Lazarus Group Exploits ManageEngine Vulnerability

2023-09-18 USHHS

https://www.hhs.gov/sites/default/files/manage-engine-vulnerability-sector-alert-tlpclear.pdf

Attachments

manage-engine-vulnerability-sector-alert-tlpclear.pdf (257 KB)

Thumbnail for Lazarus Group Exploits ManageEngine Vulnerability

Lazarus Group exploited CVE-2022-47966 in Zoho ManageEngine products to target internet backbone infrastructure and healthcare entities in Europe and the United States. After initial access, the actors deployed QuiteRAT, a Qt-based successor to MagicRAT that sends host information to command-and-control servers and executes reconnaissance commands through child cmd.exe processes. The campaign also used CollectionRAT, a remote access tool tied in the report to the Jupiter/EarlyRAT family and an Andariel-linked lineage, with capabilities for arbitrary command execution, metadata gathering, file management, and payload delivery. HC3 highlights the risk to healthcare and public health organizations because the vulnerability enables unauthenticated remote code execution across 24 ManageEngine products when SAML SSO has been enabled.

Indicators of Compromise

Type Value First Seen Last Seen
HASH db6a9934570fa98a93a979e7e0e218e… 2023-08-24 2024-12-27
HASH ed8ec7a8dd089019cfd29143f008fa0… 2023-08-24 2024-07-25
HASH 773760fd71d52457ba53a314f15dddb… 2023-08-24 2024-07-25
IPv4 146.4.21.94 2022-09-08 2023-09-22

Related Reports

« Back