Menu
Cyberespionage group Pawn Storm uses exploit for unpatched Java flaw

Cyberespionage group Pawn Storm uses exploit for unpatched Java flaw

The exploit was used in attacks against the armed forces of a NATO country and a U.S. defense organization

Big data

Big data

A sophisticated group of hackers known for targeting military, government and media organizations is currently using an exploit for a vulnerability in Java that hasn't been patched by Oracle.

The zero-day exploit was recently observed by researchers from antivirus vendor Trend Micro in attacks against the armed forces of an unnamed NATO country and a U.S. defense organization. Those targets received spear-phishing emails that contained links to Web pages hosting the exploit.

The cyberespionage group, known as APT28 and Pawn Storm, has been active since at least 2007. Some security vendors believe that it operates out of Russia and has ties to that country's intelligence services.

The group has been targeting NATO members and governments in Europe, Asia and the Middle East, as well as defense contractors and media organizations. It typically sends rogue emails to its victims with malicious links to supposed articles about geopolitical events.

The newly found exploit affects the latest version of the Java runtime environment, Java 8 Update 45, which was released in April, researchers from Trend Micro said in a blog post.

Surprisingly, the exploit doesn't affect the older Java 7 and Java 6 versions, which no longer receive public security patches from Oracle.

A couple of years ago Java was the most frequently attacked browser plug-in, which prompted Oracle to beef up security in Java 8.

This is the first Java zero-day exploit reported in nearly two years, the Trend Micro researchers said.

Zero-day exploits are those that target previously unknown vulnerabilities for which patches are not yet available.

Although unrelated, this exploit's discovery comes at a time when security researchers found three zero-day exploits for Flash Player in data leaked from a surveillance software maker called Hacking Team.

Disabling both Flash Player and Java is advisable until these vulnerabilities are patched, the Trend Micro researchers said in a separate blog post. "Extra caution should be exercised for the foreseeable future and special attention paid for the possibility of compromised ad servers."

"Flash and Java vulnerabilities are particularly well-suited for malvertising attacks, so we could possibly see these vulnerabilities incorporated into exploit kits that, in turn, are used to attack ad servers," the researchers said.

In fact, two of the newly found Flash Player exploits have already been integrated into exploit kits that are used in malvertising attacks.


Follow Us

Join the newsletter!

Or
Error: Please check your email address.

Tags securityOraclemalwaretrend microintrusionExploits / vulnerabilities

Featured

Slideshows

Bumper channel crowd kicks off first After Hours of 2018

Bumper channel crowd kicks off first After Hours of 2018

After Hours made a welcome return to the channel social calendar with a bumper crowd of partners, distributors and vendors descending on The Jefferson in Auckland to kick-start 2018. Photos by Gino Demeer.

Bumper channel crowd kicks off first After Hours of 2018
Looking back at the top 15 M&A deals in NZ during 2017

Looking back at the top 15 M&A deals in NZ during 2017

In 2017, merger and acquisitions fever reached new heights in New Zealand, with a host of big name deals dominating the headlines. Reseller News recaps the most important transactions of the Kiwi channel during the past 12 months.

Looking back at the top 15 M&A deals in NZ during 2017
Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Show Comments