• About Us
  • Disclaimer for Pledge Times
  • T & C
  • Write To Us
Monday, February 6, 2023
Pledge Times
  • World
  • Business
  • Gaming
  • Tech
  • Entertainment
  • Science
  • Lifestyle
  • Health
  • Sports
  • World
  • Business
  • Gaming
  • Tech
  • Entertainment
  • Science
  • Lifestyle
  • Health
  • Sports
No Result
View All Result
Pledge Times
No Result
View All Result
Home Tech

Internet Explorer: found a zero-day exploited by hackers

by admin_l6ma5gus
December 9, 2022
in Tech
0

Internet Explorer was taken out of support by Microsoft on June 15, 2022, unfortunately continuing to use it (many companies do it, they persist in keeping obsolete software together with Windows 7 and in the worst case XP) means submitting to considerable risks for security.

An Internet Explorer zero-day vulnerability has been actively exploited by an unknown North Korean perpetrator to target South Korean users by exploiting the recent crowd of Itaewon Halloween to trick users into downloading malware.

The discovery, reported by Google Threat Analysis Group researchers Benoît Sevens and Clément Lecigne, is the latest series of attacks perpetrated by the ScarCruft group, also known as APT37, InkySquid, Reaper and Ricochet Chollima.

“Over time, the group has focused its efforts on South Korean users, North Korean defectors, policy makers, journalists, and human rights activists.“, has stated TAG in an analysis on Thursday.

How does this vulnerability of the now deprecated Internet Explorer work?

The new findings show continued abuse by authors, exploiting Internet Explorer flaws such as CVE-2020-1380 and CVE-2021-26411 to use backdoors known as BLUELIGHT and Dolphin; the latter was discovered by Slovak cybersecurity firm ESET late last month.

See also  The Christmas spirit and magic take over the Ángela Peralta Theater

Another key tool in his arsenal is RokRata Windows-based remote access trojan that has a wide range of functions that allow it to take screenshots, log keystrokes, and even gather information about Bluetooth devices.

Internet Explorer
Korean language Internet Explorer screen

The attacks observed by Google TAG show the use of a malicious Microsoft Word document that was uploaded to VirusTotal on October 31, 2022; the abuse of another Internet Explorer zero-day flaw in the JScript9 JavaScript engine, CVE-2022-41128, which was settled from Microsoft last month.

The file references the October 29 incident in Seoul’s Itaewon Ward and exploits public interest in the tragedy to have users unknowingly open an exploit for the vulnerability upon opening it; in fact the attack is made possible by the fact that Office renders the HTML content using Internet Explorer.

As shows the MalwareHunterTeamthe same Word file was previously shared by the Shadow Chaser Group on October 31, 2022, describing it as a “interesting DOCX injection template sample” originally from Korea.

See also  iPhone 14, according to rumors only the Pros will have a new chip

Exploitation of this vulnerability is followed by delivery of shellcode that clears all traces by clearing Internet Explorer’s cache and history and downloading the next stage payload.

Google TAG said it was unable to recover the subsequent malware used in the campaign, although it is suspected to have involved the implementation of RokRat, BLUELIGHT or Dolphin.

Why don’t many people upgrade?

Unfortunately in the world (not only in Italy, unfortunately), there is the “mania”, the habit of not reading the press releases of the parent company (Microsoft in the case of Windows 7, Internet Explorer, etc.), because it is taken for granted, ignorantly, that “once we learn things, we’re good to go“.

Know that the windows updates weren’t done because the developers woke up one day and said “we invent windows updates“, there are cyber security reasons behind it.

Of course, if you don’t live in South Korea and if you don’t have relations with this state via the Internet because maybe you know Korean, you certainly have nothing to fear.

See also  AMLO and...Who are the political allies of Pedro Castillo, former president of Peru?

The fact is that the disposal of software (such as Internet Explorer) or operating systems (Windows 7, XP, etc.) is not something to be taken lightly and say “but yes, I’ll continue what do you want it to be?”, there are of the leaks that over time will get bigger and bigger like a ship that is taking on water without the captain realizing it.


#Internet #Explorer #zeroday #exploited #hackers

admin_l6ma5gus

admin_l6ma5gus

Related Posts

NFL: Myles Garrett left injured in the first Pro Bowl Games in Las Vegas

by admin_l6ma5gus
February 6, 2023
0

During the realization of the first pro bowl Games at Allegiant Stadium, home of Las Vegas Raiders of the NFL,...

He does it again! This is the new function that WhatsApp copied from Telegram

by admin_l6ma5gus
February 6, 2023
0

Although it is true that the WhatsApp app is the most widely used instant messaging platform in the world, it...

They find a 4-year-old boy crying and wandering the streets of Chihuahua

by admin_l6ma5gus
February 5, 2023
0

Chihuahua.- A 4-year-old boy who had been crying and wandering the streets for several hoursand the Sol Oriente neighborhood in...

Mexican pride! All the Mexican artists nominated at the 2023 Grammy Awards

by admin_l6ma5gus
February 5, 2023
0

USA. - Today, Sunday, February 5, 2023, the Grammy awards where important Mexican artists are nominated in the Latin category...

These are the MILLIONS that Shakira has earned after launching ‘Session 533’ with Bizarrap

by admin_l6ma5gus
February 5, 2023
0

Mexico.- Shakira continues to reap achievements in his artistic career, Well, after having released the song 'BZRP Music Sessions #53',...

Chinese spy balloon: shot down by an F-22, but what was it?

by admin_l6ma5gus
February 5, 2023
0

The Chinese spy balloon is goneindeed an F-22 fighter jet has destroyed China's spy balloon this Saturday (February 4) with...

Next Post

Bianca Balti was operated on, after the courageous decision she made. She chose her life. How is the supermodel now?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

LIVE | Police arrest six people in Zwolle, pelted ME in Heerenveen uses tear gas

7 months ago

Energy Shell to end cooperation with Russian Gazprom, also exits Nord Stream 2 gas pipeline project

11 months ago

Popular News

    • About Us
    • Disclaimer for Pledge Times
    • T & C
    • Write To Us
    Email us: [email protected]
    No Result
    View All Result
    • World
    • Business
    • Science
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Tech
    • Health