentinelone
RIG Exploit Kit Chain Internals - SentinelLabs
blogs_sentinelone·2019-09-12
RIG Exploit Kit Chain Internals - SentinelLabs
Vitali Kremez explaining the RIG Exploit Kit and the infection chain internals that led to the Amadey Stealer and Clipboard Hijacker.
## Summary
One of the active malware distribution vectors lately remain to be exploit kits via drive-by infections. Exploit kits (EK) have various components from landing page filtering and serving relevant browser exploit with the end goal of downloading and running various malware of choice on the victim host.
## Background
Exploit kits essentially experienced their heyday in 2012-2014 from the Blackhole Exploit Kit distribution to the Angler (XXX) Exploit Kit to their eventual demise. In many cases, some of the most high-profile sophisticated exploit kits disappeared due to the significant law enforcement operations, which led to the arrest of the mai
Sentinelone
RIG Exploit Kit Chain Internals
blogs_sentinelone·2019-09-12
RIG Exploit Kit Chain Internals
## RIG Exploit Kit Chain Internals
Vitali Kremez explaining the RIG Exploit Kit and the infection chain internals that led to the Amadey Stealer and Clipboard Hijacker.
## Summary
One of the active malware distribution vectors lately remain to be exploit kits via drive-by infections. Exploit kits (EK) have various components from landing page filtering and serving relevant browser exploit with the end goal of downloading and running various malware of choice on the victim host.
## Background
Exploit kits essentially experienced their heyday in 2012-2014 from the Blackhole Exploit Kit distribution to the Angler (XXX) Exploit Kit to their eventual demise. In many cases, some of the most high-profile sophisticated exploit kits disappeared due to the significant law enforcement operations
Trendmicro
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
blogs_trendmicro·2019-09-09
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
Cyber Threats
# ‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
This new iteration of Purple Fox that we came across, delivered by Rig, has a few new tricks up its sleeve. It retains its rootkit component by abusing publicly available code. It also abuses PowerShell making it capable of fileless infection.
By: Johnlery Triunfante, Earle Maui Earnshaw, Michael Jhon Ofiaza
Sep 09, 2019
Read time: ( words)
Save to Folio
Exploit kits may no longer be as prolific as it was back when their activities were detected in the millions, but their recurring activities in the first half of 2019 indicate that they won’t be going away any time soon. The Rig exploit kit, for instance, is known for delivering various payloads — such as downloader trojans, ransomware, cryptocurrency-mining malwar
Trendmicro
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
blogs_trendmicro·2019-09-09
‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
Cyber Threats
# ‘Purple Fox’ Malware Can Rootkit and Abuse PowerShell
This new iteration of Purple Fox that we came across, delivered by Rig, has a few new tricks up its sleeve. It retains its rootkit component by abusing publicly available code. It also abuses PowerShell making it capable of fileless infection.
By: Johnlery Triunfante, Earle Maui Earnshaw, Michael Jhon Ofiaza
2019/09/09
Read time: ( words)
Save to Folio
Exploit kits may no longer be as prolific as it was back when their activities were detected in the millions, but their recurring activities in the first half of 2019 indicate that they won’t be going away any time soon. The Rig exploit kit, for instance, is known for delivering various payloads — such as downloader trojans, ransomware, cryptocurrency-mining malware,
Talos
Welcome Spelevo: New exploit kit full of old tricks
blogs_talos·2019-06-27
Welcome Spelevo: New exploit kit full of old tricks
## Welcome Spelevo: New exploit kit full of old tricks
## EXECUTIVE SUMMARY
Exploit kits are an ever-present and often forgotten threat on the landscape today. Their popularity seemed to peak several years ago with the success and eventual downfall of some of the best compromise platforms ever created, including the Angler Exploit Kit . These kits generated millions of dollars from their victims and they are still effective. One of their biggest appeals today is the removal of reliance on user assistance. Increasingly, on the crimeware landscape today, user assistance is required, whether it's through blatant social engineering attacks like ongoing sextortion campaigns or through the countless malspam messages traversing the globe daily, users are required to help achieve infection. That
Talos
Welcome Spelevo: New exploit kit full of old tricks
blogs_talos·2019-06-27
Welcome Spelevo: New exploit kit full of old tricks
## EXECUTIVE SUMMARY
Exploit kits are an ever-present and often forgotten threat on the landscape today. Their popularity seemed to peak several years ago with the success and eventual downfall of some of the best compromise platforms ever created, including the Angler Exploit Kit. These kits generated millions of dollars from their victims and they are still effective. One of their biggest appeals today is the removal of reliance on user assistance. Increasingly, on the crimeware landscape today, user assistance is required, whether it's through blatant social engineering attacks like ongoing sextortion campaigns or through the countless malspam messages traversing the globe daily, users are required to help achieve infection. That is where exploit kits stand alone as an effective web-ba
Zscaler
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
blogs_zscaler·2019-05-31
Exploit Kit Activity Roundup Spring 2019 | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
blogs_unit42·2019-05-30·CVSS 8.8
[HIGH] Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system. In examining the data it collects, which are URLs extracted from emails or submitted by API, we can identify patterns and trends which help us discern prevalent web threats. This blog is the fourth (4th quarter of 2018) installment in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, CVEs, and now, phishing scams.
The key findings in this quarter’s report in summary are:
1. After Q4 saw an increase in malicious URLs, ending a trend of decreasing malicious URLs starting in Q1 and continuing through Q3.
2. For the first time in our tracking, the United States is not the number one
Unit42
Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
blogs_unit42·2019-05-30·CVSS 8.8
CVE-2018-8174 [HIGH] Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
Threat Research Center
Trend Reports
Malware
## Web-based Threats-2018 Q4: France Rises to #1 for Malicious URL Hosting, US #1 for Phishing
Bo Qu
Tao Yan
Rongbo Shao
Zhanglin He
Published: May 30, 2019
Malware
Trend Reports
Vulnerabilities
Azorult
CVE-2018-8174
ELink
Executive Summary
Our Unit 42 research team routinely evaluates the data from our Email Link Analysis (ELINK) system . In examining the data it collects, which are URLs extracted from emails or submitted by API, we can identify patterns and trends which help us discern prevalent web threats. This blog is the fourth (4th quarter of 2018) installment in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, CVEs, and now, ph
Unit42
BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat
blogs_unit42·2019-04-26
BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat
Threat Research Center
Threat Research
Malware
## BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat
Mark Lim
Published: April 26, 2019
Cybercrime
Malware
Threat Research
BabyShark
CowboyConverter
CowboyLoader
KimJongRAT
PCRat
## Executive Summary
In February 2019, Unit 42 published a blog about the BabyShark malware family and the associated spear phishing campaigns targeting U.S. national think tanks. Since that publication, malicious attacks leveraging BabyShark have continued through March and April 2019. The attackers expanded targeting to the cryptocurrency industry, showing that those behind these attacks also have interests in financial gain.
