GossiTheDog , Englisch
@GossiTheDog@cyberplace.social avatar

Good find by Elastic - possibly North Korean based threat actors using an unfixed bug in Windows to execute code, undetected across all vendors until that point (and as of writing only Elastic detect still)

They’ve named it GrimResource https://www.elastic.co/security-labs/grimresource

GossiTheDog OP ,
@GossiTheDog@cyberplace.social avatar

Still essentially zero detection for GrimResource. PoC that spawns calc: https://gist.github.com/joe-desimone/2b0bbee382c9bdfcac53f2349a379fa4

SwiftOnSecurity ,
@SwiftOnSecurity@infosec.exchange avatar

@GossiTheDog is this using an embedded iframe in MMC that has all the security turned off? I’ve always wondered about that scenario but never did anything. Will look more soon thx.

GossiTheDog OP ,
@GossiTheDog@cyberplace.social avatar

@SwiftOnSecurity essentially. I was looking at VirusTotal just now, apparently .msc misuse has been supercharged for a while now, e.g. I can see red teams using WebDAV paths in icon parameters to get SMB hashes

SwiftOnSecurity ,
@SwiftOnSecurity@infosec.exchange avatar

@GossiTheDog I mean webview*

  • Alle
  • Abonniert
  • Moderiert
  • Favoriten
  • random
  • haupteingang
  • Alle Magazine