Threat Advisory

Russian hackers use Ngrok feature and WinRAR exploit to attack embassies

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

A threat group associated with Russia's intelligence service, SVR. Targeting multiple European nations, including Azerbaijan, Greece, Romania, and Italy, the primary focus was on infiltrating embassy entities. A newly discovered vulnerability in WinRAR, CVE-2023-38831, served as the entry point for APT29's intrusion. The attackers ingeniously used enticing BMW car sale lures to exploit unsuspecting victims, exemplifying the evolving nature of cyber threats and nation-state-sponsored efforts to compromise critical entities.[/subscribe_to_unlock_form]

Summary:

A threat group associated with Russia's intelligence service, SVR. Targeting multiple European nations, including Azerbaijan, Greece, Romania, and Italy, the primary focus was on infiltrating embassy entities. A newly discovered vulnerability in WinRAR, CVE-2023-38831, served as the entry point for APT29's intrusion. The attackers ingeniously used enticing BMW car sale lures to exploit unsuspecting victims, exemplifying the evolving nature of cyber threats and nation-state-sponsored efforts to compromise critical entities.[emaillocker id="1283"]

The APT29 campaign, initiated in targeted diplomatic accounts, with embassies and international organizations falling victim. APT29 utilized phishing emails with BMW car sale themes, embedding the WinRAR vulnerability to execute arbitrary code. The attackers employed Ngrok, a versatile tool, to establish covert communication channels, complicating cybersecurity efforts and evading detection. The CVE-2023-38831 vulnerability in WinRAR was actively exploited between April and October 2023, with Sednit APT also leveraging it in a spearphishing campaign.

The APT29 cyber offensive reveals the geopolitical implications of cyber-espionage, with a focus on gathering intelligence, especially regarding Azerbaijan's activities in Nagorno-Karabakh. The synthesis of old and new techniques, such as the persistent use of the BMW car for sale lure theme and the deployment of the CVE-2023-38831 WinRAR vulnerability, highlights APT29's adaptability. The use of Ngrok for covert communications underscores the determination to remain concealed. The prevalence of similar techniques among Russian hacking groups emphasizes the need for organizations to implement robust cybersecurity practices, stay updated on vulnerabilities, and foster a culture of cybersecurity awareness to defend against complex and persistent threats in the evolving threat landscape.

Recommendations:

  • We strongly recommend you update WinRAR to version 6.24

Threat Profile:

 

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/russian-hackers-use-ngrok-feature-and-winrar-exploit-to-attack-embassies/

[/emaillocker]
crossmenu