Microsoft is warning that an Iran-based threat actor calling itself Mercury is exploiting Log4Shell flaws in applications from IT vendor SysAid against organizations located in Israel.
See also: Log4Shell: Still used for hacking into VMware servers

See also: Amazon Web Services: Fixes container escape in Log4Shell hotfix
Microsoft’s nation-state monitoring team, the Microsoft Threat Intelligence Center (MSTIC), assessed with “high confidence” that the campaign is linked to Iran’s Ministry of Intelligence and Security (MOIS). The U.S. Cyber Command tracks the group as MuddyWater, which it believes is a “subordinate element” of MOIS.
Targeting SysAid applications is a new approach for Mercury, which previously used Log4Shell remote code execution flaws in VMware applications to carry out attacks.
SysAid, an IT service management company founded in Israel, released Log4j patches for its cloud and on-premises in January, shortly after the Apache Software Foundation disclosed flaws in the Log4J Java application logging library on December 9.
"In recent weeks, the Microsoft Threat Intelligence Center (MSTIC) and the Microsoft 365 Defender Research team have identified the Iran-based Mercury group exploiting Log4j 2 vulnerabilities in SysAid applications against organizations located in Israel," Microsoft warned.
Microsoft detected the group using “most likely” Log4Shell exploits between July 23 and 25 against SysAid Server instances exposed online .The campaign is taking place as the US, Iran and Israel negotiate a new nuclear deal.
See also: Log4Shell exploits used to DDoS botnets and install cryptominers
"After gaining access, Mercury creates persistence, steals credentials , and moves laterally within the targeted organization using custom and known hacking, as well as built-in operating system for hands-on-keyboard attacks," Microsoft explained.
The group “throws” and uses web shells to execute commands related to identification, lateral movement, and persistence. It also uses the open-source pen-testing tool Mimikatz to steal credentials, as well as dump credentials into SQL servers to steal high-privilege service accounts.

While the threat appears to be exclusively targeting organizations based in Israel, Microsoft is urging all organizations to check if SysAid is present on the network and apply the company's patches for the Log4j flaws.
Microsoft recommends that security teams review all authentication activity for remote access infrastructure and focus on accounts that are configured and not protected with multi-factor authentication ( MFA ). It also recommends that organizations enable MFA.
Information source: zdnet.com
