409. Adversaries Abuse Localhost[.]run for Tunneling
Hello everyone!
Tunnels. Attackers are coming up with more and more ways to implement them. Today, we’ll take another look at the Protocol Tunneling technique (T1572).
There are plenty of free tunneling services that allow a local service to be exposed to the internet through a public URL. For example, attackers often use Cloudflare Tunnel. However, according to this report, threat actors also used localhost[.]run.
You can detect traces of its use, for example, by monitoring communications with lhr[.]life subdomains:
event_type: dnsreq*
AND
dns_rname: "lhr.life"
See you soon!

Comments
Post a Comment