📋 Top Headlines at a Glance
- Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
- APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
- New Evooo1Bot Linux botnet turns routers into traffic relay nodes
Executive Summary: Today’s intelligence highlights a critical convergence of threats across the digital landscape. We observe significant advancements in software supply chain security with expanded malware alerting, alongside persistent state-sponsored espionage leveraging sophisticated cloud-based command and control. Concurrently, new Linux-based botnets are emerging, actively exploiting internet-facing devices. Organizations must prioritize comprehensive vulnerability management, robust cloud security postures, and enhanced supply chain integrity to counter these evolving threats.
🌍 Technical Intelligence Breakdown
🚨 Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
This report details several critical security developments. GitHub’s Dependabot has significantly expanded its malware alert capabilities, now covering eight major software ecosystems beyond npm. This includes PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer packages. This expansion is a crucial step in improving software supply chain security by providing broader detection for malicious dependencies.
Additionally, the report highlights a prolonged exposure of Salesforce and ServiceNow portals, lasting 17 months. Such extended exposures can lead to significant data breaches or unauthorized access. An exploited Metabase 0-day vulnerability is also mentioned, indicating active exploitation of a critical flaw in an Unknown product.
Key Defensive Actions:
- Supply Chain Security: Implement automated dependency scanning tools like
Dependabotacross all development pipelines. Regularly audit third-party libraries and components. - Cloud Security Posture Management (CSPM): Continuously monitor
SalesforceandServiceNowconfigurations for misconfigurations, excessive permissions, and public exposures. - Vulnerability Management: Promptly patch
Metabaseinstances and other critical software, prioritizing known exploited vulnerabilities.
🕵️ APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
Researchers have uncovered an espionage operation attributed to APT36, dubbed PATCHCORD. This campaign utilizes a previously undocumented backdoor, also named PATCHCORD, which targets Afghan telecom and South Asian infrastructure. The threat actor employs fake VPN tools as an initial compromise vector, indicating a focus on social engineering or watering hole attacks. A notable tactic is the use of Google Sheets for command and control (C2) communications, a technique that can evade traditional network defenses due to its reliance on legitimate cloud services.
Key Defensive Actions:
- User Awareness Training: Educate users on the dangers of downloading software from unofficial sources, especially
fake VPN tools. - Network Monitoring: Implement advanced analytics to detect anomalous traffic patterns to legitimate cloud services like
Google Sheetsthat might indicate C2 activity. - Endpoint Detection and Response (EDR): Deploy EDR solutions to detect
PATCHCORDbackdoor activity, including persistence mechanisms and process injection.
🤖 New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Linux-based botnet, identified as Evooo1Bot, has emerged. This botnet is derived from the Mirai malware family and is modular in design. Evooo1Bot specifically targets internet-facing gateway devices, such as routers, transforming them into SOCKS5 traffic relay nodes. This allows the botnet operators to anonymize their malicious traffic, conduct further attacks, or facilitate other illicit activities through compromised devices.
Key Defensive Actions:
- IoT Security: Ensure all internet-facing gateway devices and routers are running the latest firmware.
- Strong Credentials: Enforce strong, unique passwords for all IoT devices and disable default credentials.
- Network Segmentation: Isolate IoT devices on a separate network segment to limit potential lateral movement if compromised.
- Traffic Monitoring: Monitor outbound traffic from IoT devices for unusual
SOCKS5proxy activity.
🚨 Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
Dataset provides limited detail beyond what was previously covered. This report reiterates the critical security issues from the past week, emphasizing the expanded GitHub Dependabot malware alerts now covering eight ecosystems (PyPI, Maven, RubyGems, NuGet, Go, crates.io, PHP Composer). The prolonged 17-month exposure of Salesforce and ServiceNow portals highlights a persistent risk from cloud service misconfigurations. Additionally, the active exploitation of a Metabase 0-day underscores the immediate threat posed by unpatched critical vulnerabilities.
Key Defensive Actions:
- Proactive Scanning: Regularly scan software dependencies for known vulnerabilities and malicious packages using tools that support multiple ecosystems.
- Cloud Configuration Audits: Conduct frequent audits of
SalesforceandServiceNowconfigurations to identify and remediate any public exposures or overly permissive access controls. - Patch Management: Prioritize patching for
Metabaseand other business-critical applications, especially for zero-day vulnerabilities.
🕵️ APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
Dataset provides limited detail beyond what was previously covered. This intelligence reinforces the ongoing PATCHCORD espionage campaign attributed to APT36. The campaign’s focus on Afghan telecom and South Asian infrastructure, coupled with the use of fake VPN tools for initial compromise, indicates a targeted and persistent threat. The innovative use of Google Sheets for C2 communications presents a significant challenge for traditional security controls, as it blends malicious traffic with legitimate cloud application usage.
Key Defensive Actions:
- Threat Intelligence Integration: Integrate
APT36tactics, techniques, and procedures (TTPs) into threat hunting operations. - Application Whitelisting: Consider application whitelisting to prevent the execution of unauthorized
VPN toolsor other suspicious software. - Behavioral Analytics: Implement behavioral analytics to detect unusual user or system activity, particularly related to
Google Sheetsaccess patterns that deviate from normal business operations.
📉 Threat Landscape & Trends
- Software Supply Chain Risk: The expansion of
Dependabotalerts signifies a growing industry focus on securing the software supply chain, but also highlights the pervasive nature of malicious package injection across various ecosystems. - Cloud Service Exploitation: Both the 17-month exposure of major cloud portals and the use of
Google Sheetsfor C2 demonstrate how cloud services, if misconfigured or abused, become significant attack vectors for both data exposure and sophisticated espionage. - IoT Botnet Proliferation: The emergence of new
Mirai-based botnets likeEvooo1Botcontinues to underscore the vulnerability of internet-facing IoT and gateway devices, which are easily co-opted for malicious network infrastructure. - State-Sponsored Espionage:
APT36’sPATCHCORDcampaign exemplifies the persistent threat of state-sponsored actors employing stealthy backdoors and legitimate cloud services to achieve long-term access and intelligence gathering.
📌 Strategic Takeaway
Organizations must adopt a holistic, multi-layered security strategy that prioritizes proactive supply chain security, rigorous cloud security posture management, and continuous vulnerability patching, while simultaneously enhancing threat intelligence integration and user awareness to counter sophisticated espionage and pervasive botnet threats.