Rewterz Threat Advisory – CVE-2022-41066 – Microsoft Dynamics Business Central Vulnerability
November 10, 2022Rewterz Threat Advisory – Multiple Citrix ADC and Citrix Gateway Vulnerabilities 
November 10, 2022Rewterz Threat Advisory – CVE-2022-41066 – Microsoft Dynamics Business Central Vulnerability
November 10, 2022Rewterz Threat Advisory – Multiple Citrix ADC and Citrix Gateway Vulnerabilities 
November 10, 2022Severity
High
Analysis Summary
SharpPanda, the Chinese advanced persistent (APT) threat actor that has been active since at least 2018, has reinforced its cyber warfare activities. SharpPanda APT attacks and targets Southeast Asian government users with template injection of malicious documents. The attackers use spear-phishing to gain initial access and leverage old Microsoft Office vulnerabilities together with the chain of in-memory loaders to attempt and install a previously unknown backdoor on the victim’s machines. Upon opening the document, it connects back to the hacker’s server to download the payload file.
The campaign that initiates at the beginning of 2022 starts from the distribution of malicious DOCX documents that are sent to different employees of a government entity in Southeast Asia. In some cases, the emails are spoofed to look like they were from other government-related entities. The attachments to these emails are weaponized copies of legitimate-looking official documents and use the remote template technique to pull the next stage from the attacker’s server.
Impact
- Template Injection
- Exposure of Sensitive Data
Indicators of Compromise
IP
- 45[.]91[.]225[.]139
- 107[.]148[.]165[.]151
- 45[.]121[.]146[.]88
MD5
- 22f88a6d8729a08b457d078a798ef01f
SHA-256
- 1a15a35065ec7c2217ca6a4354877e6a1de610861311174984232ba5ff749114
SHA-1
- 879bfd34263da06b057a6fc05a07095a6cab58d3
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.