Russian Hackers Exploiting Microsoft Follina Vulnerability Against Ukraine

Cyber Security

Products You May Like

The Computer Emergency Response Team of Ukraine (CERT-UA) has cautioned of a new set of spear-phishing attacks exploiting the “Follina” flaw in the Windows operating system to deploy password-stealing malware.

Attributing the intrusions to a Russian nation-state group tracked as APT28 (aka Fancy Bear or Sofacy), the agency said the attacks commence with a lure document titled “Nuclear Terrorism A Very Real Threat.rtf” that, when opened, exploits the recently disclosed vulnerability to download and execute a malware called CredoMap.

Follina (CVE-2022-30190, CVSS score: 7.8), which concerns a case of remote code execution affecting the Windows Support Diagnostic Tool (MSDT), was addressed by Microsoft on June 14, 2022, as part of its Patch Tuesday updates.

CyberSecurity

According to an independent report published by Malwarebytes, CredoMap is a variant of the .NET-based credential stealer that Google Threat Analysis Group divulged last month as having been deployed against users in Ukraine.

The malware’s main purpose is to siphon data, including passwords and saved cookies, from several popular browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox.

Russian Hackers Targeting Ukraine
Russian Hackers Targeting Ukraine

“Although ransacking browsers might look like petty theft, passwords are the key to accessing sensitive information and intelligence,” Malwarebytes said. “The target, and the involvement of APT28, a division of Russian military intelligence), suggests that campaign is a part of the conflict in Ukraine, or at the very least linked to the foreign policy and military objectives of the Russian state.”

CyberSecurity

It’s not just APT28. CERT-UA has further warned of similar attacks mounted by Sandworm and an actor dubbed UAC-0098 that leverage a Follina-based infection chain to deploy CrescentImp and Cobalt Strike Beacons on to targeted hosts.

The development comes as Ukraine continues to be a target for cyberattacks amidst the country’s ongoing war with Russia, with Armageddon hackers also spotted distributing the GammaLoad.PS1_v2 malware in May 2022.

Products You May Like

Articles You May Like

Vivo Y03t, Vivo Watch 3 Reportedly Spotted on Certification Sites; May Launch Globally Soon
Samsung Galaxy M35, iQoo Z9 Lite, Honor 200, and More New Smartphones to Go on Sale During Amazon Prime Day 2024
Revolut CEO confident on UK bank license approval as fintech firm hits record $545 million profit
CMF Student Referral Program Launched in India; Winners to Get CMF Phone 1, Buds Pro 2 or Watch Pro 2
Over 3 Million iOS, macOS Apps Found at Risk Due to CocoaPods Security Breach: Report

Leave a Reply

Your email address will not be published. Required fields are marked *