Blue Mockingbird Monero-Mining Campaign Exploits Web Apps
#1
Information 
Quote:The campaign has been dubbed Blue Mockingbird by the analysts at Red Canary that discovered the activity. Research uncovered that the cybercriminal gang is exploiting a deserialization vulnerability, CVE-2019-18935, which can allow remote code execution. The bug is found in the Progress Telerik UI front-end offering for ASP.NET AJAX.
 
AJAX stands for Asynchronous JavaScript and XML; It’s used to add script to a webpage which is executed and processed by the browser. Progress Telerik UI is an overlay for controlling it on ASP.NET implementations.
 
The vulnerability lies specifically in the RadAsyncUpload function, according to the writeup on the bug in the National Vulnerability Database. This is exploitable when the encryption keys are known (via another exploit or other attack), meaning that any campaign relies on a chaining of exploits.
 
In the current attacks, Blue Mockingbird attackers are uncovering unpatched versions of Telerik UI for ASP.NET, deploying the XMRig Monero-mining payload in dynamic-link library (DLL) form on Windows systems, then executing it and establishing persistence using multiple techniques. From there, the infection propagates laterally through the network.

The activity appears to stretch back to December, according to the analysis, and continued through April at least.

Read more: https://threatpost.com/blue-mockingbird-...ng/155581/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Publishes Firefox Roadmap With N...
Mozilla has releas...harlan4096 — 10:18
Sysinternals Suite 6.17.2026
Sysinternals Suite ...harlan4096 — 10:00
AxCrypt 3.1.1.0
AxCrypt 3.1.1.0: ...harlan4096 — 09:57
Tor Browser 15.0.16
Tor Browser 15.0.1...harlan4096 — 09:56
Bitdefender 27.0.60.338
Latest version of ...harlan4096 — 09:54

[-]
Birthdays
Today's Birthdays
avatar (39)biobdam
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>