Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • CRO Coin Falls 19% After Crypto.com Announces Rewards Cut Down To Cardholders bitcoin news
  • Report – Taxes Bitcoin News bitcoin news
  • Colombia Takes First Steps Toward Regulating Cryptocurrency Exchanges – Regulation Bitcoin News bitcoin news
  • BitcoinUSD․com Launches a Market Watch Site – Press release Bitcoin News bitcoin news
  • NoVa Battles’ NoVa (NVA) Token Is Now Listed in Bitrue – Press release Bitcoin News bitcoin news
  • DOT Rebounds Following Recent Losses, as RUNE Moves Toward Multi-Week Low – Market Updates Bitcoin News bitcoin news
  • Report Reveals Terra Holders Liquidated Their Holding When Crash Started bitcoin news
  • GameFi Platform is Gateway to Web 3.0 bitcoin news

Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive Data

Posted on June 24, 2022 By root


The U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with the Coast Guard Cyber Command (CGCYBER), on Thursday released a joint advisory warning of continued attempts on the part of threat actors to exploit the Log4Shell flaw in VMware Horizon servers to breach target networks.

“Since December 2021, multiple threat actor groups have exploited Log4Shell on unpatched, public-facing VMware Horizon and [Unified Access Gateway] servers,” the agencies said. “As part of this exploitation, suspected APT actors implanted loader malware on compromised systems with embedded executables enabling remote command-and-control (C2).”

In one instance, the adversary is said to have been able to move laterally inside the victim network, obtain access to a disaster recovery network, and collect and exfiltrate sensitive law enforcement data.

Log4Shell, tracked as CVE-2021-44228 (CVSS score: 10.0), is a remote code execution vulnerability affecting the Apache Log4j logging library that’s used by a wide range of consumers and enterprise services, websites, applications, and other products.

Successful exploitation of the flaw could enable an attacker to send a specially-crafted command to an affected system, enabling the actors to execute malicious code and seize control of the target.

Based on information gathered as part of two incident response engagements, the agencies said that the attackers weaponized the exploit to drop rogue payloads, including PowerShell scripts and a remote access tool dubbed “hmsvc.exe” that’s equipped with capabilities to log keystrokes and deploy additional malware.

“The malware can function as a C2 tunneling proxy, allowing a remote operator to pivot to other systems and move further into a network,” the agencies noted, adding it also offers a “graphical user interface (GUI) access over a target Windows system’s desktop.”

The PowerShell scripts, observed in the production environment of a second organization, facilitated lateral movement, enabling the APT actors to implant loader malware containing executables that include the ability to remotely monitor a system’s desktop, gain reverse shell access, exfiltrate data, and upload and execute next-stage binaries.

Furthermore, the adversarial collective leveraged CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager that came to light in April 2022, to implant the Dingo J-spy web shell.

CyberSecurity

Ongoing Log4Shell-related activity even after more than six months suggests that the flaw is of high interest to attackers, including state-sponsored advanced persistent threat (APT) actors, who have opportunistically targeted unpatched servers to gain an initial foothold for follow-on activity.

According to cybersecurity company ExtraHop, Log4j vulnerabilities have been subjected to relentless scanning attempts, with financial and healthcare sectors emerging as an outsized market for potential attacks.

“Log4j is here to stay, we will see attackers leveraging it again and again,” IBM-owned Randori said in an April 2022 report. “Log4j buried deep into layers and layers of shared third-party code, leading us to the conclusion that we’ll see instances of the Log4j vulnerability being exploited in services used by organizations that use a lot of open source.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Crypto and Defi Could Pose ‘Real Risks’ to Financial Stability – Regulation Bitcoin News
Next Post: NoVa Battles’ NoVa (NVA) Token Is Now Listed in Bitrue – Press release Bitcoin News

Related Posts

  • Unpatched Critical Flaws Disclosed in U-Boot Bootloader for Embedded Devices cyber security news
  • FBI Warns About Hackers Selling VPN Credentials for U.S. College Networks cyber security news
  • Google Says ISPs Helped Attackers Infect Targeted Smartphones with Hermit Spyware cyber security news
  • New NTLM Relay Attack Lets Attackers Take Control Over Windows Domain cyber security news
  • New Privacy Framework for IoT Devices Gives Users Control Over Data Sharing cyber security news
  • Conti Ransomware Gang Shut Down After Splitting into Smaller Groups cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • Unpatched DNS Related Vulnerability Affects a Wide Range of IoT Devices cyber security news
  • Do You Have Ransomware Insurance? Look at the Fine Print cyber security news
  • Dubai Virtual Assets Regulator Establishes HQ in the Metaverse – Metaverse Bitcoin News bitcoin news
  • Ukrainian Hacker Jailed for 4-Years in U.S. for Selling Access to Hacked Servers cyber security news
  • Branding Opportunities On The Lightning Network, A How-To Guide bitcoin news
  • Game Space Releases Merge Bird on Its GameFi-as-a-Service (GaaS) Platform – Press release Bitcoin News bitcoin news
  • Circle, The Company Behind The USDC Stablecoin, Announces Euro Coin bitcoin news
  • Cardano Metaverse Project Cardalonia Releases Staking Platform, Set To Release Playable Avatars On The Cardano Blockchain bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme