SUMMARY
The Cybersecurity and Infrastructure Security Agency (CISA) and the Norwegian National Cyber Security Centre (NCSC-NO) are releasing this joint Cybersecurity Advisory (CSA) in response to active exploitation of CVE-2023-35078 and CVE-2023-35081. Advanced persistent threat (APT) actors exploited CVE-2023-35078 as a zero day from at least April 2023 through July 2023 to gather information from several Norwegian organizations, as well as to gain access to and compromise a Norwegian government agency’s network.
Ivanti released a patch for CVE-2023-35078 on July 23, 2023. Ivanti later determined actors could use CVE-2023-35078 in conjunction with another vulnerability CVE-2023-35081 and released a patch for the second vulnerability on July 28, 2023. NCSC-NO observed possible vulnerability chaining of CVE-2023-35081 and CVE-2023-35078.
CVE-2023-35078 is a critical vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM) (formerly known as MobileIron Core). The vulnerability allows threat actors to access personally identifiable information (PII) and gain the ability to make configuration changes on compromised systems. CVE-2023-35081 enables actors with EPMM administrator privileges to write arbitrary files with the operating system privileges of the EPMM web application server. Threat actors can chain these vulnerabilities to gain initial, privileged access to EPMM systems and execute uploaded files, such as webshells.
Mobile device management (MDM) systems are attractive targets for threat actors because they provide elevated access to thousands of mobile devices, and APT actors have exploited a previous MobileIron vulnerability. Consequently, CISA and NCSC-NO are concerned about the potential for widespread exploitation in government and private sector networks.
This CSA provides indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) obtained by NCSC-NO investigations. The CSA also includes a nuclei template to identify unpatched devices and detection guidance organizations can use to hunt for compromise. CISA and NCSC-NO encourage organizations to hunt for malicious activity using the detection guidance in this CSA. If potential compromise is detected, organizations should apply the incident response recommendations included in this CSA. If no compromise is detected, organizations should still immediately apply patches released by Ivanti.
Download the PDF version of this report:
(XML, 277.43 KB
)
framework, version 13. See the MITRE ATT&CK Tactics and Techniques section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&CK® tactics and techniques. For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s .
Overview
In July 2023, NCSC-NO became aware of APT actors exploiting a zero-day vulnerability in Ivanti Endpoint Manager (EPMM), formerly known as MobileIron Core, to target a Norwegian government network. Ivanti confirmed that the threat actors exploited CVE-2023-35078 and released a patch on July 23, 2023.[]
vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. The vulnerability allows unauthenticated access to specific application programming interface (API) paths. Threat actors with access to these API paths can access PII such as names, phone numbers, and other mobile device details of users on the vulnerable system; make configuration changes to vulnerable systems; push new packages to mobile endpoints; and access Global Positioning System (GPS) data if enabled.
According to Ivanti, CVE-2023-35078 can be chained with a second vulnerability ] CVE-2023-35081 is directory traversal vulnerability []
CISA added CVE-2023-35078 to its ],[] to target infrastructure, and NCSC-NO observed the actors exploiting CVE-2023-35078 to obtain initial access to EPMM devices [].
/mifs/aad/api/v2/authorized/users to list users and administrators [].The APT actors deleted some of their entries in Apache httpd logs [].
The APT actors tunneled traffic []. It is unknown how they tunneled traffic. NCSC-NO observed that the network traffic used the TLS certificate of the internal Exchange server. The APT actors likely installed webshells []:
/owa/auth/logon.aspx/owa/auth/logoff.aspx/owa/auth/OutlookCN.aspx
NCSC-NO also observed mi.war on Ivanti Sentry but do not know how the actors placed it there.
MITRE ATT&CK TACTICS AND TECHNIQUES
See Table 1—Table 7 for all referenced threat actor tactics and techniques in this advisory.
