Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium

2019-11-01 Kaspersky

https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/

Thumbnail for Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium

Kaspersky reported Operation WizardOpium, a Chrome zero-day exploitation campaign using CVE-2019-13720 before Google patched it in Chrome 78.0.3904.87. The attack profiled browsers, pulled exploit chunks from attacker infrastructure, used an image-delivered key and RC4 material to decrypt the exploit code, then downloaded an encrypted final payload that was decrypted, dropped as updata.exe, and persisted through Windows Task Scheduler. Kaspersky explicitly avoided firm attribution, noting only very weak Lazarus code similarities that could be false flags and that the targeted-site profile more closely resembled earlier DarkHotel-style activity. For DPRK tracking, the report is relevant mainly because of the possible but uncertain Lazarus overlap and the operation’s advanced browser-exploit tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f614909fbd57ece81d00b01958338ec2 2019-11-01 2019-11-01
HASH cafe8f704095b1f5e0a885f75b1b41a… 2019-11-01 2019-11-01
HASH 27e941683d09a7405a9e806cc7d156c9 2019-11-01 2019-11-01
HASH 8fb2558765cf648305493e1dfea7a2b… 2019-11-01 2019-11-01
HASH 8f3cd9299b2f241daf1f5057ba0b9054 2019-11-01 2019-11-01
HASH 35373d07c2e408838812ff210aa28d9… 2019-11-01 2019-11-01
EMAIL [email protected] 2019-11-01 2019-11-01
URL http://code.jquery.cdn.behindco… 2019-11-01 2019-11-01
DOMAIN behindcorona.com 2019-11-01 2019-11-01
DOMAIN code.jquery.cdn.behindcorona.com 2019-11-01 2019-11-01
« Back