News: 1626234247

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft names Chinese group as source of new attack on SolarWinds

(2021/07/14)


Microsoft has attributed a new attack on SolarWinds to a group operating in China.

The software giant on Tuesday [1]posted details of the attack, which SolarWinds on Monday [2]patched and revealed as a Return Oriented Programming attack that targets its Serv-U managed file transfer product and allows an attacker to run arbitrary code with privileges, install programs and alter data on cracked targets.

SolarWinds acted promptly to issue the patch, however it and Microsoft both urged swift application because an actor actively exploiting the flaw had already been identified.

[3]

Microsoft’s Threat Intelligence Center today stated it has “high confidence” that actor is “DEV-0322, a group operating out of China, based on observed victimology, tactics, and procedures”. DEV-0322 is Microsoft’s name for the attacker.

[4]

[5]

Microsoft says it’s seen the group “targeting entities in the US Defense Industrial Base Sector and software companies.

“This activity group is based in China and has been observed using commercial VPN solutions and compromised consumer routers in their attacker infrastructure.”

[6]Mega-distie SYNNEX attacked and Microsoft cloud accounts it tends tampered

[7]SolarWinds backdoor gang pwns Microsoft support agent to turn sights on customers

[8]SEC still digging into SolarWinds fallout, nudges undeclared victims

[9]Security researcher says attacks on Russian government have Chinese fingerprints – and typos, too

The mention of consumer routers is notable, as vendors of such devices are often unhelpfully relaxed about security and seldom make their machines easy to upgrade or advise when an update is necessary. ISPs, which often provide such devices to users, also seldom offer update advice.

Attributing the attack to an actor in China is also notable, as the USA and the Middle Kingdom have a formal [10]No-Hack Pact that prohibits either nation from conducting, or knowingly supporting, efforts to crack systems to steal intellectual property for commercial advantage.

[11]

That pact reportedly saw China-sourced attacks on US targets decrease, but in 2018 the USA said China had breached the pact.

Microsoft’s post also details how it spotted the attack, which gave itself away by spawning an “anomalous malicious process … from the Serv-U process, suggesting that it had been compromised.

“We observed DEV-0322 piping the output of their cmd.exe commands to files in the Serv-U \Client\Common\ folder, which is accessible from the internet by default, so that the attackers could retrieve the results of the commands,” Microsoft’s post adds.

[12]

DEV-0322 would then add a new global user to Serv-U, making itself an admin.

Microsoft says its Defender 365 product is now able to detect the attack, but urged urgent application of SolarWinds’ patch. ®

Get our [13]Tech Resources



[1] https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/

[2] https://www.theregister.com/2021/07/12/solarwinds_patch_attack/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YO5hWc1KeRosTp4jgXBH6wAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YO5hWc1KeRosTp4jgXBH6wAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YO5hWc1KeRosTp4jgXBH6wAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/07/07/synnex_rnc_microsoft_attack/

[7] https://www.theregister.com/2021/06/26/in_brief_security/

[8] https://www.theregister.com/2021/06/22/sec_continues_to_probe_solarwinds/

[9] https://www.theregister.com/2021/06/09/mail_o_malware_maybe_chinese/

[10] https://www.theregister.com/2015/09/25/us_china_promise_to_stop_hacking/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YO5hWc1KeRosTp4jgXBH6wAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YO5hWc1KeRosTp4jgXBH6wAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Whenever Richard Cory went downtown,
We people on the pavement looked at him:
He was a gentleman from sole to crown,
Clean-favored, and imperially slim.
And he was always quietly arrayed,
And he was always human when he talked;
But still he fluttered pulses when he said,
"Good morning," and he glittered when he walked.
And he was rich -- yes, richer than a king --
And admirably schooled in every grace:
In fine, we thought that he was everything
To make us wish that we were in his place.
So on we worked, and waited for the light,
And went without the meat, and cursed the bread;
And Richard Cory, one calm summer night,
Went home and put a bullet through his head.
-- E. A. Robinson, "Richard Cory"