Intel Releases Security Updates
Intel has released updates to address several vulnerabilities in Intel software. An attacker could exploit some of these vulnerabilities to escalate their privileges.
Summary
Intel has released updates to address several vulnerabilities in Intel software. An attacker could exploit some of these vulnerabilities to escalate their privileges.
Threat details
It appears to share code with the MongoLock ransomware and Xbash worm, as well as using the same command and control (C2) infrastructure as MongoLock, although it does not have the same capabilities as either.
Xwo has recently been observed being hosted on a server, although at the time of publication it is not known how users are directed to download the malware.
When Xwo is executed, the affected device transmits a HTTP POST request to a C2 server that includes a user agent randomly selected from a hard-coded list. The C2 server then responds with instructions including an IP address range to scan. The affected device then scans this address range and collects information on available services, including default credentials, misconfigurations, default paths, repositories and remote file transfer tools. This information is then sent to the C2 server in another HTTP POST request.
Remediation steps
| Type | Step |
|---|---|
|
Users and administrators are encouraged to review the Intel security advisories INTEL-SA-00182, INTEL-SA-00212 and INTEL-SA-00207 and apply the necessary updates. |
Last edited: 14 February 2020 2:54 pm