Trellix Insights

Related Vulnerabilities: CVE-2023-47246   cve-2023-47246  

Properties
Threat Severity

Medium

Description

A new vulnerability (CVE-2023-47246) in SysAid on-prem software was discovered by researchers. The exploit, carried out by a group called DEV-0950 (Lace Tempest), involved uploading a malicious archive into the webroot, leading to unauthorized access. The attacker then used a WebShell to control the system, deploying a PowerShell script to execute a malware loader (user.exe), loading the GraceWire trojan into specific processes. To cover their tracks, a second PowerShell script was used to erase evidence from the disk and SysAid on-prem server logs. The Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by SysAid and shared publicly https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification

Knowledge Base
  • Available Soon
Global Prevalence
Low
High
Observed Countries8
  • Italy75.48 devices found impacted per 1M devices
  • United States2.44 devices found impacted per 1M devices
  • Germany5.99 devices found impacted per 1M devices
  • Spain30.31 devices found impacted per 1M devices
  • Israel136.52 devices found impacted per 1M devices
  • India21.46 devices found impacted per 1M devices
  • Chile15.15 devices found impacted per 1M devices
  • Colombia3.53 devices found impacted per 1M devices
Observed Sectors5
  • Unknown Sectors
    47.5 devices found impacted per 1M devices
  • Telecom
    8.32 devices found impacted per 1M devices
  • Banking/Financial/Wealth Management
    120.29 devices found impacted per 1M devices
  • Insurance
    2.8 devices found impacted per 1M devices
  • Technology/IT
    Less than 1 devices found impacted per 1M devices
Compare Detections

Detection rate is the number of artifact detections reported by McAfee global sensors for this threat over 8 days.

Threat Prevalence - Past 8 days

The detection rate bubbles are sized based on the values below:

1-20 20-50 50-100 100+
Nov 17, 2023
Nov 18, 2023
Nov 19, 2023
Nov 20, 2023
Nov 21, 2023
Nov 22, 2023
Nov 23, 2023
Nov 24, 2023
Sector
Country
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0