• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Critical 0-day that targeted security researchers gets a patch from Microsoft

March 9, 2021
Share on FacebookShare on Twitter

Microsoft has patched a critical zero-day vulnerability that North Korean hackers were using to target security researchers with malware.

The in-the-wild attacks came to light in January in posts from Google and Microsoft. Hackers backed by the North Korean government, both posts said, spent weeks developing working relationships with security researchers. To win the researchers’ trust, the hackers created a research blog and Twitter personas who contacted researchers to ask if they wanted to collaborate on a project.

Eventually, the fake Twitter profiles asked the researchers to use Internet Explorer to open a webpage. Those who took the bait would find that their fully patched Windows 10 machine installed a malicious service and an in-memory backdoor that contacted a hacker-controlled server.

Microsoft on Tuesday patched the vulnerability. CVE-2021-26411, as the security flaw is tracked, is rated critical and requires only low-complexity attack code to exploit.

From rags to riches

Google said only that the people who reached out to the researchers worked for the North Korean government. Microsoft said they were part of Zinc, Microsoft’s name for a threat group that is better known as Lazarus. Over the past decade, Lazarus has transformed from a ragtag group of hackers to what can often be a formidable threat actor.

Advertisement

A United Nations report from 2019 reportedly estimated Lazarus and associated groups have generated $2 billion for the country’s weapons of mass destruction programs. Lazarus has also been tied to the Wannacry worm that shut down computers around the world, fileless Mac malware, malware that targets ATMs, and malicious Google Play apps that targeted defectors.

Besides using the watering-hole attack that exploited IE, the Lazarus hackers who targeted the researchers also sent targets a Visual Studio Project purportedly containing source code for a proof-of-concept exploit. Stashed inside the project was custom malware that contacted the attackers’ control server.

While Microsoft describes CVE-2021-26411 as an “Internet Explorer Memory Corruption Vulnerability,” Monday’s advisory says the vulnerability also affects Edge, a browser Microsoft built from scratch that’s considerably more secure than IE. The vulnerability retains its critical rating for Edge, but there are no reports that exploits have actively targeted users of that browser.

The patch came as part of Microsoft’s Update Tuesday. In all, Microsoft issued 89 patches. Besides the IE vulnerability, a separate escalation privilege flaw in the Win32k component is also under active exploit. Patches will install automatically over the next day or two. Those who want the updates immediately should go to Start > settings (the gear icon) > Update & Security > Windows Update.

Next Post

Last-minute ROG Phone 5 renders show off some stylish changes, including a new white color option

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Steven Spielberg says Barack Obama’s alien comments are ‘so great for ‘Disclosure Day”
  • Donkey Kong Bananza Began As A Goomba With Giant Fists
  • Shark Rocket Ultra-Light Vacuum deal: $99 at Amazon
  • Instagram to discontinue end-to-end encryption for DMs [Update: Meta’s statement]
  • Best TV deals this week: Save big on TCL T7, Hisense U8, and Samsung Q8F models

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously