Attackers – INDIA NEWS http://www.indiavpn.org News Blog Tue, 09 Apr 2024 08:20:30 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 Attackers Using Obfuscation Tools to Deliver Multi-Stage Malware via Invoice Phishing http://www.indiavpn.org/2024/04/09/attackers-using-obfuscation-tools-to-deliver-multi-stage-malware-via-invoice-phishing/ http://www.indiavpn.org/2024/04/09/attackers-using-obfuscation-tools-to-deliver-multi-stage-malware-via-invoice-phishing/#respond Tue, 09 Apr 2024 08:20:30 +0000 https://www.indiavpn.org/2024/04/09/attackers-using-obfuscation-tools-to-deliver-multi-stage-malware-via-invoice-phishing/ [ad_1]

Apr 09, 2024NewsroomMalware / Cryptojacking

Multi-Stage Malware via Invoice Phishing

Cybersecurity researchers have discovered an intricate multi-stage attack that leverages invoice-themed phishing decoys to deliver a wide range of malware such as Venom RAT, Remcos RAT, XWorm, NanoCore RAT, and a stealer that targets crypto wallets.

The email messages come with Scalable Vector Graphics (SVG) file attachments that, when clicked, activate the infection sequence, Fortinet FortiGuard Labs said in a technical report.

The modus operandi is notable for the use of the BatCloak malware obfuscation engine and ScrubCrypt to deliver the malware in the form of obfuscated batch scripts.

BatCloak, offered for sale to other threat actors since late 2022, has its foundations in another tool called Jlaive. Its primary feature is to load a next-stage payload in a manner that circumvents traditional detection mechanisms.

Cybersecurity

ScrubCrypt, a crypter that was first documented by Fortinet in March 2023 in connection with a cryptojacking campaign orchestrated by the 8220 Gang, is assessed to be one of the iterations of BatCloak, according to research from Trend Micro last year.

In the latest campaign analyzed by the cybersecurity firm, the SVG file serves as a conduit to drop a ZIP archive that contains a batch script likely created using BatCloak, which then unpacks the ScrubCrypt batch file to ultimately execute Venom RAT, but not before setting up persistence on the host and taking steps to bypass AMSI and ETW protections.

Multi-Stage Malware via Invoice Phishing

A fork of Quasar RAT, Venom RAT allows attackers to seize control of the compromised systems, gather sensitive information, and execute commands received from a command-and-control (C2) server.

“While Venom RAT’s primary program may appear straightforward, it maintains communication channels with the C2 server to acquire additional plugins for various activities,” security researcher Cara Lin said. This includes Venom RAT v6.0.3 with keylogger capabilities, NanoCore RAT, XWorm, and Remcos RAT.

“This [Remcos RAT] plugin was distributed from VenomRAT’s C2 using three methods: an obfuscated VBS script named ‘remcos.vbs,’ ScrubCrypt, and Guloader PowerShell,” Lin added.

Cybersecurity

Also delivered using the plugin system is a stealer that gathers information about the system and exfiltrates data from folders associated with wallets and applications like Atomic Wallet, Electrum, Ethereum, Exodus, Jaxx Liberty (retired as of March 2023), Zcash, Foxmail, and Telegram to a remote server.

“This analysis reveals a sophisticated attack leveraging multiple layers of obfuscation and evasion techniques to distribute and execute VenomRAT via ScrubCrypt,” Lin said.

“The attackers employ a variety of methods, including phishing emails with malicious attachments, obfuscated script files, and Guloader PowerShell, to infiltrate and compromise victim systems. Furthermore, deploying plugins through different payloads highlights the versatility and adaptability of the attack campaign.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/04/09/attackers-using-obfuscation-tools-to-deliver-multi-stage-malware-via-invoice-phishing/feed/ 0
Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions http://www.indiavpn.org/2024/03/27/microsoft-edge-bug-could-have-allowed-attackers-to-silently-install-malicious-extensions/ http://www.indiavpn.org/2024/03/27/microsoft-edge-bug-could-have-allowed-attackers-to-silently-install-malicious-extensions/#respond Wed, 27 Mar 2024 13:08:10 +0000 https://www.indiavpn.org/2024/03/27/microsoft-edge-bug-could-have-allowed-attackers-to-silently-install-malicious-extensions/ [ad_1]

Mar 27, 2024NewsroomVulnerability / API Security

Microsoft Edge

A now-patched security flaw in the Microsoft Edge web browser could have been abused to install arbitrary extensions on users’ systems and carry out malicious actions.

“This flaw could have allowed an attacker to exploit a private API, initially intended for marketing purposes, to covertly install additional browser extensions with broad permissions without the user’s knowledge,” Guardio Labs security researcher Oleg Zaytsev said in a new report shared with The Hacker News.

Tracked as CVE-2024-21388 (CVSS score: 6.5), it was addressed by Microsoft in Edge stable version 121.0.2277.83 released on January 25, 2024, following responsible disclosure in November 2023. The Windows maker credited both Zaytsev and Jun Kokatsu for reporting the issue.

“An attacker who successfully exploited this vulnerability could gain the privileges needed to install an extension,” Microsoft said in an advisory for the flaw, adding it “could lead to a browser sandbox escape.”

Cybersecurity

Describing it as a privilege escalation flaw, the tech giant also emphasized that a successful exploitation of the bug requires an attacker to “take additional actions prior to exploitation to prepare the target environment.”

According to Guardio’s findings, CVE-2024-21388 allows a bad actor with the ability to run JavaScript on bing[.]com or microsoft[.]com pages to install any extensions from the Edge Add-ons store sans requiring user’s consent or interaction.

This is made possible by the fact that the browser comes with privileged access to certain private APIs that make it possible to install an add-on as long as it’s from the vendor’s own extension marketplace.

One such API in the Chromium-based Edge browser is edgeMarketingPagePrivate, which is accessible from a set of allowlisted websites that belong to Microsoft, including bing[.]com, microsoft[.]com, microsoftedgewelcome.microsoft[.]com, and microsoftedgetips.microsoft[.]com, among others.

The API also packs in a method called installTheme() that, as the name implies, is designed to install a theme from the Edge Add-ons store by passing a unique theme identifier (“themeId”) and its manifest file as input.

Microsoft Edge

The bug identified by Guardio is essentially a case of insufficient validation, thereby enabling an attacker to provide any extension identifier from the storefront (as opposed to the themeId) and get it stealthily installed.

“As an added bonus, as this extension installation is not done quite in the manner it was originally designed for, there will be no need for any interaction or consent from the user,” Zaytsev explained.

Cybersecurity

In a hypothetical attack scenario leveraging CVE-2024-21388, a threat actor could publish a seemingly harmless extension to the add-ons store and use it to inject a piece of malicious JavaScript code into bing[.]com – or any of the sites that are allowed to access the API – and install an arbitrary extension of their choice by invoking the API using the extension identifier.

Put differently, executing the specially crafted extension on the Edge browser and going to bing[.]com will automatically install the targeted extension without the victim’s permission.

Guardio told The Hacker News that while there is no evidence of this bug being exploited in the wild, it highlights the need for balancing user convenience and security, and how browser customizations can inadvertently defeat security mechanisms and introduce several new attack vectors.

“It’s relatively easy for attackers to trick users into installing an extension that appears harmless, not realizing it serves as the initial step in a more complex attack,” Zaytsev said. “This vulnerability could be exploited to facilitate the installation of additional extensions, potentially for monetary gain.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/03/27/microsoft-edge-bug-could-have-allowed-attackers-to-silently-install-malicious-extensions/feed/ 0
RunC Flaws Enable Container Escapes, Granting Attackers Host Access http://www.indiavpn.org/2024/01/31/runc-flaws-enable-container-escapes-granting-attackers-host-access/ http://www.indiavpn.org/2024/01/31/runc-flaws-enable-container-escapes-granting-attackers-host-access/#respond Wed, 31 Jan 2024 21:29:43 +0000 https://www.indiavpn.org/2024/01/31/runc-flaws-enable-container-escapes-granting-attackers-host-access/ [ad_1]

Jan 31, 2024NewsroomSoftware Security / Linux

Container Security

Multiple security vulnerabilities have been disclosed in the runC command line tool that could be exploited by threat actors to escape the bounds of the container and stage follow-on attacks.

The vulnerabilities, tracked as CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653, have been collectively dubbed Leaky Vessels by cybersecurity vendor Snyk.

