CVE detail
CVE-2012-0158
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
132 source links · newest first
- 10 Years of DLL Hijacking, and What We Can Do to Prevent 10 MoreCheck Point Research
Introduction DLL Hijacking — a technique for forcing legitimate applications to run malicious code — has been in use for about a decade at least. In this write-up we give a short introduction to the technique of DLL Hijacking, followed by a digest of several dozen documented uses of that technique over the past decade […]
vendorresearch.checkpoint.comSep 25, 2024, 12:57 PM - Old vulnerabilities are still a big problemHelp Net Security
A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →
newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM SentinelOne security researchers have analyzed the operations of a Chinese cyberespionage group that has been actively targeting education, government, and telecommunication organizations in Australia and Southeast Asia since at least 2013.
newswww.securityweek.comJun 10, 2022, 11:37 AM- Previously undocumented Aoqin Dragon APT targets entities in Southeast Asia and AustraliaSecurity Affairs
Researchers spotted a previously undocumented Chinese-speaking APT, tracked as Aoqin Dragon, targeting entities in Southeast Asia and Australia. SentinelOne documented a series of attacks aimed at government, education, and telecom entities in Southeast Asia and Australia carried out by a previously undocumented Chinese-speaking APT tracked as Aoqin Dragon. The APT primary focus on cyberespionage against targets […]
newssecurityaffairs.comJun 9, 2022, 2:52 PM For roughly a decade, a previously unknown advanced persistent threat (APT) actor has been engaging in long-term surveillance operations against academics, activists, journalists, human rights defenders, and law professionals, SentinelOne reports.
newswww.securityweek.comFeb 11, 2022, 4:08 PMTrend Micro released a research urging organizations to focus patching efforts on the vulnerabilities that pose the greatest risk to their organization, even if they are years old. Older exploits for sale more popular with criminals The research found that 22% of exploits for sale in underground forums are more than three years old. “Criminals know that organizations are struggling to prioritize and patch promptly, and our research shows that patch delays are frequently taken … More →
newswww.helpnetsecurity.comJul 15, 2021, 6:00 AM- 14th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 14th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Audi and Volkswagen have experienced data breaches that affected 3.3 million customers. Between August 2019 and May 2021, unsecured data was left exposed on the internet by a mutual vendor. During that […]
vendorresearch.checkpoint.comJun 14, 2021, 3:27 PM The biggest security trend for 2020 has been the increase of COVID-19-related phishing and other attacks targeting remote workers. New York City, for example, has gone from having to protect 80,000 endpoints to around 750,000 endpoints in its threat management since work-from-home edicts took place. As noted in a recent Check Point Software Technologies mid-year […]
newswww.csoonline.comSep 9, 2020, 10:00 AMThe typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.
vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PMFor years, a China-linked threat actor named Cycldek has been exfiltrating data from air-gapped systems using a previously unreported, custom USB malware family, Kaspersky reports.
newswww.securityweek.comJun 4, 2020, 3:28 PMIn addition to protecting the desktop, you should also pay close attention to the Office suite–in particular, Microsoft’s Object Linking and Embedding (OLE) platform. OLE allows you to make linked connections between applications and other documents, but it also provides a toehold for attackers to gain access into our systems. As a recently National Cyber […]
newswww.csoonline.comJun 3, 2020, 10:00 AMSeveral Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.
newswww.securityweek.comMay 13, 2020, 4:43 PM- Have you patched these top 10 routinely exploited vulnerabilities?Help Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →
newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM We identified 300+ COVID-19 themed malware samples that communicated with 20 unique IP addresses and domain IOCs.
vendorunit42.paloaltonetworks.comMay 11, 2020, 2:54 PM- Crooks target Healthcare facilities involved in Coronavirus containment with RansomwareSecurity Affairs
PaloAlto Networks experts warn of malicious Coronavirus themed phishing campaigns targeting government and medical organizations. Experts from Paloalto Unit 42 published a report that analyzes the cross-section between the various types of Coronavirus-themed attacks aimed at organizations in different industries. Recently organizations in healthcare, research, and government facilities have been hit by Coronavirus-themed attacks that […]
newssecurityaffairs.comApr 14, 2020, 3:25 PM New research shows COVID-19 themed phishing campaigns are targeting healthcare organizations and medical research facilities around the world.
vendorunit42.paloaltonetworks.comApr 14, 2020, 10:00 AM- LimeRAT malware delivered using 8-year-old VelvetSweatshop trickSecurity Affairs
Researchers spotted a campaign using Excel files to spread LimeRAT malware using the 8-year-old and well-known VelvetSweatshop bug. Researchers at the Mimecast Threat Center spotted a new campaign using Excel files to spread LimeRAT malware using the 8-year-old VelvetSweatshop bug. LimeRAT is a powerful Remote Administration Tool publicly available as an open-source project on Github, it […]
newssecurityaffairs.comApr 1, 2020, 8:00 AM Threat actors are taking advantage of COVID-19 with new cyber threats so we've outlined how to protect yourself and your organization.
vendorunit42.paloaltonetworks.comMar 24, 2020, 1:00 PM- Which vulnerabilities were most exploited by cybercriminals in 2019?Help Net Security
Which ten software vulnerabilities should you patch as soon as possible (if you haven’t already)? Table of top exploited CVEs between 2016 and 2019 (repeats are noted by color) Recorded Future researchers have analyzed code repositories, underground forum postings, dark web sites, closed source reports and data sets comprising of submissions to popular malware repositories to compile a list of the ten most exploited vulnerabilities by cybercriminals in 2019. The list The list is comprised … More →
newswww.helpnetsecurity.comFeb 6, 2020, 6:30 AM - The evolutions of APT28 attacksSecurity Affairs
Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]
newssecurityaffairs.comDec 5, 2019, 6:41 AM For three years, Unit 42 has tracked a set of cyber espionage attack campaigns across Asia, which used a mix of publicly available and custom malware. Unit 42 created the moniker “PKPLUG” for the threat actor group, or groups, behind these and other documented attacks referenced later in this report. We say group or groups as our current visibility doesn’t allow us to determine with high confidence if this is the work of one group, or more than one group which uses the same tools and has the same tasking. The name comes from the tactic of delivering PlugX malware inside ZIP archive files as part of a DLL side-loading package. The ZIP file format contains the ASCII magic-bytes “PK” in its header, hence PKPLUG.
vendorunit42.paloaltonetworks.comOct 3, 2019, 1:00 PMExperts at Trend Micro discovered a new variant of the Asruex Trojan that exploits old Microsoft Office and Adobe vulnerabilities to infect systems. Malware researchers at Trend Micro discovered a new variant of the Asruex Trojan that exploits old Microsoft Office and Adobe vulnerabilities to infect Windows and Mac systems. Asruex first appeared in the […]
newssecurityaffairs.comAug 23, 2019, 5:56 PMA recently observed variant of the Asruex backdoor acts as an infector by targeting old vulnerabilities in Microsoft Office and Adobe Reader and Acrobat 9.x, Trend Micro reports.
newswww.securityweek.comAug 23, 2019, 5:23 PMA cyber-espionage group, tracked as APT40, apparently linked to the Chinese government is focused on targeting countries important to the country’s Belt and Road Initiative. The cyber-espionage group tracked as APT40 (aka TEMP.Periscope, TEMP.Jumper, and Leviathan), apparently linked to the Chinese government, is focused on targeting countries important to the country’s Belt and Road Initiative […]
newssecurityaffairs.comMar 6, 2019, 7:59 AMAPT40 Hackers Appear to be Supporting China’s Belt and Road Initiative
newswww.securityweek.comMar 5, 2019, 1:19 PMA previously undisclosed threat actor is targeting nuclear-armed government and military in Pakistan as part of a new, unusually complex espionage campaign, Cylance security researchers warn.
newswww.securityweek.comNov 13, 2018, 4:24 PMResearchers from security firm CrowdStrike have observed a new campaign associated with the GOBLIN PANDA APT group. Experts from security firm CrowdStrike have uncovered a new campaign associated with the GOBLIN PANDA APT group. The group also knows as Cycldek was first spotted in September 2013, it was mainly targeting entities in Southeast Asia using different malware variants mainly PlugX and […]
newssecurityaffairs.comSep 5, 2018, 3:38 PM- GOBLIN PANDA Targets Vietnam AgainSecurityWeek
CrowdStrike security researchers have observed renewed activity associated with GOBLIN PANDA, a threat actor mainly targeting entities in Southeast Asia.
newswww.securityweek.comSep 5, 2018, 2:18 AM If the infamous bank robber, Willie Sutton , were alive today and honed his cyber skills, he might turn his attention to corporate espionage. Why? Because, as he once said about banks, “that’s where the money is.”
newswww.securityweek.comFeb 1, 2018, 12:42 PM- Threat Actors Quickly Adopt Effective ExploitsSecurityWeek
Cybercriminals and nation state groups were quick to adopt the most effective exploits last year, a new AlienVault report reveals.
newswww.securityweek.comJan 17, 2018, 3:34 PM Unit 42 tracks Subaat: a small phishing campaign targeting government organizations.
vendorunit42.paloaltonetworks.comOct 27, 2017, 2:00 AM- BadPatchUnit42
Unit 42 examines the BadPatch campaign consisting of 4 types of malware and new attack methods.
vendorunit42.paloaltonetworks.comOct 20, 2017, 2:00 AM Researchers at Trend Micro and Cisco’s Talos have identified a new wave of phishing attacks leveraging CVE-2017-0199, a previously patched remote code execution vulnerability in the OLE (Windows Object Linking and Embedding) interface of Microsoft Office. These latest attacks have paired the vulnerability with others in an attempt to bypass warning messages, but the results […]
newswww.csoonline.comAug 15, 2017, 3:00 PMResearchers at Cisco Talos have come across an attack that combines two Microsoft Office exploits, one old and one new, likely in an effort to avoid detection.
newswww.securityweek.comAug 15, 2017, 8:27 AMA report published by Kaspersky Lab on Thursday shows that the number of attacks involving exploits increased significantly in 2016 compared to the previous year, but the number of attacked users actually dropped.
newswww.securityweek.comApr 21, 2017, 1:47 PM- AKBuilder: A builder for exploit-laden Word documentsHelp Net Security
One doesn’t have to be a great coder to become a successful cybercriminal, as underground markets are filled with offerings that automate one or another step of an attack chain. Take for example the AKBuilder, a builder for Word documents that carry exploits for several vulnerabilities and a malicious, encrypted payload. The evolution of AKBuilder According to SophosLabs principal researcher Gábor Szappanos, two versions of the builder have, at one time or another, found their … More →
newswww.helpnetsecurity.comFeb 8, 2017, 6:10 PM According to the firm ProofPoint, Chinese state-sponsored actors continues to spy on military and aerospace organizations in Russia and Belarus. Chinese state-sponsored actors are spying on military and aerospace interests in Russia and Belarus. According to the experts from Proofpoint, the attacks began in the summer of 2016, the Chinese hackers launched a spear-phishing campaign leveraging […]
newssecurityaffairs.comFeb 3, 2017, 6:37 PMTaiwan has been a regular target of cyber espionage threat actors for a number of years. Reasons for Taiwan being targeted range from being one of the sovereign states of the disputed South China Sea region to its emerging economy and growth with Taiwan being one of the most innovative countries in the High-Tech industry
vendorunit42.paloaltonetworks.comNov 22, 2016, 1:30 AM- Espionage group uses cybersecurity conference invite as a lureHelp Net Security
A cyber espionage group that has been targeting organizations in Southeast Asia for years is misusing a legitimate conference invite as a phishing lure to trigger the download of backdoor malware. The APT in question is Lotus Blossom, and the security conference is Palo Alto Networks’ CyberSecurity Summit that is scheduled to take place in Jakarta, Indonesia, on November 3. About Lotus Blossom Lotus Blossom is a group that has been operating at least since … More →
newswww.helpnetsecurity.comOct 31, 2016, 6:59 PM - Lotus Blossom Chinese cyberspies leverage on fake Conference Invites in the last campaignSecurity Affairs
The Chinese APT Lotus Blossom is trying to lure victims with fake invitations to Palo Alto Networks’ upcoming Cybersecurity Summit. The Chinese APT Lotus Blossom, also known as Elise and Esile, is behind a new cyber espionage campaign that is trying to lure victims with fake invitations to Palo Alto Networks’ upcoming Cybersecurity Summit. With this […]
newssecurityaffairs.comOct 31, 2016, 9:50 AM A China-linked cyber espionage group known as Lotus Blossom, Elise and Esile has used fake invitations to Palo Alto Networks’ upcoming Cybersecurity Summit to trick users into installing a piece of malware on their systems.
newswww.securityweek.comOct 31, 2016, 8:47 AMActors related to the Operation Lotus Blossom campaign continue their attack campaigns in the Asia Pacific region. It appears that these threat actors have begun using Palo Alto Networks upcoming Cyber Security Summit hosted on November 3, 2016 in Jakarta, Indonesia as a lure to compromise targeted individuals. The payload installed in attacks using this
vendorunit42.paloaltonetworks.comOct 28, 2016, 6:11 AMA cyber-espionage campaign operating for more than eight months has been linked to an Indian Advanced Persistent Threat (APT) group known as Patchwork, which might be the same attackers behind Operation Hangover, Forcepoint researchers warn.
newswww.securityweek.comAug 12, 2016, 2:06 PMResearchers have come across a document exploit generator that has been used over the past few years by several threat actors to deliver malware in cyber espionage campaigns.
newswww.securityweek.comAug 12, 2016, 12:46 PMThreat actors tend to reuse certain tools, a trend we observed during recent Unit 42 research published on MNKit. In this post, we will discuss a fresh toolkit, which on the surface, appeared similar to MNKit, but functionally was found to be quite different. This toolkit, which we named “HOMEKit”, is similar to MNKit in
vendorunit42.paloaltonetworks.comAug 12, 2016, 2:00 AMAdobe’s Flash Player might be the most targeted product when criminal exploit kits are involved, but Microsoft products such as Office, Windows and Internet Explorer take center stage when Russian advanced persistent threat (APT) groups are involved.
newswww.securityweek.comAug 5, 2016, 2:10 PMSecurity experts at Symantec revealed that the Patchwork hacker crew is now expanding espionage activities on companies in a wide range of industries. Security experts from Symantec have spotted a new cyber espionage campaign managed by the Patchwork group targeting organizations in multiple industries. The hacker crew is a well-known group, its activities are focused on diplomatic […]
newssecurityaffairs.comJul 27, 2016, 2:34 PMA cyberespionage group known for targeting diplomatic and government institutions has branched out into many other industries, including aviation, broadcasting, and finance, researchers warn. Known as Patchwork, or Dropping Elephant, the group stands out not only through its use of simple scripts and ready-made attack tools, but also through its interest in Chinese foreign relations. […]
newswww.csoonline.comJul 26, 2016, 5:30 PM- Patchwork Threat Actor Expands Target ListSecurityWeek
The India-linked threat actor known as Patchwork or Dropping Elephant is targeting more than just government-associated organizations, Symantec researchers say.
newswww.securityweek.comJul 26, 2016, 11:26 AM Most attacks that are targeting vulnerabilities in Microsoft Office to compromise victims’ systems are currently leveraging two security issues that were discovered last year, SophosLabs researchers warn.
newswww.securityweek.comJul 19, 2016, 8:32 PMKaspersky Lab researchers investigated a threat actor that was undertaking aggressive cyber espionage activity in the Asian region, targeting multiple diplomatic and government entities with a particular focus on China and its international affairs. This group, named Dropping Elephant (also known as “Chinastrats”), used their unsophisticated tools to attack some high profile Western targets as well. In February 2016, following an alert from a partner, Kaspersky Lab’s Global Research and Analysis Team began its investigation … More →
newswww.helpnetsecurity.comJul 11, 2016, 1:15 PM- NetTraveler APT still targets European and Russian interestsSecurity Affairs
Security experts from ProofPoint have spotted a new campaign operated by the APT Group NetTraveler that is targeting Russian and European organizations. NetTraveler is an ATP group first spotted by Kaspersky in 2013, when researchers discovered an espionage activity against over 350 high profile victims from 40 countries. The name of the operation derives from the malicious […]
newssecurityaffairs.comJul 9, 2016, 10:23 AM Kaspersky Lab is monitoring a new cyber espionage group that it calls Dropping Elephant. A surprising — and somewhat worrying — feature is that this group achieves a high success rate with only low tech attacks. In fact, it has been so successful that it seems to have expanded it group membership from (probably) just India to include new members on the Pacific West Coast of America.
newswww.securityweek.comJul 8, 2016, 4:24 PMAPT Group Uses NetTraveler to Spy on Russian, European Victims
newswww.securityweek.comJul 8, 2016, 12:01 PM- Old Office Flaw Still Exploited in Many AttacksSecurityWeek
An Office vulnerability patched by Microsoft more than four years ago continues to be exploited in many attacks where malicious actors attempt to deliver malware using specially crafted documents.
newswww.securityweek.comJul 5, 2016, 12:57 PM An analysis of malicious documents created with a Microsoft Office exploit generator has allowed researchers to find connections between several malware families known to be used by different threat groups supposedly located in China.
newswww.securityweek.comJul 1, 2016, 9:19 AMUnit 42 recently identified a variant of MNKit-weaponized documents being used to deliver LURK0 Gh0st, NetTraveler, and Saker payloads. The documents were delivered to targets involved with universities, NGOs, and political/human rights groups concerning Islam and South Asia. Reuse of this MNKit variant, sender email addresses, email subject lines, attachment filenames, command and control domains,
vendorunit42.paloaltonetworks.comJun 30, 2016, 8:30 PM- Pakistan APT Group Targets Indian GovernmentSecurityWeek
An advanced persistent threat (APT) group believed to be based in Pakistan has been observed targeting government and military personnel in India using spear phishing emails and watering hole attacks.
newswww.securityweek.comJun 3, 2016, 9:37 AM Malicious actors have abused PowerShell and Google Docs to deliver a Trojan known as Laziok, FireEye reported on Thursday.
newswww.securityweek.comApr 22, 2016, 1:38 PMExperts analyzed a dozen attacks that leveraged on malicious RTF documents created using the same Four Element Sword builder. Security experts at Arbor Networks’ Security Engineering and Response Team (ASERT) have spotted a tool used in advanced persistent threat (APT) attacks against organizations in East Asia. The researchers have analyzed a dozen attacks that leveraged on malicious Rich […]
newssecurityaffairs.comApr 19, 2016, 12:35 PMResearchers at Arbor Networks’ Security Engineering and Response Team (ASERT) have identified what they believe to be a tool used in advanced persistent threat (APT) attacks aimed at various entities in East Asia.
newswww.securityweek.comApr 18, 2016, 3:05 PMBe the first to receive the latest news, cyber threat intelligence and research from Unit 42. Subscribe Now. Unit 42 is currently researching an attack campaign that targets government and military personnel of India. This attack appears to overlap with the Operation Transparent Tribe and Operation C-Major campaigns that targeted Indian embassies in Saudi Arabia
vendorunit42.paloaltonetworks.comMar 25, 2016, 8:00 AMUnit 42 has collected multiple spear phishing emails, weaponized document files, and payloads that targeted various offices of the Mongolian government during the time period of August 2015 and February 2016. The phishing emails and document files leveraged a variety of geopolitically sensitive subject matters as attractive lures, such as events in Beijing, the Dalai
vendorunit42.paloaltonetworks.comMar 14, 2016, 11:00 AMProofPoint uncovered a new cyber espionage campaign dubbed Operation Transparent Tribe targeting Indian diplomatic and military entities. A new cyber espionage campaign dubbed Operation Transparent Tribe is targeting diplomats and military personnel in India. The researchers at Proofpoint who have uncovered the hacking campaign confirmed that threat actors used a number of hacking techniques to hit the […]
newssecurityaffairs.comMar 6, 2016, 3:41 PMExecutive Summary Over the past seven months, Unit 42 has been investigating a series of attacks we attribute to a group we have code named “Scarlet Mimic.” The attacks began over four years ago and their targeting pattern suggests that this adversary’s primary mission is to gather information about minority rights activists. We do not
vendorunit42.paloaltonetworks.comJan 24, 2016, 3:00 PMUnit 42 recently identified a targeted attack against an individual working for the Foreign Ministry of Uzbekistan in China. A spear-phishing email was sent to a diplomat of the Embassy of Uzbekistan who is likely based in Beijing, China. In this report, we’ll review how the actors attempted to exploit CVE-2012-0158 to install the NetTraveler Trojan.
vendorunit42.paloaltonetworks.comJan 21, 2016, 6:45 AMThe holiday season is a time for friends and family, as well as for heightened levels of consumer shopping. It’s also a time of year when threat actors get especially opportunistic, and the 2015 holiday season was no different. Let’s take a closer look at recent holiday season-themed attacks. Happy Festivus! Unit 42 examined the
vendorunit42.paloaltonetworks.comJan 13, 2016, 1:00 PMSecurity researchers from ESET uncovered the Roaming Tiger hacking campaign, bad actors in the wild are targeting Russian organizations. Roaming Tiger is the name of a cyber espionage campaign targeting high profile organizations in Russia and former Soviet Union countries, including Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Ukraine, and Uzbekistan. The Roaming Tiger campaign was discovered by experts at […]
newssecurityaffairs.comDec 24, 2015, 6:13 AMA threat group known for targeting Russian organizations has recently started using a new tool in its cyber espionage operations, Palo Alto Networks reported on Tuesday.
newswww.securityweek.comDec 23, 2015, 2:40 PMIn late 2014, ESET presented an attack campaign that had been observed over a period of time targeting Russia and other Russian speaking nations, dubbed “Roaming Tiger”. The attack was found to heavily rely on RTF exploits and at the time, thought to make use of the PlugX malware family. ESET did not attribute the
vendorunit42.paloaltonetworks.comDec 22, 2015, 3:00 PM- Phishing campaign leveraging on Dropbox targets Hong Kong mediaSecurity Affairs
Security experts at FireEye have uncovered an ongoing phishing campaign leveraging Dropbox account linked to “admin@338” as Command and Control platform. Experts at FireEye have discovered an ongoing phishing campaign using a Dropbox account linked to “admin@338” as the delivery platform. The account ” admin@338 ” was also used in the past to deliver malware, but […]
newssecurityaffairs.comDec 1, 2015, 11:16 AM - Naikon APT Group backed by the Chinese PLA Unit 78020Security Affairs
According to a new report the popular Naikon APT group is actually backed by China’s PLA Unit 78020, a firm traced it through online activity. Ge Xing, also known as “GreenSky27,” is the name of an alleged member of the People’s Liberation Army unit 78020, a group of Chinese state-sponsored hackers. The man was identified […]
newssecurityaffairs.comSep 25, 2015, 7:10 AM On May 6 and May 11, 2015, Unit 42 observed two targeted attacks, the first against the U.S. government and the second on a European media company. Threat actors delivered the same document via spear-phishing emails to both organizations. The actors weaponized the delivery document to install a variant of the ‘9002’ Trojan called ‘3102’
vendorunit42.paloaltonetworks.comSep 23, 2015, 12:00 PMResearchers at Palo Alto Networks have identified a cyber-espionage operation targeting government and military organizations in Southeast Asia.
newswww.securityweek.comJun 16, 2015, 4:33 PMOn May 12, 2015, Unit 42 observed an apparent watering hole attack, also known as a strategic website compromise (SWC), involving the President of Myanmar's website. Visiting the main page hosted at "www.president-office.gov[.]mm" triggered the malicious content, as the threat actors injected an inline frame (IFRAME) into a JavaScript file used by Drupal for the
vendorunit42.paloaltonetworks.comJun 11, 2015, 4:00 PMIn recent weeks, Unit 42 has been analyzing delivery documents used in spear-phishing attacks that drop a custom downloader used in cyber espionage attacks. This specific downloader, Cmstar, is associated with the Lurid downloader also known as ‘Enfal’. Cmstar was named for the log message ‘CM**’ used by the downloader. Unit 42 is aware of
vendorunit42.paloaltonetworks.comMay 18, 2015, 12:01 PMA three-year-old cyber operation is using a mix of social engineering, Microsoft Windows vulnerabilities and basic stenography to target government, military and industry officials in Taiwan and the Philippines, according to Trend Micro.
newswww.securityweek.comMay 14, 2015, 6:07 PMCybercriminals are increasingly copying cyberespionage groups in using targeted attacks against their victims instead of large-scale, indiscriminate infection campaigns. This change in tactics has been observed among those who launch attacks, as well as those who create and sell attack tools on the underground market. A recent example of such behavior was seen in a […]
newswww.csoonline.comMay 5, 2015, 1:05 PMSummary While threat actors using the PlugX Trojan typically leverage legitimate executables to load their malicious DLLs through a technique called DLL side-loading, Unit 42 has observed a new executable in use for this purpose. Threat actors are now using this previously unseen executable, created by Samsung, to load variants of the PlugX Trojan. Using
vendorunit42.paloaltonetworks.comMay 1, 2015, 10:29 AMResearchers at Proofpoint recently discovered a Phishing campaign that originated form select job postings on CareerBuilder. Taking advantage of the notification system the job portal uses, the attacker uploaded malicious attachments instead of résumés, which in turn forced CareerBuilder to act as a delivery vehicle for Phishing emails. The scam is both simple and complex. […]
newswww.csoonline.comApr 30, 2015, 11:00 AMAs user habits evolve, so do the tactics of attackers . It should come as little surprise then that as enterprises upgraded to newer versions of Windows in 2014, the amount of 64-bit Windows malware being used in attack campaigns increased as well.
newswww.securityweek.comApr 14, 2015, 10:15 PMESET has discovered a new hacking campaign dubbed Operation Buhtrap based on a family of spyware targeting vulnerabilities within the Russian Windows System. Late in 2014 analysts at ESET uncovered CVE-2012-0158, a buffer overflow vulnerability in the ListView / TreeView ActiveX controls in the MSCOMCTL.OCX library. This particular malicious code can be activated by a […]
newssecurityaffairs.comApr 10, 2015, 7:31 AM- Energy companies infected by newly Laziok trojan malwareSecurity Affairs
Symantec has discovered a cyber espionage campaign targeting energy companies around the world by infecting them with a new malware dubbed Laziok trojan. Security experts at Symantec have uncovered a new cyber espionage campaign that targeted the energy industry. The threat actors behind the campaign used uses a custom-developed malware dubbed Laziok trojan to exfiltrate sensitive data from […]
newssecurityaffairs.comApr 1, 2015, 9:27 AM Researchers at Symantec have observed a sophisticated, multi-stage attack campaign focused on energy companies in the Middle East.
newswww.securityweek.comMar 31, 2015, 6:12 PM- Middle-Eastern energy firms targeted with reconnaissance TrojanHelp Net Security
An email spam campaign targeting companies in the petroleum, gas and helium industries has been spotted by Symantec researchers. Most of them are in the so-called Middle East (UAE, Saudi Arabia, Qatar, Kuwait and Oman), but UK, US, African, Asian, and Latin American companies have also been targeted. “The initial infection vector involves the use of spam emails coming from the moneytrans[.]eu domain, which acts as an open relay Simple Mail Transfer Protocol (SMTP) server. … More →
newswww.helpnetsecurity.comMar 31, 2015, 6:02 AM The minds behind PlugX have added a new twist to the malware to make it stealthier.
newswww.securityweek.comMar 2, 2015, 5:08 PMResearchers at Symantec have identified a group of attackers targeting Russian-speaking individuals since at least January 2012.
newswww.securityweek.comJan 22, 2015, 7:08 PMNearly two years after the Red October cyber espionage operation was exposed, researchers have spotted a new advanced persistent threat (APT) campaign that appears to represent the return of the Red October group.
newswww.securityweek.comDec 11, 2014, 6:26 PM- Are CloudAtlas and RedOctober campaigns managed by same APT?Security Affairs
Kaspersky Lab suspects that the bad actor who is managing a new campaign dubbed CloudAtlas is the same that run the Operation Red October two years ago. Red October is the name of a cyber espionage campaign discovered by security experts at Kaspersky Lab in late 2012 and disclosed in January 2013. The threat actors behind the […]
newssecurityaffairs.comDec 11, 2014, 7:41 AM - Gh0st RAT used in targeted attacks against Tibetan activistsSecurity Affairs
APT actors trying to use the G20 2014 summit as a lure to compromise Tibetan nongovernmental organizations (NGOs) with Gh0st RAT. Security experts at ESET uncovered a new series of cyber attacks that targeted Tibetan nongovernmental organizations (NGOs) concurrently with the G20 2014 summit in Brisbane, Australia. The experts discovered that APTs behind the attacks used a strain of the Gh0st RAT characterized […]
newssecurityaffairs.comNov 19, 2014, 12:05 PM The notorious remote access Trojan (RAT) known as PlugX (Korplug) has been used by a threat group to target users in Afghanistan, Russia, Tajikistan, Kazakhstan and Kyrgyzstan. PlugX has been observed in numerous targeted attacks since 2012, particularly in campaigns launched by Chinese advanced persistent threat (APT) actors.
newswww.securityweek.comNov 13, 2014, 4:19 PMSometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities, Adobe issued updates for Flash and ColdFusion, and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that
vendorunit42.paloaltonetworks.comOct 15, 2014, 4:45 PMIt was 2010 when the Stuxnet malware first appeared in the public consciousness. Though the years have passed however, there is no shortage of machines still vulnerable to attacks on one of the vulnerabilities the malware exploited as it trotted across the globe.
newswww.securityweek.comAug 18, 2014, 11:28 PMResearchers at FireEye have analyzed the operations of the advanced persistent threat (APT) group dubbed “Pitty Tiger,” and determined that it might have been active since as far back as 2008.
newswww.securityweek.comAug 1, 2014, 12:28 PM- Trend Micro Analyzes Targeted Attack TrendsSecurityWeek
Zero-day vulnerabilities garner well-deserved attention, but often it is older vulnerabilities that are at the center of targeted attacks.
newswww.securityweek.comMay 20, 2014, 7:22 PM Security experts at McAfee Labs have discovered a new cyber espionage based on the malware digitally signed with stolel certificates. A recent research of McAfee Labs has identified a series of spear phishing attacks against non governmental entities and activists, the offensives which interested mainly organizations in China were conducted using malicious code signed with stolen digital […]
newssecurityaffairs.comMay 7, 2014, 6:46 AMNBC News seems to think that “regular” users visiting the Sochi Winter Olympics go out of their way to ignore software updates, disregard security patches, and actively engage in unsafe online behavior. Some users may be slower to patch, or to allow software to update, but they would first have had to actively choose different […]
newswww.csoonline.comFeb 9, 2014, 7:58 PMA malware campaign targeting online banking customers in Eastern Europe uses a mix of the old and the new as it swipes data from unsuspecting victims.
newswww.securityweek.comOct 21, 2013, 5:39 PMAn Advanced Persistent Threat (APT) called NetTraveler has been spotted making mischief again, but it appears to have learned a few new tricks since it was last spotted in June. The malware is now attacking a known Java vulnerability, CVE-2013-2465, and added water holing to its propagation strategy, according to new research from Kaspersky Lab. […]
newswww.csoonline.comSep 4, 2013, 3:00 PM- NetTraveler APT hackers still active improved their attacksSecurity Affairs
Experts at Kaspersky firm provided evidences that the hackers behind cyber espionage campaign NetTraveler are still active and improved their attack methods. Last June Kaspersky firm uncovered a new global cyber espionage campaign dubbed NetTraveler. Kaspersky’s team discovered that NetTraveler targeted over 350 high profile victims from 40 countries. The name of the operation derives from […]
newssecurityaffairs.comSep 4, 2013, 6:51 AM Researchers at Kaspersky Lab revealed that they have discovered a new attack vector for NetTraveler – an attack campaign that has infected hundreds of victims across more than 40 countries.
newswww.securityweek.comSep 3, 2013, 2:53 PM- The Malware Archives: MS Office FilesMalwarebytes Labs
Recently, I posted a blog about analyzing PDF files. In that post, we covered some basics of the PDF format and…
newswww.malwarebytes.comAug 18, 2013, 5:00 PM Trend Micro uncovered targeted attack against European and Asian government agencies to steal login credentials from IE and Microsoft Outlook products. A new targeted attack has been uncovered by Trend Micro security experts, the hackers hit European government agencies trying to steal login credentials from Internet Explorer (IE) and Microsoft Outlook. The attackers trying to […]
newssecurityaffairs.comJul 17, 2013, 9:59 AMTrend Micro says it detected a targeted attack that sent malware-laden emails to representatives of 16 European countries and some Asian governments. The bogus emails purported to come from China’s defense ministry and contained a malicious attachment that exploited a now-patched vulnerability in Microsoft Office versions 2003 to 2010, wrote Jonathan Leopando, a technical communications specialist […]
newswww.csoonline.comJul 16, 2013, 3:00 PMSecurity researchers from Trend Micro have shared details on an attack targeting personnel at government agencies in Europe and Asia, the latest of many attacks that have exploited CVE-2012-0158, a vulnerability in Microsoft Office.
newswww.securityweek.comJul 15, 2013, 9:48 PMResearchers at Symantec spotted a Java remote access tool being used as part of a campaign targeting government agencies by sending phishing emails with malicious attachments. The phishing emails are using recent news coverage about the NSA PRISM surveillance program as a lure. So far, the majority of the targets are located in the United States.
newswww.securityweek.comJul 8, 2013, 11:11 PM- Google Docs Abused to Protect Malicious TrafficSecurityWeek
Researchers at FireEye have spotted a malware campaign using Google Docs to redirect victims and evade callback detection mechanisms. Connecting the malicious server via Google Docs, offers the malicious communication the protection provided by the legitimate SSL offered by Google, explained FireEye researcher Chong Rong Hwa.
newswww.securityweek.comJun 20, 2013, 8:41 PM - RARSTONE, TrendMicro revealed Naikon cyberespionage campaignSecurity Affairs
RARSTONE is the name of the RAT (REMOTE ACCESS TOOL) used in a cyber espionage campaign dubbed “Naikon” uncovered by security experts at TrendMicro. Security experts at TrendMicro revealed to have detected the RARSTONE RAT studying targeted attacks across Asia (e.g. India, Malaysia, Singapore, and Vietnam) conducted against various companies belonging to different sectors such […]
newssecurityaffairs.comJun 16, 2013, 9:09 AM Trend Micro researchers have found evidence of the Rarstone remote access tool (RAT) in targeted attacks against various organizations in the telecommunications and energy industries in Asia.
newswww.securityweek.comJun 13, 2013, 4:32 PMA spate of attacks targeting users in Vietnam and India are infecting users with a backdoor designed to steal massive amounts of information. According to researchers with Rapid7, the targeted attacks are using a malicious Microsoft Word document that exploits vulnerabilities in Microsoft Office to compromise computers with malware known as KeyBoy.
newswww.securityweek.comJun 10, 2013, 5:53 PMUsers from Vietnam, India, China, Taiwan and possibly other countries, were targeted as part of an attack campaign that uses Microsoft Word documents rigged with exploits in order to install a backdoor program that allows attackers to steal information, according to researchers from security firm Rapid7. The targeted attacks used specifically crafted Word documents as […]
newswww.csoonline.comJun 10, 2013, 3:00 PMKaspersky Lab experts published a new research report about NetTraveler, which is a family of malicious programs used by APT actors to successfully compromise more than 350 high-profile victims in 40 countries. The NetTraveler group has infected victims across multiple establishments in both the public and private sector including government institutions, embassies, the oil and gas industry, research centers, military contractors and activists. According to Kaspersky Lab’s report, this threat actor has been active since … More →
newswww.helpnetsecurity.comJun 5, 2013, 6:11 AM- NetTraveler, new global cyber espionage campaign from KasperskySecurity Affairs
NetTraveler cyber espionage campaign, revealed by Kaspersky’s team, targeted over 350 high profile victims from 40 countries. NetTraveler, this is the name of a new global cyber espionage campaign revealed by researchers at Kaspersky, the team of experts discovered an espionage activity against over 350 high profile victims from 40 countries. The name of the operation derives […]
newssecurityaffairs.comJun 5, 2013, 3:00 AM A cyber-espionage campaign discovered by Kaspersky Lab has hit more than 350 businesses and government agencies throughout the world. According to Kaspersky Lab, the main tool used in the attacks is known as ‘NetTraveler,’ named after an internal string present in early versions of the malware. The group behind the attack is believed to have been active as early as 2004 – though the highest volume of activity occurred during the past three years.
newswww.securityweek.comJun 4, 2013, 4:12 PMAn ongoing cyberespionage campaign compromised over 350 high-profile victims from more than 40 countries over the past eight years, including political activists, research centers, governmental institutions, embassies, military contractors and private companies from various industries. Researchers from antivirus vendor Kaspersky Lab named the campaign NetTraveler, after a string found in the main data stealing malware […]
newswww.csoonline.comJun 4, 2013, 3:00 PMNinety-one percent of targeted attacks start with spear- phishing email, according to a newly released research by Trend Micro. Spear-phishing emails contain a malicious attachment exploiting a Microsoft Office vulnerability (CVE-2012-0158). These emails are part of the operations of an emerging and active targeted threat called Safe campaign, the operations of which are documented in […]
newswww.csoonline.comMay 28, 2013, 3:00 PM- Attack on Telenor was part of large cyberespionage operation with Indian origins, report saysCSO Online
A recent intrusion on the computer network of Norwegian telecommunications company Telenor was the result of a large cyberespionage operation of Indian origin that for the past few years has targeted business, government and political organizations from different countries, according to researchers from security firm Norman Shark. Researchers from Norman analyzed the malware samples used […]
newswww.csoonline.comMay 20, 2013, 3:00 PM Researchers at Trend Micro shined a light on a cyber-espionage campaign that infected nearly 12,000 unique IP addresses spread across more than 100 countries.
newswww.securityweek.comMay 20, 2013, 1:06 PM- Cyber espionage campaign uses professionally-made malwareHelp Net Security
Trend Micro researchers have discovered a new, massive cyber espionage campaign that has been hitting as many as 71 victims each day, including government ministries, technology companies, academic research institutions, nongovernmental organizations and media outlets. Dubbed “Safe,” the campaign has first been spotted in October 2012 and has so far resulted in nearly 12,000 unique IP addresses spread over more than 100 countries to be connected to two sets of command-and-control (C&C) infrastructures, but the … More →
newswww.helpnetsecurity.comMay 20, 2013, 9:06 AM - Targeted data stealing attacks using fake attachmentsHelp Net Security
ESET has uncovered and analyzed a targeted campaign that tries to steal sensitive information from different organizations, particularly in Pakistan (with limited spread around the world). During the course of ESET investigations several leads were discovered that indicate the threat has its origin in India and has been going on for at least two years. This targeted attack used a code signing certificate issued to a seemingly legitimate company to sign malicious binaries and improve … More →
newswww.helpnetsecurity.comMay 17, 2013, 6:16 AM Researchers at ESET have discovered a targeted cyber espionage campaign in Pakistan, which is attempting to compromise sensitive information from various organizations. While limited, traces of the same attack have also been discovered in other parts of the globe.
newswww.securityweek.comMay 17, 2013, 5:46 AM- Red October, RBN and too many questions still unresolvedSecurity Affairs
The recently discovered cyber espionage campaign “Red October” has shocked world wide security community, the principal questions raised are: Who is behind the attacks? How is possible that for so long time the campaign went undetected? Which is the role of AV company in these operations? To try to understand who is behind the attacks […]
newssecurityaffairs.comJan 17, 2013, 8:15 AM On Monday, Kaspersky Lab uncovered details of a complex cyber espionage campaign dubbed ‘Operation Red October’ that has been targeting specific groups throughout the world for over five years.
newswww.securityweek.comJan 15, 2013, 8:54 AMLast October Kaspersky Lab’s Global Research & Analysis Team started a new investigation after several attacks hit computer networks of various international diplomatic service agencies. The attacks appeared very suspect, a new large scale cyber-espionage operation has been discovered, the operation is dubbed «Red October», a name inspired by famous novel «The Hunt For The Red […]
newssecurityaffairs.comJan 15, 2013, 7:52 AMCyber security researchers have turned up evidence of a sophisticated cyber-espionage campaign that has been targeting political and business groups throughout the world for more than five years.
newswww.securityweek.comJan 14, 2013, 1:15 PMMost Popular Exploit Documents Used in April 2012 Trend Micro researchers recently offered a peek into just how prevalent the use of certain document types is among attackers.
newswww.securityweek.comMay 14, 2012, 4:58 PMBooby-trapped RTF documents are one of the most common types of malicious Microsoft Office files that are used to infect computers with advanced persistent threats (APTs), according to security researchers from Trend Micro. “Taking data from exploit documents gathered last April, we can see that the most exploited MS Office software is MS Word,” said […]
newswww.csoonline.comMay 10, 2012, 3:00 PM- Week in review: Targeted attacks exploiting Windows flaw, massive Utah data breach and Flashback malware falloutHelp Net Security
Here’s an overview of some of last week’s most interesting news, podcasts and articles: Smart meters vulnerable to false data injection False data injection attacks exploit the configuration of power grids by introducing arbitrary errors into state variables while bypassing existing techniques for bad measurement detection. Poor internal security processes spell disaster Poor internal security management processes present more risk than malicious threats. More than 50 percent of an AlgoSec survey respondents incurred a system … More →
newswww.helpnetsecurity.comApr 16, 2012, 2:02 AM - Microsoft warns of targeted attacks exploiting Windows flawHelp Net Security
With the April Patch Tuesday, Microsoft has issued six bulletins – four critical, two important – and has delivered patches for 11 vulnerabilities. One particular bulletin (MS12-027) stands out and patching the vulnerability (CVE-2012-0158) documented in it should be considered a priority, as Microsoft shared that it is currently being exploited in the wild. The flaw is in Windows Common Controls ActiveX control and consequently affects a great many Microsoft products such as Office 2003 … More →
newswww.helpnetsecurity.comApr 11, 2012, 11:17 AM Microsoft released its April 2012 Security Bulletin a few minutes ago. As expected, this is a six-bulletin package addressing a total of 11 vulnerabilities. Per usual, I’m sharing the early analysis that’s been dropped into my inbox… Symantec: “The WinVerifyTrust Signature Validation Vulnerability is interesting because it lets attackers modify signed Portable Executable files undetected,” […]
newswww.csoonline.comApr 10, 2012, 4:48 PMMicrosoft today delivered six security updates to patch 11 vulnerabilities in Windows, Internet Explorer (IE), Office and several other products, including one bug that attackers are already exploiting. The company also issued the first patch for Windows 8 Consumer Preview, the beta-like build Microsoft released at the end of February. But it was MS12-027 that […]
newswww.csoonline.comApr 10, 2012, 3:00 PM- Microsoft released six comprehensive security updatesHelp Net Security
This month Microsoft issued six bulletins, four critical, two important, addressing 11 distinct vulnerabilities. Organizations should focus most of their attention on MS12-027. What makes this bulletin stand out is that Microsoft is aware of attacks in the wild against it and that it affects an unsually wide-range of Microsoft products, including Office 2003 through 2010 on Windows, SQL Server 2000 through 2008 R2, BizTalk Server 2002, Commerce Server 2002 through 2009 R2, Visual FoxPro … More →
newswww.helpnetsecurity.comApr 10, 2012, 1:30 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2012-1856CVSS 8.8 · High
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Ser…
KEV listed13 mentions - CVE-2007-1201CVSS 9.3 · Critical
Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to Dat…
- CVE-2009-1136CVSS 9.3 · Critical
The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 200…
- CVE-2007-0065CVSS 10.0 · Critical
Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual…
- CVE-2009-2496CVSS 9.3 · Critical
Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3,…
- CVE-2009-1534CVSS 9.3 · Critical
Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Vis…