Advisory ID: ngCERT-2025-100002
SUMMARY
ngCERT has detected about 78 (medium to low) vulnerabilities primarily impacting Microsoft Windows components like Windows Digital Media and Secure Boot, as well as Dell firmware. These weaknesses include elevation of privilege (EoP), security feature bypasses, and improper access controls, with CVSS v3.1 scores from 4.3 to 8.1 (low to high severity). Most of these require local access, but exploitation could lead to system compromise or data exposure. Although the vulnerabilities have been patched, there is an urgent need for these systems to be updated and the patches applied to safeguard against exploits and possible cyberattacks.
Damage: Critical
Probability: High
Platform(s): Microsoft Windows, Dell Firmware
DESCRIPTION
The vulnerabilities mainly affect Microsoft Windows 10/11 and Server 2019/2022, with some impacting Dell firmware and older non-Microsoft products. Key details include:
a) Windows Digital Media (EoP):Over 40 CVEs, such as (CVE-2025-21229 and CVE-2025-21255), involve improper input validation or out-of-bounds reads, allowing local attackers to gain SYSTEM-level privileges.
b) Windows Secure Boot:CVE-2025-21211 allows bypassing Secure Boot via flaws in DBX update validation, enabling unsigned bootloader execution.
c) Dell Firmware: CVE-2024-52537 permits high-privileged attackers to exploit symlink issues in the Dell Client Platform Firmware Update Utility for privilege escalation.
d) Other Microsoft Issues:CVEs like CVE-2024-55541 (audio driver buffer overflow) and CVE-2024-51456 (SMB Remote Code Execution) cover Denial-of-Service (DoS), kernel exploits, and remote code execution.
e) Legacy/Other Vendors: Older CVEs such as CVE-2023-50946 in OpenSSH, CVE-2021-29669 in Zyxel) involve RCE, EoP, or information disclosure in non-Microsoft products.
CONSEQUENCES
Successful exploitation of these flaws could result in:
- Privilege Escalation: Local attackers could gain SYSTEM access, enabling malware persistence, data theft, or network lateral movement.
- System Integrity Loss: Secure Boot bypass (CVE-2025-21211) allows rootkits or tampered firmware to evade boot protections.
- Service Disruption: Denial of Service (DoS) issues, such as (CVE-2024-55541), may crash services or leak kernel memory.
- Chained Attacks: These flaws could enable ransomware or APTs. No active exploits are reported as of October 2025, but local access increases insider threat risks.
SOLUTION/MITIGATION
To mitigate these vulnerabilities, ngCERT recommends the following measures:
- Apply Patches: Install Microsoft January 2025 updates via Windows Update or WSUS. For CVE-2024-52537, update Dell firmware using Dell Command Update.
- Enhance Access Controls: Enforce least privilege, disable untrusted media playback, and use AppLocker/WDAC to block unsigned binaries.
- Monitor and Harden: Enable Secure Boot and TPM 2.0; use EDR tools to detect privilege escalation. Apply upstream patches for legacy CVEs such as OpenSSH.
- Verify Systems: Scan for vulnerable versions with tools like Qualys or Tenable. Check Microsoft Security Response Centre for updates.
- Best Practices: Segment networks, adopt zero-trust, and test patches in staging environments. Isolate or retire end-of-support systems.
HYPERLINK
Advisory ID: ngCERT-2025-100001
SUMMARY
ngCERT has detected over 100 (Critical and high) vulnerabilities primarily affecting Microsoft Windows components like Office and a few third-party issues. Key risks include remote code execution (RCE), elevation of privilege (EoP), and zero-day exploits, with high CVSS scores (up to 9.8). Ten critical flaws and eight zero-days were noted, some actively exploited and listed in the US Cybersecurity and Infrastructure Security Agency's catalogue. It is pertinent to note that these vulnerabilities have been patched by Microsoft, hence the urgent need for system updates and the application of available patches.
Damage: Critical
Probability: High
Platform(s): Microsoft Windows
DESCRIPTION
The vulnerabilities principally affect Microsoft systems categorized as follows:
a) RCE in Core Windows Components (About 36% of Microsoft CVEs): Flaws enabling arbitrary code execution via emails, packets, or files with low interaction. Examples include Windows OLE (e.g., CVE-2025-21298 for zero-click Outlook previews), Telephony Service (over 20 CVEs like CVE-2025-21286, CVE-2025-21266, all CVSS 8.8), Remote Desktop Services (e.g., CVE-2025-21297), and others like BranchCache and SPNEGO authentication.
b) EoP in Virtualization and Installers (About 25% of Microsoft CVEs): Allows attackers to escalate to SYSTEM privileges. Notable are Hyper-V flaws, including CVE-2025-21333, exploited zero-days with CVSS 7.8, and App Installer issues such as CVE-2025-21275. Also includes NTLMv1 remote exploitation.
c) Office and Developer Tools Issues:RCE/EoP in Access, Excel, Outlook, .NET, and Visual Studio, including CVE-2025-21186, zero-days with CVSS 7.8, often via malicious documents.
d) DoS and Information Disclosure:Impacts services like MSMQ (e.g., CVE-2025-21251) and kernel memory leaks.
e) Third-Party and Older CVEs:Includes authentication bypass in Progress WhatsUp Gold, such as CVE-2024-12108, CVSS 9.6 and legacy issues like Kerberos (2022 CVEs).
CONSEQUENCES
Successful exploitation of these flaws could result in:
- Full System Compromise: RCE flaws allow attackers to run arbitrary code as the user or SYSTEM, enabling malware deployment, ransomware, or persistent access.
- Privilege Escalation and Lateral Movement: EoP in Hyper-V or installers facilitates VM escapes, domain dominance, or supply-chain attacks in enterprise networks.
- Data Theft/Exfiltration: Information disclosures (e.g., NTLM hashes via CVE-2025-21308) enable pass-the-hash attacks; Office flaws risk sensitive document leaks.
- Service Disruption: DoS in MSMQ or RDP could halt critical operations in monitored environments.
- Broader Impact: Zero-days like CVE-2025-21298 are wormable via email, amplifying spread in unpatched fleets. For third parties such as WhatsUp Gold, unauthorized server access risks network-wide reconnaissance. Unmitigated, these could lead to regulatory non-compliance issues with GDPR and NIST, and financial losses from breaches.
SOLUTION/MITIGATION
To mitigate these vulnerabilities, ngCERT recommends the following measures:
- Patch Urgently: Apply January 2025 updates such as KB5040431 through Windows Update or management tools; prioritize exposed systems and test first.
- Hardening Measures: Disable NTLMv1, block unnecessary ports such as PGM UDP, restrict email previews in Outlook, enable Credential Guard for Hyper-V, and use EPA for authentication. For third-party tools like WhatsUp Gold, upgrade to patched versions and rotate keys.
- Detection Strategies: Deploy EDR for anomaly monitoring (e.g., Telephony or OLE activity), enable logging for RDP/MSMQ, and scan for PoCs.
- General Practices: Ensure network segmentation, least privilege, regular scans, and MSRC subscriptions to reduce exposure.
HYPERLINK
- https://jetpatch.com/blog/patch-tuesday/microsoft-january-2025-patch-tuesday/
- https://www.tenable.com/blog/microsofts-january-2025-patch-tuesday-157-cves-cve-2025-21333-cve-2025-21334-cve-2025-21335
- https://www.tenable.com/blog/microsofts-august-2025-patch-tuesday-addresses-107-cves-cve-2025-53779
- https://support.microsoft.com/en-us/topic/protections-for-cve-2025-26647-kerberos-authentication-5f5d753b-4023-4dd3-b7b7-c8b104933d53
Advisory ID: NCC-CSIRT-2025-019
Summary:
Europol and Eurojust have dismantled a cybercrime-as-a-service (CaaS) network, Operation SIMCARTEL, which operated large-scale SIM-farm systems used to create over 49 million fake online accounts across more than 80 countries. In Nigeria and West Africa, similar operations threaten KYC integrity, telecom infrastructure, and financial systems, facilitating smishing, phishing, money-mule schemes, and social-media manipulation. Telecom operators, fintech platforms, and regulators must assume that phone numbers can be rented or abused at scale and strengthen verification, detection, and onboarding controls.
Damage/Probability: Critical/High
Product(s):
- Mobile network services (SIM cards, SMS/MMS delivery, voice)
- Mobile Virtual Network Operators (MVNOs), retail SIM distribution channels
- Online services relying on phone-number verification (social media, messaging apps, Fintech, e-commerce)
- SMS gateway providers and aggregators
Version(s):
Not version-specific (Telecom operations, KYC and provisioning processes, Verification services)
Platform(s):
- Mobile networks (GSM/3G/4G/5G)
- SMS/SS7/SS8/SS7-like routing infrastructure
- Web platforms using phone verification, number-rental marketplaces
Description:
SIM farms are collections of GSM modems and SIM cards used to automate OTP receipt and account registration. They enable criminals to bypass phone verification and conduct large-scale fraud. In Nigeria, this threat can support financial fraud and phishing schemes, election-related disinformation, bulk SMS scams, and exploitation of weak SIM registration and KYC enforcement. Enhanced telecom monitoring, cross-sector collaboration, and strict KYC compliance are essential to mitigate this risk.
Impacts:
- Fraudulent fintech and bank accounts opened with rented SIMs.
- Smishing campaigns using new numbers to evade blacklists.
- Large-scale fake social-media profiles spreading scams and misinformation.
- Weakening of phone-based verification and erosion of trust in KYC systems.
- Regulatory and reputational risks for operators enabling number abuse.
Solutions:
|
Focus Area |
Recommended Action |
|
Detection & Monitoring |
• Analyze for bulk SIM provisioning or activation spikes. |
|
KYC & SIM Controls |
• Enforce strict ID and biometric verification for new SIMs. |
|
Fraud Prevention |
• Apply behavioral/velocity checks for phone-verified accounts. |
|
Coordination & Awareness |
• Establish shared blocklists for abused numbers/resellers. |
References:
-
https://thehackernews.com/2025/10/europol-dismantles-sim-farm-network.html
-
https://www.europol.europa.eu/media-press/newsroom/news/cybercrime-service-takedown-7-arrested
-
https://cyberscoop.com/europol-dismantles-cybercime-network-sim-boxes-fraud/
-
https://therecord.media/europe-sim-farms-raided-latvia-austria-estonia
-
https://www.bleepingcomputer.com/news/security/europol-dismantles-sim-box-operation-renting-numbers-for-cybercrime/
Advisory ID: NCC-CSIRT-2025-018
Summary:
Researchers have discovered ClayRat, a new Android spyware disguised as popular apps like WhatsApp and TikTok. It spreads through Telegram and fake websites, stealing messages, photos, and other personal data. The malware can also take secret pictures and send malicious links to contacts, making it hard to detect and remove.
Damage/Probability: Critical/High
Product(s):
- Android mobile devices (APK (Android Package Kit) side-loaded or installed from untrusted stores / Telegram channels)
- Popular mobile app brands used as lures (WhatsApp, TikTok, YouTube, Google Photos)
Version(s):
Not version-specific, it affects affects Android devices where a malicious APK is installed and granted required roles/permissions.
Platform(s):
- Android OS (various versions).
- Devices with SMS/notification privileges and browsers/Telegram clients used to download APK droppers.
Description:
Zimperium security researchers have discovered a new Android spyware called ClayRat, which pretends to be popular apps like WhatsApp, TikTok, YouTube, and Google Photos. The attackers share these fake apps through Telegram channels and phishing websites, often using lookalike domains and fake reviews to appear genuine.
When users download and install these fake apps manually, they are tricked into giving the spyware special permissions, such as access to text messages and notifications. This allows ClayRat to read messages (including security codes), check call logs, view contacts, take photos, and send stolen data to the attackers’ servers. It can also send harmful links to the victim’s contacts, spreading the infection further.
The malware is constantly changing, with over 600 different versions found in just a few months. It also uses advanced hiding techniques to avoid detection by antivirus software, making it difficult to remove once installed. Because it spreads through public channels like Telegram, the spyware can reach a large number of victims very quickly.
Impacts:
- Disclosure of sensitive communications (SMS, verification codes) and account takeover risk.
- Loss of privacy (photos, location, microphone/camera capabilities).
- Rapid lateral spread via messages to contacts and Telegram channels, increasing scale of compromise.
- Potential secondary payloads installed by the loader (additional RATs, credential stealers).
Solutions:
- Deploy Mobile Threat Defense (MTD) and Google Play Protect to detect malicious APKs and abnormal behaviors.
- Validate apps against an approved allowlist; remove any mismatched packages immediately.
- Block malicious domains, phishing sites, and suspicious Telegram channels at the DNS/network level.
- Disable side-loading on managed devices; allow installations only from the Play Store or enterprise app store.
- For suspected devices, remove unknown APKs, revoke sensitive permissions, rotate credentials, and enforce phishing-resistant MFA.
- Isolate and analyze compromised devices, collecting relevant artifacts for forensics.
- Educate users to avoid installing apps from untrusted links or channels and to verify app sources.
- Keep MTD/antivirus and EDR signatures updated and configure alerts for suspicious app or SMS-handler activities.
References:
-
https://zimperium.com/blog/clayrat-a-new-android-spyware-targeting-russia
-
https://thehackernews.com/2025/10/new-clayrat-spyware-targets-android.html
-
https://www.csoonline.com/article/4070281/clayrat-spyware-turns-phones-into-distribution-hubs-via-sms-and-telegram.html
-
https://securityaffairs.com/183169/malware/clayrat-campaign-uses-telegram-and-phishing-sites-to-distribute-android-spyware.html
Advisory ID: NCC-CSIRT-2025-017
Summary:
win.satacom is a family of Trojan-downloaders (also reported as Satacom / LegionLoader) that has been active since at least 2019. It functions primarily as a loader/downloader, installing follow-on payloads such as cryptocurrency-stealing browser extensions and information-stealers. Recent campaigns have delivered stealthy Chromium extensions that intercept web sessions and siphon cryptocurrencies from victims on exchange and web wallet pages. Microsoft Defender, Kaspersky, and other AV vendors detect variants of this family.
Damage/Probability: High/High
Product(s):
- Windows endpoints
- Chromium-based browsers (via malicious extensions)
- Downloader distribution chains (phishing, droppers, packers)
Version(s):
Not version-specific, it affects Windows systems where the downloader is executed and Chromium browsers that accept malicious extensions.
Platform(s):
- Microsoft Windows (x86/x64)
- Chromium browser families (Chrome, Edge, Brave, etc.)
- Common enterprise environments where browser-based crypto wallets are used
Description:
Satacom acts as a downloader/dropper. After initial execution (often from a malicious installer, bundled software, or an obfuscated dropper), it contacts Command & Control servers to retrieve additional payloads and loaders. Variant analysis shows multiple string-deobfuscation and packing techniques.
Documented campaigns (2023 onward) show Satacom delivering malicious Chromium extensions engineered to perform web injections on crypto exchange and wallet pages to exfiltrate funds and session cookies. Other follow-on binaries observed include RedLine, other stealers, and loaders.
Variants use common downloader evasion (packing/obfuscation, staged encryption of strings, anti-analysis checks), persistence via scheduled tasks/startup entries, and fallback C2 techniques.
Campaigns have targeted users in multiple regions (e.g., Brazil, India, Indonesia, Turkey, Egypt and others in prior reporting) with a focus on users who transact in cryptocurrency.
Impacts:
- Loss/theft of cryptocurrency from web wallets and exchange accounts via browser extension or web-inject attacks.
- Compromise of user credentials, session cookies, and stored secrets leading to account takeover (ATO).
- Persistent foothold through additional downloaded payloads (infostealers, RATs).
- Lateral movement in poorly segmented networks if follow-on payloads include remote access tools.
Solutions:
- Scan endpoints with up-to-date anti-malware signatures (Microsoft Defender, Kaspersky, Broadcom/Symantec, Fortinet, etc.). Microsoft Defender and other engines include detections for Satacom variants.
- Monitor for suspicious child processes of browser and common installer processes, and for downloads from known malicious gateways.
- Inspect installed Chromium extensions centrally (via endpoint management or browser management policies) and flag any extension installed outside official enterprise channels or having excessive permissions.
- Employ End Point Detection and Response (EDR) mechanism to hunt for known behavior patterns
- Quarantine and remove detected Satacom binaries; block related Command & Control domains/IPs at network perimeter and in DNS
- Enforce browser extension policy, allow only approved extensions via enterprise browser management; remove all unapproved/unknown extensions; rotate credentials and revoke sessions for any accounts accessed from infected hosts.
- For users with suspected exposure, reset passwords, enable phishing-resistant Multi Factor Authentication where possible, and move high-value crypto to cold storage or wallets with hardware isolation.
References:
-
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description/
-
https://www.broadcom.com/support/security-center/protection-bulletin/satacom-malware-spreading-cryptocurrency-infostealers
-
https://threats.kaspersky.com/en/threat/Trojan-Downloader.Win32.Satacom.zs/
-
https://securelist.com/satacom-delivers-cryptocurrency-stealing-browser-extension/109807/
-
https://medium.com/%40tanmaymore06/reversing-satacom-decoding-c2-server-3696bfcb9111
- CISA Sound Alarm over Hackers Targeting Cisco Security Devices
- ngCERT SECURITY ADVISORY ON AVALANCHE BOTNET INFRSTARUCTURE
- Multiple Critical Vulnerabilities in Google Chrome, Microsoft Edge, IBM, and Asterisk Products
- ngCERT S E C U R I T Y A D V I S O R Y - COBALT STRIKE BEACON MALWARE AFFECTING NETWROKS/SYSTEMS