MITRE Company Breached by Nation-State Hackers Exploiting Ivanti Flaws

Apr 22, 2024The Hacker InformationCommunity Safety / Cybersecurity

The MITRE Company revealed that it was the goal of a nation-state cyber assault that exploited two zero-day flaws in Ivanti Join Safe home equipment beginning in January 2024.

The intrusion led to the compromise of its Networked Experimentation, Analysis, and Virtualization Surroundings (NERVE), an unclassified analysis and prototyping community.

The unknown adversary “performed reconnaissance of our networks, exploited one of our Virtual Private Networks (VPNs) through two Ivanti Connect Secure zero-day vulnerabilities, and skirted past our multi-factor authentication using session hijacking,” Lex Crumpton, a defensive cyber operations researcher on the non-profit, mentioned final week.

Cybersecurity

The assault entailed the exploitation of CVE-2023-46805 (CVSS rating: 8.2) and CVE-2024-21887 (CVSS rating: 9.1), which could possibly be weaponized by risk actors to bypass authentication and run arbitrary instructions on the contaminated system.

Upon gaining preliminary entry, the risk actors moved laterally and breached its VMware infrastructure utilizing a compromised administrator account, in the end paving the best way for the deployment of backdoors and internet shells for persistence and credential harvesting.

“NERVE is an unclassified collaborative network that provides storage, computing, and networking resources,” MITRE mentioned. “Based on our investigation to date, there is no indication that MITRE’s core enterprise network or partners’ systems were affected by this incident.”

The group mentioned that it has since taken steps to comprise the incident, and that it undertook response and restoration efforts in addition to forensic evaluation to determine the extent of the compromise.

The preliminary exploitation of the dual flaws has been attributed to a cluster tracked by cybersecurity firm Volexity underneath the identify UTA0178, a nation-state actor seemingly linked to China. Since then, a number of different China-nexus hacking teams have joined the exploitation bandwagon, in response to Mandiant.

Cybersecurity

“No organization is immune from this type of cyber attack, not even one that strives to maintain the highest cybersecurity possible,” Jason Providakes, president and CEO of MITRE, mentioned.

“We are disclosing this incident in a timely manner because of our commitment to operate in the public interest and to advocate for best practices that enhance enterprise security as well as necessary measures to improve the industry’s current cyber defense posture.”

Discovered this text fascinating? This text is a contributed piece from one in all our valued companions. Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.

Recent articles

Hackers Use Microsoft MSC Information to Deploy Obfuscated Backdoor in Pakistan Assaults

Dec 17, 2024Ravie LakshmananCyber Assault / Malware A brand new...

INTERPOL Pushes for

Dec 18, 2024Ravie LakshmananCyber Fraud / Social engineering INTERPOL is...

Patch Alert: Essential Apache Struts Flaw Discovered, Exploitation Makes an attempt Detected

Dec 18, 2024Ravie LakshmananCyber Assault / Vulnerability Risk actors are...