Attackers weaponized Excel documents as part of an espionage campaign targeting high-ranking government officials in western Asia, Trellix Threat Labs reports. The security vendor — formerly McAfee-FireEye — believes the cyberattack may have been carried out by Russian state-sponsored hacking group APT28, aka Fancy Bear.

“A number of the attack indicators and apparent geopolitical objectives resemble those associated with the previously uncovered threat actor APT28,” Trellix Security Researcher Marc Elias wrote in a blog post. “While we don’t believe in attributing any campaign solely based on such evidence, we have a moderate level of confidence that our assumption is accurate.”

The attack utilizes a Microsoft Excel downloader, likely embedded in an email, to exploit a known remote-code execution vulnerability (CVE-2021-40444) in MSHTML. This enables malicious code called Graphite to be injected into system memory and executed.

“Graphite is a newly discovered malware sample based on a OneDrive Empire Stager which leverages OneDrive accounts as a command and control server via the Microsoft Graph API,” Elias explained.

This enabled attackers to coopt Microsoft OneDrive to gain control of the target’s system.

The attack is unique both with regard to the prominence of its targets and the attack vector. This is a “technique our team has not seen before,” he wrote, adding the attack was likely broken into multiple stages to skirt detection.

In fact, the technique enabled attackers to bypass some antivirus-scanning engines and office analysis tools, he added.

The command and control functions used an Empire server instantiated in July last year, however, the actual attacks took place between, October and November, Trellix reports.

“The actors behind the attack seem very advanced based on the targeting, the malware, and the infrastructure used in the operation, so we presume that the main goal of this campaign is espionage,” Elias concluded.

Linux Bug Amps Open Source Security Woes

The disclosure comes shortly after a high-severity vulnerability was discovered in the Linux kernel (CVE-2022-0185), fueling open source security concerns raised by the White House earlier this month.

The vulnerability takes advantage of either the "CAP_SYS_ADMIN" capability or the unshare Linux command in many container runtime interfaces, Aqua Security’s Rory McCune wrote in a blog post.

While neither feature is standard in the popular Docker container runtime, and the unshare command is explicitly blocked, McCune notes any container using the "privileged" flag is still vulnerable.

More concerning are the implications for Kubernetes environments where the "seccomp" filters used by Docker to block the unshare command are explicitly disabled.

While there is no known public exploit of the bug, Aqua Security advises users to patch their Linux distributions as soon as possible, but warn the patch will likely require a reboot of the host to be effective.

Where rebooting isn’t advisable, McCune recommends minimizing the use of privileged containers that have "CAP_SYS_ADMIN" privileges.