News: 1658940311

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Knotweed Euro cyber mercenaries attacking private sector, says Microsoft

(2022/07/27)


Microsoft has published an analysis of a Europe-based "private-sector offensive actor" with a view to helping its customers spot signs of attacks by money-hungry gangsters.

[1]Dubbed Knotweed by Microsoft's Threat Intelligence Center and Security Response Center, the private sector targeting crew has made use of multiple Windows and Adobe zero-day exploits in attacks against European and Central American customers.

The group itself is, according to Microsoft, an Austria-based PSOA. While the outfit looks very above board, with a website rammed full of business-speak concerning information gathering and the company's 20 years of expertise, according to Microsoft's report the group is connected to the development and sale of the SubZero malware.

[2]

"Observed victims to date," noted Microsoft, "include law firms, banks, and strategic consultancies in countries such as Austria, the United Kingdom, and Panama."

[3]

[4]

Unsurprisingly the malware makes use of a number of exploits, including zero-days, to infiltrate the computers of victims. In 2022, exploits were found packaged in a PDF document sent via email which, when combined with a zero day Windows privilege escalation exploit, resulted in the deployment of SubZero. SubZero itself is a rootkit which grants full control over a compromised system.

The patched [5]CVE-2022-22047 vulnerability featured in the attacks and enabled an escape from sandboxes. Naturally, Microsoft is keen that users apply the security patch, although there have been [6]some unfortunate side effects...

[7]

"The exploit chain starts," explained Microsoft, "with writing a malicious DLL to disk from the sandboxed Adobe Reader renderer process. The CVE-2022-22047 exploit was then used to target a system process by providing an application manifest with an undocumented attribute that specified the path of the malicious DLL.

"Then, when the system process next spawned, the attribute in the malicious activation context was used, the malicious DLL was loaded from the given path, and system-level code execution was achieved."

Reminder: if it looks like it came from a real estate agent...

Other attacks were tracked in 2021, utilizing vulnerabilities patched that year. One deployment was traced to an Excel file masquerading as a real estate document containing a malicious Excel 4.0 macro (obfuscated with large chunks of text from the Kama Sutra.)

Once in, the malware lurks in memory and can capture screenshots, perform keylogging, exfiltrate files, run a remote shell and download plug-ins from Knotweed's C2 server.

Investigators have identified a host of IP addresses under the control of Knotweed. Depressingly, Microsoft noted "this infrastructure, largely hosted by Digital Ocean and Choopa, has been actively serving malware since at least February of 2020 and continues through the time of this writing."

[8]Windows Network File System flaw results in arbitrary code execution as SYSTEM

[9]Microsoft warns Windows 10 patch broke printing for some

[10]Another Windows 10 patch that breaks printers ups ante to full-on Blue Screen of Death

[11]Microsoft struggles to wake from PrintNightmare: Latest print spooler patch can be bypassed, researchers say

[12]Security flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns

With the group's activities ongoing, Microsoft's only advice appears to be keeping up to date with both patching and malware detection and looking out for post-compromise actions such as credential dumping and the enabling of plaintext credentials.

In addition, a switch to multifactor authentication is recommended and a change to Excel macro security settings to ensure runtime macro scanning by Antimalware Scan Interface is enabled.

[13]

Overall, Microsoft's analysis is both an interesting assessment of an active group and a sobering reminder of the race underway between miscreants and researchers. Sadly, it looks like the [14]game of whack-a-mole with regard to vulnerabilities, exploits and patches is unlikely to end any time soon. ®

Get our [15]Tech Resources



[1] https://www.microsoft.com/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YuG1hRaUzKPAcKwR7yOizAAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuG1hRaUzKPAcKwR7yOizAAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuG1hRaUzKPAcKwR7yOizAAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22047

[6] https://www.theregister.com/2022/07/18/windows_11_patch_problems/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuG1hRaUzKPAcKwR7yOizAAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/07/15/windows_nfs_patch/

[9] https://www.theregister.com/2022/07/26/windows_10_printer_bork/

[10] https://www.theregister.com/2021/03/11/printer_problems_windows_10/

[11] https://www.theregister.com/2021/07/07/printnightmare_fix_fail/

[12] https://www.theregister.com/2022/07/19/micodus_gps_tracker_vulns/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuG1hRaUzKPAcKwR7yOizAAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2022/07/27/palo_alto_unit_42/

[15] https://whitepapers.theregister.com/



Zippy´s Sausage Factory

Excel macros... why is it always Excel?

I remember installing VB 5 a few years ago to open some legacy project and it said something along the lines of "write code that downloads and executes on the user's machine - without prompting!".

Bless* 'em, how naive they were...

* (that's a euphemism, of course)

pdf has permission to make DLLs?

Anonymous Coward

MS why do you give so much access to a fricking document? Why do you keep creating insecure OSs that allow alteration?

you'd think by now you would "get it" but nope

Microsoft

VoiceOfTruth

Why is Microsoft able to identify Austria based rogues, but not rogues that exist on Microsoft's own IP space?

I notice that Microsoft points out Digital Ocean hosts some of these bad actors. While this is undoubtedly true, based on what I see myself, how about the baddies on MS's own network? I see plenty of bad traffic sourced from there.

Re: Microsoft

Clausewitz4.0

True. A lot of phishing pages jump from Azure -> AWS and vice versa, sometimes in round-robin. Probably to make the takedown harder / slower.

Death wish, n.:
The only wish that always comes true, whether or not one wishes it to.