EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 Release Date September 07, 2023 Alert Code AA23-250A Related topics: Nation-State Threats , Cyber Threats and Response Actions to take today to mitigate malicious cyber activity: Patch all systems for known exploited vulnerabilities (KEVs), including firewall security appliances. Monitor for unauthorized use of remote access software using endpoint detection tools. Remove unnecessary (disabled) accounts and groups from the enterprise that are no longer needed, especially privileged accounts. SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Cyber National Mission Force (CNMF) identified the presence of indicators of compromise (IOCs) at an Aeronautical Sector organization as early as January 2023. Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application. Additional APT actors were also observed exploiting CVE-2022-42475 to establish presence on the organization’s firewall device. CISA and co-sealers are releasing this joint Cybersecurity Advisory (CSA) to provide network defenders with tactics, techniques, and procedures (TTPs), IOCs, and methods to detect and protect against similar exploitation. Download the PDF version of this report: AA23-250A Actors Exploit CVE-2022-47966 and CVE-2022-42475 (PDF, 681.49 KB ) For a downloadable copy of IOCs, see: AA23-250A STIX XML (XML, 69.24 KB ) AA23-250A STIX JSON (JSON, 69.89 KB ) For

Indicatori CISA verificabili

38 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T06:31:14.599535+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
ipv4-addr102[.]129[.]145[.]232
ipv4-addr191[.]96[.]106[.]40
ipv4-addr184[.]170[.]241[.]27
ipv4-addr154[.]6[.]93[.]24
ipv4-addr154[.]6[.]93[.]32
ipv4-addr154[.]6[.]93[.]12
ipv4-addr154[.]6[.]93[.]5
ipv4-addr154[.]6[.]93[.]22
ipv4-addr154[.]6[.]91[.]26
ipv4-addr103[.]105[.]49[.]108
ipv4-addr80[.]85[.]241[.]15
ipv4-addr92[.]118[.]39[.]82
ipv4-addr192[.]142[.]226[.]153
domain-namexpack[.]disqus[.]com
MD5a33354d598b58f2e55eb3619c3465f24
SHA-1e1c6f76085234554e9a47b61105cd45981eb35d2
SHA-2566dcc7b5e913154abac69687fcfb6a58ac66ec9b8cc7de7afd8832a9066b7bdde
MD51a0e111e60e543810423ef073b545c77
SHA-123cb74b530c49837595d766492279cc0cdc4692d
SHA-25647dacb8f0b157355a4fd59ccbac1c59b8268fe84f3b8a462378b064333920622
ipv4-addr207[.]246[.]105[.]240
ipv4-addr193[.]142[.]146[.]226
ipv4-addr104[.]238[.]234[.]145
ipv4-addr68[.]177[.]56[.]38
MD576adb0e36aac40cae0ebeb9f4bd38b52
SHA-182885f8c57cf4460f52db0a85e183d372f0aeb7e
SHA-25679a9136eedbf8288ad7357ddaea3a3cd1a57b7c6f82adffd5a9540e1623bfb63
ipv4-addr108[.]62[.]118[.]160
ipv4-addr144[.]202[.]2[.]71
ipv4-addr179[.]60[.]147[.]4
MD5b8967a33e6c1aee7682810b6b994b991
SHA-1bbda2ad0634aa535b9df40dc39a2d4dfdd763476
SHA-256334c2d0af191ed96b15095a4a098c400f2c0ce6b9c66d1800f6b74554d59ff4b
ipv4-addr45[.]90[.]123[.]194
domain-namemain[.]cloudfronts[.]net
domain-namecloudfronts[.]net
ipv4-addr47[.]90[.]240[.]218
ipv4-addr45[.]77[.]121[.]232

Provenance

Allegato ufficiale CISA · 2023-09-06T15:15:48Z

SHA-512: 7e98fe2d4d2f2bef5585a3d1babaa5563ff502fc7f3ccb3b48aac911be8f23e74241d07ab110d1c94bf32ed92d42f7cfa69ed17c04307686f44a8eb7ce0199c2

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
07/09/2023 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1003, T1003.001, T1003.002, T1005, T1012, T1016, T1018, T1021, T1021.001, T1027, T1027.009, T1033, T1036, T1036.004, T1036.008, T1040, T1046, T1049, T1053.005, T1057, T1059, T1059.001, T1059.005, T1059.007, T1068, T1070, T1070.001, T1071, T1071.001, T1074, T1074.001, T1078.003, T1082, T1083, T1113, T1133, T1136, T1136.001, T1140, T1190, T1219, T1505, T1505.003, T1543.003, T1553, T1553.002, T1564, T1564.001, T1564.003, T1570, T1571, T1572, T1573, T1573.002, T1583, T1583.005, T1587, T1587.001, T1588, T1588.002
CVE
CVE-2022-47966, CVE-2022-42475, CVE-2021-44228
Classification
Critical
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source