HomeSecurityHackers exploit MinIO storage system to breach corporate networks

Hackers exploit MinIO storage system to breach corporate networks

Hackers exploit MinIO storage system to breach corporate networks

Hackers exploit two recent vulnerabilities in MinIO to breach object storage systems and gain access to private information, execute arbitrary code, and potentially take over servers.

See also: VIPRE research on spam and phishing emails

MinIO is an open source object storage service that offers compatibility with Amazon S3 and the ability to store unstructured data, logs, backups, and container images up to 50 TB in size.

Its high performance and flexibility, especially for large-scale AI/ML applications and data lakes, make MinIO a popular, cost-effective choice.

The two vulnerabilities that were found chained in attacks by the incident response team of Security Joes are CVE-2023-28432 and CVE-2023-28434, two high-severity issues affecting all MinIO releases prior to RELEASE.2023-03-20T20-16-18Z.

The two vulnerabilities were disclosed and patched by the vendor on March 3, 2023.

Evil MinIO attacks

During an incident response engagement, Security Joes analysts discovered that attackers attempted to install a modified version of the MinIO application, dubbed Evil MinIO, which is available on GitHub.

In the context of the attack, Evil MinIO chains together both the information disclosure flaw CVE-2023-28432 and the CVE-2023-28434 flaw to replace the MinIO software with modified code that adds a backdoor with remote access.

The attack started with the actors who used some social engineering to convince a DevOps engineer to downgrade to an older version of the MinIO software that is affected by the two vulnerabilities.

Once installed, the hackers exploited CVE-2023-28432 to gain remote access to the server's environment variables, including the MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD variables.

These administrative credentials allow hackers to access the MinIO management console using the MinIO client. Using this client, the attackers modify the software update URL to an address they control, in order to push a malicious update.

As part of this process, the exploit chain uses the flaw to replace the legitimate .go source code file with a tampered one.

Proposal: Hackers are holding healthcare providers "hostage"

This malicious update is identical to the legitimate MinIO application, but it contains additional code that allows remote command execution on a compromised server via the following URLs:

http://vulnerable.minio.server/?alive=[CMD_TO_EXECUTE] https://vulnerable.minio.server/anything?alive=[CMD_TO_EXECUTE]
Hackers exploit MinIO storage system to breach corporate networks

In the incident seen by Security Joes, analysts saw the perpetrators using this backdoor to execute Bash commands and download Python scripts.

Hackers exploit MinIO storage system to breach corporate networks

“This endpoint functions as an embedded backdoor, providing unauthorized individuals the ability to execute commands on the computer running the application”, explain the researchers.

“Specifically, the commands that are executed inherit the system permissions of the user who launched the application. In this case, due to insufficient security practices, the DevOps engineer who launched the application held root-level permissions”, add the analysts.

Security is not detected by the engines of the Virus Total scanning platform, despite the fact that the tool was published a month ago.

Hackers exploit MinIO storage system to breach corporate networks

Activity after the compromise

Having breached the object storage system, the attackers create a communication channel with the command and control (C2) server, from which they pull additional payloads that support post-compromise activity.

The payloads are downloaded to Linux via ‘curl’ or ‘wget’ and to Windows via ‘winhttpjs.bat’ or ‘bitsadmin’ and include the following:

  • System profiling script – collects system information, such as user data, memory, cronjobs, and disk usage.
  • Network script identifier – identifies accessible network interfaces, hosts, and ports.
  • Windows account creation script – creates user accounts on compromised systems with the name either “support” or “servicemanager”.
  • PING scan script – identifies accessible components within the compromised network using the asyncio Python module.
  • China Chopper-like webshell – a one-line webshell that bears similarities to China Chopper.

Security Joes warns that there are 52,125 instances of MinIO exposed on the public internet and about 38% of them were confirmed to be running a non-vulnerable version of the software .

This means that cloud system administrators need to act quickly to apply the available updated security version to protect their assets from the malicious operators of MinIO.

Read also: Anonymous Sudan: They hacked X to pressure Elon Musk

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS