APT Upgrades With Windows Kernel Zero-Day Exploit
ID: c2965750-896b-51ee-aaaf-380b54f1579c
STIX ID: report--c2965750-896b-51ee-aaaf-380b54f1579c
Feed Name: Cyble Blog
Cyble reports that the Bitter APT (T-APT-17) has been observed exploiting a Windows kernel privilege-escalation zero-day (CVE-2021-1732) in the wild to elevate process tokens to SYSTEM and deploy a RAT (dllhost.exe) via a self-extractor decoy; the analysis details exploit mechanics (win32kfull.sys / ClientAllocWindowClassExtraBytes callback), post-exploit behavior (memory execution, system enumeration, HTTP-based C2), provides IOCs (file hashes, C2 IPs/URLs), a YARA rule, and recommended mitigations (patching, AV updates, IOC hunting).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
