Last week, South Korea’s CERT identified an exploit in Adobe Flash 28.0.0.137 (and all previous versions of course) that could allow remote code execution on Windows, macOS, Linux, and Chrome OS.
Adobe immediately announced in a security bulletin that it would patch the vulnerability in the version scheduled for release this week. …on time, just how the exploit is being released…
Cisco researchers from Talos said the payload contained in an Excel spreadsheet was ROKRAT and pointed to Group 123.“
Group 123 has united some elite hacking groups around this latest ROKRAT payload.
They’ve used an Adobe Flash Zero Day that was outside their previous capabilities – they’ve used exploits in previous campaigns but never had a clean new exploit like they’ve done now,” Talos researchers Warren Mercer and Paul Rascagneres wrote.
“While we at Talos have no information on any victims, we suspect that the victim was a very specific and high-value target. The use of a brand-new exploit, which did not exist, indicates that they were very determined to succeed in the attack.”
FireEye, on the other hand, said that the malicious file must have originated in North Korea, and is known as TEMP.Reaper.
While Adobe suggests that administrators could use Protected View for Office to protect themselves, FireEye stressed that it is very likely that we will see more attacks until the vulnerability is patched.
Last July, Adobe said that it would stop supporting Flash in 2020, with Microsoft claiming to completely remove Flash support from Windows the same year.
- Binary Option Trading: Scam or Risk Minimization?
- Intel: End of BIOS from 2020. Improved UEFI is coming
