News | HiddenRefer

Navigation

  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Subscribe
News | HiddenRefer

The Best Curated Freebies in One Place

0
0
0
0
News | HiddenRefer
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
  • Security

Initial Access Broker Involved in Log4Shell Attacks Against VMware Horizon Servers

  • January 26, 2022
  • hiddenrefer
Initial Access Broker Involved in Log4Shell Attacks Against VMware Horizon Servers
Total
0
Shares
0
0
0
Advertisements

An initial access broker group tracked as Prophet Spider has been linked to a set of malicious activities that exploits the Log4Shell vulnerability in unpatched VMware Horizon Servers.

According to new research published by BlackBerry Research & Intelligence and Incident Response (IR) teams today, the cybercrime actor has been opportunistically weaponizing the shortcoming to download a second-stage payload onto the victimized systems.

The payloads observed include cryptocurrency miners, Cobalt Strike Beacons, and web shells, corroborating a previous advisory from the U.K. National Health Service (NHS) that sounded the alarm on active exploitation of the vulnerabilities in VMware Horizon servers to drop malicious web shells and establish persistence on affected networks for follow-on attacks.

Automatic GitHub Backups

Log4Shell is a moniker used to refer to an exploit affecting the popular Apache Log4j library that results in remote code execution by logging a specially crafted string. Since public disclosure of the flaw last month, threat actors have been quick to operationalize this new attack vector for a variety of intrusion campaigns to gain full control of affected servers.

BlackBerry said it observed instances of exploitation mirroring tactics, techniques, and procedures (TTPs) previously attributed to the Prophet Spider eCrime cartel, including the use of “C:WindowsTemp7fde” folder path to store malicious files and “wget.bin” executable to fetch additional binaries as well as overlaps in infrastructure used by the group.

Log4Shell vulnerability

“Prophet Spider primarily gains access to victims by compromising vulnerable web servers, and uses a variety of low-prevalence tools to achieve operational objectives,” CrowdStrike noted in August 2021, when the group was spotted actively exploiting flaws in Oracle WebLogic servers to gain initial access to target environments.

Like with many other initial access brokers, the footholds are sold to the highest bidder on underground forums located in the dark web, who then exploit the access for ransomware deployment. Prophet Spider is known to be active since at least May 2017.

Prevent Data Breaches

This is far from the first time internet-facing systems running VMware Horizon have come under attack using Log4Shell exploits. Earlier this month, Microsoft called out a China-based operator tracked as DEV-0401 for deploying a new ransomware strain called NightSky on the compromised servers.

The onslaught against Horizon servers has also prompted VMware to urge its customers to apply the patches immediately. “The ramifications of this vulnerability are serious for any system, especially ones that accept traffic from the open Internet,” the virtualization services provider cautioned.

“When an access broker group takes interest in a vulnerability whose scope is so unknown, it’s a good indication that attackers see significant value in its exploitation,” Tony Lee, vice president of global services technical operations at BlackBerry, said.

“It’s likely that we will continue to see criminal groups exploring the opportunities of the Log4Shell vulnerability, so it’s an attack vector against which defenders need to exercise constant vigilance,” Lee added.

.



Total
0
Shares
Share 0
Tweet 0
Pin it 0
hiddenrefer

Previous Article
Jacobi Hospital gunman Keber Martinez arrested
  • Crime News

Jacobi Hospital gunman Keber Martinez arrested

  • January 26, 2022
  • hiddenrefer
View & Download
Next Article
How to See More, But Respond Less with Enhanced Threat Visibility
  • Security

How to See More, But Respond Less with Enhanced Threat Visibility

  • January 26, 2022
  • hiddenrefer
View & Download
You May Also Like
Learn NIST Inside Out With 21 Hours of Training @ 86% OFF
View & Download
  • Security

Learn NIST Inside Out With 21 Hours of Training @ 86% OFF

  • hiddenrefer
  • June 25, 2022
ToddyCat claws at Asian governments
View & Download
  • Security

ToddyCat claws at Asian governments

  • hiddenrefer
  • June 24, 2022
Mitel VoIP Zero-Day
View & Download
  • Security

Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

  • hiddenrefer
  • June 24, 2022
Hacking Smartphones with Hermit Spyware
View & Download
  • Security

Google Says ISPs Helped Attackers Infect Targeted Smartphones with Hermit Spyware

  • hiddenrefer
  • June 24, 2022
Backdoored Python Libraries
View & Download
  • Security

Multiple Backdoored Python Libraries Caught Stealing AWS Secrets and Keys

  • hiddenrefer
  • June 24, 2022
Ransomware as a Decoy for Cyber Espionage Attacks
View & Download
  • Security

State-Backed Hackers Using Ransomware as a Decoy for Cyber Espionage Attacks

  • hiddenrefer
  • June 24, 2022
New 'Quantum' Builder Lets Attackers Easily Create Malicious Windows Shortcuts
View & Download
  • Security

New ‘Quantum’ Builder Lets Attackers Easily Create Malicious Windows Shortcuts

  • hiddenrefer
  • June 24, 2022
Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive Data
View & Download
  • Security

Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive Data

  • hiddenrefer
  • June 24, 2022
  • NYPD reports slashed in the face on subway near Wall Street station
    NYPD reports slashed in the face on subway near Wall Street station
    • June 26, 2022
  • Man pushed onto NYC subway tracks after trying to break up fight
    Man pushed onto NYC subway tracks after trying to break up fight
    • June 26, 2022
  • Fire in Jurupa Valley prompts mandatory evacuations
    Fire in Jurupa Valley prompts mandatory evacuations
    • June 26, 2022
  • Man injured in shooting on BART train in Oakland
    Man injured in shooting on BART train in Oakland
    • June 26, 2022
  • Bodies of victims in NYC triple homicide decomposed
    Bodies of victims in NYC triple homicide decomposed
    • June 25, 2022

Featured Categories

Cloud Security
248 Posts
View Posts
Crime News
3834 Posts
View Posts
Cybersecurity
234 Posts
View Posts
Data Breaches
82 Posts
View Posts
Drug Raids
137 Posts
View Posts
Privacy
101 Posts
View Posts
Security
1180 Posts
View Posts
about
Navigation
  • Home
  • Cloud
  • Crime
  • Cyber
  • Data Breaches
  • Drug Raids
  • Privacy
  • Security
Featured
  • NYPD reports slashed in the face on subway near Wall Street station
    NYPD reports slashed in the face on subway near Wall Street station
    • June 26, 2022
  • Man pushed onto NYC subway tracks after trying to break up fight
    Man pushed onto NYC subway tracks after trying to break up fight
    • June 26, 2022
  • Fire in Jurupa Valley prompts mandatory evacuations
    Fire in Jurupa Valley prompts mandatory evacuations
    • June 26, 2022
  • Man injured in shooting on BART train in Oakland
    Man injured in shooting on BART train in Oakland
    • June 26, 2022
  • Bodies of victims in NYC triple homicide decomposed
    Bodies of victims in NYC triple homicide decomposed
    • June 25, 2022
News | HiddenRefer
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Input your search keywords and press Enter.