Where China leads, Iran follows: US warns of 'contract' hackers exploiting Citrix, Pulse Secure and F5 VPNs
- Reference: 1600281608
- News link: https://www.theregister.co.uk/2020/09/16/iran_targets_citrix_pulse_secure_f5_vpns/
- Source link:
The warning mirrors one [1]issued earlier this week for exactly the same vendors , except with China as the malevolent party instead of Iran.
“CISA and FBI are aware of a widespread campaign from an Iran-based malicious cyber actor targeting several industries mainly associated with information technology, government, healthcare, financial, insurance, and media sectors across the United States”, said the agencies in a [2]joint statement.
What do F5, Citrix, Pulse Secure all have in common? China exploiting their flaws to hack govt, biz – Feds [3]READ MORE
The threat actor uses nmap to scan target networks before exploiting any of a host of CVEs to force its way within. Those include [4]CVE-2019-11510 (Pulse Secure Connect’s remote entry vuln), [5]CVE-2019-11539 (Pulse Secure remote code injection), [6]CVE-2019-19781 (Citrix directory traversal), and [7]CVE-2020-5902 (F5’s BIG-IP takeover vuln)
Once inside the target network, the Iranians do the usual thing: gain a foothold, establish persistence, and then steal data. In doing so they also make use of the China Chopper web shell, released as a [8]separate advisory by US CISA. That shell also deploys a Powershell script that steals encrypted passwords from password manager app KeePass, as well as another utility that establishes an outbound remote desktop session.
The Iranians are said to make “significant” use of ngrok, which shows up as TCP port 443 connections to “external cloud-based infrastructure” as well as FRPC over network port 7557. CISA warned the world to patch the CVEs, especially the Citrix directory traversal flaw detailed in 2019-19781.
It is significant that the Iranians, identified only as Pioneer Kitten or UNC 757, appear to be copying Chinese TTPs. Crowdstrike said in a roundup that the crew has been [9]active since 2017 , describing them as “Highly opportunistic with a focus on Technology, Government, Defense and Healthcare” and speculating that they may be private contractors operating for the Iranian state, rather than units of the Iranian government themselves.
The group is also said to have been offering to sell access to compromised networks on “an underground forum”, something Crowdstrike thought may have been an unofficial side hustle from the Iranian government work. ®
Get our [10]Tech Resources
[1] https://www.theregister.com/2020/09/14/chinas_hackers_f5_citrix/
[2] https://us-cert.cisa.gov/ncas/alerts/aa20-259a
[3] https://www.theregister.com/2020/09/14/chinas_hackers_f5_citrix/
[4] https://www.theregister.com/2020/01/07/pulse_secure_attacks/
[5] https://nvd.nist.gov/vuln/detail/CVE-2019-11539
[6] https://www.theregister.com/2019/12/23/patch_now_published_citrix_applications_leave_network_vulnerable_to_unauthorised_access/
[7] https://www.theregister.com/2020/07/03/f5_critical_flaws_big_ip/
[8] https://us-cert.cisa.gov/ncas/analysis-reports/ar20-259a
[9] https://www.crowdstrike.com/blog/who-is-pioneer-kitten/
[10] https://whitepapers.theregister.com/
"malicious persons from Iran"
Well isn't there a simple solution ? Block all Iran IP addresses on the router, problem solved.
I can understand that media sectors and, eventually, financial sectors could welcome IP traffic from Iran, but please explain how exactly an Iranian citizen in Iran is going to sign up for US healthcare, insurance or use US government facilities ? Don't they all require US residency ?
Maybe there are dual-citizenship US/Iranian people who regularly go to Iran, but they can understand that they need to be in the US to conduct their US business. And a VPN is not all that expensive.
Why is it that key government websites accept traffic from any country other than their own anyway ? I fail to see what benefit a Chinese citizen in China can find in browsing impots.gouv.fr, especially as that site is exclusively in French, and they don't have a login anyway.
>> The Iranians are said to make “significant” use of ngrok... <<
Says who? Have they been caught lying before - MAYBE?!?