{"id":48066,"date":"2017-10-18T06:14:50","date_gmt":"2017-10-18T06:14:50","guid":{"rendered":"https:\/\/www.biphoo.com\/bipnews\/?p=48066"},"modified":"2017-10-18T06:16:51","modified_gmt":"2017-10-18T06:16:51","slug":"blackoasis-apt-exploits-flash-zero-day-to-download-finfisher-spyware","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/blackoasis-apt-exploits-flash-zero-day-to-download-finfisher-spyware.html","title":{"rendered":"BlackOasis APT exploits Flash zero-day to download FinFisher spyware"},"content":{"rendered":"<h2 style=\"text-align: justify\"><span style=\"font-size: 18pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">BlackOasis APT exploits Flash zero-day to download FinFisher spyware<\/span><\/strong><\/span><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">BlackOasis APT exploits Flash zero-day to download FinFisher spyware:- AN ADVANCED PERSISTENT THREAT (APT) exploiting a new Adobe Flash zero-day exploit that downloads Gamma FinFisher surveillance software has been uncovered by security vendor Kaspersky.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">The threat starts with an infected RTF or other Office file, which then triggers an exploit that utilises the Flash zero-day to download FinFisher, which is used to exfiltrate data and monitor activity on the infected Windows machine.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">FinFisher is the product of Anglo-German firm Gamma International which sells exploits and surveillance software to nefarious regimes such as Angola, Saudi Arabia and Venezuela. The company was itself hacked in 2014, and many of its secrets were uploaded to the internet. However, the perpetrator of the latest threat seems to be a group known as BlackOasis, one of Gamma\u2019s \u2018legitimate\u2019 customers. It uses the latest version of FinFisher.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">BlackOasis is probably based in the Middle East, and Kaspersky says it has been tracking the group\u2019s activities since May 2016. The latest exploit uses command and control servers deployed in previous attacks that were attributed to that actor, it claims, and has a similar modus operandi.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">The targets of BlackOasis include senior figures in the UN, think tank members, opposition bloggers and activists and journalists, mostly in the Middle East but also in the UK, Russia, Afghanistan, Nigeria, Libya, Netherlands and Angola. Oil seems to be a common factor linking many of the targets.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">\u201cThe attack begins with the delivery of an Office document, presumably in this instance via e-mail,\u201d says Kaspersky. \u201cEmbedded within the document is an ActiveX object which contains the Flash exploit.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">The Flash object contains an ActionScript which is responsible for extracting the malware which then attacks a memory corruption vulnerability.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">If this exploit is successful, \u201cit will gain arbitrary read \/ write operations within memory, thus allowing it to execute a second stage shellcode,\u201d the company continues, adding that the first stage shellcode is designed \u201cto avoid detection by antivirus products looking for large NOP blocks inside Flash files\u201d.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">This second stage payload is the Gamma FinFisher software which is then injected into the Windows login process. Once active it communicates with three command and control servers which are used to exfiltrate information from the infected machine and to monitor activity.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Adobe has released a patch for the critical exploit, which it has listed as CVE-2017-11292, for Adobe Flash Player for Windows, Macintosh, Linux and Chrome OS.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Kaspersky is aware of one incident in which the APT has been used to attack a customer. It advises organisations and individuals to disable Flash where possible and to deploy a \u201cmulti-layered approach including access policies, anti-virus, network monitoring and whitelisting\u201d to protect against similar attacks.<\/span><\/p>\n<p><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 8pt\">Source:-\u00a0http:\/\/gearsofbiz.com\/blackoasis-apt-exploits-flash-zero-day-to-download-finfisher-spyware\/132765<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/blackoasis-apt-exploits-flash-zero-day-to-download-finfisher-spyware.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>BlackOasis APT exploits Flash zero-day to download FinFisher spyware BlackOasis APT exploits Flash zero-day to download FinFisher spyware:- AN ADVANCED PERSISTENT THREAT (APT) exploiting a new Adobe Flash zero-day exploit that downloads Gamma FinFisher surveillance software has been uncovered by security vendor Kaspersky. The threat starts with an infected RTF [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":48070,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[80741,80737,80738,80736,80740,80739],"class_list":["post-48066","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-adobe-flash-player","tag-adobe-flash-zero-day","tag-anglo-german-firm-gamma","tag-blackoasis-apt-exploits","tag-gamma-finfisher-software","tag-latest-version-of-finfisher"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/48066","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=48066"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/48066\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/48070"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=48066"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=48066"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=48066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}