HomeSecuritySophos Firewall: Vulnerability was being used by hackers before it was fixed

Sophos Firewall: Vulnerability was being used by hackers before it was fixed

Chinese hackers used a zero-day exploit for a critical vulnerability in Sophos Firewall to compromise a company and then its cloud-hosted web servers.

Sophos Firewall vulnerability

The vulnerability has been patched by the company, but cybercriminals continued to exploit it to bypass authentication . and execute code remotely on vulnerable systems of many organizations

Sophos Firewall zero-day

On March 25, Sophos published a security advisory regarding CVE-2022-1040 , an authentication bypass vulnerability affecting the User Portal and Webadmin of Sophos Firewall. This vulnerability could be exploited by malicious users to execute code remotely.

See also: Critical flaw exposes Eufy smart home hubs to RCE attacks

Three days later, the company warned that cybercriminals were exploiting the security gap to target organizations in the South Asian region.

Now, cybersecurity firm Volexity has revealed an attack by Chinese hackers, whom the company is tracking as “DriftingClou.” These hackers appear to have been exploiting the Sophos Firewall vulnerability, CVE-2022-1040, since early March. This means that the hackers were exploiting the flaw and using it against victims for more than three weeks before Sophos released a patch.

Chinese hackers used the zero-day exploit to breach the firewall and install webshell backdoors and malware that would allow the compromise of external systems outside the network protected by the Sophos Firewall.

Sophos Firewall: Vulnerability was being used by hackers before it was fixed

When Volexity began its investigation, the Chinese attackers were still active and researchers were able to trace the steps of the attack.

See also: MaliBot Android malware: Bypasses multi-factor authentication

Researchers note that the hackers attempted to blend their traffic by gaining access to the installed webshell through requests to the legitimate “login.jsp” file.

“At first glance, this may appear to be an attempted brute-force attack rather than interaction with a backdoor,” Volexity said.

Upon further investigation, experts found that the attacker was using the Behinder framework, which they believe was also used by other Chinese APT groups exploiting the CVE-2022-26134 vulnerability in Confluence servers.

Access to web servers

In addition to the webshell, Volexity researchers identified other malicious activity that ensured persistence on vulnerable systems and allowed hackers to further their attack:

  • Creating VPN user accounts and associating certificate pairs on the firewall for legitimate remote network access
  • Writing “pre_install.sh” to “/conf/certificate/”
  • “pre_install.sh” runs a malicious command to download a binary, execute it, and then delete it from disk

Researchers say that gaining access to the Sophos Firewall was the first step of the attack, which allowed hackers to carry out a man-in-the-middle (MitM) attack by modifying DNS responses for specific websites managed by the victim company.

See also: Africa's largest supermarket chain Shoprite hit by ransomware

“This allowed the attacker to intercept user credentials and session cookies from administrator access to the websites’ content management system (CMS)” – Volexity

According to the researchers, the attackers appear to have succeeded as they gained access to the CMS admin pages using session cookies and installed the File Manager plugin to handle files on the website (upload, download, delete, edit).

Once they gained access to the web server, the DriftingCloud hackers installed PupyRAT, Pantegana, and Sliver, three malware that allow remote access.

Volexity researchers believe that the Chinese hacking group DrifitingCloud that exploited the vulnerability in Sophos Firewall is quite sophisticated.

Sophos has provided hotfixes that automatically address CVE-2022-1040, as well as mitigations that help organizations using its firewall protect themselves from exploitation of the vulnerability.

More details about the attack can be found in the Volexity report

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS