Security firm Trend Micro is warning that attackers associated with Operation Pawn Storm are currently using unpatched zero-day in Flash Playerto target various foreign ministries as part of a larger campaign believed to be coordinated with the Russian government.
Pawn Storm is a massive cyber espionage campaign that relies primarily on zero-day vulnerabilities to achieve attacks on various high-profile targets, including overseas ministries and government agencies, such as NATO and the White House .
This time, attackers are using holes in Flash Player to launch similar attacks, according to Trend Micro, attempting to redirect members of ministries and other organizations to websites with malicious code to exploit the vulnerabilities.
Emails containing fake headlines on the following topics are said to be used in the campaign:
“Suicide car bomb targets NATO troop convoy Kabul”
“Syrian troops make gains as Putin defends air strikes”
"Israel launches airstrikes on targets in Gaza"
"Russia warns of response to reported US nuke buildup in Turkey, Europe"
"US military reports 75 US-trained rebels return Syria"
Although this has not yet been verified, it appears that the hackers associated with the old and new leaks are reportedly linked to the Russian government, and judging by the target organizations, this seems quite likely.
What's worse is the fact that although Adobe has released a new version of Flash Player that supposedly fixes a number of vulnerabilities, the zero-days used in the campaign have not been patched, meaning that the only way to stay safe for now is to avoid clicking on links that come from unknown sources.
The vulnerable versions of Adobe Flash Player are 19.0.0.185 and 19.0.0.207, again according to Trend Micro, with the latter being released by the company just yesterday.
Adobe is already aware of the zero-days, so a new out-of-band is expected soon.
