Operation RussianDoll: Adobe & Windows Zero-Day Exploits Likely
Leveraged by Russia’s APT28 in Highly-Targeted Attack[html]
FireEye Labs recently detected a limited APT campaign exploiting
zero-day vulnerabilities in Adobe Flash and a brand-new one in
Microsoft Windows. Using the href="/content/fireeye-www/en_US/mandiant/threat-intelligence.html"
target="_self">Dynamic Threat Intelligence Cloud (DTI), FireEye
researchers detected a pattern of attacks beginning on April
13th href="/content/fireeye-www/en_US/mandiant/threat-intelligence.html">,
2015. Adobe independently patched the vulnerability (CVE-2015-3043) in
href="https://helpx.adobe.com/security/products/flash-player/apsb15-06.html">APSB15-06.
Through correlation of technical indicators and command and control
infrastructure, FireEye assess that APT28 is probably responsible for
this activity.
Microsoft is aware of the outstanding local privilege escalation
vulnerability in Windows (CVE-2015-1701). While there is not yet a
patch available for the Windows vulnerability, updating Adobe Flash to
the latest version will render this in-the-wild exploit innocuous. We
have only seen CVE-2015-1701 in use in conjunction with the Adobe
Flash exploit for CVE-2015-3043. The Microsoft Security Team is
working on a fix for CVE-2015-1701.
Exploit Overview
The high level flow of the exploit is as follows:
1.