HomeSecurityWindows MSHTML bug: Ransomware groups exploit the flaw

Windows MSHTML bug: Ransomware groups exploit the flaw

Microsoft says that many attackers, including ransomware gangs, are using the RCE Windows MSHTML vulnerability, which the company recently patched.

Windows MSHTML bug: Ransomware groups exploit the flaw

Exploitation of this vulnerability (CVE-2021-40444) began on August 18, about two weeks before Microsoft published a security advisory to partially address the issue.

See also: Millions of HP OMEN PCs affected by a serious vulnerability

According to telemetry data analyzed by security researchers from the Microsoft 365 Defender Threat Intelligence Team and the Microsoft Threat Intelligence Center (MSTIC), the small number of initial attacks (less than 10) used malicious Office documents.

These attacks used the CVE-2021-40444 flaw “as part of an initial access campaign distributing custom Cobalt Strike Beacon loaders.”

Beacons deployed on at least one victim's network were communicating with malicious infrastructure linked to multiple criminal campaigns, including ransomware groups.

See also: Grief ransomware: We will destroy the decryption key if a negotiator is hired

Some of the Cobalt Strike infrastructure used in the August attacks was also used in the past to distribute the BazaLoader and Trickbot payloads.

Windows MSHTML ransomware

Ransomware gangs exploit Windows MSHTML vulnerability after public disclosure

Microsoft observed a huge increase in attempts to exploit the vulnerability within 24 hours of the publication of the CVE-2021-40444 advisory.

"Following the disclosure, Microsoft observed multiple threat actors, including ransomware-as-a-service affiliates, adopting the proof-of-concept code in their toolkits," the researchers added.

See also: Microsoft has fixed a vulnerability in Azure Container Instances

Microsoft continues to monitor the situation and work to protect users.

MSTIC Threat Intelligence analyst Justin Warnersaid that other hacking groups will add the CVE-2021-40444 exploits to their arsenal in the coming days and weeks.

Microsoft recommends immediate application of the Patch Tuesday released on Tuesday to fix the Windows MSHTML vulnerability and prevent attacks.

The CVE-2021-40444 flaw affects systems running Windows Server 2008 through 2019 and Windows 8.1 or later. It is rated 8.1/10 in terms of severity.

Security updates released by Microsoft address the vulnerability for all affected versions of Windows.

If someone is unable to update their system, they can implement the security measures recommended by Microsoft to partially address the issue.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS