

Rewterz Threat Advisory – CVE2023-6345 – Google Chrome Zero-Day Vulnerability
November 29, 2023
Rewterz Threat Advisory – ICS: Multiple Delta Electronics InfraSuite Device Master Vulnerabilities
November 30, 2023
Rewterz Threat Advisory – CVE2023-6345 – Google Chrome Zero-Day Vulnerability
November 29, 2023
Rewterz Threat Advisory – ICS: Multiple Delta Electronics InfraSuite Device Master Vulnerabilities
November 30, 2023Severity
High
Analysis Summary
APT-17, also known as “Bitter APT” or “DeputyDog” is a state-sponsored cyber espionage group that is believed to operate out of China. They have been active since at least 2012 and have primarily targeted organizations in the aerospace, defense, and technology industries. They are known for targeting China, Pakistan, and Saudi Arabia and have expanded to set their sights on Bangladeshi government agencies. The group is known for using a wide range of custom malware and tools to carry out their operations, including Remote Access Trojans (RATs), keyloggers, and backdoors. The group’s malware is known to be complex, and multi-stage and used a range of techniques to evade detection, such as code signing, the use of legitimate tools and third-party tools, and the use of encrypted communications. They are also known to use spear-phishing campaigns to gain initial access to targeted systems. They have been active for more than a decade and are known to use a wide range of custom malware and tools to carry out their operations. Organizations in these sectors should be aware of the threat actors and take appropriate measures to protect against their attacks. This includes implementing robust security measures, such as advanced threat detection and response capabilities, as well as employee training on how to identify and respond to spear-phishing campaigns. The group was observed using Powershell and curl instead of msiexe in one of the latest campaigns.
Impact
- Information Theft and Espionage
Indicators of Compromise
Domain Name
- sparksteam.site
- clamstew.website
- maxdimservice.com
MD5
- 30605c57f69b6a5549dc9450a8f28903
- 367bec8d5ff1dbb2e94050cf946ab64e
- 35639088a2406aa9e22fa8c03e989983
SHA-256
- fc72bd3e21cddcb3c181d7bdf1cacd2886701cdf9cc12be63061c2eeeda47ce9
- 9887dc107bc97fd3847bb0a599a50a764a32f2e78f216b8cfb8d0e6f8342a612
- 132098213b5923463611e6fc77bfce0cfad3d727566ce0e87e9723456c698ae6
SHA-1
- ebea5145e27e47b86d233bc9d395e838aa189037
- 5d030c59a4f29a62ba8ec7cd67c927134706c017
- ceabacacb2714e0101870765c728d5255584cd14
IP
- 104.243.33.214
- 69.164.40.8
Remediation
- Block all threat indicators at your respective controls.
- Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls
- Along with network and system hardening, code hardening should be implemented within the organization so that their websites and software are secure. Use testing tools to detect any vulnerabilities in the deployed codes.
- Patch and upgrade any platforms and software timely and make it into a standard security policy. Prioritize patching known exploited vulnerabilities and zero-days.
- Enable antivirus and anti-malware software and update signature definitions in a timely manner. Using a multi-layered protection is necessary to secure vulnerable assets
- Maintain cyber hygiene by updating your anti-virus software and implementing a patch management lifecycle.
- Enable two-factor authentication.
- Do not download document ?les attached in emails from unknown sources and strictly refrain from enabling macros when the source isn’t reliable.