Microsoft Detects, Patches Zero-Day Exploit Used to Target European, Central American Users

Microsoft has published a report apprising its customers about a vulnerability to improve detection of these attacks.

Advertisement
By Sourabh Kulesh | Updated: 28 July 2022 14:29 IST
Highlights
  • Cybercriminals sold, used Subzero malware to attack customers
  • The attack was seen in Austria, Panama, and the UK
  • Knotweed promotes itself as data-driven intelligence services provider

Subzero malware can be used to hack targets’ phones and internet devices

Photo Credit: Reuters

Microsoft has published an analysis of Knotweed, a private-sector offensive actor (PSOA) that developed and used a malware called Subzero to attack Windows as well as Adobe customers by using multiple zero-day exploits. The company intends to use the analysis to inform customers and industry partners to improve detection of these attacks. The company says that the exploit, which included the one that was patched in the July 2022 security update, was used to target customers in Europe and Central America.

The Microsoft Threat Intelligence Center (MSTIC) and the Microsoft Security Response Center (MSRC) found the Austria-based PSOA which was carrying out limited and targeted attacks against European and Central American customers by using malware called Subzero. The malware can be used to hack targets' phones, computers, networks as well as internet-connected devices.

As per Microsoft, Knotweed was not only selling the hacking tools to third parties but also running targeted operations. The Windows-maker was able to spot two business models — access-as-a-service and hack-for-hire — associated with the “cyber mercenaries.”

Advertisement

“In access-as-a-service, the PSOA sells full end-to-end hacking tools that can be used by the purchaser in operations, with the PSOA not involved in any targeting or running of the operation,” Microsoft said. In hack-for-hire, the actor runs the targeted operations based on the detailed information provided by the purchaser. Microsoft observed Knotweed-associated infrastructure in some attacks, suggesting a combination of both business tactics deployed by cyber criminals.

Advertisement

Citing a web archive link of DSIRF (the name by which Knotweed is publicly known), Microsoft says MSTIC found the Subzero malware being deployed through a variety of methods, including zero-day exploits in Windows and Adobe Reader, in 2021 and 2022. It says that the victims of the attacks include law firms, banks, and strategic consultancies in countries such as Austria, Panama, and the United Kingdom.

As per the website, DSIRF offers data-driven intelligence services in the form of research and forensics to corporations.

Advertisement

Microsoft says it will continue to monitor Knotweed's activities “and implement protections for our customers.” The company is also encouraging quick deployment of the July 2022 Microsoft security updates to protect their systems against exploits. “Microsoft Defender Antivirus and Microsoft Defender for Endpoint have also implemented detections against Knotweed's malware and tools,” it said.


Why is Oppo making strange choices with its flagship Reno series? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Price Leaked; Could Be Cheaper Than its Predecessor at Launch
  2. JioSaavn Announces 'Limited-Time' Annual Plan: Price, Benefits
  3. Redmi K90, Redmi K90 Pro Max Launch Today: All You Need to Know
  4. Nubia Z80 Ultra Launched With 7,200mAh Battery, Snapdragon 8 Elite Gen 5
  5. These iPhones May Launch Next Year to Mark iPhone's 20th Anniversary
  6. OnePlus 15 Camera Details Revealed Ahead of October 27 Launch
  7. OnePlus 15: Everything We Know Ahead of Its October 27 Launch in China
  8. Best Mobiles Under Rs. 40,000 in India
  9. iQOO 15 Microsite Confirms Availability on Amazon Ahead of Launch
  10. Redmi Partners With Lamborghini for Redmi K90 Pro Max Champion Edition
  1. iQOO 15 Microsite Confirms Availability on Amazon, India Launch Timeline
  2. Redmi K90 Pro Max Champion Edition Teased in Partnership With Lamborghini Squadra Corse
  3. OnePlus Ace 6 Key Specifications Confirmed Ahead of China Launch; Teased to Pack 7,800mAh Battery, 120W Charging
  4. Redmi K90, Redmi K90 Pro Max Launching Today: Know Price, Features and Specifications
  5. Astrophotographer Captures Stunning “Raging Baboon Nebula” in Deep Space
  6. Cambridge Team Uncovers Unexpected Quantum Behaviour in Non-Metal Organic Molecule
  7. New Fossil Teeth Evidence Suggests Herbivorous Dinosaurs Preferred Nutrient-Rich, Textured Plants
  8. Ek Deewane Ki Deewaniyat OTT Release Reportedly Revealed Online: When and Where to Watch?
  9. Final Destination: Bloodlines Now Available for Streaming on JioHotstar
  10. Vash Level 2 Now Streaming Online: Know Where to Watch This Janki Bodiwala Starrer Horror Movie
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.