Circumstances of the Andariel Group Exploiting an Apache ActiveMQ Vulnerability (CVE-2023-46604) – ASEC BLOG

The Andariel threat group is suspected of exploiting the Apache ActiveMQ CVE-2023-46604 remote code execution vulnerability to deploy malware, including NukeSped and TigerRat backdoors, after observing related activity such as HelloKitty-related components. The attacks target South Korean organizations across defense, government, industry, and academia, and use downloader activity, CobaltStrike/Meterpreter stagers, and various URLs and IPs to control infected hosts. #Andariel #NukeSped #TigerRat #HelloKitty #CobaltStrike #Metasploit #Lazarus #ApacheActiveMQ #CVE-2023-46604

Keypoints

  • The Andariel threat group is linked to South Korean targets and possibly to Lazarus, with activity dating back to 2008 across defense, political, shipbuilding, energy, and telecom sectors.
  • CVE-2023-46604 in Apache ActiveMQ is leveraged to execute remote commands on unpatched servers exposed to the Internet.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – ‘CVE-2023-46604 is a remote code execution vulnerability in Apache ActiveMQ… If an unpatched Apache ActiveMQ server is exposed externally, the threat actor can execute malicious commands remotely and take control over the system.’
  • [T1105] Ingress Tool Transfer – ‘The threat actor used the following malicious Java class file during the vulnerability attack process. This malware ultimately downloads and installs an additional payload in Windows or Linux environments.’
  • [T1071.001] Web Protocols – ‘During the initial communication with the C&C server, the POST method was used, but a GET method disguised as being for visiting Google was used to transmit the results of executing commands received from the C&C and any command execution failure messages.’
  • [T1027] Obfuscated/Compressed Files and Information – ‘The encryption method is a 1-byte XOR algorithm with the key value 0xA1. Besides 0xA1, in past attack cases, key values 0x97 and 0xAB were also used.’
  • [T1059] Command and Scripting Interpreter – ‘The following three commands are supported. The only actual available actions are downloading files from the C&C server, executing commands received from the C&C, and returning their results.’
  • [T1070.004] Indicator Removal on Host – ‘When a connection to the C&C server is not established properly, auto-deletion is executed by using a batch file, which is similar to that of ordinary NukeSped backdoors. The batch file used for auto-deletion is created in the “%TEMP%uninst.bat” path.’

Indicators of Compromise

  • [IP Address] C2 servers and download endpoints – 27.102.114.215:8000, 137.175.17.221:48084, and 137.175.17.172:41334
  • [Domain/URL] CobaltStrike server and download pages – hxxps://206.166.251.186/jquery-3.3.1.min.js
  • [MD5] File hashes for detected components – 7699ba4eab5837a4ad9d5d6bbedffc18; c2f8c9bb7df688d0a7030a96314bb493
  • [File Name] Sample executables observed – rang.exe, load.exe, agent_w.exe
  • [MD5] Additional related drops – 478dcb54e0a610a160a079656b9582de; 26ff72b0b85e764400724e442c164046
  • [URL] Key download endpoints – hxxp://137.175.17[.]221:1443/ac.jar; hxxp://168.100.9[.]154:9090/Notification.msi

Read more: https://asec.ahnlab.com/en/59318/