{"id":2177,"date":"2023-12-08T19:00:00","date_gmt":"2023-12-08T19:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug"},"modified":"2023-12-08T19:00:00","modified_gmt":"2023-12-08T19:00:00","slug":"russian-espionage-group-hammers-zero-click-microsoft-outlook-bug","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/08\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug\/","title":{"rendered":"Russian Espionage Group Hammers Zero-Click Microsoft Outlook Bug"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltbd1d0bc83e84b149\/64f179185bee981cbbc9bc81\/russia_cybercrime_Klaus_Ohlenschlaeger_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An espionage group linked to the Russian military continues to use a zero-click vulnerability in Microsoft Outlook in attempts to compromise systems and gather intelligence from government agencies in NATO countries, as well as the United Arab Emirates (UAE) and Jordan in the Middle East.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A spate of recent attacks in September and October by the Fighting Ursa group \u2014 better known as Forest Blizzard, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/russian-fancy-bear-apt-exploited-unpatched-cisco-routers-to-hack-us-eu-government-agencies\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">APT28, or Fancy Bear<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 is the third wave to use the dangerous Outlook privilege-escalation vulnerability, tracked as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-23397\" target=\"_self\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-23397<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which allows attackers a way to steal a user&#8217;s password hash by coercing the victim&#8217;s Microsoft Outlook client to connect to an attacker-controlled server without user interaction.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So far, the advanced persistent threat (APT) has targeted at least 30 organizations in 14 countries using an exploit for the bug, network security firm Palo Alto Networks <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/russian-apt-fighting-ursa-exploits-cve-2023-233397\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">stated in an analysis<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> published Dec. 7. The attacks focus on organizations related to energy production and distribution, oil and gas pipelines, and government ministries in charge of defense, the economy, and domestic and foreign affairs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It&#8217;s one thing to suspect a nation or industry is at risk from a nation-state APT actor \u2014 it&#8217;s another to be able to examine an APT&#8217;s campaigns in depth and provide concrete observations as to which nations and industries are being targeted,&#8221; says Michael Sikorski, vice president and chief technology officer for the Unit 42 threat intelligence team at Palo Alto Networks. &#8220;Given that 11 of the 14 nations targeted throughout all three campaigns are NATO members, we assess that intelligence regarding NATO, Ukraine, and its allies remains a high priority for the Russian military.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Targeting NATO, Ukraine, and the Middle East<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The espionage campaigns targeting the vulnerability happened in three waves: an initial wave using the Outlook bug as a zero-day flaw between March and December 2022, then in March of this year following the patch for the issue, and the most recent campaign, in September and October, according to Palo Alto Networks&#8217; analysis. The targets included one of the nine <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.nato.int\/cps\/en\/natohq\/topics_50088.htm\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">NATO Rapid Deployable Corps<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a unit focused on rapid response to a variety of incidents, including natural disaster, counterterrorism, and war fighting, the firm stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers at multiple firms have linked the APT to Unit 26165 of the Russian Federation&#8217;s military intelligence agency, otherwise known as the Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Forest Blizzard continually refines its footprint by employing new custom techniques and malware, suggesting that it is a well-resourced and well-trained group posing long-term challenges to attribution and tracking its activities,&#8221; Microsoft stated in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/03\/24\/guidance-for-investigating-attacks-using-cve-2023-23397\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">an analysis updated on Dec. 4<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft worked with the Polish Cyber Command to investigate the attack and develop mitigations against the attackers. Poland is one of the nations targeted by the Outlook-exploitation campaign.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">CVE-2023-23397: No Longer Zero-Day, but Still Valuable<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First patched in March, the Microsoft Outlook vulnerability allows a specially crafted email to trigger a leak of the users Net-NTLMv2 hashes, and does not require any user interaction. Using those hashes, the attacker can then authenticate as the victim to other systems that support NTLM authentication.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft addressed the original vulnerability issue with a patch that essentially prevented the Outlook client from making malicious connections. However, soon thereafter, a researcher from Akamai examining the fix found another issue in a related Internet Explorer component that allowed him to bypass the patch altogether. Microsoft assigned a separate identifier for the new bug (<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-29324\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-29324<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">) and issued a patch for it in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/microsoft-patches-two-zero-day-vulnerabilities\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">May&#8217;s Patch Tuesday release<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the latest attacks using what some termed<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/microsoft-outlook-vulnerability-2023-it-bug\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\"> 2023&#8217;s &#8220;It&#8221; bug,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> the behavior suggests the &#8220;access and intelligence generated by these operations outweighed the ramifications of public outing and discovery,&#8221; Palo Alto Networks stated in its analysis.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Palo Alto Networks has urged its customers to patch the vulnerability, but the company has no data on how many \u2014 or how few \u2014 companies have taken the defensive measure, says Sikorski.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We have been following this CVE since it was announced, and have also been closely monitoring Russian threat activity since before the invasion of Ukraine,&#8221; he says. &#8220;Based upon Fighting Ursa&#8217;s &#8230; continued exploitation attempts against this vulnerability, we assess that organizations have either failed to patch or improperly configured their systems.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Outlook vulnerability is not the only one exploited by Fancy Bear. Microsoft&#8217;s analysis points out that the group also exploited a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/patch-now-apts-pummel-winrar-bug\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">vulnerability in the WinRAR archiving utility (CVE 2023-38831)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in early September, and six other software flaws in recent months.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An espionage group linked to the Russian military continues to<\/p>\n","protected":false},"author":12,"featured_media":2178,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2177","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=2560%2C1509&ssl=1",2560,1509,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=300%2C177&ssl=1",300,177,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=640%2C378&ssl=1",640,378,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=640%2C378&ssl=1",640,378,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=1536%2C906&ssl=1",1536,906,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=2048%2C1207&ssl=1",2048,1207,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=1024%2C604&ssl=1",1024,604,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/russian-espionage-group-hammers-zero-click-microsoft-outlook-bug-scaled.jpg?fit=2560%2C1509&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2177"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2177\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2178"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}