Newsletter
REAL HACKER NEWS
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home APPLICATIONS

Iranian Hackers Compromised a U.S. Federal Agency’s Network Using Log4Shell Exploit

Real Hacker Staff by Real Hacker Staff
November 20, 2022
in APPLICATIONS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

A mobile gaming subscription war looms as Netflix sets its sights on Apple Arcade

A mobile gaming subscription war looms as Netflix sets its sights on Apple Arcade

March 20, 2023

New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads

March 20, 2023


Iranian government-sponsored risk actors have been blamed for compromising a U.S. federal company by profiting from the Log4Shell vulnerability in an unpatched VMware Horizon server.

The main points, which had been shared by the U.S. Cybersecurity and Infrastructure Safety Company (CISA), are available in response to incident response efforts undertaken by the authority from mid-June by mid-July 2022.

“Cyber risk actors exploited the Log4Shell vulnerability in an unpatched VMware Horizon server, put in XMRig crypto mining software program, moved laterally to the area controller (DC), compromised credentials, after which implanted Ngrok reverse proxies on a number of hosts to take care of persistence,” CISA famous.

LogShell, aka CVE-2021-44228, is a crucial distant code execution flaw within the widely-used Apache Log4j Java-based logging library. It was addressed by the open supply venture maintainers in December 2021.

The most recent growth marks the continued abuse of the Log4j vulnerabilities in VMware Horizon servers by Iranian state-sponsored teams because the begin of the yr. CISA didn’t attribute the occasion to a selected hacking group.

Nevertheless, a joint advisory launched by Australia, Canada, the U.Okay., and the U.S. in September 2022 pointed fingers at Iran’s Islamic Revolutionary Guard Corps (IRGC) for leveraging the shortcoming to hold out post-exploitation actions.

The affected group, per CISA, is believed to have been breached as early as February 2022 by weaponizing the vulnerability so as to add a brand new exclusion rule to Home windows Defender that allowlisted your complete C: drive.

Doing so made it doable for the adversary to obtain a PowerShell script with out triggering any antivirus scans, which, in flip, retrieved the XMRig cryptocurrency mining software program hosted on a distant server within the type of a ZIP archive file.

The preliminary entry additional afforded the actors to fetch extra payloads reminiscent of PsExec, Mimikatz, and Ngrok, along with utilizing RDP for lateral motion and disabling Home windows Defender on the endpoints.

“The risk actors additionally modified the password for the native administrator account on a number of hosts as a backup ought to the rogue area administrator account get detected and terminated,” CISA famous.

Additionally detected was an unsuccessful try at dumping the Native Safety Authority Subsystem Service (LSASS) course of utilizing the Home windows Job Supervisor, which was blocked by the antivirus resolution deployed within the IT setting.

Microsoft, in a report final month, revealed that cybercriminals are focusing on credentials within the LSASS course of owing to the truth that it “can retailer not solely a present consumer’s OS credentials but additionally a site admin’s.”

“Dumping LSASS credentials is essential for attackers as a result of in the event that they efficiently dump area passwords, they’ll, for instance, then use authentic instruments reminiscent of PsExec or Home windows Administration Instrumentation (WMI) to maneuver laterally throughout the community,” the tech large mentioned.





Source link

Tags: AgencysCompromisedExploitFederalhackersIranianLog4ShellNetworkU.S
Share76Tweet47

Related Posts

A mobile gaming subscription war looms as Netflix sets its sights on Apple Arcade

A mobile gaming subscription war looms as Netflix sets its sights on Apple Arcade

by Real Hacker Staff
March 20, 2023
0

Microsoft and Netflix are ready to take on Apple in the mobile gaming space — and the first shots have...

New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads

by Real Hacker Staff
March 20, 2023
0

î ‚Mar 20, 2023î „Ravie LakshmananCyber Threat / Malware A new piece of malware dubbed dotRunpeX is being used to distribute numerous...

Russia’s Kremlin bans iPhones as Putin’s workers fear espionage threat

by Real Hacker Staff
March 20, 2023
0

Russians working on President Putin's 2024 re-election campaign have been told that they cannot use an iPhone over espionage fears.Workers...

Mispadu Banking Trojan Targets Latin America: 90,000+ Credentials Stolen

Mispadu Banking Trojan Targets Latin America: 90,000+ Credentials Stolen

by Real Hacker Staff
March 20, 2023
0

î ‚Mar 20, 2023î „Ravie LakshmananCyber Threat / Malware A banking trojan dubbed Mispadu has been linked to multiple spam campaigns targeting...

New Cyber Platform Lab 1 Decodes Dark Web Data to Uncover Hidden Supply Chain Breaches

by Real Hacker Staff
March 20, 2023
0

î ‚Mar 20, 2023î „The Hacker NewsData Breach / Dark Web This article has not been generated by ChatGPT. 2022 was the...

Load More
  • Trending
  • Comments
  • Latest

eSIMs Will Transform the Way You Think About Mobile Data and Security

March 7, 2023

Sennheiser Starts Shipping EW-DX Digital Wireless Microphone Series

November 22, 2022

Chinese Hackers Using Russo-Ukrainian War Decoys to Target APAC and European Entities

December 7, 2022

Spitfire Audio unveils Aperture: Cassette Symphony

November 25, 2022

Hello world!

0
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Mothers emerge as leaders in Cuban resistance movement | Politics News

Mothers emerge as leaders in Cuban resistance movement | Politics News

March 20, 2023
Tecno Phantom V Fold review

Tecno Phantom V Fold review

March 20, 2023
PSA: You Only Have One Week To Purchase 3DS And Wii U eShop Games

PSA: You Only Have One Week To Purchase 3DS And Wii U eShop Games

March 20, 2023
A mobile gaming subscription war looms as Netflix sets its sights on Apple Arcade

A mobile gaming subscription war looms as Netflix sets its sights on Apple Arcade

March 20, 2023

Recent News

Mothers emerge as leaders in Cuban resistance movement | Politics News

Mothers emerge as leaders in Cuban resistance movement | Politics News

March 20, 2023
Tecno Phantom V Fold review

Tecno Phantom V Fold review

March 20, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
  • Uncategorized
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO

© 2003 Real Hacker News

Go to mobile version