407. That's How Paper Werewolf Obtains Credentials

Hello everyone!

Attackers are often able to extract authentication material from files, so today we'll take a look at the Credentials In Files (T1552.001) technique.

According to Kaspersky's report on the activity of the GOFFEE (Paper Werewolf) cluster, the threat actors showed a strong interest in various configuration files containing sensitive information, including:

cmd.exe /c type "%APPDATA%\AnyDesk\service.conf"

cmd.exe /c type "%USERPROFILE%\OpenVPN\config\avia\avia.ovpn"

cmd.exe /c type "%APPDATA%\Kerio\VpnClient\user.cfg"

cmd.exe /c dir "%USERPROFILE%\Downloads\Telegram Desktop"

Naturally, this kind of activity creates opportunities for proactive threat hunting. For example:

event_type: "processcreatewin"

AND

proc_file_path: "cmd.exe"

AND

cmdline: ("type" OR "dir")

AND

cmdline: ("anydesk" OR "openvpn" OR "vpnclient" OR "telegram desktop")

See you soon!

Comments

Popular posts from this blog

343. Ransomware Gangs Abuse SystemSettingsAdminFlows to Evade Defenses

013. It Can Remove Rootkits. And Your EDR!

391. Hunting for TeamPCP's Stealer