While tracking the latest activities of the threat group, Unit 42 researchers were able to collect
Unit42
BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat
blogs_unit42·2019-04-26
BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat
# Executive Summary
In February 2019, Unit 42 published a blog about the BabyShark malware family and the associated spear phishing campaigns targeting U.S. national think tanks. Since that publication, malicious attacks leveraging BabyShark have continued through March and April 2019. The attackers expanded targeting to the cryptocurrency industry, showing that those behind these attacks also have interests in financial gain.
While tracking the latest activities of the threat group, Unit 42 researchers were able to collect both the BabyShark malware’s server-side and client-side files, as well as two encoded secondary PE payload files that the malware installs on the victim hosts upon receiving an operator’s command. By analyzing the files, we were able to further understand the overall
Trendmicro
New SLUB Backdoor Uses GitHub, Communicates via Slack
blogs_trendmicro·2019-03-07·CVSS 7.5
[HIGH] New SLUB Backdoor Uses GitHub, Communicates via Slack
# New SLUB Backdoor Uses GitHub, Communicates via Slack
We discovered a malware that uses three different online services -- including Slack and GitHub-- as part of its routine. Analysis of the attacker's TTPs lead us to believe that this might be a targeted attack from capable threat actors.
By: Cedric Pernet, Daniel Lunghi, Jaromir Horejsi, Joseph C Chen
2019/03/07
Read time: ( words)
Save to Folio
We recently came across a previously unknown malware that piqued our interest in multiple ways. For starters, we discovered it being spread via watering hole attacks, a technique that involves an attacker compromising a website before adding code to it so visitors are redirected to the infecting code. In this case, each visitor is redirected only once. The infection was done by exploiting
Trendmicro
New SLUB Backdoor Uses GitHub, Communicates via Slack
blogs_trendmicro·2019-03-07·CVSS 7.5
[HIGH] New SLUB Backdoor Uses GitHub, Communicates via Slack
## New SLUB Backdoor Uses GitHub, Communicates via Slack
We discovered a malware that uses three different online services -- including Slack and GitHub-- as part of its routine. Analysis of the attacker's TTPs lead us to believe that this might be a targeted attack from capable threat actors.
By: Cedric Pernet, Daniel Lunghi, Jaromir Horejsi, Joseph C Chen 2019/03/07 Read time: ( words)
Save to Folio
We recently came across a previously unknown malware that piqued our interest in multiple ways. For starters, we discovered it being spread via watering hole attacks , a technique that involves an attacker compromising a website before adding code to it so visitors are redirected to the infecting code. In this case, each visitor is redirected only once. The infection was done by exploitin
Trendmicro
New SLUB Backdoor Uses GitHub, Communicates via Slack
blogs_trendmicro·2019-03-07·CVSS 7.5
[HIGH] New SLUB Backdoor Uses GitHub, Communicates via Slack
## New SLUB Backdoor Uses GitHub, Communicates via Slack
We discovered a malware that uses three different online services -- including Slack and GitHub-- as part of its routine. Analysis of the attacker's TTPs lead us to believe that this might be a targeted attack from capable threat actors.
By: Cedric Pernet, Daniel Lunghi, Jaromir Horejsi, Joseph C Chen Mar 07, 2019 Read time: ( words)
Save to Folio
We recently came across a previously unknown malware that piqued our interest in multiple ways. For starters, we discovered it being spread via watering hole attacks , a technique that involves an attacker compromising a website before adding code to it so visitors are redirected to the infecting code. In this case, each visitor is redirected only once. The infection was done by exploit
Zscaler
Top EK Activity Roundup – Winter 2019 | Zscaler Blog
blogs_zscaler·2019-01-18
Top EK Activity Roundup – Winter 2019 | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
blogs_unit42·2018-12-27·CVSS 9.8
[CRITICAL] Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
# Executive Summary
Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
During Quarter 3 (Q3), July – September, a notable shift occurred with the malicious URL and domain data; there was a significant drop in the number of malicious URLs as well as a drop in malicious domains that will be discussed below. In addition, we will be covering an interesting malicious Flash SWF that exploits CVE-2015-5119.
# URLs
Based on our analysis of dat
Unit42
Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
blogs_unit42·2018-12-27·CVSS 9.8
CVE-2015-5119 [CRITICAL] Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
Threat Research Center
Trend Reports
Malware
## Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
Bo Qu
Tao Yan
Rongbo Shao
Zhanglin He
Xingyu Jin
Published: December 27, 2018
Malware
Trend Reports
Vulnerabilities
CVE-2015-5119
ELink
## Executive Summary
Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
During Quarter 3 (Q3), July – September, a notable shift occurred with the malicious URL and domain d
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
- Introduction
- Targeted attack campaigns
- Mobile APT campaigns
- Exploits
- Browser extensions – extending the reach of cybercriminals
- The World Cup of fraud
- Financial fraud on an industrial scale
- Ransomware – still a threat
- Asacub and banking Trojans
- Smart doesn’t mean secure
- Our data in their hands
Authors
- David Emm
- Victor Chebyshev
- Kaspersky Security Bulletin 2018. Statistics
- Kaspersky Security Bulletin 2018. Story of the year: miners
- Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses a
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
Introduction
Targeted attack campaigns
Mobile APT campaigns
Exploits
Browser extensions – extending the reach of cybercriminals
The World Cup of fraud
Financial fraud on an industrial scale
Ransomware – still a threat
Asacub and banking Trojans
Smart doesn’t mean secure
Our data in their hands
Authors
David Emm
Victor Chebyshev
Kaspersky Security Bulletin 2018. Statistics
Kaspersky Security Bulletin 2018. Story of the year: miners
Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses and consumers provide
Unit42
New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
blogs_unit42·2018-11-21·CVSS 7.5
CVE-2018-8174 [HIGH] New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
Threat Research Center
Threat Research
Malware
## New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
Tao Yan
Xingyu Jin
Bo Qu
Zhanglin He
Published: November 21, 2018
Cybercrime
Malware
Threat Research
Azorult
Coins
Cryptocurrency
CVE-2018-8174
Electrum
Electrum-LTC
Ethereum
Exodus
Fallout Exploit Kit
FindMyName
Jaxx
MultiBitHD
Wallet
Overview
Observed in the wild as early as 2016, Azorult is a Trojan family which has been delivered in malicious macro-based documents via spam campaigns, or as a secondary payload in the RIG Exploit Kit campaigns. On October 20 th , 2018 we discovered that new Azorult variants were being used as primary payloads in a new ongoing campaign using the Fallout Exploit Kit. We named this c
Unit42
New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
blogs_unit42·2018-11-21·CVSS 7.5
[HIGH] New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit
Overview
Observed in the wild as early as 2016, Azorult is a Trojan family which has been delivered in malicious macro-based documents via spam campaigns, or as a secondary payload in the RIG Exploit Kit campaigns. On October 20th, 2018 we discovered that new Azorult variants were being used as primary payloads in a new ongoing campaign using the Fallout Exploit Kit. We named this campaign ‘FindMyName’ because all of the final exploit pages land on the domain findmyname[.]pw. These new Azorult samples variants use advanced obfuscation techniques, such as API flooding and control flow flattening, to evade anti-virus products. Also, we discovered that Azorult has further evolved, the samples we captured support stealing sensitive information in more browsers, applications, and cryptocurrenc
Trendmicro
New CVE-2018-8373 Exploit Spotted
blogs_trendmicro·2018-09-25·CVSS 8.8
CVE-2018-8373 [HIGH] New CVE-2018-8373 Exploit Spotted
Exploits & Vulnerabilities
# New CVE-2018-8373 Exploit Spotted
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability.
By: Elliot Cao
2018/09/25
Read time: ( words)
Save to Folio
On September 18, 2018, more than a month after we published a blog revealing the details of a use-after-free (UAF) vulnerability CVE-2018-8373 that affects the VBScript engine in newer Windows versions, we spotted another exploit that uses the same vulnerability. It's important to note that this exploit doesn't work on systems with updated Internet Explorer versions.
Instead of modifying the CONTEXT structure of NtCo
Unit42
Traps Prevents In-The-Wild VBScript Zero-Day Exploit in Internet Explorer
blogs_unit42·2018-09-07·CVSS 7.5
CVE-2018-8373 [HIGH] Traps Prevents In-The-Wild VBScript Zero-Day Exploit in Internet Explorer
On August 15, Trend Micro published a blog post detailing a high-risk vulnerability in the VBScript Engine of Microsoft Internet Explorer being exploited in-the-wild (CVE-2018-8373). This vulnerability still affects endpoints running the latest versions of Internet Explorer and Windows which do not have the relevant patches applied.
The exploit was served on a malicious web host: hxxp://windows-updater[.]net/realmuto/wood.php?who=1?????? which was linked to the DarkHotel APT campaign by Qihoo 360, and this actor also exploited another VBScript vulnerability earlier this year (CVE-2018-8174). The preliminary payload was also analyzed thoroughly by Qihoo 360, and is dubbed zlib1.dll.
Figure 1. The attack flow as observed in the malicious sample
In Figure 1 we show the attack flow as obser
Unit42
Traps Prevents In-The-Wild VBScript Zero-Day Exploit in Internet Explorer
blogs_unit42·2018-09-07·CVSS 7.5
CVE-2018-8373 [HIGH] Traps Prevents In-The-Wild VBScript Zero-Day Exploit in Internet Explorer
Threat Research Center
Threat Research
Vulnerabilities
## Traps Prevents In-The-Wild VBScript Zero-Day Exploit in Internet Explorer
Tomer Harpaz
Maor Dokhanian
Published: September 7, 2018
Malware
Threat Research
Vulnerabilities
CVE-2018-8373
DarkHotel
On August 15, Trend Micro published a blog post detailing a high-risk vulnerability in the VBScript Engine of Microsoft Internet Explorer being exploited in-the-wild ( CVE-2018-8373 ). This vulnerability still affects endpoints running the latest versions of Internet Explorer and Windows which do not have the relevant patches applied.
The exploit was served on a malicious web host: hxxp://windows-updater[.]net/realmuto/wood.php?who=1?????? which was linked to the DarkHotel APT campaign by Qihoo 360 , and this actor also exploi
Unit42
Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
blogs_unit42·2018-09-05·CVSS 7.5
CVE-2018-8174 [HIGH] Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
Threat Research Center
Trend Reports
Vulnerabilities
## Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
Bo Qu
Tao Yan
Rongbo Shao
Zhanglin He
Published: September 5, 2018
Malware
Trend Reports
Vulnerabilities
CVE-2018-8174
ELink
Executive Summary
In Q2, the United States was number one for hosting malicious domains and exploit kits.
Unit 42 regularly analyzes statistical data from our Email Link Analysis (ELINK) to understand the patterns and trends in current web threats. This blog outlines our analysis for April – June (Q2) 2018 and follows up our previous blog analyzing web-based threats for January – March (Q1) 2018 that can be found here . We also provide detailed analysis of attacks against CVE-2018-8174 (a vulnerabil
Unit42
Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
blogs_unit42·2018-09-05·CVSS 7.5
CVE-2018-8174 [HIGH] Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7
Executive Summary
In Q2, the United States was number one for hosting malicious domains and exploit kits.
Unit 42 regularly analyzes statistical data from our Email Link Analysis (ELINK) to understand the patterns and trends in current web threats. This blog outlines our analysis for April – June (Q2) 2018 and follows up our previous blog analyzing web-based threats for January – March (Q1) 2018 that can be found here. We also provide detailed analysis of attacks against CVE-2018-8174 (a vulnerability we discuss below) using the Double Kill exploit.
What we found this quarter was that vulnerabilities under attack remained consistent, including very old vulnerabilities. One new vulnerability used zero-day attacks did rocket to near the top of the list.
The United States remained the num
Trendmicro
UAF Bug Affects Internet Explorer, Runs Shellcode
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] UAF Bug Affects Internet Explorer, Runs Shellcode
Exploits & Vulnerabilities
## UAF Bug Affects Internet Explorer, Runs Shellcode
We discovered a high-risk Internet Explorer (IE) vulnerability. This vulnerability, designated as CVE-2018-8373, affects the VBScript engine in the latest versions of Windows, but Internet Explorer 11 is not vulnerable.
By: Elliot Cao, Zero Day Initiative Aug 15, 2018 Read time: ( words)
Save to Folio
We discovered a high-risk Internet Explorer (IE) vulnerability in the wild on July 11, just a day after Microsoft’s July Patch Tuesday. We immediately sent Microsoft the details to help fix this flaw. While this vulnerability, now designated as CVE-2018-8373 , affects the VBScript engine in the latest versions of Windows, Internet Explorer 11 is not vulnerable since VBScript in Windows 10 Redstone 3 (RS3) has
Trendmicro
August Patch Tuesday: A Tale of Two Zero-Days
blogs_trendmicro·2018-08-15·CVSS 7.5
[HIGH] August Patch Tuesday: A Tale of Two Zero-Days
Ausnutzung von Schwachstellen
## August Patch Tuesday: A Tale of Two Zero-Days
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
By: Trend Micro Aug 15, 2018 Read time: ( words)
Save to Folio
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
The first of these zero day vulnerabilities is CVE-2018-8373 , a use-after-free (UAF) vulnerability in VBscript engine that Trend Micro researchers found in Internet Explorer. This vulnerability bears many similarities to CVE-2018-8174 , another VBscript engine vulnerability that was patched back in May . Successful exploitation of this vulnerability could
Trendmicro
UAF Bug Affects Internet Explorer, Runs Shellcode
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] UAF Bug Affects Internet Explorer, Runs Shellcode
Exploits y vulnerabilidades
## UAF Bug Affects Internet Explorer, Runs Shellcode
We discovered a high-risk Internet Explorer (IE) vulnerability. This vulnerability, designated as CVE-2018-8373, affects the VBScript engine in the latest versions of Windows, but Internet Explorer 11 is not vulnerable.
By: Elliot Cao, Zero Day Initiative Aug 15, 2018 Read time: ( words)
Save to Folio
We discovered a high-risk Internet Explorer (IE) vulnerability in the wild on July 11, just a day after Microsoft’s July Patch Tuesday. We immediately sent Microsoft the details to help fix this flaw. While this vulnerability, now designated as CVE-2018-8373 , affects the VBScript engine in the latest versions of Windows, Internet Explorer 11 is not vulnerable since VBScript in Windows 10 Redstone 3 (RS3) ha
Trendmicro
UAF Bug Affects Internet Explorer, Runs Shellcode
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] UAF Bug Affects Internet Explorer, Runs Shellcode
Ausnutzung von Schwachstellen
## UAF Bug Affects Internet Explorer, Runs Shellcode
We discovered a high-risk Internet Explorer (IE) vulnerability. This vulnerability, designated as CVE-2018-8373, affects the VBScript engine in the latest versions of Windows, but Internet Explorer 11 is not vulnerable.
By: Elliot Cao, Zero Day Initiative Aug 15, 2018 Read time: ( words)
Save to Folio
We discovered a high-risk Internet Explorer (IE) vulnerability in the wild on July 11, just a day after Microsoft’s July Patch Tuesday. We immediately sent Microsoft the details to help fix this flaw. While this vulnerability, now designated as CVE-2018-8373 , affects the VBScript engine in the latest versions of Windows, Internet Explorer 11 is not vulnerable since VBScript in Windows 10 Redstone 3 (RS3)
Trendmicro
August Patch Tuesday: A Tale of Two Zero-Days
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] August Patch Tuesday: A Tale of Two Zero-Days
Exploits y vulnerabilidades
## August Patch Tuesday: A Tale of Two Zero-Days
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
By: Trend Micro Aug 15, 2018 Read time: ( words)
Save to Folio
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
The first of these zero day vulnerabilities is CVE-2018-8373 , a use-after-free (UAF) vulnerability in VBscript engine that Trend Micro researchers found in Internet Explorer. This vulnerability bears many similarities to CVE-2018-8174 , another VBscript engine vulnerability that was patched back in May . Successful exploitation of this vulnerability could a
Trendmicro
August Patch Tuesday: A Tale of Two Zero-Days
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] August Patch Tuesday: A Tale of Two Zero-Days
Exploits & Vulnerabilities
# August Patch Tuesday: A Tale of Two Zero-Days
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
By: Trend Micro
2018/08/15
Read time: ( words)
Save to Folio
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
The first of these zero day vulnerabilities is CVE-2018-8373, a use-after-free (UAF) vulnerability in VBscript engine that Trend Micro researchers found in Internet Explorer. This vulnerability bears many similarities to CVE-2018-8174, another VBscript engine vulnerability that was patched back in May. Successful exploitation of this vulnerability could allow a
Trendmicro
August Patch Tuesday: A Tale of Two Zero-Days
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] August Patch Tuesday: A Tale of Two Zero-Days
Exploits & Vulnerabilities
## August Patch Tuesday: A Tale of Two Zero-Days
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
By: Trend Micro Aug 15, 2018 Read time: ( words)
Save to Folio
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
The first of these zero day vulnerabilities is CVE-2018-8373 , a use-after-free (UAF) vulnerability in VBscript engine that Trend Micro researchers found in Internet Explorer. This vulnerability bears many similarities to CVE-2018-8174 , another VBscript engine vulnerability that was patched back in May . Successful exploitation of this vulnerability could al
Trendmicro
UAF Bug Affects Internet Explorer, Runs Shellcode
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] UAF Bug Affects Internet Explorer, Runs Shellcode
Exploits & Vulnerabilities
## UAF Bug Affects Internet Explorer, Runs Shellcode
We discovered a high-risk Internet Explorer (IE) vulnerability. This vulnerability, designated as CVE-2018-8373, affects the VBScript engine in the latest versions of Windows, but Internet Explorer 11 is not vulnerable.
By: Elliot Cao, Zero Day Initiative 2018/08/15 Read time: ( words)
Save to Folio
We discovered a high-risk Internet Explorer (IE) vulnerability in the wild on July 11, just a day after Microsoft’s July Patch Tuesday. We immediately sent Microsoft the details to help fix this flaw. While this vulnerability, now designated as CVE-2018-8373 , affects the VBScript engine in the latest versions of Windows, Internet Explorer 11 is not vulnerable since VBScript in Windows 10 Redstone 3 (RS3) has b
Trendmicro
UAF Bug Affects Internet Explorer, Runs Shellcode
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] UAF Bug Affects Internet Explorer, Runs Shellcode
Exploits & Vulnerabilities
# UAF Bug Affects Internet Explorer, Runs Shellcode
We discovered a high-risk Internet Explorer (IE) vulnerability. This vulnerability, designated as CVE-2018-8373, affects the VBScript engine in the latest versions of Windows, but Internet Explorer 11 is not vulnerable.
By: Elliot Cao, Zero Day Initiative
2018/08/15
Read time: ( words)
Save to Folio
We discovered a high-risk Internet Explorer (IE) vulnerability in the wild on July 11, just a day after Microsoft’s July Patch Tuesday. We immediately sent Microsoft the details to help fix this flaw. While this vulnerability, now designated as CVE-2018-8373, affects the VBScript engine in the latest versions of Windows, Internet Explorer 11 is not vulnerable since VBScript in Windows 10 Redstone 3 (RS3) has be
Trendmicro
August Patch Tuesday: A Tale of Two Zero-Days
blogs_trendmicro·2018-08-15·CVSS 7.5
CVE-2018-8373 [HIGH] August Patch Tuesday: A Tale of Two Zero-Days
Exploits & Vulnerabilities
## August Patch Tuesday: A Tale of Two Zero-Days
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
By: Trend Micro 2018/08/15 Read time: ( words)
Save to Folio
This month’s Microsoft Patch Tuesday includes important updates that patch two zero-day vulnerabilities that are already being actively exploited.
The first of these zero day vulnerabilities is CVE-2018-8373 , a use-after-free (UAF) vulnerability in VBscript engine that Trend Micro researchers found in Internet Explorer. This vulnerability bears many similarities to CVE-2018-8174 , another VBscript engine vulnerability that was patched back in May . Successful exploitation of this vulnerability could allo
Zscaler
Exploit kits go Cryptomining | Zscaler Blog
blogs_zscaler·2018-08-07
Exploit kits go Cryptomining | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Securelist
IT threat evolution Q2 2018. Statistics
blogs_securelist·2018-08-06
IT threat evolution Q2 2018. Statistics
Table of Contents
- Q2 figures
- Mobile threats
- Attacks on IoT devices
- Online threats in the financial sector
- Vulnerable apps used by cybercriminals
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Alexander Liskin
- Oleg Kupreev
## Q2 figures
According to KSN:
- Kaspersky Lab solutions blocked 962,947,023 attacks launched from online resources located in 187 countries across the globe.
