HomeSecurityMicrosoft: Windows, Adobe zero-day exploits for Subzero development

Microsoft: Windows, Adobe zero-day exploits for Subzero development

Microsoft has revealed details about the Austrian company DSIRF that uses zero-day exploits for the Subzero malware.

Microsoft a cyber mercenary named DSIRF that targets European and Central American entities using a malware toolkit called Subzero.

On its website, DSIRF bills itself as a company that provides intelligence research, forensic services, and data-driven intelligence services to companies.

However, it has been linked to the development of the Subzero that its clients can use to hack target phones, computers, and devices connected to the network and the Internet.

Read also: Robin Banks: New phishing service targets customers of major banks

Using passive DNS data while investigating Knotweed attacks, threat intelligence firm RiskIQ also found that infrastructure actively serving malware since February 2020 is linked to DSIRF, including its official website and domains likely used to debug and configure the Subzero malware.

Microsoft: Windows, Adobe zero-day exploits for Subzero development
Microsoft: Windows, Adobe zero-day exploits for Subzero development

The Microsoft Threat Intelligence Center (MSTIC) has also found multiple links between DSIRF and malicious tools used in Knotweed attacks.

«!– /wp:paragraph –>

Some Knotweed attacks observed by Microsoft have targeted law firms, banks, and strategic consulting organizations around the world, including in Austria, the United Kingdom, and Panama.

"As part of our investigation into the usefulness of this malware, Microsoft's communications with a victim of Subzero revealed that they had not commissioned any red team or penetration testing and confirmed that it was unauthorized, malicious activity," Microsoft added.

"Victims observed to date include law firms, banks and strategic consultants in countries such as Austria, the United Kingdom and Panama."

On compromised devices, attackers deployed Corelump, the main payload that runs from memory to evade detection, and Jumplump, a malware loader that downloads and loads Corelump into memory.

The main Subzero payload has many capabilities, including keyboard logging, taking screenshots, extracting data, and executing remote shells and arbitrary plugins received from its command and control server.

On systems where Knotweed leveraged its malware, Microsoft has observed a variety of post-compromise actions, including:

Microsoft: Windows, Adobe zero-day exploits for Subzero development
Microsoft: Windows, Adobe zero-day exploits for Subzero development
  • Setting UseLogonCredential to “1” to enable plaintext credentials
  • Credential dumping via comsvcs.dll
  • Attempt to access email with credentials from a KNOTWEED IP
  • Using Curl to download KNOTWEED tools from public file shares, such as vultrobjects[.]com
  • Run PowerShell scripts directly from GitHub created by an account associated with DSIRF

Among the zero-day exploits used in Knotweed campaigns, Microsoft highlights the recently patched CVE-2022-22047, which helped attackers escalate privileges, escape sandboxes, and gain system-level code execution.

Last year, Knotweed also used an exploit chain consisting of two Windows (CVE-2021-31199 and CVE-2021-31201) combined with an Adobe Reader (CVE-2021-28550), which were updated in June 2021.

In 2021, the Knotweed group was also linked to the exploitation of a fourth zero-day, a Windows privilege escalation flaw in the Windows Update Medic (CVE-2021-36948) that was used to force the service to load an arbitrary signed DLL.

Microsoft: Windows, Adobe zero-day exploits for Subzero development
Microsoft: Windows, Adobe zero-day exploits for Subzero development

To defend against such zero-day attacks, Microsoft advises customers to:

  • Prioritize the patch for CVE-2022-22047.
  • Confirm that Microsoft Defender Antivirus is updated to version 1.371.503.0 or later to detect the relevant indications.
  • Use the included indicators of compromise to investigate whether they exist in their environment and assess for a potential intrusion.
  • Change Excel macro security settings to control which macros run and under what conditions when a workbook is opened. Customers can also stop malicious XLM or VBA macros by ensuring runtime macro scanning is enabled through the Antimalware Scan Interface (AMSI).
  • Enable multi-factor authentication (MFA) to reduce potentially compromised credentials and ensure that MFA is enforced for all remote connections.
  • Review all authentication activity for the remote access infrastructure, focusing on accounts configured with single-factor authentication, to confirm authenticity and investigate any abnormal activity.

See also: Play Store: Malware apps have over 10 million downloads

“To mitigate these attacks, we have issued a software update to mitigate the use of vulnerabilities and published malware signatures that will protect Windows customers from exploits that Knotweed was using to help deliver its malware,” said Cristin Goodwin, General Manager in Microsoft’s Digital Security Unit.

“We are increasingly seeing PSOAs selling their tools to authoritarian governments that act inconsistently with the rule of law and human rights norms, where they are used to target human rights defenders, journalists, dissidents and others involved in society,” Goodwin added.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS