March 29, 2022

Weekly Threat Digest: 21 – 27 March 2022

The fourth week of March 2022 witnessed the discovery of 340 vulnerabilities out of which 10 gained the attention of Threat Actors and security researchers worldwide. Among these 10, there was 1 which is undergoing reanalysis, and 2 were not present in the NVD at all. Hive Pro Threat Research Team has curated a list of 10 CVEs that require immediate action.

Furthermore, we also observed five threat actor groups being highly active in the last week. The Lapsus$, a new extortion threat actor group had attacked popular organizations such as Brazilian Ministry of Health, NVIDIA, Samsung, Vodafone, Ubisoft, Octa, and Microsoft for data theft and destruction, was observed using the Redline info-stealer. Additionally, North Korean state hackers known as Lazarus group, was exploiting the zero-day vulnerability in Google Chrome’s web browser (CVE-2022-0609). AvosLocker is a Ransomware as a Service (RaaS) affiliate-based group that has targeted 50+ organizations is currently exploiting Proxy Shell vulnerabilities (CVE-2021-31206, CVE-2021-31207, CVE-2021-34523, CVE-2021-34473, CVE-2021-26855). The threat actor APT35 aka Magic Hound, an Iranian-backed threat group is exploiting the Proxy Shell vulnerabilities to attack organizations across the globe. Another South Korean APT group DarkHotel was targeting the hospitality industry in China. Common TTPs which could potentially be exploited by these threat actors or CVEs can be found in the detailed section below.

Active Actors:

APT 35 (Magic Hound, Cobalt Illusion, Charming Kitten, TEMP.Beanie, Timberworm, Tarh Andishan, TA453, ITG18, Phosphorus, Newscaster)IranInformation theft and espionage 
AvosLockerUnknownEcrime, Information theft, and Financial gain
Lazarus Group (Labyrinth Chollima, Group 77, Hastati Group, Whois Hacking Team, NewRomanic Cyber Army Team, Zinc, Hidden Cobra, Appleworm, APT-C-26, ATK 3, SectorA01, ITG03)North KoreaInformation theft and espionage, Sabotage and destruction, Financial crime
Lapsus$ (DEV-0537)UnknownData theft and Destruction
DarkHotel (APT-C-06, SIG25, Dubnium, Fallout Team, Shadow Crane, CTG-1948, Tungsten Bridge, ATK 52, Higaisa, TAPT-02, Luder)South KoreaInformation theft and espionage

Targeted Location:

Targeted Sectors:

Common TTPs:

Threat Advisories:

Microsoft’s privilege escalation vulnerability that refuses to go away

Google Chrome’s second zero-day in 2022

Magic Hound Exploiting Old Microsoft Exchange ProxyShell Vulnerabilities

AvosLocker Ransomware group has targeted 50+ Organizations Worldwide

North Korean state-sponsored threat actor Lazarus Group exploiting Chrome Zero-day vulnerability

LAPSUS$ – New extortion group involved in the breach against Nvidia, Microsoft, Okta and Samsung

DarkHotel APT group targeting the Hospitality Industry in China

New Threat Actor using Serpent Backdoor attacking French Entities

Muhstik botnet adds another vulnerability exploit to its arsenal

