News: 1670482929

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

North Korea hits new low by using Seoul Halloween tragedy to exploit Internet Explorer zero-day

(2022/12/08)


North Korea has hit a new low, using the death of over 150 people to exploit a zero-day flaw in Internet Explorer.

Google’s Threat Analysis Group on Wednesday [1]spotted the flaw, [2]CVE-2022-41128 , an RCE bug in the JScript9 scripting language engine.

Microsoft [3]fixed it in November 2022’s patch dump .

[4]

But Google says the North Korean government-backed actors known as APT37 created an exploit for the flaw and embedded it in a document titled ““221031 Seoul Yongsan Itaewon accident response situation (06:00).docx”.

[5]

[6]

The Seoul Yongsan Itaewon accident took place in late October and saw over 150 people crushed to death when Halloween celebrations went very wrong. Hundreds more were injured, many seriously.

South Korea declared a week of national mourning after the incident.

[7]

And now APT37 has used it – while memories are still very, very, raw in the South - to distribute malware.

[8]China is likely stockpiling and deploying vulnerabilities, says Microsoft

[9]US puts $10 million bounty on North Korean cyber-crews

[10]North Koreans spotted harassing SMBs with malware

[11]Here today, gone to Maui: That's your data captured by North Korean ransomware

And nasty malware, too.

“The vulnerability can be exploited to execute arbitrary code when rendering an attacker-controlled website,” Google explained. It does so by infecting documents so they download “a rich text file (RTF) remote template, which in turn fetched remote HTML content. Because Office renders this HTML content using Internet Explorer (IE).”

Internet Explorer has of course been deprecated but is still present on many PCs. Quite possibly more PCs in South Korea than elsewhere given some of the nation’s government websites relied on [12]legacy Microsoft browser technologies until 2021.

North Korea stands accused of using cyber-ops to steal data, money, and whatever else it can get its hands on.

[13]

And now it’s also used hacking to exploit the deaths of children in the hope of infecting innocent individuals’ PCs.

Which is horrible, grim, behaviour. But far from atypical for North Korea’s government, which those of you with a strong stomach can learn about in horrifying detail in this [14]searing United Nations report that details the regime’s excesses. ®

Get our [15]Tech Resources



[1] https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/

[2] https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41128

[3] https://www.theregister.com/2022/11/09/microsoft_november_2022_patch_tuesday/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y5HD0As1ILMV-xIhn1WkYwAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5HD0As1ILMV-xIhn1WkYwAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5HD0As1ILMV-xIhn1WkYwAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5HD0As1ILMV-xIhn1WkYwAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/11/07/china_stockpiles_vulnerabilities_microsoft_asserts/

[9] https://www.theregister.com/2022/07/27/north_korea_us_reward/

[10] https://www.theregister.com/2022/07/16/north_korea_targets_small_business/

[11] https://www.theregister.com/2022/07/06/here_today_gone_to_maui/

[12] https://www.theregister.com/2020/12/10/south_korea_activex_certs_dead/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5HD0As1ILMV-xIhn1WkYwAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.michaelkirby.com.au/content/report-united-nations-commission-inquiry-dprk-north-korea-released-geneva

[15] https://whitepapers.theregister.com/



Little Mouse

I'm not cross, North Korea, just disappointed.

Hubert Cumberdale

I'm disappointed that Internet Explorer still exists in this timeline. I was refusing to manage machines with it installed as far back as 2006 (and it had to be removed by a form of minor surgery back then) because I got so bored of cleaning up the mess when it got exploited.

Eliminate the zero

Refugee from Windows

Surely the weak link is the now orphaned Internet Explorer. I remember Adobe Flash being killed off, is it time for this to be removed?

Will a Tuesday set of fixes contain a tool to remove it and either point at another browser of your own choice that hasn't been abandoned or install the dreaded Edge.

Its North Korea, they're probably still using IE6 anyway.

Groundhog day

elsergiovolador

Microsoft products seem to be littered with backdoors.

As if to help certain services gather data on their targets.

Now that this exploit is public, they are moving onto the next one.

Maybe Microsoft is already baking a new service pack, with new set of backdoors.

Re: Groundhog day

Binraider

Backdoors by design, and then also the ones "by accident".

And if those are figured out, launch a new version of an application to make sure some new ones are made available.

Say what you like about DOS, the small size of the attack surface made it much more auditable, and it persists in embedded for this reason. I'm sure I'm not alone in appreciating the benefits of a generic and very compact OS for certain applications.

wolfetone

I mean yeah, it's disgusting that they can use a tragedy like this for their own gains. But what about the people clicking on it? They're the same as the fuckers who just stand there filming it on Facebook when someone's getting their head kicked in.

We can predict everything, except the future.