Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
Cosa significa
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Perché conta
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Azioni consigliate
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Cybersecurity Advisory Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 Release Date September 07, 2023 Alert Code AA23-250A Related topics: Nation-State Threats , Cyber Threats and Response Actions to take today to mitigate malicious cyber activity: Patch all systems for known exploited vulnerabilities (KEVs), including firewall security appliances. Monitor for unauthorized use of remote access software using endpoint detection tools. Remove unnecessary (disabled) accounts and groups from the enterprise that are no longer needed, especially privileged accounts. SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Cyber National Mission Force (CNMF) identified the presence of indicators of compromise (IOCs) at an Aeronautical Sector organization as early as January 2023. Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application. Additional APT actors were also observed exploiting CVE-2022-42475 to establish presence on the organization’s firewall device. CISA and co-sealers are releasing this joint Cybersecurity Advisory (CSA) to provide network defenders with tactics, techniques, and procedures (TTPs), IOCs, and methods to detect and protect against similar exploitation. Download the PDF version of this report: AA23-250A Actors Exploit CVE-2022-47966 and CVE-2022-42475 (PDF, 681.49 KB ) For a downloadable copy of IOCs, see: AA23-250A STIX XML (XML, 69.24 KB ) AA23-250A STIX JSON (JSON, 69.89 KB ) For
Indicatori CISA verificabili
38 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T06:31:14.599535+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| ipv4-addr | 102[.]129[.]145[.]232 | |
| ipv4-addr | 191[.]96[.]106[.]40 | |
| ipv4-addr | 184[.]170[.]241[.]27 | |
| ipv4-addr | 154[.]6[.]93[.]24 | |
| ipv4-addr | 154[.]6[.]93[.]32 | |
| ipv4-addr | 154[.]6[.]93[.]12 | |
| ipv4-addr | 154[.]6[.]93[.]5 | |
| ipv4-addr | 154[.]6[.]93[.]22 | |
| ipv4-addr | 154[.]6[.]91[.]26 | |
| ipv4-addr | 103[.]105[.]49[.]108 | |
| ipv4-addr | 80[.]85[.]241[.]15 | |
| ipv4-addr | 92[.]118[.]39[.]82 | |
| ipv4-addr | 192[.]142[.]226[.]153 | |
| domain-name | xpack[.]disqus[.]com | |
| MD5 | a33354d598b58f2e55eb3619c3465f24 | |
| SHA-1 | e1c6f76085234554e9a47b61105cd45981eb35d2 | |
| SHA-256 | 6dcc7b5e913154abac69687fcfb6a58ac66ec9b8cc7de7afd8832a9066b7bdde | |
| MD5 | 1a0e111e60e543810423ef073b545c77 | |
| SHA-1 | 23cb74b530c49837595d766492279cc0cdc4692d | |
| SHA-256 | 47dacb8f0b157355a4fd59ccbac1c59b8268fe84f3b8a462378b064333920622 | |
| ipv4-addr | 207[.]246[.]105[.]240 | |
| ipv4-addr | 193[.]142[.]146[.]226 | |
| ipv4-addr | 104[.]238[.]234[.]145 | |
| ipv4-addr | 68[.]177[.]56[.]38 | |
| MD5 | 76adb0e36aac40cae0ebeb9f4bd38b52 | |
| SHA-1 | 82885f8c57cf4460f52db0a85e183d372f0aeb7e | |
| SHA-256 | 79a9136eedbf8288ad7357ddaea3a3cd1a57b7c6f82adffd5a9540e1623bfb63 | |
| ipv4-addr | 108[.]62[.]118[.]160 | |
| ipv4-addr | 144[.]202[.]2[.]71 | |
| ipv4-addr | 179[.]60[.]147[.]4 | |
| MD5 | b8967a33e6c1aee7682810b6b994b991 | |
| SHA-1 | bbda2ad0634aa535b9df40dc39a2d4dfdd763476 | |
| SHA-256 | 334c2d0af191ed96b15095a4a098c400f2c0ce6b9c66d1800f6b74554d59ff4b | |
| ipv4-addr | 45[.]90[.]123[.]194 | |
| domain-name | main[.]cloudfronts[.]net | |
| domain-name | cloudfronts[.]net | |
| ipv4-addr | 47[.]90[.]240[.]218 | |
| ipv4-addr | 45[.]77[.]121[.]232 |
Provenienza
Allegato ufficiale CISA · 2023-09-06T15:15:48Z
SHA-512: 7e98fe2d4d2f2bef5585a3d1babaa5563ff502fc7f3ccb3b48aac911be8f23e74241d07ab110d1c94bf32ed92d42f7cfa69ed17c04307686f44a8eb7ce0199c2
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 07/09/2023 14:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1003, T1003.001, T1003.002, T1005, T1012, T1016, T1018, T1021, T1021.001, T1027, T1027.009, T1033, T1036, T1036.004, T1036.008, T1040, T1046, T1049, T1053.005, T1057, T1059, T1059.001, T1059.005, T1059.007, T1068, T1070, T1070.001, T1071, T1071.001, T1074, T1074.001, T1078.003, T1082, T1083, T1113, T1133, T1136, T1136.001, T1140, T1190, T1219, T1505, T1505.003, T1543.003, T1553, T1553.002, T1564, T1564.001, T1564.003, T1570, T1571, T1572, T1573, T1573.002, T1583, T1583.005, T1587, T1587.001, T1588, T1588.002
- CVE
- CVE-2022-47966, CVE-2022-42475, CVE-2021-44228
- Classificazione
- Critica
- Paese indicato
- US
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.
Azione indicata dalla fonte
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
Riferimenti tecnici ufficiali
- https://www.cisa.gov/sites/default/files/2023-09/aa23-250a-apt-actors-exploit-cve-2022-47966-and-cve-2022-42475_1.pdf
- https://www.cisa.gov/sites/default/files/2023-09/AA23-250A.stix_.xml
- https://www.cisa.gov/sites/default/files/2023-09/AA23-250A%20Multiple%20Nation-State%20Threat%20Actors%20Exploit%20CVE-2022-47966%20and%20CVE-2022-42475.stix_.json
- https://www.cisa.gov/sites/default/files/2023-09/MAR-10430311.c1.v1.CLEAR_.pdf
- https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf
- https://www.cisa.gov/sites/default/files/publications/CISAInsights-Cyber-RemediateVulnerabilitiesforInternetAccessibleSystems_S508C.pdf
- https://www.cisa.gov/sites/default/files/publications/layering-network-security-segmentation_infographic_508_0.pdf
- https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf