News: 1654775109

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Symantec: More malware operators moving in to exploit Follina

(2022/06/09)


While enterprises are still waiting for Microsoft to issue a fix for the critical "Follina" vulnerability in Windows, yet more malware operators are moving in to exploit it.

Microsoft late last month acknowledged the remote code execution (RCE) vulnerability – tracked as [1]CVE-2022-30190 – but has yet to deliver a patch for it. The company has outlined [2]workarounds that can be used until a fix becomes available.

In the meantime, reports of active exploits of the [3]flaw continue to surface. Analysts with Proofpoint's Threat Insight team earlier this month [4]tweeted about a phishing campaign, possibly aligned with a nation-state targeting US and European Union agencies, which uses Follina. The Proofpoint researchers said the malicious spam messages were sent to fewer than 10 Proofpoint product users.

[5]

Then, this week, Proofpoint researchers [6]detected another phishing campaign run by a group connected to the Qbot data-stealing and backdoor botnet that was using Follina to infect systems with its malware.

[7]

[8]

Now Symantec threat hunters say they also have detected other groups using the flaw to deliver payloads of malware. In one instance, the attackers are deploying the remote access trojan (RAT) AsyncRAT, which includes a valid digital signature. Other attackers are deploying information stealer malware as the payload onto a compromised system.

"Since the details of the vulnerability started surfacing online, attackers were quick to start taking advantage of the flaw to install their payloads," the researchers wrote in a [9]blog post . "Symantec has observed attackers using a similar HTML file to that used in the initial attack. Multiple attackers are using a variety of payloads at the end of successful exploitation."

[10]

Follina is a RCE vulnerability in the Microsoft Support Diagnostic Tool (MSDT) that allows attackers to subvert the ms-msdt protocol handler process. Attackers can use a specially crafted Word document that loads a malicious HTML file through the application's remote template function, according to Symantec.

If exploited, the attacker can perform such tasks as running arbitrary code with privileges, installing programs, viewing, changing or deleting data and creating new accounts. They also can load and execute PowerShell code within Windows and the vulnerability can additionally be exploited via the Rich Text Format (RTF) file format, the researchers wrote.

One of the problems is that attackers don't need to use macros, so they don't need to trick victims into enabling macros for the attack to work. The vulnerability is on all supported versions of Windows.

[11]Now Windows Follina zero-day exploited to infect PCs with Qbot

[12]Zero-day vuln in Microsoft Office: 'Follina' will work even when macros are disabled

[13]Conti spotted working on exploits for Intel Management Engine flaws

[14]Microsoft seizes 41 domains tied to 'Iranian phishing ring'

According to the Symantec researchers, when the AsyncRAT runs, it will check for analysis functions on the system and work to shut them down. It then collects information about the compromised system, such as hardware identification, the username, executed path and operating system information. The information is then sent to a command-and-control (C2) server and executes the commands from the C2 server on the infected machine.

The information stealer that is being deployed by some threat groups steals such information as cookies and saved login data from web browsers, including Microsoft Edge, Chrome and Firefox.

[15]

Threat hunters with cybersecurity vendor Kaspersky also have been tracking attacks using the Follina flaw, noting in a [16]blog post this week that organizations in the US are particularly being targeted. Other countries under attack include Russia, Brazil and India, as well as some in Western Europe.

"We expect to see more Follina exploitation attempts to gain access to corporate resources, including for ransomware attacks and data breaches," they wrote.

While bad actors are going hard to exploit the vulnerability, it has been known about since 2020, when an [17]academic paper was published outlining the flaw. In April, the Shadow Chaser Group [18]tweeted that it had reported its own take on the vulnerability to Microsoft. ®

Get our [19]Tech Resources



[1] https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-30190

[2] https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/

[3] https://www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/

[4] https://twitter.com/threatinsight/status/1532830739208732673

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YqIZI4NPCtajCK1W0ZPQOwAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://www.theregister.com/2022/06/09/qbot-malware-microsoft-follina/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqIZI4NPCtajCK1W0ZPQOwAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqIZI4NPCtajCK1W0ZPQOwAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/follina-msdt-exploit-malware

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YqIZI4NPCtajCK1W0ZPQOwAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2022/06/09/qbot-malware-microsoft-follina/

[12] https://www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/

[13] https://www.theregister.com/2022/06/02/conti_rasomware_intel_firmware/

[14] https://www.theregister.com/2022/06/07/microsoft_bohrium_domains/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YqIZI4NPCtajCK1W0ZPQOwAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://securelist.com/cve-2022-30190-follina-vulnerability-in-msdt-description-and-counteraction/106703/

[17] https://benjamin-altpeter.de/doc/thesis-electron.pdf

[18] https://twitter.com/shadowchasing1

[19] https://whitepapers.theregister.com/



"a specially crafted Word document"

Pascal Monett

Once again, an attack that is based on the user opening an attachment from someone they don't know.

I've been getting a few mails this week with the subject "Re: your order is blocked", containing an attachment.

I haven't ordered anything. If you really think I'm stupid enough to open an attachment from an email I did not request concerning something I did not order, I just wish I had Thor's lightning at my disposal, because I would use it.

Liberally.

Re: "a specially crafted Word document"

IGotOut

Except for the purchasing department that get a thousand such emails a week.

Re: "a specially crafted Word document"

VoiceOfTruth

Try the HR department. Please send us your CVs in Word format. OK...

Please Explain

Arthur Daily

Why is there some proprietary protocol back-channel talking to MS HQ - in a text processing program. Say WORD for DOS. Every MS protocol - say SMB or this back-channel is bad security, and obscure to deliberate privacy intrusion. Lets hope the EU investigates data leakage . If my document had 'Takeover Bid' some inside traders would be well placed. Lets investigate what leaked, and how much over time.

A better question

Anonymous Coward

Is how many other magic url types for it's own purposes has MS embedded?

guaranteed this is not the only one or two....I've seen at least one other that looks like a possible attack vector

Re: A better question

Anonymous Coward

There's probably loads. Teams has one, and the Teams API is pretty much Swiss cheese as far as I can tell. When people start getting their hands on that things are gonna get juicy.

The Lord and I are in a sheep-shepherd relationship, and I am in
a position of negative need.
He prostrates me in a green-belt grazing area.
He conducts me directionally parallel to non-torrential aqueous
liquid.
He returns to original satisfaction levels my psychological makeup.
He switches me on to a positive behavioral format for maximal
prestige of His identity.
It should indeed be said that notwithstanding the fact that I make
ambulatory progress through the umbragious inter-hill mortality slot, terror
sensations will no be initiated in me, due to para-etical phenomena.
Your pastoral walking aid and quadrupic pickup unit introduce me
into a pleasurific mood state.
You design and produce a nutriment-bearing furniture-type structure
in the context of non-cooperative elements.
You act out a head-related folk ritual employing vegetable extract.
My beverage utensil experiences a volume crisis.
It is an ongoing deductible fact that your inter-relational
empathetical and non-ventious capabilities will retain me as their
target-focus for the duration of my non-death period, and I will possess
tenant rights in the housing unit of the Lord on a permanent, open-ended
time basis.