“These container escapes could allow an attacker to gain unauthorized access to the underlying host operating system from within the container and potentially permit access to sensitive data (credentials, customer info, etc.), and launch further attacks, especially when the access gained includes superuser privileges,” the company said in a report shared with The Hacker News.

Cybersecurity

runC is a tool for spawning and running containers on Linux. It was originally developed as part of Docker and later spun out into a separate open-source library in 2015.

A brief description of each of the flaws is below –

  • CVE-2024-21626 – WORKDIR: Order of operations container breakout
  • CVE-2024-23651 – Mount Cache Race
  • CVE-2024-23652 – Buildkit Build-time Container Teardown Arbitrary Delete
  • CVE-2024-23653 – Buildkit GRPC SecurityMode Privilege Check

The most severe of the flaws is CVE-2024-21626, which could result in a container escape centered around the `WORKDIR` command.

“This could occur by running a malicious image or by building a container image using a malicious Dockerfile or upstream image (i.e. when using `FROM`),” Snyk said.

Cybersecurity

There is no evidence that any of the newly discovered shortcomings have been exploited in the wild to date. That said, the issues have been addressed in runC version 1.1.12 released today.

“Because these vulnerabilities affect widely used low-level container engine components and container build tools, Snyk strongly recommends that users check for updates from any vendors providing their container runtime environments, including Docker, Kubernetes vendors, cloud container services, and open source communities,” the company said.

In February 2019, runC maintainers addressed another high-severity flaw (CVE-2019-5736, CVSS score: 8.6) that could be abused by an attacker to break out of the container and obtain root access on the host.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/01/31/runc-flaws-enable-container-escapes-granting-attackers-host-access/feed/ 0
New Glibc Flaw Grants Attackers Root Access on Major Linux Distros http://www.indiavpn.org/2024/01/31/new-glibc-flaw-grants-attackers-root-access-on-major-linux-distros/ http://www.indiavpn.org/2024/01/31/new-glibc-flaw-grants-attackers-root-access-on-major-linux-distros/#respond Wed, 31 Jan 2024 06:51:39 +0000 https://www.indiavpn.org/2024/01/31/new-glibc-flaw-grants-attackers-root-access-on-major-linux-distros/ [ad_1]

Jan 31, 2024NewsroomVulnerability / Endpoint Security

Linux Hacking

Malicious local attackers can obtain full root access on Linux machines by taking advantage of a newly disclosed security flaw in the GNU C library (aka glibc).

Tracked as CVE-2023-6246, the heap-based buffer overflow vulnerability is rooted in glibc’s __vsyslog_internal() function, which is used by syslog() and vsyslog() for system logging purposes. It’s said to have been accidentally introduced in August 2022 with the release of glibc 2.37.

“This flaw allows local privilege escalation, enabling an unprivileged user to gain full root access,” Saeed Abbasi, product manager of the Threat Research Unit at Qualys, said, adding it impacts major Linux distributions like Debian, Ubuntu, and Fedora.

Cybersecurity

A threat actor could exploit the flaw to obtain elevated permissions via specially crafted inputs to applications that employ these logging functions.

“Although the vulnerability requires specific conditions to be exploited (such as an unusually long argv[0] or openlog() ident argument), its impact is significant due to the widespread use of the affected library,” Abbasi noted.

The cybersecurity firm said further analysis of glibc unearthed two more flaws in the __vsyslog_internal() function (CVE-2023-6779 and CVE-2023-6780) and a third bug in the library’s qsort () function that can lead to memory corruption.

The vulnerability found in qsort() has affected all glibc versions released since 1992.

Cybersecurity

The development comes nearly four months after Qualys detailed another high-severity flaw in the same library called Looney Tunables (CVE-2023-4911, CVSS score: 7.8) that could result in privilege escalation.

“These flaws highlight the critical need for strict security measures in software development, especially for core libraries widely used across many systems and applications,” Abbasi said.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/01/31/new-glibc-flaw-grants-attackers-root-access-on-major-linux-distros/feed/ 0
PAX PoS Terminal Flaw Could Allow Attackers to Tamper with Transactions http://www.indiavpn.org/2024/01/17/pax-pos-terminal-flaw-could-allow-attackers-to-tamper-with-transactions/ http://www.indiavpn.org/2024/01/17/pax-pos-terminal-flaw-could-allow-attackers-to-tamper-with-transactions/#respond Wed, 17 Jan 2024 15:47:03 +0000 https://www.indiavpn.org/2024/01/17/pax-pos-terminal-flaw-could-allow-attackers-to-tamper-with-transactions/ [ad_1]

Jan 17, 2024NewsroomFinancial Data / Vulnerability

point-of-sale

The point-of-sale (PoS) terminals from PAX Technology are impacted by a collection of high-severity vulnerabilities that can be weaponized by threat actors to execute arbitrary code.

The STM Cyber R&D team, which reverse engineered the Android-based devices manufactured by the Chinese firm owing to their rapid deployment in Poland, said it unearthed half a dozen flaws that allow for privilege escalation and local code execution from the bootloader.

Cybersecurity

Details about one of the vulnerabilities (CVE-2023-42133) have been currently withheld. The other flaws are listed below –

  • CVE-2023-42134 & CVE-2023-42135 (CVSS score: 7.6) – Local code execution as root via kernel parameter injection in fastboot (Impacts PAX A920Pro/PAX A50)
  • CVE-2023-42136 (CVSS score: 8.8) – Privilege escalation from any user/application to system user via shell injection binder-exposed service (Impacts All Android-based PAX PoS devices)
  • CVE-2023-42137 (CVSS score: 8.8) – Privilege escalation from system/shell user to root via insecure operations in systool_server daemon (Impacts All Android-based PAX PoS devices)
  • CVE-2023-4818 (CVSS score: 7.3) – Bootloader downgrade via improper tokenization (Impacts PAX A920)

Successful exploitation of the aforementioned weaknesses could permit an attacker to elevate their privileges to root and bypass sandboxing protections, effectively gaining carte blanche access to perform any operation.

Cybersecurity

This includes interfering with the payment operations to “modify data the merchant application sends to the [Secure Processor], which includes transaction amount,” security researchers Adam Kliś and Hubert Jasudowicz said.

It’s worth mentioning that exploiting CVE-2023-42136 and CVE-2023-42137 requires an attacker to have shell access to the device, while the remaining three necessitate that the threat actor has physical USB access to it.

The Warsaw-based penetration testing company said it responsibly disclosed the flaws to PAX Technology in early May 2023, following which patches were released by the latter in November 2023.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/01/17/pax-pos-terminal-flaw-could-allow-attackers-to-tamper-with-transactions/feed/ 0
New Flaw Lets Attackers Bypass Security and Spoof Emails http://www.indiavpn.org/2024/01/03/new-flaw-lets-attackers-bypass-security-and-spoof-emails/ http://www.indiavpn.org/2024/01/03/new-flaw-lets-attackers-bypass-security-and-spoof-emails/#respond Wed, 03 Jan 2024 13:14:08 +0000 https://www.indiavpn.org/2024/01/03/new-flaw-lets-attackers-bypass-security-and-spoof-emails/ [ad_1]

Jan 03, 2024NewsroomCyber Threat / Email Security

SMTP Smuggling

A new exploitation technique called Simple Mail Transfer Protocol (SMTP) smuggling can be weaponized by threat actors to send spoofed emails with fake sender addresses while bypassing security measures.

“Threat actors could abuse vulnerable SMTP servers worldwide to send malicious emails from arbitrary email addresses, allowing targeted phishing attacks,” Timo Longin, a senior security consultant at SEC Consult, said in an analysis published last month.

SMTP is a TCP/IP protocol used to send and receive email messages over a network. To relay a message from an email client (aka mail user agent), an SMTP connection is established between the client and server in order to transmit the actual content of the email.

Cybersecurity

The server then relies on what’s called a mail transfer agent (MTA) to check the domain of the recipient’s email address, and if it’s different from that of the sender, it queries the domain name system (DNS) to look up the MX (mail exchanger) record for the recipient’s domain and complete the mail exchange.

The crux of SMTP smuggling is rooted in the inconsistencies that arise when outbound and inbound SMTP servers handle end-of-data sequences differently, potentially enabling threat actors to break out of the message data, “smuggle” arbitrary SMTP commands, and even send separate emails.

SMTP Smuggling

It borrows the concept from a known attack method known as HTTP request smuggling, which takes advantage of discrepancies in the interpretation and processing of the “Content-Length” and “Transfer-Encoding” HTTP headers to prepend an ambiguous request to the inbound request chain.

