Thursday, February 27, 2025
HomeComputer SecurityAPT Hackers Group Exploiting the Window OS Using New Zero day Vulnerability

APT Hackers Group Exploiting the Window OS Using New Zero day Vulnerability

Published on

SIEM as a Service

Follow Us on Google News

Cyber criminals started exploiting the Microsoft windows os using recently discovered win32k zero day vulnerability that was patched by Microsoft recently.

A zero-day vulnerability that resides in the win32k.sys allows attackers to exploit 64-bit operating systems in the range from Windows 8 to Windows 10.

This vulnerability ( CVE-2019-0797) was initially discovered by the kaspersky lab researchers who was reported to Microsoft and the fixed patch was released on March 2019 security update.

A Privilege escalation vulnerability that exists in Windows OS when the Win32k component fails to properly handle objects in memory let allow attackers to run arbitrary code in kernel mode.

This new Exploit is currently used by several ATP threat actors in wide including FruityArmor and SandCat, both are recently active APT groups that specifically targeting the victims using zero day exploits.

According to Costin Raiu, director of global research, Kaspersky Lab, “SandCat is a relatively new APT group; we first observed them in 2018, although it would appear they have been around for some time,” ,

Kaspersky researcher discovered this new windows exploit using 2 different technologies

  1. Behavioral detection engine and Automatic Exploit Prevention for endpoint products;
  2. Advanced Sandboxing and Anti Malware engine for Kaspersky Anti Targeted Attack Platform (KATA)

New Zero day vulnerability (CVE-2019-0797)

This vulnerability resides in the win32k driver due to improper synchronization between undocumented two syscalls,

1.NtDCompositionDiscardFrame
2.NtDCompositionDestroyConnection

Kaspersky researchers explained that, “The problem lies in the fact that when the syscalls NtDCompositionDiscardFrame and NtDCompositionDestroyConnection are executed simultaneously, the function DiscardAllCompositionFrames may be executed at a time when the NtDCompositionDiscardFrame syscall is already looking for a frame to release or has already found it. This condition leads to a use-after-free scenario.”

Researcher observed that the attackers made a few attacks by exploiting this zero day vulnerability and all the windows users need to apply the necessary patch to prevent from this attack.

Attackers are using the exploitation process in same way for all the vulnerable OS versions using heap spraying palettes to leak their kernel addresses. 

Besides that, the exploit performs a check on whether it’s running from Google Chrome and stops execution if it is because vulnerability CVE-2019-0797 can’t be exploited within a sandbox. kaspersky said.

All the windows users urged to update your operating system let Microsoft apply the patches for this vulnerability on your windows system.

Also Learn: Certified Advanced Persistent Threat Analyst online course

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.


Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Cisco Nexus Switch Vulnerability Allows Attackers to Cause DoS

Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000...

Silver Fox APT Hackers Target Healthcare Services to Steal Sensitive Data

A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver...

Ghostwriter Malware Targets Government Organizations with Weaponized XLS File

A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group...

LCRYX Ransomware Attacks Windows Machines by Blocking Registry Editor and Task Manager

The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Cisco Nexus Switch Vulnerability Allows Attackers to Cause DoS

Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000...

LCRYX Ransomware Attacks Windows Machines by Blocking Registry Editor and Task Manager

The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its...

Windows Virtualization-Based Security Exploited to Develop Highly Evasive Malware

In a groundbreaking development, researchers have uncovered how attackers are exploiting Windows Virtualization-Based Security...