216.73.216.226

Brain Cipher Ransomware uses CVE-2023-28252

· Published 17/12/2024 16:31 · Modified 17/12/2024 17:06

Export JSON

Essential information

Published
17/12/2024 16:31
Modified
17/12/2024 17:06
Tags
2024-12-17 CVE-2023-28252 brain cipher clfs filename privilege-escalation ransomware
Related entities
2 observables, 1 intrusion sets (apt), 6 techniques (mitre), 1 malware

Description

is suspected of exploiting , a vulnerability previously utilized by the now-inactive Nokowaya Group. The exploit, often disguised as 'clfs_eop.exe', targets the Microsoft Windows CLFS Driver for privilege escalation. This vulnerability is being sold on underground networks for $5K to $25K, indicating the existence of unpatched systems. The analysis provides multiple MD5 hashes associated with the exploit, along with several IP addresses potentially related to the CVE or operations. The exploitation of this vulnerability highlights the ongoing threat posed by groups adapting to use newly discovered security flaws.

External references