Get Even More Visitors To Your Blog, Upgrade To A Business Listing >>

Google says North Korea targeted an Internet Explorer zero-day vulnerability

Cybersecurity researchers from Google’s Threat Analysis Group (TAG) have discovered a zero-day vulnerability in the Internet Explorer (IE) browser (opens in new tab) being exploited by a well-known North Korean threat actor.

In a blog post (opens in new tab) detailing its findings, the group said it spotted the APT37 (AKA Erebus) group, targeting individuals in South Korea with a weaponized Microsoft Word file. 

The file is titled “221031 Seoul Yongsan Itaewon accident response situation (06:00).docx”, which is a reference to the recent tragedy that took place in Itaewon, Seoul, during this year’s Halloween celebration, where at least 158 people lost their lives, with another 200 injured. Apparently, the attackers wanted to take advantage of the public and media attention the incident got.

Abusing old flaws

After analyzing the document being distributed, TAG found it downloading a rich text file (RTF) remote template to the target endpoint, which then grabs remote HTML content. Microsoft may have retired Internet Explorer and replaced it with Edge, but Office still renders HTML content using IE, which is a known fact threat actors have been abusing since at least 2017, TAG said.

Now that Office renders HTML content with IE, the attackers can abuse the zero-day they discovered in IE’s JScript engine.

The team found the flaw in “jscript9.dll”, the JavaScript engine of Internet Explorer, which allowed threat actors to execute arbitrary code when rendering a website under their control. 

Microsoft was tipped off on October 31 2022, with the flaw labeled CVE-2022-41128 three days later, and a patch being released on November 8.

While the process so far only compromises the device, TAG did not discover to what end. It did not find the final APT37’s payload for this campaign, it said, but added that the group was observed in the past delivering malware such as Rokrat, Bluelight, or Dolphin.

Via: The Verge (opens in new tab)

FOLLOW us ON GOOGLE NEWS

 

Read original article here

Denial of responsibility! TechCodex is an automatic aggregator of the all world’s media. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials, please contact us by email – [email protected]. The content will be deleted within 24 hours.

The post Google says North Korea Targeted an Internet Explorer zero-day vulnerability appeared first on TechCodex.



This post first appeared on TechCodex, please read the originial post: here

Share the post

Google says North Korea targeted an Internet Explorer zero-day vulnerability

×

Subscribe to Techcodex

Get updates delivered right to your inbox!

Thank you for your subscription

×