Operation SteelGateway: Advanced VPN Zero-Day Analysis
Operation SteelGateway: Advanced VPN Zero-Day Analysis | Art Of Vector Lab Operation SteelGateway: VPN Zero-Day Campaign Analysis Threat Overview CRITICAL CVE: CVE-2023-XXXXX CVSS 3.1: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) First Observed: 2024-03-27T14:32:00Z Threat Actor: Suspected APT41 affiliate Attack Vector: Network-adjacent Exploit Complexity: Low Technical Analysis Vulnerability Root Cause The exploit leverages a type confusion vulnerability in the VPN's: IPSec IKEv2 implementation (isakmp_parse_payload) Fragmented packet reassembly logic Custom cryptographic module (libvpn_crypto.so) Exploitation Chain Malformed IK...