For a detailed advisory, download the pdf file here.
Microsoft Exchange Server vulnerabilities have been officially patched for five months now. These vulnerabilities are actively exploited by multiple threat actors named DeadRinger. DeadRinger has been affecting the telecommunication industry all around the world. DeadRinger consists of three clusters. The first one includes threat group Softcell which has been active since 2012. The Naikon group, which has been active since 2020, is the second cluster. We discovered that the signatures match those of TG-3390, making it the third cluster.
As a response, Hive Pro Threat Researchers advises that you address these vulnerabilities.
The Techniques used by the DeadRinger includes:T1592: Gather Victim Host InformationT1595: Active ScanningT1590: Gather Victim Network InformationT1190: Exploit Public-Facing ApplicationT1059: Command and Scripting InterpreterT1047: Windows Management InstrumentationT1059.001: Command and Scripting Interpreter: PowerShellT1505.003: Server Software Component: Web ShellT1136: Create AccountT1053: Scheduled Task/JobT1078: Valid AccountsT1574: Hijack Execution FlowT1027.005: Obfuscated Files or Information: Indicator Removal from ToolsT1027: Obfuscated Files or InformationT1036: MasqueradingT1070.006: Indicator Removal on Host: TimestompT1140: Deobfuscate/Decode Files or InformationT1040: Network SniffingT1087: Account DiscoveryT1018: Remote System DiscoveryT1071.001: Application Layer Protocol: Web ProtocolsT1041: Exfiltration Over C2 ChannelT1021.002: Remote Services: SMB/Windows Admin SharesT1550.002: Use Alternate Authentication Material: Pass the HashT1105: Ingress Tool TransferT1555: Credentials from Password StoresT1003: OS Credential DumpingT1016: System Network Configuration DiscoveryT1069: Permission Groups DiscoveryT1560: Archive Collected DataT1569: System ServicesT1543.003: Create or Modify System Process: Windows ServiceT1574.002: Hijack Execution Flow: DLL Side-LoadingT1570: Lateral Tool TransferT1056.001: Input Capture: KeyloggingT1573: Encrypted Channel
Vulnerability Detail
Actor Details
Indicators of Compromise (IoCs)
Patch Links
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26857
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26858
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-27065
References
https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
https://www.zdnet.com/article/deadringer-chinese-apts-strike-major-telecommunications-companies/
