- Threat actors are targeting exposed Microsoft SQL (MSSQL) servers using brute-force attacks in a campaign called DBJammer.
- The attackers deploy a new variant of Mimic ransomware called Freeworld.
- Sophisticated tooling includes enumeration software, RAT payloads, and credential-stealing software.
- The campaign exhibits rapid execution and high levels of sophistication, including system and registry modifications to establish persistence.
A new cybersecurity threat is looming over organizations that rely on Microsoft SQL (MSSQL) servers. Dubbed as the DBJammer campaign, this attack begins with threat actors brute-forcing their way into exposed MSSQL databases. Once inside, they use the servers as a beachhead to launch a variety of payloads, including Remote Access Trojans (RATs) and a new variant of Mimic ransomware known as Freeworld.
The Freeworld ransomware is particularly noteworthy for its presence in binary file names and ransomware extensions. The attackers are well-equipped, using a range of tools for system enumeration, exploitation, and credential stealing. They also make extensive system and registry modifications to impair defenses and establish persistence on the host. For instance, they disable User Account Control (UAC) remote restrictions and ensure that Network Level Authentication is not required for Remote Desktop Protocol (RDP).
The campaign is not only sophisticated in its tooling but also in its execution speed, indicating a high level of preparation and possibly signaling an ongoing, targeted operation. Given the complexity and rapid escalation of these attacks, organizations are advised to limit their MSSQL services' exposure to the internet and strengthen account credentials.
- Cybercriminals are increasingly using dark AI tools like WormGPT, PoisonGPT, and FraudGPT for malicious activities.
- These tools are available for sale on the dark web and are designed to bypass traditional security measures.
- Experts warn that we are less than a year away from a successful cyberattack being credited to such AI tools.
- The underground economy is exploring business models for these tools, with some being offered on a subscription basis.
The future of cybersecurity is facing a new challenge with the rise of dark AI tools. These are AI-driven software designed for malicious activities such as phishing, malware creation, and exploiting vulnerabilities. Notable examples include WormGPT, which can create phishing emails to bypass spam filters, and FraudGPT, designed for creating malware and identifying vulnerabilities.
The underground economy is actively exploring the profitability of these tools. They are often advertised on a subscription basis, with prices ranging from €100 for one month to $700 for a year. The alarming part is that 51% of IT professionals predict that a successful cyberattack attributed to these dark AI tools is imminent within a year.
While some experts question the legitimacy of these tools, suggesting they may just be "wrapper services" that redirect to legitimate AI models, the threat they pose is real and evolving. Organizations need to be prepared for a future where cybercriminals are increasingly leveraging AI for malicious purposes.
- A severe SSH authentication bypass vulnerability has been discovered in VMware's Aria Operations for Networks, formerly known as vRealize Network Insight.
- The vulnerability is tracked as CVE-2023-34039 and has been patched by VMware.
- Security researchers have released a proof-of-concept exploit that targets all Aria Operations for Networks versions from 6.0 to 6.10.
- VMware highly recommends applying security patches to mitigate the flaw, as the exploit code has been published online.
A critical SSH authentication bypass vulnerability has been identified in VMware's Aria Operations for Networks, previously known as vRealize Network Insight. The flaw, designated as CVE-2023-34039, was discovered by security analysts at ProjectDiscovery Research and has been patched by VMware. The vulnerability allows remote attackers to bypass SSH authentication on unpatched appliances and gain access to the tool's command line interface (CLI).
The root cause of this issue lies in hardcoded SSH keys that VMware forgot to regenerate. This oversight makes it possible for attackers to execute low-complexity attacks without requiring user interaction. A proof-of-concept (PoC) exploit targeting versions 6.0 to 6.10 of the software has been released by Summoning Team vulnerability researcher Sina Kheirkhah.
This vulnerability is particularly alarming because it comes on the heels of another arbitrary file write vulnerability (CVE-2023-20890) that could allow attackers to gain remote code execution after obtaining admin access. Given the severity and the release of the PoC exploit, it is crucial for administrators to apply the necessary security patches immediately to prevent potential attacks.
Sign up for Mandos Way
Join Mandos Way for tips and strategies to make security your business accelerator. Receive weekly cybersecurity briefs for you and your team.
No spam. Unsubscribe anytime.