The LOG4J crisis continues: new vulnerabilities have appeared in the library for Java, more than 800 thousand cyber attacks occurred
Hackers create botnets, modify the banking trojans and try to write “worms” while companies urgently update software.
"Folk" logo of the vulnerability of Log4Shell Wikipedia
The crisis in the IT industry, which in early December provoked vulnerability in the LOG4J library continues. Companies produce patches and update server software, but even such security measures cannot prevent a possible leakage of data from technological companies, Gizmodo writes .
Patches for LOG4J have created new vulnerabilities, and years will go to correct the situation
On December 17, Apache published an extraordinary safety update LOG4J (number 2.17.0). This is the third urgent release of the library, published in December: the twoprevious patches coped with the vulnerability of Log4Shell, but opened new gaps in corporate systems.
CVE-2021-45046allowed to operate LOG4Shell on servers running MacOS. Vulnerability to LOG4J 2.15.0 only servers with non -standard configuration are subject to. Hackers have not yet been used, notes the cybersecurity specialist Kevin Bomont. In other environments, attempts to attack failed.
By the time of publication of the article, the Internet scanner Shodan determines only 1113 suitable servers, 319 of them are in the USA. Over the past year, more than a million cars have been included in the base of the similar service of Zoomeye, which operate 331 thousand websites.
With the help of the vulnerability of the CVE-2021-45105, it has become possible to conduct DDOS attacks. The vulnerability was estimated at a threat of 7.5 points out of ten possible on the CVSS scale due to the complexity of the preparation of such attacks.
The problem of urgent updates is well known to developers: patches for vulnerable in terms of safety often do not solve safety issues, but rather create new threats, emphasize the N-Ble IT company. Before installing the updates, they should be tested in a virtual machine, and before changing the current infrastructure - to make a backup copy of the software. Many companies still ignore updates, emphasize in the company.
Against the backdrop of these discussions, the Google cybersecurity group found out that Log4Shell affects about 36 thousand packages loaded with Maven Central - the largest libraries for Java. For the correction of all vulnerable components associated with LOG4J, years will go away, the company notes.
Hacker attacks continue
Attempts to operate the Bigtech and Gorgens servers in different countries continue, despite the published patches and a large number of recommendations. According to December 13, Check Point Technologies recorded more than 800 thousand cyber attacks operating Log4shell. Hackers are actively experimenting with exploites that have previously become free access, and rewrite them in order to implement new attack scenarios, explain in the company.
So, the Conti cybercriminals group using LOG4Shell spreads malicious software for redeems. The goal of hackers was the servers and virtualization systems VMware. The Iranian group of Phosphorus and Chinese Hafnium act similarly, but are looking for vulnerable cloud servers and attack DNS services, writes Microsoft.
According to the Chinese company Netlab 360, by December 13, Log4Shell and its modifications use at least ten hacker groups from different countries. The company determined the list of countries of residence of attackers according to their IP addresses: Germany, Netherlands, China, USA and Great Britain became anti-rating leaders. Attempts to operate vulnerabilities have been seen from 12 Russian IP addresses.
On December 20, the Belgian Ministry of Defense announced the disconnection of part of state servers due to attempts to hack state networks using LOG4Shell.
Cybercriminals may test the “worm” for automation of hacks
On Twitter, they continue to argue about the nature and tools of the December cyber attacks using Log4Shell. On December 19, the information security researcher Herman Fernandez discovered that hackers modified Mirai and created the Log4Shell worm . The malicious program scans the network and infects all found servers found with vulnerable versions of LOG4J harmful software. Subsequently, infected servers can form a large botnet.
Some information security experts reacted to the discovery of Fernandez skeptically: Greg Linares added that the worm probably threatens only unprotected Huawei roots, and Marcus Khatchins called the new worm “ineffective” and said that he “does not work” at all.
Personally, I did not call this program “worm”, because in fact it does not multiply on its own. The program only sends the lines of the exploit JNDI, into which the LDAP server is encoded ( component for access to remote catalogs, TJ explains ). Vulnerable systems will receive a request to connect to the LDAP server, which will operate. This is [not a worm, but] a guided scan program.
Marcus Hatchins
Tom Kellerman, the head of the VMware cybersecurity strategy, noted in an interview with ZDNET that high qualifications are required to create a working worm, which can have intelligence services of foreign states of hostile US.
At the same time, information security researchers so far know only one politically motivated log4shell attack. The hacker group of Iran Charming Kitten (“charming kitten” from English), also known as the APT-35, on December 15, tried to access the critical infrastructure of the Israel state.
At the time of publication of this material, LOG4Shell and related vulnerabilities use mainly financially motivated criminal groups, including the creators of the CHONSARI encryption and XMRIG miner, banking trojan operators and cryptocurrency abductors, Gizmodo explains.
* * *
According to Check Point Software Technologies, in Russia, the vulnerability of Log4Shell affected 72% of telecom companies, 58% of production and 57% of retail and wholesale enterprises. Its exposure to up to 52% of corporate networks.
On December 17, hackers tried to crack the Raiffeisenbank infrastructure, operating Log4Shell, wrote Vedomosti. According to two interlocutors of the publication in the information security services of Russian banks from the TOP-20, banks learned about vulnerability shortly before its official publication in the database on December 10, and then took measures to eliminate the threat.
More than 4.5 thousand attacks on Russian companies using Log4Shell were recorded in Kaspersky Laboratory, RBC wrote . At the same time, Group-Ib did not reveal a single case when such an attack caused significant damage to the victim, the publication of 3dnews noted .
With the filing of the IT community and the media, the vulnerability of Log4Shell got into memes.
The LOG4J crisis continues: new vulnerabilities have appeared in the library for Java, more than 800 thousand cyber attacks occurred • TJournal • RIMA — Russian Independent Media Archive