216.73.216.6

StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms

· Published 05/08/2024 11:29 · Modified 05/08/2024 11:35

Export JSON

Essential information

Published
05/08/2024 11:29
Modified
05/08/2024 11:35
Tags
2024-08-05 dazzlespy dns poisoning insecure updates macma malware osx.cdds pocostick reloadext
Related entities
1 vulnerabilities (cve), 2 observables, 1 intrusion sets (apt), 15 techniques (mitre), 5 malware

Description

Volexity detected and responded to multiple incidents involving systems infected with linked to StormBamboo, a threat actor known for compromising internet service providers (ISPs) and leveraging to redirect software update traffic to attacker-controlled servers hosting malicious payloads. The threat actor abused insecure software update mechanisms that used HTTP, enabling them to surreptitiously install including new variants of and on victim machines running macOS and Windows. Post-exploitation activities involved deploying a malicious browser extension to exfiltrate victim email data. The incidents highlight StormBamboo's sophisticated tactics and the risks posed by insecure update mechanisms.

External references