Auteur Sujet: [FireEye]CVE-2017-0199 Used as Zero Day to Distribute FINSPY Espionage Malware and LATENTBOT Cyber Crime Malware  (Lu 3142 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
CVE-2017-0199 Used as Zero Day to Distribute FINSPY Espionage Malware
and LATENTBOT Cyber Crime Malware


[html]

FireEye recently identified a vulnerability – CVE-2017-0199 – that
  allows a malicious actor to download and execute a Visual Basic script
  containing PowerShell commands when a user opens a Microsoft Office
  RTF document containing an embedded exploit. We worked with Microsoft
  and     href="https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199-hta-handler.html">published
    the technical details of this vulnerability as soon as a patch
  was made available.


 

In this follow-up post, we discuss some of the campaigns we observed
  leveraging the CVE-2017-0199 zero-day in the days, weeks and months
  leading up to the patch being released.


 

CVE-2017-0199 Used by Multiple Actors


 

FireEye assesses with moderate confidence that CVE-2017-0199 was
  leveraged by financially motivated and nation-state actors prior to
  its disclosure. Actors leveraging FINSPY and LATENTBOT used the
  zero-day as early as January and March, and similarities between their
  implementations suggest they obtained exploit code from a shared
  source. Recent DRIDEX activity began following a disclosure on April
  7, 2017.


 

FINSPY Malware Used to Target Russian-Speaking Victims


 

As early as Jan. 25, 2017, lure documents referencing a
  Russian Ministry of Defense decree and a manual allegedly published in
  the "Donetsk People's Republic" exploited CVE-2017-0199 to
  deliver FINSPY payloads. Though we have not identified the targets,
  FINSPY is sold by Gamma Group to multiple nation-state clients, and we
  assess with moderate confidence that it was being used along with the
  zero-day to carry out cyber espionage.


 

The malicious document, СПУТНИК


Tags: