HomeSecurityRussian hackers APT29 use WinRAR exploit to attack embassies

Russian hackers APT29 use WinRAR exploit to attack embassies

Russian government-backed hackers APT29 appear to be exploiting the CVE-2023-38831 vulnerability in WinRAR for cyberattacks .

Russian hackers APT29

The APT29 group is known by many different names, including UNC3524, NobleBaron, Dark Halo, NOBELIUM, Cozy Bear, CozyDuke, SolarStorm, and targets embassies by luring victims with the sale of BMW.

The CVE-2023-38831 vulnerability affects WinRAR versions prior to 6.23 and allows the creation archives .RAR and .ZIP that can be executed in the background code prepared by the attacker for malicious purposes.

The vulnerability has been used as a zero-day since April, when criminals targeted cryptocurrency forums and exchanges.

See also: TA402 hackers use new IronWind downloader in phishing attacks

In a recent report, the Council Security of Ukraine (NDSC) says that Russian hackers APT29 are using a malicious ZIP file that runs a script in the background to display a decoy PDF and download PowerShell code that downloads and executes a payload.

The malicious file is called “DIPLOMATIC-CAR-FOR-SALE-BMW.pdf” and has targeted multiple countries in Europe, including Azerbaijan, Greece, Romania, and Italy.

The APT29 group has used the lure of advertisement car BMW in the past to target diplomats in Ukraine.

In these attacks, the Ukrainian NDSC says APT29 combined the old phishing tactic with a new technique to allow communication with the malicious server.

The Ukrainian NDSC says that Russian hackers used a free Ngrok static domain to gain access to the command and control (C2) server hosted on their Ngrok instance.

“ In this tactic, they use services Ngrok using free static domains provided by Ngrok, usually in the form of a subdomain under “ngrok-free.app.” These subdomains act as separate and indistinguishable rendezvous points for their malicious payloads ,” the National Security and Defense Council of Ukraine reports .

In this way, Russian hackers managed to hide their malicious activity without being noticed.

See also: WhatsApp: Hackers hold phones hostage for ransom

WinRAR

Attacks exploiting the CVE-2023-38831 vulnerability in WinRAR

When researchers at cybersecurity firm Group-IB reported that the CVE-2023-38831 vulnerability in WinRAR was exploited as a zero-day, hacking groups began incorporating it into their attacks.

Security researchers at ESET discovered attacks in August attributed to the Russian group APT28. The hackers used the vulnerability in a phishing campaign targeting political entities in the EU and Ukraine.

A Google report last month said the vulnerability had been used by Russian and Chinese state hackers to steal credentials and other sensitive data.

The Ukrainian NDSC says the observed campaign by Russian hackers APT29 stands out because it combines old and new techniques, such as using the WinRAR vulnerability to deliver malicious payloads and using Ngrok services to hide communication with the C2.

Examples of attacks that can be carried out

Russian hackers APT29 and other groups can use the CVE-2023-38831 vulnerability in WinRAR for a variety of attacks. One example is hacking into companies and organizations with the aim of stealing sensitive information. Attackers can gain access to files and data containing confidential information, such as personal files, professional communications, or confidential business information.

See also: Imperial Kitten hackers target organizations in the Middle East

Another type of attack that can be carried out with the CVE-2023-38831 vulnerability is the installation of malware on victims' computers. Attackers can execute malicious code, such as viruses or spyware, that can monitor victims' activity, steal personal information, or cause damage to the system.

Finally, APT29 can exploit the CVE-2023-38831 vulnerability to carry out attacks aimed at destroying or disabling victims' systems. This can cause serious disruptions to businesses or organizations, as access to important data can be cut off or the operation of computer systems can be paralyzed.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS