Lazarus Group Exploits ManageEngine Vulnerability
2023-09-18 • USHHS •
https://www.hhs.gov/sites/default/files/manage-engine-vulnerability-sector-alert-tlpclear.pdf
Attachments
Lazarus Group exploited CVE-2022-47966 in Zoho ManageEngine products to target internet backbone infrastructure and healthcare entities in Europe and the United States. After initial access, the actors deployed QuiteRAT, a Qt-based successor to MagicRAT that sends host information to command-and-control servers and executes reconnaissance commands through child cmd.exe processes. The campaign also used CollectionRAT, a remote access tool tied in the report to the Jupiter/EarlyRAT family and an Andariel-linked lineage, with capabilities for arbitrary command execution, metadata gathering, file management, and payload delivery. HC3 highlights the risk to healthcare and public health organizations because the vulnerability enables unauthenticated remote code execution across 24 ManageEngine products when SAML SSO has been enabled.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | db6a9934570fa98a93a979e7e0e218e… | 2023-08-24 | 2024-12-27 |
| HASH | ed8ec7a8dd089019cfd29143f008fa0… | 2023-08-24 | 2024-07-25 |
| HASH | 773760fd71d52457ba53a314f15dddb… | 2023-08-24 | 2024-07-25 |
| IPv4 | 146.4.21.94 | 2022-09-08 | 2023-09-22 |