HomeSecurityEspionage group used CVE-2018-8589 Windows Zero-Day in attacks in the Middle East

Spying group used CVE-2018-8589 Windows Zero-Day in attacks in the Middle East

dayKaspersky has revealed that the CVE-2018-8589 Windows zero-day, fixed by Microsoft's Nov. 2018 Patch Tuesday, has been exploited by at least one APT group for attacks in the Middle East.

Kaspersky Lab experts have revealed that the Windows CVE-2018-8589 zero-day vulnerability, patched by Microsoft November 2018 Patch Tuesday, has been exploited by an APT group for targeted attacks against entities in the Middle East.

Kaspersky reported the flaw to Microsoft on October 17, the security firm observed attacks against systems and attempts to exploit the zero-day flaw affecting the Win32k component in Windows.

Kaspersky Lab described the flaw CVE-2018-8589 as a race condition in win32k! XxxMoveWindow, caused by improper locking of messages sent concurrently between threads.

The CVE-2018-8589 vulnerability only affects Windows 7 and Windows Server 2008.

The attackers exploited the flaw as the first stage of installing malware targeting a limited number of entities in the Middle East.

It is clear how the malware was spread by the attackers:

“The exploit was executed by the first stage of a malware installer, in order to gain the necessary persistence privileges on the victim’s system. So far, we have detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East,” the analysis published by Kaspersky states.

Kaspersky does not explicitly attribute the attack to a specific actor, but noted that the CVE-2018-8589 exploit code is being used by at least one APT cyber espionage group.

In October, Kaspersky also reported to Microsoft the CVE-2018-8453 flaw that had been exploited by a group known as FruityArmor for a highly targeted campaign.

The FruityArmor APT has been active since at least 2016 and targets activists, researchers, and individuals associated with government organizations.

In October, the espionage group exploited a Windows zero-day flaw in attacks targeting entities in the Middle East.

The researchers noted that both issues affect the Win32k component and both flaws were used in attacks targeting users in the Middle East, but Kaspersky did not link the two attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS