409. Adversaries Abuse Localhost[.]run for Tunneling

Hello everyone!

Tunnels. Attackers are coming up with more and more ways to implement them. Today, we’ll take another look at the Protocol Tunneling technique (T1572).

There are plenty of free tunneling services that allow a local service to be exposed to the internet through a public URL. For example, attackers often use Cloudflare Tunnel. However, according to this report, threat actors also used localhost[.]run.

You can detect traces of its use, for example, by monitoring communications with lhr[.]life subdomains:

event_type: dnsreq*

AND

dns_rname: "lhr.life"

See you soon!

Comments

Popular posts from this blog

343. Ransomware Gangs Abuse SystemSettingsAdminFlows to Evade Defenses

013. It Can Remove Rootkits. And Your EDR!

391. Hunting for TeamPCP's Stealer