• Home
  • Contact
  • News
What's Hot

New license deal reached by Apple and Ericsson ends a patent feud that started in 2015

December 10, 2022

Tor browser finally gets Apple Silicon support in new update

December 10, 2022

Nothing will open its first brick & mortar location in Soho this weekend

December 10, 2022
Facebook Twitter Instagram
  • Demos
  • Buy Now
Facebook Twitter Instagram
Latest Tech News
  • Home
  • Contact
  • News
Latest Tech News
Home»news»Google says North Korea targeted an Internet Explorer zero-day vulnerability
news

Google says North Korea targeted an Internet Explorer zero-day vulnerability

anitjha31@gmail.comBy anitjha31@gmail.comDecember 8, 2022No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Cybersecurity researchers from Google’s Threat Analysis Group (TAG) have discovered a vulnerability in the Internet Explorer (IE) browser. (Opens in a new tab) It is being exploited by a known North Korean threat actor.

in blog post (Opens in a new tab) Detailing its findings, the group said it spotted the group APT37 (AKA Erebus), targeting individuals in South Korea with an armed Microsoft Word file.

The file is titled “Seoul Yongsan Itaewon Incident Response Case 221031 (06:00).docx,” which is a reference to the recent tragedy that occurred in Itaewon, Seoul, during this year’s Halloween celebration, in which at least 158 ​​lives were missing. live, with 200 others injured. Apparently, the attackers wanted to exploit the public and media interest in the incident.

Exploit old flaws

After analyzing the document being distributed, TAG finds that it downloads a remote formatted text file (RTF) template to the target endpoint, which then captures the remote HTML content. Microsoft may have retired Internet Explorer and replaced it with Edge, TAG said, but Office still renders HTML content using IE, a fact known by abusers since at least 2017.

Now that Office renders HTML content using IE, attackers can abuse the zero-day they discovered in IE’s JScript engine.

The team discovered the flaw in “jscript9.dll,” the JavaScript engine in Internet Explorer, that allowed threat actors to execute arbitrary code when a website was brought under their control.

Microsoft was notified on October 31, 2022, with the bug named CVE-2022-41128 three days later, and a patch released on November 8.

While the operation so far only compromises the device, TAG has yet to find out what the purpose is. The company said it had not found the final APT37 payload for this campaign, but added that the group has been seen in the past delivering malware such as Rokrat, Bluelight or Dolphin.

Across: the edge (Opens in a new tab)

See here for more

Featured trending
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
anitjha31@gmail.com
  • Website

Related Posts

New license deal reached by Apple and Ericsson ends a patent feud that started in 2015

December 10, 2022

Tor browser finally gets Apple Silicon support in new update

December 10, 2022

Nothing will open its first brick & mortar location in Soho this weekend

December 10, 2022

Microsoft testing a new Windows 11 screen recorder so you can stop using the Xbox Game Bar

December 10, 2022
Add A Comment

Leave A Reply Cancel Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Top Posts

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Advertisement
Demo

Your source for the serious news. This demo is crafted specifically to exhibit the use of the theme as a news site. Visit our main page for more demos.

We're social. Connect with us:

Facebook Twitter Instagram Pinterest YouTube
Top Insights

New license deal reached by Apple and Ericsson ends a patent feud that started in 2015

December 10, 2022

Tor browser finally gets Apple Silicon support in new update

December 10, 2022

Nothing will open its first brick & mortar location in Soho this weekend

December 10, 2022
Get Informed

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook Twitter Instagram Pinterest
  • Home
  • Contact
  • News
© 2023 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.