Cyber Attacks

Russian hackers target embassies with Ngrok feature and WinRAR exploit

0

A state-sponsored Russian hacker group, APT29, is leveraging the CVE-2023-38831 vulnerability in WinRAR for cyberattacks.

APT29 which is also known by the names (UNC3524,/NobleBaron/Dark Halo/NOBELIUM/Cozy Bear/CozyDuke, SolarStorm) has been targeting embassy entities with a BMW car sale lure.

The CVE-2023-38831 security flaw affects WinRAR versions before 6.23 and allows crafting .RAR and .ZIP archives that can execute in the background code prepared by the attacker for malicious purposes.

The vulnerability has been exploited as a zero-day since April by threat actors targeting cryptocurrency and stock trading forums.

The Ukrainian National Security and Defense Council (NDSC) says that APT29 has been using a malicious ZIP archive that runs a script in the background to show a PDF lure and to download PowerShell code that downloads and executes a payload.

The malicious archive is called “DIPLOMATIC-CAR-FOR-SALE-BMW.pdf” and targeted multiple countries on the European continent, including Azerbaijan, Greece, Romania, and Italy.

APT29 has used the BMW car ad phishing lure before to target diplomats in Ukraine during a campaign in May that delivered ISO payloads through the HTML smuggling technique.

NDSC says that the Russian hackers used a Ngrok free static domain to access the command and control (C2) server hosted on their Ngrok instance.

By using this method, the attackers managed to hide their activity and communicate with compromised systems without being detected.

Since researchers at cybersecurity company Group-IB reported that the CVE-2023-38831 vulnerability in WinRAR was exploited as a zero-day, advanced threat actors started to incorporate it into their attacks.

Security researchers at ESET saw attacks in August attributed to the Russian APT28 hacker group that exploited the vulnerability in a spear phishing campaign that targeted political entities in the EU and Ukraine using the European Parliament agenda as a lure.

The observed campaign from APT29 stands out because it mixes old and new techniques such as the use of the WinRAR vulnerability to deliver payloads and Ngrok services to hide communication with the C2.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Toyota financial services hack claimed by Medusa Ransomware

Previous article

Canadian government discloses data breach after contractor hacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *