On Tuesday, Microsoft patched the vulnerabilities affecting its products. One of the internet explorer zero-day vulnerabilities was, identified as CVE-2016-3298, described as information disclosure issue which affected Internet Explorer in the wild. The internet explorer zero-day vulnerability targets the object handling of the web-browser in the memory and tests for the presence of data on disk by directing a targeted user into opening a specific website.
After the patch, the attackers found a way to avoid automated analysis systems and researchers to exploit the said vulnerability to exploit in malvertising campaigns, discovered by security firm “Proofpoint.”
The researchers at Proofpoint identified the exploit is now affecting the vulnerability into massive malvertising campaigns by AdGholas and GooNky, the two threat actors.
Experts at Proofpoint first spotted the malvertising campaign back in April, which was targeting users in France, they believe that it had been leveraged by AdGholas.
The group also exploited the patched internet explorer zero-day vulnerability CVE-2016-3351 which affected Microsoft Edge last month. Experts at Proofpoint believe that the flaw is being exploited since 2014. These two vulnerabilities allowed the cybercriminals in ensuring that the targeted systems don’t belong to the security researchers.
The attackers used MIME-type checks to look for file types usually used by security researchers that are associated with any program. They checked for the association of file extensions such as .pcap, .py and .saz with any application, which typically indicates the existence of analysis environment. The hackers also searched for common file types such as .doc, .mp4, .mkv to determine if the system is used by regular users.
In a blog post, Proofpoint explained that “Threat actors, particularly those in the AdGholas and GooNky groups, continue to look for new means to exploit browser flaws. More importantly, though, they are turning to flaws that allow them to focus on “high-quality users”, specifically consumers rather than researchers, vendors, and sandbox environments that could detect their operations. Information disclosure vulnerabilities like CVE-2016-3298 described here and the previously discussed CVE-2016-3351 allow actors to filter based on software and configurations typically associated with security research environments.”
Share this article
About the Author
Peter Buttler an Infosec Journalist and Tech Reporter, Member of IDG Network. In 2011, he completed Masters in Cybersecurity and technology. He worked for leading security and tech giants as Staff Writer. Currently, he contributes to a number of online publications, including The Next Web, CSO Online, Infosecurity Mag, SC Magazine, Tripwire, GlobalSign CSO Australia, etc. His favorite areas Online Privacy, AI, IoT, VR, Blockchain, Big Data, ML, Fintech, etc. You can follow him on twitter.
More from Peter ButtlerRelated Posts
Google and FBI Disrupt NetNut Residential Proxy Network Used by 2M+ Devices
Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as ...
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
FBI Warns of ‘Kali365’ Subscription Service Targeting Microsoft 365 Accounts
The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for s...