News: 1648172382

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

We blocked North Korea's Chrome exploit, says Google

(2022/03/25)


Google on Thursday described how it apparently caught and thwarted North Korea's efforts to exploit a remote code execution vulnerability in Chrome.

The security flaw was spotted being abused in the wild on February 10, according to Googler Adam Weidemann, and there was evidence it was exploited as early as January 4. The web giant patched the bug on February 14. Exploiting the bug clears the way to compromise a victim's browser and potentially take over their computer to spy on them.

We're told two North Korean government teams used the vulnerability to target organizations in the worlds of news media, IT and internet infrastructure, cryptocurrencies, and fintech in America, though it is possible there were other industries and countries in the groups' sights.

[1]

These two Pyongyang-backed crews were previously tracked under the names Operation Dream Job and Operation AppleJeus. Google suspects the pair were acting on behalf of the same entity, as both used the same exploit code, though their targets and deployment techniques differed.

[2]

[3]

Operation Dream Job, we're told, targeted individuals working at major news organizations, domain registrars, hosting providers, and software vendors. The team masqueraded as recruiters, emailing marks bogus details of roles at Google, Oracle, and Disney, with links to websites designed to look like Indeed, ZipRecruiter and DisneyCareers. Once on the site, visitors were served a hidden iframe that exploited the browser bug to achieve arbitrary code execution.

The second team, Operation AppleJeus, targeted people in the cryptocurrency and fintech business, involved setting up spoof websites that hosted the exploit code as well as putting it in a hidden iframe on two compromised fintech websites.

[4]North Korea pulled in $400m in cryptocurrency heists last year – report

[5]This is a BlackCat you don't want crossing your path

[6]Dunno about you, but we're seeing an 800% increase in cyberattacks, says one MSP

[7]Second data-wiping malware found in Ukraine, says ESET

The exploit itself used JavaScript to build a system fingerprint, and then triggered the vulnerability when an unknown set of conditions were met.

If remote code execution is successful, some JavaScript requests the next stage in the attack: a browser sandbox escape to gain further access to the machine running Chrome. After that, the trail went cold. "Careful to protect their exploits, the attackers deployed multiple safeguards to make it difficult for security teams to recover any of the stages," Weidemann explained in a technical [8]write-up that includes indicators of compromise.

[9]

We're told the North Koreans ensured the iframes only appeared at specific times, and sent unique links to victims that potentially expired after a single activation. The AES algorithm was used to encrypt each step, and it stopped trying to serve additional stages if one failed.

Weidemann also said that while Google only recovered the materials for exploiting the Chrome remote code execution hole, it found evidence that the attackers also checked for Safari on macOS and Firefox, and in those cases directed them to specific pages. Yet again, a cold trail: those links were already dead when Google investigated.

The patch that closed [10]the vulnerability in question was released for Chromium on Valentine's Day, and Google noted that the North Koreans made multiple exploitation attempts in the days immediately following. That, Weidemann said, "stresses the importance of applying security updates as they become available." ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yj1MfqDnf8c0wVVnVkOVsAAAAJM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yj1MfqDnf8c0wVVnVkOVsAAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yj1MfqDnf8c0wVVnVkOVsAAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2022/01/16/in_brief_security/

[5] https://www.theregister.com/2022/03/22/talos-ransomware-blackcat/

[6] https://www.theregister.com/2022/03/11/russia-invasion-cyber-war-rages/

[7] https://www.theregister.com/2022/03/01/ukraine_wiper_apple_visa_mastercard/

[8] https://blog.google/threat-analysis-group/countering-threats-north-korea/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yj1MfqDnf8c0wVVnVkOVsAAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-0609

[11] https://whitepapers.theregister.com/



They "checked for Safari on macOS and Firefox"

DS999

But that trail was cold? Or was it because North Korea hadn't inserted any exploits to handle those browsers yet? Which wouldn't be surprising since the Chrome monoculture outside of mobile (where Safari still matters) means if you can attack Chrome you can attack over 90% of people, and it isn't worth bothering with the <10% who are Mac users or PC users running Firefox!

Re: They "checked for Safari on macOS and Firefox"

Clausewitz 4.0

They couldn't get even all the stages of this exploit, nor the sandbox escape vuln.

Its certain there is a zero day for sandbox escape out there, and possible there are zero days for other browsers.

Well done op.

It's better to be wanted for murder that not to be wanted at all.
-- Marty Winch