{"id":44393,"date":"2022-08-04T06:22:00","date_gmt":"2022-08-04T06:22:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/44393"},"modified":"2022-08-04T06:22:00","modified_gmt":"2022-08-04T06:22:00","slug":"spyware-activity-particularly-impactful-in-july","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=44393","title":{"rendered":"Spyware activity particularly impactful in July"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/08\/spyware-activity-particularly-impactful-in-july.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Developers of mercenary <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/spyware\">spyware<\/a> seem to have been unusually active in their weaponisation of common vulnerabilities and exposures (CVEs) during July 2022 \u2013 according to research published this week by <a href=\"https:\/\/www.recordedfuture.com\/\">Recorded Future<\/a> \u2013 although whether or not that is simply down to other threat actors being less busy during the summer months remains to be seen.<\/p>\n<p>This is <a href=\"https:\/\/www.computerweekly.com\/news\/252521295\/Cyber-researchers-step-in-to-fill-Patch-Tuesdays-shoes\">the third monthly vulnerability bulletin<\/a> produced by the threat research team at Recorded Future\u2019s Insikt Group \u2013 the first was published in June to coincide with the introduction of Microsoft\u2019s <a href=\"https:\/\/www.computerweekly.com\/news\/252522608\/Microsoft-Windows-Autopatch-now-generally-available\">automated patching service for enterprises<\/a>, which has taken the sting out of Patch Tuesday for many.<\/p>\n<p>Going forward, Recorded Future plans to publish its <em><a href=\"https:\/\/go.recordedfuture.com\/hubfs\/reports\/cve-monthly-202208.pdf\">CVE monthly<\/a><\/em> report on the first Tuesday of every month \u2013 Patch Tuesday continues to drop on the second Tuesday.<\/p>\n<p>In its latest report, the research team said it had observed exploitation of newly disclosed zero-day vulnerabilities affecting both Microsoft and Google, in both cases to distribute spyware, which it said demonstrated an often close link between top-of-the-line spyware developers and new zero-days.<\/p>\n<p>\u201cOn 4 July 2022, Google disclosed an actively exploited zero-day vulnerability, CVE-2022-2294, which affects Google Chrome,\u201d the team said. \u201cWhile the company did not disclose details about attacks involving this flaw, it was not long before exploitation was reported by others.<\/p>\n<p>\u201cAvast threat researchers (who had originally informed Google about the vulnerability) released a report <a href=\"https:\/\/decoded.avast.io\/janvojtesek\/the-return-of-candiru-zero-days-in-the-middle-east\/\">on 21 July 2022<\/a>, about a campaign in which Israeli spyware vendor Candiru exploited CVE-2022-2294 to deploy DevilsTongue spyware.<\/p>\n<p>\u201cSpyware was [also] associated with another zero-day vulnerability, this time for Microsoft. On 12 July 2022, Microsoft disclosed a zero-day vulnerability, CVE-2022-22047, that affects current versions of Windows and Windows Server. This vulnerability was exploited by the Austria-based mercenary threat group Knotweed <a href=\"https:\/\/www.computerweekly.com\/news\/252523308\/Austrian-data-firm-accused-of-selling-malware-conducting-cyber-attacks\">to distribute its Subzero spyware<\/a>.<\/p>\n<p>\u201cA second vulnerability, CVE-2022-30216, also affects current versions of Windows and Windows Server and has a very high CVSS score due to allowing remote code execution, but we have not yet seen exploitation attempts,\u201d the researchers said.<\/p>\n<p>Among the other more impactful vulnerabilities in July 2022 were a remote code execution (RCE) vulnerability in Apache Spark, <a href=\"https:\/\/lists.apache.org\/thread\/p847l3kopoo5bjtmxrcwk21xp6tjxqlc\">tracked as CVE-2022-33891<\/a> \u2013 discovered by Databricks researcher Kostya Kortchinsky \u2013 exploitation of which was observed in the wild within 48 hours of disclosure, and an SQL injection vulnerability in the Django Python web framework, tracked as CVE-2022-34265.<\/p>\n<p>July also saw continued high levels of exploitation of CVE-2022-30190, or Follina, a dangerous zero-click vulnerability in Microsoft Office which, left unchecked, allows a threat actor to execute PowerShell commands with no user interaction. Follina was <a href=\"https:\/\/www.computerweekly.com\/news\/252520855\/Researchers-discover-zero-day-Microsoft-vulnerability-in-Office\">disclosed at the end of May<\/a> and fixed in <a href=\"https:\/\/www.techtarget.com\/searchwindowsserver\/news\/252521541\/Microsoft-fixes-Follina-zero-day-for-June-Patch-Tuesday\">the June Patch Tuesday update<\/a>, but naturally remains unpatched by many.<\/p>\n<p>\u201cIf we could have predicted any vulnerability to see high-profile exploitation after initial disclosure, it would have been Follina,\u201d said the Recorded Future team.<\/p>\n<p>\u201cSure enough, on 6 July 2022, Fortinet researchers <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/follina-rozena-leveraging-discord-to-distribute-a-backdoor\">released an analytic report<\/a> on a phishing campaign using Follina to distribute the Rozena backdoor, a malware that allows attackers to completely take over Windows systems. Fortinet researchers observed adversaries using Rozena to inject a remote shell connection back to the attacker\u2019s machine.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Developers of mercenary spyware seem to have been unusually active in their weaponisation of common vulnerabilities and exposures (CVEs) during July 2022 \u2013 according to research published this week by Recorded Future \u2013 although whether or not that is simply down to other threat actors being less busy during the summer months remains to be [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":44394,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-44393","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/44393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=44393"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/44393\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/44394"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=44393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=44393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=44393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}