Threat Advisory

Cacti, Realtek, and IBM Aspera Faspex Vulnerabilities Under Active Exploitation

Threat: Vulnerability/Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

The Researchers observed In January and March of this year variety of attack bursts spread ShellBot and Moobot malware by targeting Cacti and Realtek vulnerabilities. The Realtek vulnerabilities (CVE-2021-35394) to insufficient legality detection on commands received from clients CVE-2021-35394 affect UDPServer and allow for arbitrary command injection. A server running Cacti is vulnerable to CVE-2022-46169 a command injection flaw that enables an unauthorized user to run arbitrary code. The "remote agent.php" file, which may be accessed without authentication contains the vulnerability.

 

Execution Flow

 

The Script file needed to continue downloading Moobot Malware. The Moobot is run with the Realtek argument. According to Mirai variations, it analyses the MISP (Microprocessor without Interlocked Pipeline Stages) version which has an encrypted data section with a configuration for a botnet and identifies a Moobot from a specified generation random string. That moment it receives the command from the C2 server and starts communicating with the C2 host and then attack will start. The ShellBot has been discovered in a minimum of three different versions, including PowerBots (C) GohacK, LiGhT's Modded Perlbot v2, and B0tchZ 0.2a. The malicious website contains All files on this website are IRC botnets that use the same C2 server they configure from the payload that targets vulnerable Cacti servers. it performs several perlbot commands. It includes various varieties of hacking and flooding attacks. Also, it has an exploit enhancement module that receives information from a public website that provides security alerts and exploits.

Threat actors have been using vulnerable servers to spread the malware ShellBot and Moobot over the past few months. When commanded via a C2 server, compromised victims can be controlled and exploited as DDoS bots. Administrators should use secure passwords and change them frequently because Moobot has the ability to terminate other botnet processes and conduct brute force attacks. Moreover, some ShellBot variants have a C2 server that can be used to install additional malware.

 

Threat Profile:

Tactic Technique ID Technique
Initial Access T1190 Exploit Public-Facing Application
 Execution T1059 Command and Scripting Interpreter
T1204 User Execution
 Persistence T1053 Scheduled Task/Job
 Defense Evasion T1027 Obfuscated Files or Information
T1202 Indirect Command Execution
T1036 Masquerading
Credential Access T1110 Brute Force
T1040 Network Sniffing
 Discovery T1082 System Information Discovery
Collection T1005 Data from Local System
Command and Control T1105 Ingress Tool Transfer

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/04/cacti-realtek-and-ibm-aspera-faspex.html

[/emaillocker]
crossmenu