- 351,913,075 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to bank accounts were logged on the computers of 215,762 users.
- Ransomware attacks were registered on the computers of 158,921 unique users.
- Our File Anti-Virus logged 192,053,
Fortinet
An Analysis of the DLL Address Leaking Trick used by the “Double Kill” Internet Explorer Zero-Day exploit (CVE-2018-8174)
blogs_fortinet·2018-08-06·CVSS 7.5
CVE-2018-8174 [HIGH] An Analysis of the DLL Address Leaking Trick used by the “Double Kill” Internet Explorer Zero-Day exploit (CVE-2018-8174)
FORTIGUARD LABS THREAT RESEARCH
An Analysis of the DLL Address Leaking Trick used by the “Double Kill” Internet Explorer Zero-Day exploit (CVE-2018-8174)
By Dehui Yin | August 06, 2018
“Double Kill” is an Internet Explorer(IE) Zero-Day exploit which was discovered in the wild and fixed in the Microsoft May Patch. It exploits a use-after-free vulnerability of vbscript.dll to execute arbitrary code when a vulnerable system browses a malicious web page via IE. Multiple exploit kits have already added this exploit, and it is still active in the wild.
This use-after-free bug causes a type confusion in vbscript.dll, which allows the attacker to access and overwrite the whole user space memory address. However, before the shellcode can be finally executed, the attacker has to get the address o
Securelist
IT threat evolution Q2 2018
blogs_securelist·2018-08-06
IT threat evolution Q2 2018
Table of Contents
- Targeted attacks and malware campaigns
- Malware stories
Authors
- David Emm
## Targeted attacks and malware campaigns
### Operation Parliament
In April, we reported the workings of Operation Parliament, a cyber-espionage campaign aimed at high-profile legislative, executive and judicial organizations around the world – with its main focus in the MENA (Middle East and North Africa) region, especially Palestine. The attacks, which started early in 2017, target parliaments, senates, top state offices and officials, political science scholars, military and intelligence agencies, ministries, media outlets, research centers, election commissions, Olympic organizations, large trading companies and others.
The attackers have taken great care to stay under the radar, imi
Securelist
IT threat evolution Q2 2018. Statistics
blogs_securelist·2018-08-06
IT threat evolution Q2 2018. Statistics
Table of Contents
Q2 figures
Mobile threats
General statistics
Distribution of detected mobile apps by type
TOP 20 mobile malware
Geography of mobile threats
Mobile banking Trojans
Mobile ransomware Trojans
Attacks on IoT devices
Telnet attacks
TOP 10 countries by shares of IoT devices infected via Telnet
TOP 10 malware downloaded to infected IoT devices in successful Telnet attacks
SSH attacks
TOP 10 countries by shares of IoT devices attacked via SSH
Online threats in the financial sector
Q2 events
New banking Trojan DanaBot
The peculiar BackSwap technique
Carbanak gang leader detained
Ransomware Trojan uses Doppelgänging technique
General statistics on financial threats
Geography of attacks
TOP 10 countries by percentage of attacked users
TOP 10 banking malware f
Securelist
IT threat evolution Q2 2018
blogs_securelist·2018-08-06
IT threat evolution Q2 2018
Table of Contents
Targeted attacks and malware campaigns
Operation Parliament
Energetic Bear
ZooPark
The king is dead, long live the king!
VPNFilter
LuckyMouse
Olympic Destroyer
Malware stories
Leaking ads
SynAck targeted ransomware uses the Doppelganging technique
Roaming Mantis
If it’s smart, it’s potentially vulnerable
An MitM extension for Chrome
The World Cup of fraud
Authors
David Emm
## Targeted attacks and malware campaigns
## Operation Parliament
In April, we reported the workings of Operation Parliament , a cyber-espionage campaign aimed at high-profile legislative, executive and judicial organizations around the world – with its main focus in the MENA (Middle East and North Africa) region, especially Palestine. The attacks, which started early in 2017, target
Unit42
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
blogs_unit42·2018-07-24
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
Nearly all of us have a use for Microsoft Office documents. Whether they are work documents, e-receipts, or a lease on a new apartment – Office documents are useful to all of us, and this is part of the reason we’re very likely to open an office document we receive as an attachment in e-mail. Armed with the knowledge that many people will open nearly any document, even those from an untrusted source, adversaries commonly choose these files in attacks to compromise a system.
In this threat brief we show you five different ways that Office documents can be subverted and abused to attack and compromise a Windows endpoint, some we’ve already posted about before, and some are new.
Macros
Macros are the most straight-forward way for an attacker to weaponize Office documents. Office applicatio
Unit42
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
blogs_unit42·2018-07-24
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
## Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)
Liat Hayun
Published: July 24, 2018
High Profile Threats
Malware
Embedded Flash files
HTA Handlers
Macros
Microsoft Office Documents
OLE Objects
Nearly all of us have a use for Microsoft Office documents. Whether they are work documents, e-receipts, or a lease on a new apartment – Office documents are useful to all of us, and this is part of the reason we’re very likely to open an office document we receive as an attachment in e-mail. Armed with the knowledge that many people will open nearly any document, even those from an untrusted source, adversaries commonly choose these files in attacks to compromise a system.
In this threat brief we show you five different ways that Office documents
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
- GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informat
Securelist
APT Trends Report Q2 2018
blogs_securelist·2018-07-10
APT Trends Report Q2 2018
Authors
GReAT
In the second quarter of 2017, Kaspersky Lab’s Global Research and Analysis Team (GReAT) began publishing summaries of the quarter’s private threat intelligence reports, in an effort to make the public aware of the research we have been conducting. This report serves as the latest installment, focusing on the relevant activities that we observed during Q2 2018.
These summaries are a representative snapshot of what has been discussed in greater detail in our private reports. They aim to highlight the significant events and findings that we feel people should be aware of. For brevity’s sake, we are choosing not to publish indicators associated with the reports highlighted. However, readers who would like to learn more about our intelligence reports or request more informatio
Securelist
Delving deep into VBScript
blogs_securelist·2018-07-03·CVSS 8.8
CVE-2018-8174 [HIGH] Delving deep into VBScript
Authors
Boris Larin
## Analysis of CVE-2018-8174 exploitation
In late April we found and wrote a description of CVE-2018-8174 , a new zero-day vulnerability for Internet Explorer that was picked up by our sandbox. The vulnerability uses a well-known technique from the proof-of-concept exploit CVE-2014-6332 that essentially “corrupts” two memory objects and changes the type of one object to Array (for read/write access to the address space) and the other object to Integer to fetch the address of an arbitrary object.
But whereas CVE-2014-6332 was aimed at integer overflow exploitation for writing to arbitrary memory locations, my interest lay in how this technique was adapted to exploit the use-after-free vulnerability. To answer this question, let’s consider the internal structure of th
Securelist
Delving deep into VBScript
blogs_securelist·2018-07-03·CVSS 8.8
CVE-2018-8174 [HIGH] Delving deep into VBScript
Authors
- Boris Larin
## Analysis of CVE-2018-8174 exploitation
In late April we found and wrote a description of CVE-2018-8174, a new zero-day vulnerability for Internet Explorer that was picked up by our sandbox. The vulnerability uses a well-known technique from the proof-of-concept exploit CVE-2014-6332 that essentially “corrupts” two memory objects and changes the type of one object to Array (for read/write access to the address space) and the other object to Integer to fetch the address of an arbitrary object.
But whereas CVE-2014-6332 was aimed at integer overflow exploitation for writing to arbitrary memory locations, my interest lay in how this technique was adapted to exploit the use-after-free vulnerability. To answer this question, let’s consider the internal structure of t
Trendmicro
Down but Not Out: Recent Exploit Kit Activities
blogs_trendmicro·2018-07-02·CVSS 7.5
[HIGH] Down but Not Out: Recent Exploit Kit Activities
Ausnutzung von Schwachstellen
## Down but Not Out: Recent Exploit Kit Activities
Based on the exploit kits’ latest activities, it appears they and their users are shifting tactics by joining the bandwagon, like capitalizing on cryptocurrency’s popularity or using off-the-rack malware.
By: Martin Co, Joseph C Chen Jul 02, 2018 Read time: ( words)
Save to Folio
Exploit kits may be down, but they’re not out. While they're still using the same techniques that involve malvertisements or embedding links in spam and malicious or compromised websites, their latest activities are making them significant factors in the threat landscape again. This is the case with Rig and GrandSoft, as well as the private exploit kit Magnitude — exploit kits we found roping in relatively recent vulnerabilities
Trendmicro
Down but Not Out: Recent Exploit Kit Activities
blogs_trendmicro·2018-07-02·CVSS 7.5
[HIGH] Down but Not Out: Recent Exploit Kit Activities
Exploits & Vulnerabilities
# Down but Not Out: Recent Exploit Kit Activities
Based on the exploit kits’ latest activities, it appears they and their users are shifting tactics by joining the bandwagon, like capitalizing on cryptocurrency’s popularity or using off-the-rack malware.
By: Martin Co, Joseph C Chen
2018/07/02
Read time: ( words)
Save to Folio
Exploit kits may be down, but they’re not out. While they're still using the same techniques that involve malvertisements or embedding links in spam and malicious or compromised websites, their latest activities are making them significant factors in the threat landscape again. This is the case with Rig and GrandSoft, as well as the private exploit kit Magnitude — exploit kits we found roping in relatively recent vulnerabilities to de
Trendmicro
Down but Not Out: Recent Exploit Kit Activities
blogs_trendmicro·2018-07-02·CVSS 7.5
[HIGH] Down but Not Out: Recent Exploit Kit Activities
Exploits & Vulnerabilities
## Down but Not Out: Recent Exploit Kit Activities
Based on the exploit kits’ latest activities, it appears they and their users are shifting tactics by joining the bandwagon, like capitalizing on cryptocurrency’s popularity or using off-the-rack malware.
By: Martin Co, Joseph C Chen 2018/07/02 Read time: ( words)
Save to Folio
Exploit kits may be down, but they’re not out. While they're still using the same techniques that involve malvertisements or embedding links in spam and malicious or compromised websites, their latest activities are making them significant factors in the threat landscape again. This is the case with Rig and GrandSoft, as well as the private exploit kit Magnitude — exploit kits we found roping in relatively recent vulnerabilities to de
Trendmicro
Down but Not Out: Recent Exploit Kit Activities
blogs_trendmicro·2018-07-02·CVSS 7.5
[HIGH] Down but Not Out: Recent Exploit Kit Activities
Exploits & Vulnerabilities
## Down but Not Out: Recent Exploit Kit Activities
Based on the exploit kits’ latest activities, it appears they and their users are shifting tactics by joining the bandwagon, like capitalizing on cryptocurrency’s popularity or using off-the-rack malware.
By: Martin Co, Joseph C Chen Jul 02, 2018 Read time: ( words)
Save to Folio
Exploit kits may be down, but they’re not out. While they're still using the same techniques that involve malvertisements or embedding links in spam and malicious or compromised websites, their latest activities are making them significant factors in the threat landscape again. This is the case with Rig and GrandSoft, as well as the private exploit kit Magnitude — exploit kits we found roping in relatively recent vulnerabilities to
Trendmicro
Down but Not Out: Recent Exploit Kit Activities
blogs_trendmicro·2018-07-02·CVSS 7.5
[HIGH] Down but Not Out: Recent Exploit Kit Activities
Exploits y vulnerabilidades
## Down but Not Out: Recent Exploit Kit Activities
Based on the exploit kits’ latest activities, it appears they and their users are shifting tactics by joining the bandwagon, like capitalizing on cryptocurrency’s popularity or using off-the-rack malware.
By: Martin Co, Joseph C Chen Jul 02, 2018 Read time: ( words)
Save to Folio
Exploit kits may be down, but they’re not out. While they're still using the same techniques that involve malvertisements or embedding links in spam and malicious or compromised websites, their latest activities are making them significant factors in the threat landscape again. This is the case with Rig and GrandSoft, as well as the private exploit kit Magnitude — exploit kits we found roping in relatively recent vulnerabilities to
Fortinet
An Analysis of the Use-After-Free Bug in the Microsoft Edge Chakra Engine (CVE-2018-0946)
blogs_fortinet·2018-06-28·CVSS 7.5
CVE-2018-0946 [HIGH] An Analysis of the Use-After-Free Bug in the Microsoft Edge Chakra Engine (CVE-2018-0946)
FORTIGUARD LABS THREAT RESEARCH
An Analysis of the Use-After-Free Bug in the Microsoft Edge Chakra Engine (CVE-2018-0946)
By Dehui Yin | June 28, 2018
Microsoft fixed an use-after-free bug in the Edge Chakra Engine in the May 2018 Patch. This bug (CVE-2018-0946) causes the Chakra Engine to access a freed function address that can possibly be exploited to execute arbitrary code when a vulnerable system browses a malicious web page via Microsoft Edge.
This use-after-free bug occurs when the Chakra Engine tries to execute the optimized function code generated by the just-in-time (JIT) compiler, which has already been freed when closing the related context. In this post, the team at FortiGuard Labs looks deeply into the Microsoft Edge Chakra Engine assembly codes to expose the root cause of
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva 2018/05/31 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on the
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on t
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits y vulnerabilidades
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on t
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Exploits & Vulnerabilities
# Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva
2018/05/31
Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based on the
Trendmicro
Rig Abuses CVE-2018-8174 to Deliver Monero Miner
blogs_trendmicro·2018-05-31·CVSS 8.8
CVE-2018-8174 [HIGH] Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Ausnutzung von Schwachstellen
## Rig Abuses CVE-2018-8174 to Deliver Monero Miner
Sometime around February to March last year, we saw the Rig exploit kit’s Seamless campaign adding another gate before the actual landing page.
By: Miguel Carlo Ang, Martin Co, Michael Villanueva May 31, 2018 Read time: ( words)
Save to Folio
An exploit kit such as Rig usually starts off with a threat actor compromising a website to inject a malicious script/code that eventually redirects would-be victims to the exploit kit’s landing page. Sometime around February to March last year, however, we saw Rig’s Seamless campaign adding another layer or gate before the actual landing page.
Along with updates in code, we also observed Rig integrating a cryptocurrency-mining malware as its final payload. Based o
Securelist
The King is dead. Long live the King!
blogs_securelist·2018-05-09·CVSS 7.5
CVE-2018-8174 [HIGH] The King is dead. Long live the King!
Authors
- Vladislav Stolyarov
- Boris Larin
- Anton Ivanov
## Root cause analysis of the latest Internet Explorer zero day – CVE-2018-8174
In late April 2018, a new zero-day vulnerability for Internet Explorer (IE) was found using our sandbox; more than two years since the last in the wild example (CVE-2016-0189). This particular vulnerability and subsequent exploit are interesting for many reasons. The following article will examine the core reasons behind the latest vulnerability, CVE-2018-8174.
### Searching for the zero day
Our story begins on VirusTotal (VT), where someone uploaded an interesting exploit on April 18, 2018. This exploit was detected by several AV vendors including Kaspersky, specifically by our generic heuristic logic for some older Microsoft Word exploits.
After
Securelist
The King is dead. Long live the King!
blogs_securelist·2018-05-09·CVSS 7.5
CVE-2018-8174 [HIGH] The King is dead. Long live the King!
Authors
Vladislav Stolyarov
Boris Larin
Anton Ivanov
## Root cause analysis of the latest Internet Explorer zero day – CVE-2018-8174
In late April 2018, a new zero-day vulnerability for Internet Explorer (IE) was found using our sandbox; more than two years since the last in the wild example (CVE-2016-0189). This particular vulnerability and subsequent exploit are interesting for many reasons. The following article will examine the core reasons behind the latest vulnerability, CVE-2018-8174.
## Searching for the zero day
Our story begins on VirusTotal (VT), where someone uploaded an interesting exploit on April 18, 2018. This exploit was detected by several AV vendors including Kaspersky, specifically by our generic heuristic logic for some older Microsoft Word exploits.
After the
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that cou
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits y vulnerabilidades
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that co
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Ausnutzung von Schwachstellen
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro May 09, 2018 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
# Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro
2018/05/09
Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174, which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that could
Tenable
Microsoft May Madness
blogs_tenable·2018-05-09
Microsoft May Madness
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Microsoft’s May Patch Tuesday Fixes Exploited Bugs
blogs_trendmicro·2018-05-09·CVSS 7.6
[HIGH] Microsoft’s May Patch Tuesday Fixes Exploited Bugs
Exploits & Vulnerabilities
## Microsoft’s May Patch Tuesday Fixes Exploited Bugs
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
By: Trend Micro 2018/05/09 Read time: ( words)
Save to Folio
For May 2018, Microsoft’s monthly release of security updates — also known as Patch Tuesday — addressed a number of vulnerabilities, most notably two vulnerabilities that were already actively exploited in attacks.
One of these vulnerabilities is CVE-2018-8174 , which is a remote code execution flaw in the way the VBScript engine handles objects in memory. Exploiting this vulnerability results in a system memory corruption that could
Tenable
Microsoft May Madness
blogs_tenable·2018-05-09·CVSS 9.8
[CRITICAL] Microsoft May Madness
Blog / Research
Subscribe
# Microsoft May Madness
Josef Weiss
May 9, 2018
4 Min Read
Patch Tuesday was anything but typical in the month of May. On May 8, Microsoft released security patches for a total of 67 vulnerabilities, addressing 21 critical vulnerabilities, 42 important and four low-severity, while Adobe addressed a critical flaw in Adobe Flash Player. This is a big push from Microsoft in securing Windows, coming right after the recent release of Windows 10, version 1803, which added several security improvements, among other feature updates.
However, what makes this update particularly important is that it addresses two zero-day vulnerabilities that are being actively exploited in the wild and a further two for which public exploits have been published.
The first critical v
Qualys
May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
## OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174 , which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
Krebs
Microsoft Patch Tuesday, May 2018 Edition
blogs_krebs·2018-05-08
Microsoft Patch Tuesday, May 2018 Edition
Microsoft today released a bundle of security updates to fix at least 67 holes in its various Windows operating systems and related software, including one dangerous flaw that Microsoft warns is actively being exploited. Meanwhile, as it usually does on Microsoft’s Patch Tuesday — the second Tuesday of each month — Adobe has a new Flash Player update that addresses a single but critical security weakness.
First, the Flash Tuesday update , which brings Flash Player to v. 29.0.0.171 . Some (present company included) would argue that Flash Player is itself “a single but critical security weakness.” Nevertheless, Google Chrome and Internet Explorer/Edge ship with their own versions of Flash, which get updated automatically when new versions of these browsers are made available.
You can check
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008, which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16.
### Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of these is notable and requires prompt attenti
Talos
Microsoft Patch Tuesday - May 2018
blogs_talos·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - May 2018
## Microsoft Patch Tuesday - May 2018
Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 67 new vulnerabilities, with 21 of them rated critical, 42 of them rated important, and four rated as low severity. These vulnerabilities impact Outlook, Office, Exchange, Edge, Internet Explorer and more.
In addition to the 67 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180008 , which addresses the vulnerability CVE-2018-4944 described in the Adobe security bulletin APSB18-16 .
## Critical Vulnerabilities
This month, Microsoft is addressing 21 vulnerabilities that are rated as critical. Talos believes one of thes
Krebs
Microsoft Patch Tuesday, May 2018 Edition
blogs_krebs·2018-05-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday, May 2018 Edition
Microsoft today released a bundle of security updates to fix at least 67 holes in its various Windows operating systems and related software, including one dangerous flaw that Microsoft warns is actively being exploited. Meanwhile, as it usually does on Microsoft’s Patch Tuesday — the second Tuesday of each month — Adobe has a new Flash Player update that addresses a single but critical security weakness.
You can check if your browser has Flash installed/enabled and what version it’s at by pointing your browser at this link. Adobe is phasing out Flash entirely by 2020, but most of the major browsers already take steps to hobble Flash. And with good reason: It’s a major security liability.
Google Chrome blocks Flash from running on all but a handful of popular sites, and then only after u
Qualys
May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
### OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174, which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
Tenable
Why Are You Still Using IE? Double Kill Is Just the Latest Issue
blogs_tenable·2018-04-27
Why Are You Still Using IE? Double Kill Is Just the Latest Issue
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Why Are You Still Using IE? Double Kill Is Just the Latest Issue
blogs_tenable·2018-04-27·CVSS 7.5
CVE-2018-8174 [HIGH] Why Are You Still Using IE? Double Kill Is Just the Latest Issue
Blog / Cyber Exposure Alerts
Subscribe
# Why Are You Still Using IE? Double Kill Is Just the Latest Issue
Steve Tilson
April 27, 2018
4 Min Read
[UPDATE] When we released this warning over a week ago, we suspected it might gain traction and become a bigger issue. As expected, Microsoft addressed this vulnerability on Patch Tuesday. Of the many items addressed in the patch, the most important fixes are around CVE-2018-8174. This CVE references a Windows VBScript engine remote code execution vulnerability – otherwise known as the Double Kill IE zero-day vulnerability.
Microsoft's legacy browser Internet Explorer (IE) has been used for almost three decades, but not without issues. IE has been so plagued with security problems that Microsoft built a new, more secure browser called Edge.
Fortinet
New jRAT/Adwind Variant Being Spread With Package Delivery Scam
blogs_fortinet·2018-02-16
New jRAT/Adwind Variant Being Spread With Package Delivery Scam
FORTIGUARD LABS THREAT RESEARCH
New jRAT/Adwind Variant Being Spread With Package Delivery Scam
By Xiaopeng Zhang | February 16, 2018
At the beginning of February 2018, FortiGuard Labs collected a malicious email with the subject “UPS DELIVERY UPDATE”, as shown in Figure 1. Phishers and scammers traditionally misuse the names of well-known organizations and individuals in order to make their malicious messages seem legitimate, allowing them to more easily trick unsuspecting victims. This email message contains a fake order tracking number with a bogus hyperlink that, rather than connecting the user to a legitimate website, downloads a jar malware. After a quick analysis, I was able to determine that this malware is jRAT/Adwind.
jRAT (also called Adwind) is a commercial cross-platform re
Crowdstrike
What is Maze Ransomware? [Technical Analysis]
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] What is Maze Ransomware? [Technical Analysis]
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Threat Intel
Cobalt Group (Cobalt Group, GOLD KINGSWOOD, Cobalt Gang)
threat_intel
Cobalt Group (Cobalt Group, GOLD KINGSWOOD, Cobalt Gang)
# Threat Actor Profile: Cobalt Group
ATT&CK ID: G0080
Also known as: Cobalt Group, GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider
## Overview
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.(Citation: Talos Cobalt Group July 2018)(Citation: PTSecurity Cobalt Group Aug 2017)(Citation
Crowdstrike
Magniber Ransomware Caught Using PrintNightmare Vulnerability
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Magniber Ransomware Caught Using PrintNightmare Vulnerability
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018 | Recorded Future
## Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report , and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
## Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to she
Recorded Future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
blogs_recorded_future
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
# Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018
Click here to download the complete analysis as a PDF.
This analysis focuses on an exploit kit, phishing attack, or remote access trojan co-occurrence with a vulnerability from January 1, 2018 to December 31, 2018. We analyzed thousands of sources, including code repositories, deep web forum postings, and dark web sites. This is a follow-up to our 2017 report, and the intended audience includes information security practitioners, especially those supporting vulnerability risk assessments.
### Executive Summary
Many vulnerability management practitioners face the daunting task of prioritizing vulnerabilities without adequate insight into which vulnerabilities are actively exploited by cybercriminals. Here, we’ll attempt to shed
Sentinelone
Maze
blogs_sentinelone
Maze
# Maze Ransomware: In-Depth Analysis, Detection, and Mitigation
Since its discovery in 2019, Maze ransomware has consistently made headlines due to its infamous attacks on MSPs and its ability move laterally to other networks. Although this particular strain of ransomware has been used to attack businesses and governmental organizations, its attacks on MSPs are worrying since a single compromise can create a cascade effect on the MSP’s clients, their business partners, and so on.
Maze was reportedly shut down in 2020, but there still exist numerous similar ransomware strains posing threats to businesses around the world today. A deeper understanding of Maze ransomware may help organizations strengthen their cybersecurity defenses against similar types of ransomware attacks in the future.
Zscaler
Zscaler protects against new vulnerabilities for Internet E
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler protects against new vulnerabilities for Internet E
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Threat Intel
Tonto Team (Tonto Team, Earth Akhlut, BRONZE HUNTLEY)
threat_intel·CVSS 7.8
[HIGH] Tonto Team (Tonto Team, Earth Akhlut, BRONZE HUNTLEY)
# Threat Actor Profile: Tonto Team
ATT&CK ID: G0131
Also known as: Tonto Team, Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda
Suspected origin: China
## Overview
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).(Citation: Kaspersky CactusPete Aug 2020)(Citation: ESET Exchange Mar 2021)(Citation: FireEye Chinese Espionage October 2019)(Citation: ARS Te
Crowdstrike
Magniber Ransomware Caught Using PrintNightmare Vulnerability
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Magniber Ransomware Caught Using PrintNightmare Vulnerability
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
arXiv
CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis
arxiv_fulltext·2025-07-12
CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis
1
.001
[mode = title]CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis
[1].
[1]Jingwen Li[style=chinese]
Conceptualization, Methodology, Writing–original draft
[1]organization=Beijing University of Posts and Telecommunications,
city=Beijing,
postcode=100876,
country=China
[1]Ru Zhang[style=chinese, orcid=0000-0001-6641-3236]
[1]
[email protected]
Supervision, Writing-Review & Editing
[1]Jianyi Liu[style=chinese]
Methodology, Writing-Review & Editing, Resources
[2]WanGuo Zhao[style=chinese]
Data curation, Resources
[2]organization=Beijing Anheng Xin'an Technology Co., Ltd,
city=Beijing,
postcode=100089,
country=China
[1]Corresponding author
## Abstract
With the increasing complexity of cyberattacks, the proactive and f
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
arXiv
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
arxiv_fulltext·2022-02-03
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
Octavian Suciu,
Connor Nelson ,
Zhuoer Lyu ,
Tiffany Bao ,
Tudor Dumitras
University of Maryland, College Park
State University
comment
\@IEEEpubidpullup6.5
Network and Distributed Systems Security (NDSS) Symposium 2020
23-26 February 2020, San Diego, CA, USA
ISBN 1-891562-61-4
https://dx.doi.org/10.14722/ndss.2020.23xxx
www.ndss-symposium.org
[ ]
comment
empty
## Abstract
Assessing the exploitability of software vulnerabilities at the time of disclosure is difficult and error-prone, as features extracted via technical analysis by existing metrics are poor predictors for exploit development.
Moreover, exploitability assessments suffer from a class bias because ``not exploitable'' labels could be inaccurate.
To overcome these challenges, we propose a new metric, called Expecte
http://www.securityfocus.com/bid/103998https://blog.0patch.com/2018/05/a-single-instruction-micropatch-for.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8174https://www.exploit-db.com/exploits/44741/http://www.securityfocus.com/bid/103998https://blog.0patch.com/2018/05/a-single-instruction-micropatch-for.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8174https://www.exploit-db.com/exploits/44741/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8174
2018-05-09
Published
2022-02-15
Added to CISA KEV
Exploited in the wild