Posts

Showing posts with the label medusa ransomware

386. Ransomware Affiliates Abuse Bandizip for Data Collection

Image
Hello everyone! Today we’re going to talk about collecting data from compromised systems, and we’ll look at an example of the technique Archive Collected Data: Archive via Utility (T1560.001) . The example comes from a Microsoft Threat Intelligence report on the activity of the Storm-1175 cluster, which is associated with the distribution of the Medusa ransomware. Despite the attackers using zero-day vulnerabilities to gain initial access, most of their tactics, techniques, and procedures were fairly trivial. Nevertheless, one of the tools caught my attention. To collect data for later publication on DLS, the attackers used Bandizip — a legitimate file archiving tool. This tool is not encountered very often and is quite suitable for proactive hunting, for example: event_type: "processcreatewin" AND proc_file_productname: "bandzip" See you soon!

089. Detecting RMMs from Ransomware Affiliate's Toolkit: NinjaRMM

Image
Hello everyone! I think it's not a secret that ransomware gangs often abuse various RMMs. Some are quite well-know, while others are not seen that often. Recently I spotted another RMM I don't often see in ransomware incidents - it's called NinjaRMM . For example, this tool was used by Medusa ransomware affiliates. As always, we can start from detecting related network communications: event_type: "dnsreq" AND dns_rname: "ninjarmm.com" Next thing - common file names related to RMM components, for example: event_type: "processcreatewin" AND proc_file_name: ("NinjaRMMAgent.exe" OR "NinjaRMMAgenPatcher.exe" OR "ninjarmm-cli.exe") Finally, let's search for renamed binaries based on product name: event_type: "processcreatewin" AND proc_file_productname: "NinjaRMM" See you tomorrow!

074. Detecting Ransomware Affiliate's Toolkit: Cloudflared

Image
Hello everyone! Let's keep talking about modern ransomware affiliate's toolkit. Today we'll look at defense evasion and command and control capabilities. I came across this CISA advisory on Medusa Ransomware, and spotted the following tool - Cloudflared. It's used to securely expose applications, services, or servers to the internet via Cloudflare Tunnel without exposing them directly. Of course, adversaries abuse this feature! To create a tunnel, the threat actor should run the following command (or just run the installer, it creates a service and runs the command): cloudflared.exe tunnel run --token [redacted] Not very common command line arguments, right? Let's use it to build detection: event_type: "processcreate"  AND  cmdline: ("tunnel" AND "run" AND "token") Have you observed any other interesting tunneling tools ITW recently? See you tomorrow!