HomeSecurityHackers exploit a new Zoho ServiceDesk exploit

Hackers exploit new Zoho ServiceDesk exploit

A group of sophisticated hackers who were exploiting an exploit in Zoho ManageEngine ADSelfService Plus software have turned to exploiting a different vulnerability in another Zoho product.

Zoho ServiceDesk

See also: Zoho fixes exploitable flaw in ADSelfService Plus

The group is exploiting an unauthenticated remote code execution exploit in Zoho ServiceDesk Plus versions 11305 and earlier, currently reported as CVE-2021-44077.

Zoho patched the RCE flaw on September 16, 2021, and on November 22, 2021, the company published a security advisory to warn customers about an active exploit. However, users were slow to update their systems and remained vulnerable to attacks.

According to a report from Palo Alto Networks' Unit42, there is no public proof of the exploitation of CVE-2021-44077, which suggests that the APT exploiting it developed the exploit code itself and is using it exclusively for now.

See also: FBI and CISA: Hackers exploit critical Zoho bug

Hackers exploit the exploit by sending two requests to the REST API, one to upload an executable file (msiexec.exe) and one to launch the payload.

Hackers

This process is performed remotely and does not require authentication on the vulnerable ServiceDesk server.

When ServiceDesk executes the payload, a mutex is created and a hardcoded Java module is written to “../lib/tomcat/tomcat-postgres.jar”, ​​a variant of the “Godzilla” web shell that is loaded into ServiceDesk after killing the “java. .exe” and restarting the process.

According to the researchers, the group used the same secret webshell key that appeared in the ADSelfService Plus campaign, but this time it is installed as an Apache Tomcat Java Servlet.

See also: Chinese hackers use Cisco, Citrix, Zoho Exploits and attack!

Palo Alto Networks has discovered evidence that may link these attacks to the Chinese group APT27 (Emissary Panda), which has previously deployed Godzilla against high-profile targets, but the evidence is insufficient for a clear attribution.

Organizations are advised to patch their Zoho software as soon as possible and review all files created in ServiceDesk Plus directories since early October 2021.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS