HomeSecurityAdobe Flash 0day: North Korea behind the exploit being released

Adobe Flash 0day: North Korea behind the exploit being released

Last week, South Korea’s CERT identified an exploit in Adobe Flash 28.0.0.137 (and all previous versions of course) that could allow remote code execution on Windows, macOS, Linux, and Chrome OS.Adobe Flash
Adobe immediately announced in a security bulletin that it would patch the vulnerability in the version scheduled for release this week. …on time, just how the exploit is being released…
Cisco researchers from Talos said the payload contained in an Excel spreadsheet was ROKRAT and pointed to Group 123.“
Group 123 has united some elite hacking groups around this latest ROKRAT payload.
They’ve used an Adobe Flash Zero Day that was outside their previous capabilities – they’ve used exploits in previous campaigns but never had a clean new exploit like they’ve done now,” Talos researchers Warren Mercer and Paul Rascagneres wrote.
“While we at Talos have no information on any victims, we suspect that the victim was a very specific and high-value target. The use of a brand-new exploit, which did not exist, indicates that they were very determined to succeed in the attack.”
FireEye, on the other hand, said that the malicious file must have originated in North Korea, and is known as TEMP.Reaper.
While Adobe suggests that administrators could use Protected View for Office to protect themselves, FireEye stressed that it is very likely that we will see more attacks until the vulnerability is patched.
Last July, Adobe said that it would stop supporting Flash in 2020, with Microsoft claiming to completely remove Flash support from Windows the same year.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS