• Academy
  • News
    • Blockchain
    • Fintech
  • Devices
  • Reviews
    • Ai
    • SOFTWARE
  • 0 - ₫0.00

MyCadie

The future is here

You are here: Home / Academy / Pro-Russia hackers target inboxes with 0-day in webmail app used by millions

Pro-Russia hackers target inboxes with 0-day in webmail app used by millions

November 19, 2023 November 19, 2023 admin

Pro-Russia hackers target inboxes with 0-day in webmail app used by millions
Enlarge
Getty Images

reader comments

42
with

Maybe you are interested:
  • The XL Productivity Appliance™
  • Blog
  • Best 5 TaxDome alternatives to consider for your accounting practice management software
  • SIMMS Software
  • TOP 6 Software TPV para Hostelería 2023: mejora la gestión de tu restaurante

A relentless team of pro-Russia hackers has been exploiting a zero-day vulnerability in widely used webmail software in attacks targeting governmental entities and a think tank, all in Europe, researchers from security firm ESET said on Wednesday.

You are watching:: Pro-Russia hackers target inboxes with 0-day in webmail app used by millions

The previously unknown vulnerability resulted from a critical cross-site scripting error in Roundcube, a server application used by more than 1,000 webmail services and millions of their end users. Members of a pro-Russia and Belarus hacking group tracked as Winter Vivern used the XSS bug to inject JavaScript into the Roundcube server application. The injection was triggered simply by viewing a malicious email, which caused the server to send emails from selected targets to a server controlled by the threat actor.

No manual interaction required

“In summary, by sending a specially crafted email message, attackers are able to load arbitrary JavaScript code in the context of the Roundcube user’s browser window,” ESET researcher Matthieu Faou wrote. “No manual interaction other than viewing the message in a web browser is required.”

See more: : Azure Certifications: Which is Right for You and Your Team?

The attacks began on October 11, and ESET detected them a day later. ESET reported the zero-day vulnerability to Roundcube developers on the same day, and they issued a patch on October 14. The vulnerability is tracked as CVE-2023-5631 and affects Roundcube versions 1.6.x before 1.6.4, 1.5.x before 1.5.5, and 1.4.x before 1.4.15.

Further Reading

Pro-Russian hackers target elected US officials supporting Ukraine

Winter Vivern has been operating since at least 2020 and targets governments and think tanks, primarily in Europe and Central Asia. In March, the threat group was spotted targeting US government officials who had voiced support for Ukraine in its bid to drive back Russia’s invasion. Those attacks also exfiltrated targets’ emails but exploited a separate, already-patched XSS in Zimbra Collaboration, a software package that’s also used to host webmail portals.

“This actor has been tenacious in its targeting of American and European officials as well as military and diplomatic personnel in Europe,” a threat researcher from security firm Proofpoint said in March when disclosing the attacks exploiting the Zimbra vulnerability. “Since late 2022, [Winter Vivern] has invested an ample amount of time studying the webmail portals of European government entities and scanning publicly facing infrastructure for vulnerabilities all in an effort to ultimately gain access to emails of those closely involved in government affairs and the Russia-Ukraine war.”

Advertisement

See more: : Email Encryption Software

The email Winter Vivern used in the recent campaign came from the address team.managemen[email protected] and had the subject “Get started in your Outlook.”

The email sent in the campaign.
The email sent in the campaign.

Buried deep in the HTML source code was a malformed code element known as an SVG tag. It contained base-64 encoded text that, when decoded, translated to JavaScript that contained a command to run in the event an error occurred. Since the tag contained an intentional error, the malicious command was invoked, and the XSS bug ensured that Roundcube executed the resulting JavaScript.

HTML source code for the email, with a SVG tag at the end.
Enlarge / HTML source code for the email, with a SVG tag at the end.
ESET

The final JavaScript payload instructed vulnerable servers to list folders and emails in the target’s email account and to exfiltrate email messages to an attacker-controlled server by making HTTP requests to https://recsecas[.]com/controlserver/saveMessage.

The final JavaScript payload.
Enlarge / The final JavaScript payload.
ESET

Winter Vivern’s previous success exploiting an already-patched Zimbra vulnerability should be a warning. Anyone using Roundcube as either a server admin or an end user should ensure the software is running a patched version.

Source:: https://www.mycadie.com
Category:: Academy

Related articles

Quantum computer performs error-resistant operations with logical qubits
Holy chips! Microsoft’s new AI silicon will power its chatty assistants
Study: Why a spritz of water before grinding coffee yields less waste, tastier espresso
Bing Chat is now “Microsoft Copilot” in potentially confusing rebranding move
YouTube cracks down on synthetic media with AI disclosure requirement
Daily Telescope: A super-hot jet 1,000 light-years from Earth
Man dies on way home from Panera after having three “charged” lemonades
People think white AI-generated faces are more real than actual photos, study says
Intel fixes high-severity CPU bug that causes “very strange behavior”
Unlocking the secrets of oobleck—strange stuff that’s both liquid and solidvar abtest_1988470 = new ABTest(1988470, ‘click’);

Chuyên mục: Academy

Previous Post: « Lunatik Taktik Extreme Review – iPhone 5/5S
Next Post: Cross-border banking service meets cross-border savings in one app »

Primary Sidebar

Recent Posts

  • Quantum computer performs error-resistant operations with logical qubits
  • Holy chips! Microsoft’s new AI silicon will power its chatty assistants
  • Survey Reveals 100% of Digital Agencies Are Using AI
  • Study: Why a spritz of water before grinding coffee yields less waste, tastier espresso
  • Bing Chat is now “Microsoft Copilot” in potentially confusing rebranding move

Featured Articles

Quantum computer performs error-resistant operations with logical qubits

December 7, 2023

Holy chips! Microsoft’s new AI silicon will power its chatty assistants

December 7, 2023

Survey Reveals 100% of Digital Agencies Are Using AI

December 7, 2023

Study: Why a spritz of water before grinding coffee yields less waste, tastier espresso

December 7, 2023

Bing Chat is now “Microsoft Copilot” in potentially confusing rebranding move

December 7, 2023

Microsoft Fabric Overview

December 6, 2023

AI joins you in the DJ booth with Algoriddim’s djay Pro 5

December 6, 2023

Google’s Gemini AI is coming to Android

December 6, 2023

Google Introduces Gemini And Updates Bard With Gemini Pro

December 6, 2023

Google announces new AI processing chips and a cloud ‘hypercomputer’

December 6, 2023

YouTube cracks down on synthetic media with AI disclosure requirement

December 6, 2023

Google’s answer to GPT-4 is Gemini: ‘the most capable model we’ve ever built’

December 6, 2023

TikTok pledges €12B European investment as Norway data centre nears completion

December 6, 2023

Daily Telescope: A super-hot jet 1,000 light-years from Earth

December 6, 2023

Silo AI releases checkpoint on mission to democratise LLMs

December 6, 2023

Tech is bringing ancient ruins back to life. Here’s how

December 6, 2023

Is Next.js right for you? Here are the top 5 Performance Benefits

December 6, 2023

5 Ways to Boost Sales Performance with Dynamics 365 CE/CRM

December 6, 2023

5 Ways to Effectively Improve Sales Team Adoption of Dynamics 365 CE/CRM

December 6, 2023

Man dies on way home from Panera after having three “charged” lemonades

December 6, 2023

Footer

About Us

Mycadie is a global business technology website providing the latest news, analysis, and business insight for IT decision-makers. Whether it’s cyber security, cloud computing, IT infrastructure, or business strategy, we aim to equip leaders with the data they need to make informed IT investments.

Follow Us: Google News

Categories

  • Academy
  • Ai
  • Devices
  • Fintech
  • News
  • Reviews
  • SOFTWARE

Menu

  • Trang chủ
  • ABOUT US
  • Privacy Policy

Registered Address: Full 7th Floor, 130 West 42nd Street, New York, NY 10036. © Mycadie. All Rights Reserved.© 2023