AI
AI

Iranian Hackers Exploit Windows Vulnerabilities to Target Critical Systems in the Gulf and Emirates

Photo credit: www.csoonline.com

Recent investigations have uncovered that the cyber incidents involving OilRig can be traced back to their use of a remote monitoring and management (RMM) solution called ngrok, which played a significant role in their operations.

Sensitive data exfiltration through Windows vulnerabilities

These cyberattacks have shown a clear pattern of exploiting unprotected web servers that host public-facing applications. Attackers leveraged a web shell to execute PowerShell scripts and move files, which gave them initial access to the network. This breach allowed attackers to download ngrok, facilitating their lateral movement across the system.

A key focus for these threat actors was the Domain Controller—a critical server responsible for managing permissions within a Windows domain. Their entry point was linked to the exploitation of CVE-2024-30088, a vulnerability associated with Windows Kernel Elevation of Privilege, as reported by Trend Micro. By deploying an exploit binary via the open-source tool RunPE-In-Memory, the attackers successfully escalated their privileges, thereby solidifying their control over the compromised system.

Source
www.csoonline.com

Related by category

Navigating the CISO Cloud Security Dilemma: Purchase, Build, or a Combination of Both?

Photo credit: www.csoonline.com Cloud security is not solely focused on...

Cyberkriminelle optimieren ihre Angriffsstrategien.

Photo credit: www.csoonline.com Cyberkriminalität zielt zunehmend auf kleine und mittelständische...

CNAPP-Kaufberatung

Photo credit: www.csoonline.com Cloud-Sicherheit bleibt ein anspruchsvolles Thema, vor allem,...

Latest news

Priyanka Chopra Declares WAVES 2025 a ‘Historic’ Event, Expresses Gratitude to PM Modi for Industry Support

Photo credit: www.news18.com Last Updated: May 01, 2025, 04:13 IST WAVES...

Ultimate Zani Build in Wuthering Waves: Weapons, Echoes, and Team Composition

Photo credit: dotesports.com Currently working with the Montelli family, Zani...

Explaining the Mandela Effect in Season 7 of ‘Black Mirror’

Photo credit: movieweb.com In Black Mirror Season 7, Episode 2,...

Breaking news