EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 Release Date September 07, 2023 Alert Code AA23-250A Related topics: Nation-State Threats , Cyber Threats and Response Actions to take today to mitigate malicious cyber activity: Patch all systems for known exploited vulnerabilities (KEVs), including firewall security appliances. Monitor for unauthorized use of remote access software using endpoint detection tools. Remove unnecessary (disabled) accounts and groups from the enterprise that are no longer needed, especially privileged accounts. SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Cyber National Mission Force (CNMF) identified the presence of indicators of compromise (IOCs) at an Aeronautical Sector organization as early as January 2023. Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application. Additional APT actors were also observed exploiting CVE-2022-42475 to establish presence on the organization’s firewall device. CISA and co-sealers are releasing this joint Cybersecurity Advisory (CSA) to provide network defenders with tactics, techniques, and procedures (TTPs), IOCs, and methods to detect and protect against similar exploitation. Download the PDF version of this report: AA23-250A Actors Exploit CVE-2022-47966 and CVE-2022-42475 (PDF, 681.49 KB ) For a downloadable copy of IOCs, see: AA23-250A STIX XML (XML, 69.24 KB ) AA23-250A STIX JSON (JSON, 69.89 KB ) For

Indicatori CISA verificabili

38 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T06:31:14.599535+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
ipv4-addr102[.]129[.]145[.]232
ipv4-addr191[.]96[.]106[.]40
ipv4-addr184[.]170[.]241[.]27
ipv4-addr154[.]6[.]93[.]24
ipv4-addr154[.]6[.]93[.]32
ipv4-addr154[.]6[.]93[.]12
ipv4-addr154[.]6[.]93[.]5
ipv4-addr154[.]6[.]93[.]22
ipv4-addr154[.]6[.]91[.]26
ipv4-addr103[.]105[.]49[.]108
ipv4-addr80[.]85[.]241[.]15
ipv4-addr92[.]118[.]39[.]82
ipv4-addr192[.]142[.]226[.]153
domain-namexpack[.]disqus[.]com
MD5a33354d598b58f2e55eb3619c3465f24
SHA-1e1c6f76085234554e9a47b61105cd45981eb35d2
SHA-2566dcc7b5e913154abac69687fcfb6a58ac66ec9b8cc7de7afd8832a9066b7bdde
MD51a0e111e60e543810423ef073b545c77
SHA-123cb74b530c49837595d766492279cc0cdc4692d
SHA-25647dacb8f0b157355a4fd59ccbac1c59b8268fe84f3b8a462378b064333920622
ipv4-addr207[.]246[.]105[.]240
ipv4-addr193[.]142[.]146[.]226
ipv4-addr104[.]238[.]234[.]145
ipv4-addr68[.]177[.]56[.]38
MD576adb0e36aac40cae0ebeb9f4bd38b52
SHA-182885f8c57cf4460f52db0a85e183d372f0aeb7e
SHA-25679a9136eedbf8288ad7357ddaea3a3cd1a57b7c6f82adffd5a9540e1623bfb63
ipv4-addr108[.]62[.]118[.]160
ipv4-addr144[.]202[.]2[.]71
ipv4-addr179[.]60[.]147[.]4
MD5b8967a33e6c1aee7682810b6b994b991
SHA-1bbda2ad0634aa535b9df40dc39a2d4dfdd763476
SHA-256334c2d0af191ed96b15095a4a098c400f2c0ce6b9c66d1800f6b74554d59ff4b
ipv4-addr45[.]90[.]123[.]194
domain-namemain[.]cloudfronts[.]net
domain-namecloudfronts[.]net
ipv4-addr47[.]90[.]240[.]218
ipv4-addr45[.]77[.]121[.]232

Provenienza

Allegato ufficiale CISA · 2023-09-06T15:15:48Z

SHA-512: 7e98fe2d4d2f2bef5585a3d1babaa5563ff502fc7f3ccb3b48aac911be8f23e74241d07ab110d1c94bf32ed92d42f7cfa69ed17c04307686f44a8eb7ce0199c2

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
07/09/2023 14:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1003, T1003.001, T1003.002, T1005, T1012, T1016, T1018, T1021, T1021.001, T1027, T1027.009, T1033, T1036, T1036.004, T1036.008, T1040, T1046, T1049, T1053.005, T1057, T1059, T1059.001, T1059.005, T1059.007, T1068, T1070, T1070.001, T1071, T1071.001, T1074, T1074.001, T1078.003, T1082, T1083, T1113, T1133, T1136, T1136.001, T1140, T1190, T1219, T1505, T1505.003, T1543.003, T1553, T1553.002, T1564, T1564.001, T1564.003, T1570, T1571, T1572, T1573, T1573.002, T1583, T1583.005, T1587, T1587.001, T1588, T1588.002
CVE
CVE-2022-47966, CVE-2022-42475, CVE-2021-44228
Classificazione
Critica
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale