Google on Friday shipped emergency fixes to address a security
vulnerability in the Chrome web browser that it said is being actively
exploited in the wild.
The issue, assigned the identifier CVE-2022-3075, concerns a case of insufficient data validating in Mojo,
which refers to a collection of runtime libraries that provide a
platform-agnostic mechanism for inter-process communication (IPC).
An anonymous researcher has been credited with reporting the high-severity flaw on August 30, 2022.
"Google is aware of reports that an exploit for CVE-2022-3075 exists in the wild," the internet giant said,
without delving into additional specifics about the nature of the
attacks to prevent additional threat actors from taking advantage of the
flaw.
The latest update makes it the sixth zero-day vulnerability in Chrome that Google has resolved since the start of the year -
CVE-2022-2856 - Insufficient validation of untrusted input in Intents
Users are recommended to upgrade to version 105.0.5195.102 for
Windows, macOS, and Linux to mitigate potential threats. Users of
Chromium-based browsers such as Microsoft Edge, Brave, Opera, and
Vivaldi are also advised to apply the fixes as and when they become
available.
Google Chrome users should
install the latest security updates immediately, following reports that
hackers are exploiting a "high-severity vulnerability" flaw, the
Singapore Computer Emergency Response Team (SingCERT) said on Friday
(Aug 19).
Google did not provide further
information, but released Chrome 104.0.5112.101 for Mac and Linux, and
Chrome 104.0.5112.102/101 for Windows to address multiple
vulnerabilities.
The high-severity vulnerability is "being exploited in the wild", or active and can be found in devices belonging to ordinary users.
The security fix for this bug is included in an update currently
being rolled out, and users who have automatic updates turned on are
expected to receive it in the coming days or weeks, according to
technology website Bleeping Computer.
SingCERT has advised Google Chrome users on Windows, Mac and Linux computers to install the latest security updates immediately.
They are also encouraged to enable the automatic update function in Chrome to ensure that their software is updated promptly.
The vulnerability is a high-severity security issue linked to
"Intents” - a feature that enables launching applications and web
services directly from a web page, Bleeping Computer reported.
The vulnerability was reported on Jul 19 by Ashley Shen and Christian Resell of the Google Threat Analyst Group.
Google said it was aware that an exploit for the bug exists in the
wild, but may restrict access to bug details and links until a majority
of users are updated with a fix.
"We will also retain restrictions if the bug exists in a third party
library that other projects similarly depend on, but haven't yet fixed,"
it added.
A new botnet called 'RapperBot' is being used in attacks since
mid-June 2022, focusing on brute-forcing its way into Linux SSH servers
to establish a foothold on the device.
The researchers show that RapperBot is based on the Mirai trojan but
deviates from the the original malware's normal behavior, which is
uncontrolled propagation to as many devices as possible.
Instead, RapperBot is more tightly controlled, has limited DDoS
capabilities, and its operation appears geared towards initial server
access, likely to be used as stepping stones for lateral movement within
a network.
Over
the past 1.5 months since its discovery, the new botnet used over 3,500
unique IPs worldwide to scan and attempt brute-forcing Linux SSH
servers.
Mirai-based, but different
The new botnet was discovered in the wild by threat hunters at
Fortinet, who noticed the IoT malware featured some unusual SSH-related
strings and decided to investigate further.
RapperBot proved to be a Mirai fork, but with its own command and
control (C2) protocol, unique features, and atypical (for a botnet)
post-compromise activity.
"Unlike the majority of Mirai variants, which natively brute force
Telnet servers using default or weak passwords, RapperBot exclusively
scans and attempts to brute force SSH servers configured to accept
password authentication," explains the Fortinet report.
"The bulk of the malware code contains an implementation of an SSH
2.0 client that can connect and brute force any SSH server that supports
Diffie-Hellmann key exchange with 768-bit or 2048-bit keys and data
encryption using AES128-CTR."
The SSH brute-forcing relies on a list of credentials downloaded from
the C2 via host-unique TCP requests, while the malware reports back to
the C2 when it succeeded.
Fortinet researchers followed the bot and continued to sample new
variants, noticing that RapperBot used a self-propagation mechanism via a
remote binary downloader, which was removed by the threat actors in
mid-July.
The newer variants circulating at that time featured a shell command
that replaced the victim's SSH keys with the actor's, essentially
establishing persistence that's maintained even after SSH password
changes.
Moreover,
RapperBot added a system to append the actor's SSH key to the host's
"~/.ssh/authorized_keys," which helps maintain access on the server
between reboots or even if the malware is found and deleted.
In the most recent samples analyzed by the researchers, the bot adds
the root user "suhelper" on the compromised endpoints and creates a Cron
job that re-adds the user every hour in case an admin discovers the
account and deletes it.
RapperBot's attack overview(Fortinet)
Also, it's worth noting that the malware authors added extra layers
of obfuscation to the strings in later samples, like XOR encoding.
String obfuscation added on later variants(Fortinet)
RapperBot's goal
Most botnets either perform DDoS attacks or engage in coin-mining by
hijacking the host's available computational resources, and some do
both.
The goal of RapperBot, however, isn't evident, as the authors have
kept its DDoS functions limited and even removed and re-introduced them
at some point.
Also, the removal of self-propagation and the addition of persistence
and detection-avoidance mechanisms indicate that the botnet's operators
may be interested in initial access sales to ransomware actors.
Fortinet reports that its analysts saw no additional payloads
delivered post-compromise during the monitoring period, so the malware
just nests on the infected Linux hosts and sits dormant.
A North Korean-backed threat group tracked as Kimsuky is using a
malicious browser extension to steal emails from Google Chrome or
Microsoft Edge users reading their webmail.
The extension, dubbed SHARPEXT by Volexity researchers who spotted
this campaign in September, supports three Chromium-based web browsers
(Chrome, Edge, and Whale) and can steal mail from Gmail and AOL
accounts.
The attackers install the malicious extension after compromising a
target's system using a custom VBS script by replacing the 'Preferences'
and 'Secure Preferences' files with ones downloaded from the malware's
command-and-control server.
Once
the new preferences files are downloaded on the infected device, the
web browser automatically loads the SHARPEXT extension.
"The malware directly inspects and exfiltrates data from a victim's webmail account as they browse it," Volexity said Thursday.
"Since its discovery, the extension has evolved and is currently at version 3.0, based on the internal versioning system."
As Volexity further revealed today,
this latest campaign aligns with previous Kimsuky attacks as it also
deploys the SHARPEXT "in targeted attacks on foreign policy, nuclear and
other individuals of strategic interest" in the United States, Europe,
and South Korea.
SHARPEXT workflow (Volexity)
Stealthy and highly effective attacks
By taking advantage of the target's already-logged-in session to
steal emails, the attack remains undetected by the victim's email
provider, thus making detection very challenging if not impossible.
Also, the extension's workflow will not trigger any suspicious
activity alerts on the victims' accounts which ensures that the
malicious activity will not be discovered by checking the webmail
account's status page for alerts.
The North Korean threat actors can use SHARPEXT to collect a wide range of information using commands that:
List previously collected emails from the victim to ensure
duplicates are not uploaded. This list is continuously updated as
SHARPEXT executes.
List email domains with which the victim has previously communicated. This list is continuously updated as SHARPEXT executes.
Collect a blacklist of email senders that should be ignored when collecting emails from the victim.
Add a domain to the list of all domains viewed by the victim.
Upload a new attachment to the remote server.
Upload Gmail data to the remote server.
Commented by the attacker; receive an attachments list to be exfiltrated.
Upload AOL data to the remote server.
This is not the first time the North Korean APT group has used
browser extensions to harvest and exfiltrate confidential data from
targets' breached systems.
As Netscout's ASERT Team said in
December 2018, a spear-phishing campaign orchestrated by Kimsuky pushed
a malicious Chrome extension since at least May 2018 in attacks
targeting a large number of academic entities across multiple
universities.
The Tor Project team has announced the release of Tor Browser 11.5, a
major release that brings new features to help users fight censorship
easier.
The Tor Browser has been created specifically for accessing sites
through The Onion Router (Tor) network to offer users anonymity and
privacy when accessing information on the internet.
It achieves this by routing traffic through nodes on the network and
encrypting it at every step. The connection reaches the destination
through an exit node that is used to relay the information back to the
user.
Auto block bypassing
The updates in Tor Browser 11.5 focus on circumventing censorship, a process that started a year ago in version 10.5 with improving the Tor connection experience.
In the new version, users no longer have to manually try out bridge configurations to unblock Tor.
Tor Browser version 11.5 comes with a new feature called “Connection
Assist”, which assigns automatically the bridge configuration known to
work best for the user’s location.
“Connection Assist works by looking up and downloading an up-to-date
list of country-specific options to try using your location (with your
consent),” explains the release announcement.
“It manages to do so without needing to connect to the Tor Network
first by utilizing moat – the same domain-fronting tool that Tor Browser
uses to request a bridge from torproject.org.”
Connection Assist in action(Tor)
Since Connection Assist is still in an early stage of development
(v1.0), the Tor team welcomes user feedback and reports, which would
help them iron out any kinks and improve on the system.
HTTPS on by default
Another important new feature in version 11.5 is making ‘HTTPS-Only
Mode’ the default browsing mode, so that the connection is through a
secure tunnel.
This ensures that all data exchange between the user and the server
hosting the website will be encrypted, to defend against
man-in-the-middle (MitM) attacks and to protect users from SSL stripping
on malicious exit relays.
The
Tor team assures users that SecureDrop will continue to work as
intended despite the deprecation and replacement of the HTTPS-Everywhere
extension that served as an onion name interpreter.
The only exception to replacing HTTPS-Everywhere with the new HTTPS-Only Mode is Android, which has generally fallen behind.
Tor’s development team admitted this and promised to do more about
Android, releasing updates more frequently, fixing the many bugs that
have accumulated, and catching up with the Fenix (Firefox for Android)
releases.
Better settings
The third significant improvement in Tor Browser 11.5 is a heavily
revamped Network Settings menu, now called “Connection Settings”, which
should make it easier to find and understand specific settings.
Most notably, bridge configuration and connection options have been redesigned to enable quick and easy review and management.
Using emojis on the saved Bridges, the new interface offers
visualization for the configuration for the first time, making it easy
to identify the right bridge and select it when needed.
Redesigned network settings (Tor)
You can download the latest Tor Browser from the official download portal as an installable package or a portable binary for your OS architecture.
A
new ransomware operation called RedAlert, or N13V, encrypts both
Windows and Linux VMWare ESXi servers in attacks on corporate networks.
The new operation was discovered today by MalwareHunterTeam, who tweeted various images of the gang’s data leak site.
The
ransomware has been called ‘RedAlert’ based on a string used in the
ransom note. However, from a Linux encryptor obtained by
BleepingComputer, the threat actors call their operation ‘N13V’
internally, as shown below.
The
Linux encryptor is created to target VMware ESXi servers, with
command-line options that allow the threat actors to shut down any
running virtual machines before encrypting files.
The full list of command-line options can be seen below.
-w Run command for stop all running VM`s
-p Path to encrypt (by default encrypt only files in directory, not include subdirectories)
-f File for encrypt
-r Recursive. used only with -p ( search and encryption will include subdirectories )
-t Check encryption time(only encryption, without key-gen, memory allocates ...)
-n Search without file encryption.(show ffiles and folders with some info)
-x Asymmetric cryptography performance tests. DEBUG TESTS
-h Show this message
When running the ransomware with the ‘-w‘ argument, the Linux encryptor will shut down all running VMware ESXi virtual machines using the following esxcli command:
esxcli --formatter=csv --format-param=fields=="WorldID,DisplayName" vm process list | tail -n +2 | awk -F $',' '{system("esxcli vm process kill --type=force --world-id=" $1)}'
When encrypting files, the ransomware utilizes the NTRUEncrypt public-key encryption algorithm, which support various ‘Parameter Sets’ that offer different levels of security.
An
interesting feature of RedAlert/N13V is the ‘-x’ command-line option
that performs ‘asymmetric cryptography performance testing’ using these
different NTRUEncrypt parameter sets. However, it is unclear if there is
a way to force a particular parameter set when encrypting and/or if the
ransomware will select a more efficient one.
The only other ransomware operation known to use this encryption algorithm is FiveHands.
NTRUEncrypt encryption speed test Source: BleepingComputer
When
encrypting files, the ransomware will only target files associated with
VMware ESXi virtual machines, including log files, swap files, virtual
disks, and memory files, as listed below.
.log
.vmdk
.vmem
.vswp
.vmsn
In the sample analyzed by BleepingComputer, the ransomware would encrypt these file types and append the .crypt658 extension to the file names of encrypted files.
Encrypting files in Linux with RedAlert Source: BleepingComputer
In each folder, the ransomware will also create a custom ransom note named HOW_TO_RESTORE, which contains a description of the stolen data and a link to a unique TOR ransom payment site for the victim.
Red Alert / N13V ransom note Source: BleepingComputer
The
Tor payment site is similar to other ransomware operation sites as it
displays the ransom demand and provides a way to negotiate with the
threat actors.
However,
RedAlert/N13V only accepts the Monero cryptocurrency for payment, which
is not commonly sold in USA crypto exchanges because it is a privacy
coin.
RedAlert / N13V Tor negotiation site Source: BleepingComputer
While only a Linux encryptor has been found, the payment site has hidden elements showing that Windows decryptors also exist.
“Board of Shame”
Like
almost all new enterprise-targeting ransomware operations, RedAlert
conducts double-extortion attacks, which is when data is stolen, and
then ransomware is deployed to encrypt devices.
This
tactic provides two extortion methods, allowing the threat actors to
not only demand ransom to receive a decryptor but also demand one to
prevent the leaking of stolen data.
When
a victim does not pay a ransom demand, the RedAlert gang publishes
stolen data on their data leak site that anyone can download.
RedAlert / N13V Data Leak Site Source: BleepingComputer
Currently, the RedAlert data leak site only contains the data for one organization, indicating that the operation is very new.
While
there has not been a lot of activity with the new N13V/RedAlert
ransomware operation, it is one that we will definitely need to keep an
eye on due to its advanced functionality and immediate support for both
Linux and Windows.