HomeSecurityCicada group exploits ZeroLogon in its new attacks

Cicada group exploits ZeroLogon in its new attacks

Researchers have uncovered a global campaign targeting businesses using the recently disclosed ZeroLogon vulnerability. The cyberattack is believed to be the work of the Cicada hacking group, also known as APT10, Stone Panda, and Cloud Hopper.

ZeroLogon
Cicada Group Exploits ZeroLogon in New Hacking Campaign

Historically, the hacking group – first discovered in 2009 and a group the US believes is funded by the Chinese government – ​​has targeted organizations linked to Japan, and this latest wave of attacks appears to be no different from previous ones.

Symantec researchers have reported that the Cicada group's recent targets include companies in the automotive, pharmaceutical, engineering, and managed service provider ( MSP ) industries.

According to the company, the latest wave of attacks by the Cicada group has been active since mid-October 2019 and continued until at least October of this year.

Cicada appears to have resources and uses a variety of tools and techniques. Some of these include DLL side-loading, network reconnaissance, credential theft, command-line capable of installing browser root certificates, and data. Of course, all of these are aimed at obtaining and extracting stolen information.

Also a recent addition to the hacking group's toolkit is a tool capable of exploiting ZeroLogon. ZeroLogon is listed as CVE-2020-1472 with a CVSS score of 10 and was disclosed and patched by Microsoft in August. The vulnerability can be used to spoof domain controller accounts and domain compromises, as well as to compromise Active Directory identity services.

Cicada also released Backdoor.Hartip, a custom malware form that we had never seen before associated with APT.

The group appears to be focused on stealing information. The data it is interested in includes corporate records, HR documents, and more – which are often “packaged” and transferred to Cicada’s command-and-control (C2) servers.

“The amount of time attackers spent on victims’ networks varied, with attackers spending significant time on some victims’ networks while remaining on others for only days,” the researchers say. “In some cases, attackers also stayed on a network for a short time and then stopped their activity , only to resume it after a few months.”

Researchers say they have some evidence that points to the Cicada group. Some of this is the use of DLL side-loading and DLL names, including “FuckYouAnti,” which has previously been reported in a Cylance report as being used by Cicada. Additionally, the final payload combines QuasarRAT, previously used by Cicada, as well as Backdoor.Hartip.

Source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS