Skip to main content

Intel Releases Security Updates

Intel has released updates to address several vulnerabilities in Intel software. An attacker could exploit some of these vulnerabilities to escalate their privileges.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Intel has released updates to address several vulnerabilities in Intel software. An attacker could exploit some of these vulnerabilities to escalate their privileges.


Threat details

It appears to share code with the MongoLock ransomware and Xbash worm, as well as using the same command and control (C2) infrastructure as MongoLock, although it does not have the same capabilities as either.

Xwo has recently been observed being hosted on a server, although at the time of publication it is not known how users are directed to download the malware.

When Xwo is executed, the affected device transmits a HTTP POST request to a C2 server that includes a user agent randomly selected from a hard-coded list. The C2 server then responds with instructions including an IP address range to scan. The affected device then scans this address range and collects information on available services, including default credentials, misconfigurations, default paths, repositories and remote file transfer tools. This information is then sent to the C2 server in another HTTP POST request.


Remediation steps

Type Step

Users and administrators are encouraged to review the Intel security advisories INTEL-SA-00182, INTEL-SA-00212 and INTEL-SA-00207 and apply the necessary updates.


Last edited: 14 February 2020 2:54 pm