Table 1: APT Actors ATT&CK Techniques for Initial Access
Technique Title | ID | Use |
|---|---|---|
Exploit Public-Facing Application | The APT actors may have exploited CVE-2023-35081 to upload webshells on the EPMM device and run commands. |
Table 3: APT Actors ATT&CK Techniques for Discovery
Technique Title | ID | Use |
|---|---|---|
Account Discovery: Domain Account | The APT actors retrieved LDAP endpoints. |
Table 4: APT Actors ATT&CK Techniques for Persistence
Technique Title | ID | Use |
|---|---|---|
Masquerading: Match Legitimate Name or Location | The APT actors implanted webshells on the compromised infrastructure. |
Table 5: APT Actor ATT&CK Techniques for Defense Evasion
Technique Title | ID | Use |
|---|---|---|
Indicator Removal | APT actors regularly checked EPMM Core audit logs. |
Table 7: APT Actor ATT&CK Techniques for Command and Control
Technique Title | ID | Use |
|---|---|---|
Protocol Tunneling | The actors leveraged compromised SOHO routers to proxy to and compromise infrastructure. The actors tunneled traffic from the internet to at least one Exchange server. | |
Proxy: Internal Proxy |
|
CISA recommends administrators use the following CISA-developed nuclei template to determine vulnerability to CVE-2023-35081:
To get started:
CISA recommends continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&CK techniques identified in this advisory. REFERENCES[1] [3] RESOURCES
ACKNOWLEDGEMENTSIvanti contributed to this joint advisory. NCSC-NO wishes to acknowledge Mnemonic’s contributions. VERSION HISTORYAugust 1, 2023: Initial version. August 2, 2023: Added stix file, updated Acknowledgements section, and added Resources section. APPENDIX: INDICATORS OF COMPROMISENCSC-NO observed the following webshell hash:
NCSC-NO observed the following hash of
NCSC-NO observed the following JA3 hashes used against MobileIron Core:
NCSC-NO observed the following JA3 hashes used against Exchange when tunneling via EPMM Sentry:
NCSC-NO observed the following user agents communicating with Exchange (OWA and EWS):
NCSC-NO observed the following user agents communicating with Exchange webshell:
NCSC-NO observed the following user agents communicating with Exchange Autodiscover:
NCSC-NO observed the following user agents communicating with EWS (/ews/Exchange.asmx):
NCSC-NO observed the following user agent communicating with Exchange (/powershell):
Vollständiger Original-Bericht Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf cisa.gov. Wie bewertest du diesen Beitrag? 1 Klick Feedback Teilen mit Netzwerk & Team: Hat Ihnen dieser Tipp / Anleitung geholfen? Community-Analysen & Experten-Meinungen 0Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog. Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf „ Eigene Analyse verfassen“! Community Pulse: Relevanz-Einschätzung 1 Klick Experten-Votum 🔴 Akute Relevanz 0% 🟡 In Evaluierung 0% 🟢 Keine Auswirkung 0% Spannende Innovation 0% Verwandte Story-Cluster & Quellen (Vektor-KI) Tipp: Mit Pfeiltasten [ ← ] und [ → ] blättern
Ähnliche Beiträge
🔍 Verwandte News
Auch interessante Nachrichten Threat Actors Exploiting Ivanti EPMM VulnerabilitiesThematisch verwandte Begriffe: Threat, Actors, Exploiting, Ivanti · 6 Treffer ⚠️ Malware / Trojaner / Viren Elastic Security Labs Stopping Vulnerable Driver Attacks 🕵️ Sicherheitslücken GBHackers Security | #1 Glob Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter 🕵️ Sicherheitslücken Elastic Security Labs Detecting and responding to Dirty Pipe with Elastic 🕵️ Sicherheitslücken Security Affairs PaperCut Flaws Exploited in Attacks on U.S. and European Schools 🕵️ Sicherheitslücken GBHackers Security | #1 Glob Telerik UI Flaws Let Attackers Chain AES-CBC Padding Oracle to Unauthenticated RCE
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ... 🔖 Gespeicherte Artikel
📂
Keine gespeicherten Artikel vorhanden.
📂 News
⏱️ 3 Min
vor 10 Min
Artikeldaten werden geladen...
tsecurity.de AppOffline-Lesen, Eilmeldungen & 0ms Ladezeit
Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.
Nächster Beitrag
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster:
Security Explorer
Match:
lädt…
Aktivitäten deiner Analystenlädt…
Neues Thema oder Eilmeldung einreichenReiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung. Heiß diskutierte Einreichungen |
SOCIAL SHARE CARD GENERATOR