Specifically, it exploits security flaws in messaging servers from Microsoft, GMX, and Cisco to send emails spoofing millions of domains. Also impacted are SMTP implementations from Postfix and Sendmail.

Cybersecurity

This allows for sending forged emails that seemingly look like they are originating from legitimate senders and defeat checks in place erected to ensure the authenticity of incoming messages – i.e., DomainKeys Identified Mail (DKIM), Domain-based Message Authentication, Reporting and Conformance (DMARC), and Sender Policy Framework (SPF).

While Microsoft and GMX have rectified the issues, Cisco said the findings do not constitute a “vulnerability, but a feature and that they will not change the default configuration.” As a result, inbound SMTP smuggling to Cisco Secure Email instances is still possible with default configurations.

As a fix, SEC Consult recommends Cisco users change their settings from “Clean” to “Allow” in order to avoid receiving spoofed emails with valid DMARC checks.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/01/03/new-flaw-lets-attackers-bypass-security-and-spoof-emails/feed/ 0
New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security http://www.indiavpn.org/2024/01/01/new-terrapin-flaw-could-let-attackers-downgrade-ssh-protocol-security/ http://www.indiavpn.org/2024/01/01/new-terrapin-flaw-could-let-attackers-downgrade-ssh-protocol-security/#respond Mon, 01 Jan 2024 10:44:41 +0000 https://www.indiavpn.org/2024/01/01/new-terrapin-flaw-could-let-attackers-downgrade-ssh-protocol-security/ [ad_1]

Jan 01, 2024NewsroomEncryption / Network Security

SSH Protocol Security

Security researchers from Ruhr University Bochum have discovered a vulnerability in the Secure Shell (SSH) cryptographic network protocol that could allow an attacker to downgrade the connection’s security by breaking the integrity of the secure channel.

Called Terrapin (CVE-2023-48795, CVSS score: 5.9), the exploit has been described as the “first ever practically exploitable prefix truncation attack.”

“By carefully adjusting the sequence numbers during the handshake, an attacker can remove an arbitrary amount of messages sent by the client or server at the beginning of the secure channel without the client or server noticing it,” researchers Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk said.

Cybersecurity

SSH is a method for securely sending commands to a computer over an unsecured network. It relies on cryptography to authenticate and encrypt connections between devices.

This is accomplished by means of a handshake in which a client and server agree upon cryptographic primitives and exchange keys required for setting up a secure channel that can provide confidentiality and integrity guarantees.

However, a bad actor in an active adversary-in-the-middle (AitM) position with the ability to intercept and modify the connection’s traffic at the TCP/IP layer can downgrade the security of an SSH connection when using SSH extension negotiation.

“The attack can be performed in practice, allowing an attacker to downgrade the connection’s security by truncating the extension negotiation message (RFC8308) from the transcript,” the researchers explained.

“The truncation can lead to using less secure client authentication algorithms and deactivating specific countermeasures against keystroke timing attacks in OpenSSH 9.5.”

Another crucial prerequisite necessary to pulling off the attack is the use of a vulnerable encryption mode such as ChaCha20-Poly1305 or CBC with Encrypt-then-MAC to secure the connection.

“In a real-world scenario, an attacker could exploit this vulnerability to intercept sensitive data or gain control over critical systems using administrator privileged access,” Qualys said. “This risk is particularly acute for organizations with large, interconnected networks that provide access to privileged data.”

Cybersecurity

The flaw impacts many SSH client and server implementations, such as OpenSSH, Paramiko, PuTTY, KiTTY, WinSCP, libssh, libssh2, AsyncSSH, FileZilla, and Dropbear, prompting the maintainers to release patches to mitigate potential risks.

“Because SSH servers and OpenSSH in particular are so commonly used throughout cloud-based enterprise application environments, it’s imperative for companies to ensure they have taken appropriate measures to patch their servers,” Yair Mizrahi, senior security researcher of security research at JFrog, told The Hacker News.

“However, a vulnerable client connecting to a patched server will still result in an vulnerable connection. Thus, companies must also take steps to identify every vulnerable occurrence across their entire infrastructure and apply a mitigation immediately.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/01/01/new-terrapin-flaw-could-let-attackers-downgrade-ssh-protocol-security/feed/ 0