pwshub.com

Symantec warns of new sophisticated backdoor exploiting patched PHP vulnerability

A new report out today from Symantec, a division of Broadcom Inc., is warning of a new sophisticated backdoor threat that has been spotted in the wild targeting a university in Taiwan.

Dubbed Backdoor.Msupedge, the backdoor uses an infrequently seen technique that involves communicating with a command-and-control service via DNS traffic. Though the technique has been used in the past by multiple actors, it’s not often seen.

Msupedge is a backdoor in the form of a dynamic link library and has been found installed in the following file paths:

• csidl_drive_fixed\xampp\wuplog.dll
• csidl_system\wbem\wmiclnt.dll

While wuplog.dll is loaded by Apache (httpd.exe), the parent process for wmiclnt.dll is unknown. Msupedge uses DNS tunneling for communication with the C&C server, with the code for the DNS tunneling tool based on the publicly available dnscat2 tool.

The backdoor and C&C communicate by performing name resolution. The results can include error notifications that include the success or failure of memory allocation, decompression of received commands, and execution of the commands. Msupedge is also noted as not only receiving commands via DNS traffic but also using the resolved IP address of the C&C server as a command.

In the case of the Taiwanese university, the attack vector was the exploitation of a recently patched PHP vulnerability that allows for a CGI argument injection flaw affecting all versions of PHP installed on Windows systems. Successful exploitation of the vulnerability can also lead to remote code execution.

The origin of the backdoor is unknown.

“Symantec has seen multiple threat actors scanning for vulnerable systems in recent weeks,” the report notes. “To date, we have found no evidence allowing us to attribute this threat and the motive behind the attack remains unknown.”

Source: siliconangle.com

Related stories
2 weeks ago - Unlike previous VMware Explore/VMWorld events, which are typically filled with product announcements, this year’s VMware by Broadcom’s user event, Explore 2024, was very light on the news. The most notable announcement at the event in Las...
2 weeks ago - Artificial intelligence and machine learning cybersecurity company Protect AI Inc. today announced the availability of a new free four-part video training and certification program on how to build security into AI and machine learning...
15 hours ago - This company's artificial intelligence presence spans across semiconductors, cybersecurity, and data center software.
2 weeks ago - Prominent billionaires are dumping shares of the "brains" behind artificial intelligence (AI)-driven data centers in favor of two AI stocks that have announced or completed stock splits in 2024.
1 week ago - Even though Intel's days as a Dow component are likely numbered, and Nvidia has leapfrogged Intel in the innovation department, Wall Street's artificial intelligence (AI) darling is no lock to enter the Dow.
Other stories
19 minutes ago - The Fed's cutting cycle in 1995 sparked an economic boom, with the stock market more than doubling in value by the end of the decade.
19 minutes ago - There's nothing like a potentially massive government contract to win the hearts of both investors and analysts.
1 hour ago - Shares of Truth Social’s parent company fell Thursday, extending the latest round of declines for Trump Media & Technology Group.
1 hour ago - European Union officials are taking new steps to ensure that Apple Inc. complies with the bloc’s DMA tech industry regulation. The European Commission, the EU’s executive arm, announced the initiative today. The DMA is a piece of...
1 hour ago - Shares in automotive chip maker Mobileye Global Inc. jumped nearly 15% today after its majority shareholder, Intel Corp., said that it has no plans to divest its interest in the company. Reports earlier this month suggested that Intel...