The move toward quantum-resilient security keys is vital as progress toward practical quantum computers accelerates. While quantum attacks are still in the distant future, deploying cryptography at internet scale is a massive undertaking, and early preparation is essential. Google's efforts in this direction signify a clear path to secure security keys against quantum attacks, with further improvements and standardization expected in the future.
- Microsoft has discovered multiple high-severity vulnerabilities in CODESYS V3 SDK, affecting all versions prior to 3.5.1.90.
- These vulnerabilities could lead to remote code execution (RCE) or denial of service (DoS) attacks, potentially shutting down power plants or tampering with industrial operations.
- CODESYS is used in over 1000 different device types across various industries, including power generation, factory automation, and energy automation.
- Microsoft has worked with CODESYS to release patches, and users are urged to apply these security updates as soon as possible to mitigate the risks.
Microsoft's cyber-physical system researchers have recently identified multiple high-severity vulnerabilities in the CODESYS V3 Software Development Kit (SDK), a platform widely used to program and engineer programmable logic controllers (PLCs). These vulnerabilities, which affect all versions of CODESYS V3 prior to version 3.5.1.90, could put operational technology (OT) infrastructure at risk of attacks such as remote code execution (RCE) and denial of service (DoS).
The discovery highlights the critical importance of securing industrial control systems. CODESYS is compatible with approximately 1000 different device types from over 500 manufacturers, and several million devices use the solution to implement the international industrial standard IEC 61131-3. A DoS attack against a device using a vulnerable version of CODESYS could enable threat actors to shut down a power plant, while remote code execution could create a backdoor for devices, allowing attackers to tamper with operations or steal critical information.
Exploiting these vulnerabilities requires user authentication and deep knowledge of the proprietary protocol of CODESYS V3. Microsoft reported the discovery to CODESYS in September 2022 and worked closely with them to ensure that the vulnerabilities are patched.
- Lax policies for package naming in Microsoft's PowerShell Gallery allow threat actors to perform typosquatting attacks, spoofing popular packages.
- Attackers can spoof module details, including author and copyright, making it difficult for users to distinguish between legitimate and malicious packages.
- A flaw allows attackers to expose unlisted packages on the platform, gaining unrestricted access to the complete PowerShell package database.
- Despite acknowledging the flaws and claiming to have implemented short-term solutions, Microsoft has not fully remediated the issues, leaving users vulnerable.
Recent findings by Aqua Nautilus have exposed significant flaws in the PowerShell Gallery's policy regarding package names and owners. These flaws make typosquatting attacks inevitable, allowing attackers to mimic popular Microsoft PowerShell modules, downloaded millions of times. The PowerShell Gallery lacks protection against typosquatting, enabling malicious actors to upload malicious PowerShell modules that appear genuine. For example, the popular module "aztable" could be easily impersonated with a new name like "az.table," deceiving users into installing a malicious module.
Furthermore, attackers can forge module metadata, faking details like authors, copyright, and description fields, making the spoofed package appear legitimate. Another flaw allows the discovery of unlisted packages, uncovering deleted secrets within the registry. These flaws pave the way for potential supply chain attacks on the registry's vast user base, especially popular around AWS and Azure.
Despite reporting the flaws to Microsoft and claims of ongoing fixes, the issues remain reproducible as of August 2023, indicating that no tangible changes have been implemented. Users of the PowerShell Gallery are advised to adopt policies that allow execution of only signed scripts, utilize trusted private repositories, regularly scan for sensitive data in module source code, and implement real-time monitoring systems in cloud environments to detect suspicious activity.
- The LabRat campaign leverages a critical flaw in GitLab (CVE-2021-22205) to initiate cryptojacking and proxyjacking.
- The attacker uses undetected signature-based tools, cross-platform malware, and kernel-based rootkits for stealth.
- Services like tryCloudflare are abused to obfuscate the command-and-control (C2) network.
- Besides financial gains, the malware provides backdoor access, potentially paving the way for data theft, ransomware, and other attacks.
The LabRat campaign is a new financially motivated operation that has been observed exploiting a critical GitLab flaw. This flaw, known as CVE-2021-22205, has been weaponized for cryptojacking and proxyjacking activities. The attacker employs sophisticated tools, including undetected signature-based tools and kernel-based rootkits, to hide their presence.
One notable aspect is the use of compiled binaries written in Go and .NET, which helps the attacker fly under the radar. The attacker also abuses legitimate services like tryCloudflare to obfuscate their C2 network, making detection more challenging.
Proxyjacking allows the attacker to rent the compromised host to a proxy network, while cryptojacking refers to the abuse of system resources to mine cryptocurrency. The LabRat operation also provides backdoor access to infected systems, potentially leading to follow-on attacks, data theft, and ransomware.
The attack chain begins with the exploitation of the GitLab vulnerability, followed by the retrieval of a dropper shell script that sets up persistence and conducts lateral movement. The attacker also uses tryCloudflare to redirect connections to a password-protected web server hosting malicious scripts.
The Sysdig team discovered that the attacker linked directly to a private GitLab repository to download binaries related to malicious activity. This repository has been active since September 2022, with some of the latest commits being very recent.
The LabRat campaign emphasizes stealth and defense evasion, with the attacker continuously updating their tools. The goal is not only financial but also potentially opens doors for other malicious activities. Users impacted by the vulnerability should follow security incident and disaster recovery processes to deprovision the compromised instance and restore to a new GitLab instance. The vulnerability has been patched since 2021, but the impact remains on customers who are on vulnerable versions.
Sign up for Mandos Way
Join Mandos Way for tips and strategies to make security your business accelerator. Receive weekly cybersecurity briefs for you and your team.
No spam. Unsubscribe anytime.