Attackers are trying to exploit a vulnerability in corporate VPNs to steal money.

Experts from Kaspersky Lab have identified a series of hacker attacks targeting telecommunications and financial companies in Eastern Europe and Central Asia. In this campaign, the attackers attempted to seize funds and financial data from the victims. The report indicates that the hackers tried to siphon off tens of millions of dollars from the accounts of the attacked companies.

Attackers are trying to exploit a vulnerability in corporate VPNs to steal money.

In each documented case, the hackers employed a single technique, exploiting a vulnerability in corporate VPN-solutions utilized by the targeted companies. The attackers leveraged the CVE-2019-11510 vulnerability, the exploitation tools for which can be found online. This vulnerability allows for the retrieval of information about administrator accounts in corporate networks, thereby granting access to valuable data.

The report states that the cyber groups did not exploit this vulnerability. Kaspersky Lab experts believe that the series of attacks on financial and telecommunications companies is orchestrated by Russian-speaking hackers. They reached this conclusion after analyzing the techniques used by the attackers to execute the attacks.

“Despite the fact that the vulnerability was discovered back in spring 2019, many companies still have not installed the necessary update. Given the availability of the exploit, such attacks could become widespread. Therefore, we strongly recommend that companies install the latest versions of their VPN solutions,” said Sergey Golovanov, lead antivirus expert at Kaspersky Lab.



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster