Blue Mockingbird Monero-Mining Campaign Exploits Web Apps
#1
Information 
Quote:The campaign has been dubbed Blue Mockingbird by the analysts at Red Canary that discovered the activity. Research uncovered that the cybercriminal gang is exploiting a deserialization vulnerability, CVE-2019-18935, which can allow remote code execution. The bug is found in the Progress Telerik UI front-end offering for ASP.NET AJAX.
 
AJAX stands for Asynchronous JavaScript and XML; It’s used to add script to a webpage which is executed and processed by the browser. Progress Telerik UI is an overlay for controlling it on ASP.NET implementations.
 
The vulnerability lies specifically in the RadAsyncUpload function, according to the writeup on the bug in the National Vulnerability Database. This is exploitable when the encryption keys are known (via another exploit or other attack), meaning that any campaign relies on a chaining of exploits.
 
In the current attacks, Blue Mockingbird attackers are uncovering unpatched versions of Telerik UI for ASP.NET, deploying the XMRig Monero-mining payload in dynamic-link library (DLL) form on Windows systems, then executing it and establishing persistence using multiple techniques. From there, the infection propagates laterally through the network.

The activity appears to stretch back to December, according to the analysis, and continued through April at least.

Read more: https://threatpost.com/blue-mockingbird-...ng/155581/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes 19.1.6
25.1.3 The  --...Kool — 15:23
AppCheck Anti-Ransomware 3.1.39.3
Version 3.1.39.3 (...harlan4096 — 07:51
Antivirus Removal Tool 2025.01 (v.1)
An updated version...harlan4096 — 07:48
GFYI [Official] IObit Christmas 2024 Bl...
Merry Christmas and ...divinenews — 19:11
GFYI [Official] Ashampoo Christmas 2024...
Merry Christmas and ...dhruv2193 — 16:55

[-]
Birthdays
Today's Birthdays
avatar (38)ixofehym
Upcoming Birthdays
avatar (49)theoldevext
avatar (44)algratCep
avatar (49)Qlaude2Sap
avatar (43)tabthinLem
avatar (50)Josepharelf
avatar (39)kholukrefar
avatar (48)Lauraimike
avatar (50)WilsonWag
avatar (48)StevenPiole
avatar (39)zetssToomy
avatar (46)GornOr
avatar (44)StephenViedy
avatar (49)Jamesmog
avatar (37)opeqyrav
avatar (38)theatidere
avatar (47)denisEquivok
avatar (35)mikebrian01
avatar (37)ivanoFloom
avatar (40)uxegihor

[-]
Online Staff
There are no staff members currently online.

>