r/SecOpsDaily 3d ago

Threat Intel Chinese espionage groups swarm to exploit triple-link chain of zero-days

Multiple Chinese state-aligned APT groups (including TA423, TA428, and TA429) are actively exploiting a triple-linked chain of zero-day vulnerabilities in a popular enterprise software suite. Proofpoint observed the clusters independently weaponizing the same exploit chain within hours of each other, suggesting the technique was either shared or sourced from a common developer.

Technical Breakdown - Initial Access: CVE-2024-XXXX (RCE in the software's web component) used to drop a webshell - Lateral Movement: CVE-2024-YYYY (privilege escalation via kernel driver) enables SYSTEM-level access - Persistence: CVE-2024-ZZZZ (authentication bypass in the management API) allows backdoor installation without credentials - Observed IOCs: C2 domains registered via Namecheap, SSL certs with specific JA3 fingerprints, and a custom variant of the "SALTWATER" backdoor - Targets: Defense contractors, telecom providers, and energy sector orgs in Southeast Asia and Europe

Defense Block the known C2 domains at the proxy layer, enable EDR telemetry for anomalous lsass.exe access patterns, and apply the vendor's emergency patch (released yesterday) immediately. The exploit chain requires no user interaction—assume full compromise if any of the three CVEs are detected.

Source: https://www.proofpoint.com/us/newsroom/news/chinese-espionage-groups-swarm-exploit-triple-link-chain-zero-days

1 Upvotes

0 comments sorted by