Federal agency hacked by 2 groups thanks to flaw that went unpatched for 4 years

A federal agency was hacked by two groups thanks to a four-year unpatched flaw

Getty Images

US government warns that multiple attackers, one acting on behalf of the nation, have exploited a four-year-old unpatched vulnerability to gain access to US federal agency networks Did.

According to an advisory jointly issued by the Cybersecurity and Infrastructure Security Agency, the FBI, and the Multi-State Information Sharing and Analysis Center, exploit activity by one group began in August 2021, while the other group began operating in August last year. It may have started on the moon. From last November to early January, the server showed signs of compromise.

No vulnerabilities detected in 4 years

Both groups exploited a code execution vulnerability tracked as CVE-2019-18935 and used a developer tool known as the Telerik User Interface (UI) for ASP.NET AJAX. This tool was deployed on the government’s Microsoft Internet Information Services (IIS) web server. The recommendation does not identify the agency, other than to say that it is a federal civilian administration under the jurisdiction of CISA.

Telerik UI for ASP.NET AJAX is marketed by a company called Progress, headquartered in Burlington, Massachusetts and Rotterdam, Netherlands. The tool bundles over 100 of his UI components that developers can use to reduce the time it takes to create custom web applications. In late 2019, Progress released version 2020.1.114. This patched his CVE-2019-18935, an insecure deserialization vulnerability that allows remote code execution on vulnerable servers. This vulnerability received a severity rating of 9.8 out of 10. In 2020, the NSA warned that this vulnerability was being exploited by actors backed by the Chinese government.

“This exploit provided interactive access to the web server and allowed the attacker to successfully execute remote code on the vulnerable web server,” the advisory said Thursday. “The agency’s vulnerability scanner had the appropriate plugin for CVE-2019-18935, but was unable to detect the vulnerability because the Telerik UI software was installed in a file path it would not normally scan. This can be the case for many software installations, as file paths vary widely between organizations and installation methods.”

Increase in unpatched vulnerabilities

To successfully exploit CVE-2019-18935, a hacker must first have knowledge of the encryption key used by a component called Telerik RadAsyncUpload. Federal investigators suspect the attacker exploited one of his two vulnerabilities discovered in 2017.

Both groups used a technique called DLL sideloading, which replaces legitimate Microsoft Windows dynamic link library files with malicious ones. Some of the DLL files uploaded by the group were disguised as PNG images. The malicious file was then executed using a legitimate process on the IIS server called w3wp.exe. A review of the antivirus logs revealed that some of the uploaded DLL files were present on the system as of August 2021.

The advisory made little mention of nation state-sponsored threat groups other than identifying IP addresses used to host command and control servers. The group, dubbed TA1 in Thursday’s advisory, began using his CVE-2019-18935 to enumerate systems within government networks last August. Investigators probed the server and identified nine of her DLL files that were used to bypass security defenses.The file communicated with the controlling server at IP address 137.184.130[.]162 or 45.77.212[.]12. Traffic to these IP addresses used unencrypted Transmission Control Protocol (TCP) on port 443. The attacker’s malware was able to load additional libraries and remove DLL files to hide its malicious activity on the network.

The advisory called the other group TA2 and identified it as the XE group. Researchers at security firm Volexity say the group is likely based in Vietnam. Volexity and fellow security firm Malwarebytes say financially motivated groups are involved in payment card skimming.

“Like TA1, TA2 was able to exploit CVE-2019-18935 and upload at least three unique DLL files to the C:\Windows\Temp\ directory, which TA2 ran via the w3wp.exe process. ,” said the advisory. “These DLL files drop and run reverse (remote) shell utilities for unencrypted communication with C2 IP addresses associated with malicious domains.”

The breach was the result of someone at an unnamed agency failing to install a patch that had been available for years. Restrict to a specific set of predefined file paths. If this could happen within a federal agency, it could happen within any other organization.

Anyone using Telerik UI for ASP.NET AJAX should read Thursday’s advisory and progress published in 2019 carefully to ensure that it has not been published.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *