Technical Analysis Of Vetta Loader

Related Vulnerabilities: CVE-2023-42793  

Properties
Threat Severity

Medium

Description

The FBI, CISA, NSA, SKW, CERT.PL, and NCSC have jointly reported that Russian Foreign Intelligence Service (SVR) cyber actors, also known as APT 29, CozyBear, and NOBELIUM, are actively exploiting the CVE-2023-42793 vulnerability on servers hosting JetBrains TeamCity software since September 2023. The attackers leverage this access to escalate privileges, move laterally, deploy additional backdoors, and maintain long-term access to compromised networks. To evade detection, the threat actors employ various techniques, including a "Bring Your Own Vulnerable Driver" method, DLL hijacking vulnerabilities in Zabbix and Webroot antivirus software, and a covert communication channel using Microsoft OneDrive and Dropbox. Additionally, data exchanged via OneDrive and Dropbox are concealed within randomly generated BMP files for enhanced obfuscation. The Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by CISA and shared publicly https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a

Knowledge Base
  • Available Soon
Global Prevalence
Low
High
Observed Countries9
  • Italy253.37 devices found impacted per 1M devices
  • Turkey314.88 devices found impacted per 1M devices
  • Israel203.11 devices found impacted per 1M devices
  • United States6.02 devices found impacted per 1M devices
  • Germany22.47 devices found impacted per 1M devices
  • Vietnam85.27 devices found impacted per 1M devices
  • Luxembourg340.9 devices found impacted per 1M devices
  • Japan0.86 devices found impacted per 1M devices
  • United Kingdom1.35 devices found impacted per 1M devices
Observed Sectors8
  • Unknown Sectors
    125.02 devices found impacted per 1M devices
  • Banking/Financial/Wealth Management
    4127.46 devices found impacted per 1M devices
  • Outsourcing & Hosting
    10.63 devices found impacted per 1M devices
  • Retail
    51.7 devices found impacted per 1M devices
  • Transportation & Shipping
    24.18 devices found impacted per 1M devices
  • Automotive
    5.45 devices found impacted per 1M devices
  • Construction
    16.98 devices found impacted per 1M devices
  • Pharma
    7.57 devices found impacted per 1M devices
Compare Detections

Detection rate is the number of artifact detections reported by McAfee global sensors for this threat over 8 days.

Threat Prevalence - Past 8 days

The detection rate bubbles are sized based on the values below:

1-20 20-50 50-100 100+
Dec 29, 2023
Dec 30, 2023
Dec 31, 2023
Jan 1, 2024
Jan 2, 2024
Jan 3, 2024
Jan 4, 2024
Jan 5, 2024
Sector
Country
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0