Posts

Showing posts with the label rmm

358. Adversaries Abuse GoToHTTP for Redundant Access

Image
Hello everyone! It's time to look at another interesting RMM abused by threat actors for redundant access, and check if your detections cover it. According to this report , the adversary dropped a renamed copy  GotoHTTP to the compromised system. It's interesting that the threat actors just need to install this RMM on the system they want to control, and to manipulate it they need just a web-browser! So, you can look for related network connections: event_type: "dnsreqwin" AND dns_rname: "gotohttp.com" And for binary itself, of course: event_type: "processcreatewin" AND proc_file_productname: "gotohttp" See you tomorrow!

271. Does an Adversary Need to Install an RMM?

Image
Hello everyone! Adveraries, especially ransomware gangs, often abuse legitimate RMMs. But do them need to bring such software with them? In some cases - they don't! For example, this case covered by Barracuda. Akira ransomware affiliates got access to Datto RMM tool’s management console and used it to execute the attack. So it's always a good idea to hunt for abnormal RMM-related behavior. To find Datto RMM, for example, you can look for accordingly signed files: event_type: "processcreatewin" AND proc_file_sig: "datto" Also, you can always look for Datto-related domain resolutions: event_type: "dnsreqwin" AND dns_rname: "rmm.datto.com" See you tomorrow!

257. Adversaries Abuse ITarian for Command and Control

Image
Hello everyone! Adversaries keep experimenting with various RMM tools. So, today we'll look at another example of  Remote Access Tools: Remote Desktop Software (T1219.002) . According to Red Canary report , this time threat actors abused  ITarian . Despite the fact the installer dropped ITarian executable to legitimate location, I think it's better to focus on its metadata, for example, CompanyName, so we can hunt for renamed versions of this RMM as well: event_type: "processcreatewin" AND proc_file_companyname: "itarian" See you tomorrow!

127. Detecting RMMs from Ransomware Affiliate's Toolkit: Supremo

Image
Hello everyone! Let's keep looking at RMMs observed in ransomware gangs' toolkit. This time we'll look at Supremo . It's a legitimate remote access tool observed to be used by Black Basta ransomware affiliates ITW. Usually the adversary do not modify the binary, so it look absolutely legitimate. It means we can focus on metadata again and again. So here's the query: event_type: "processcreatewin" AND proc_file_productname: "Supremo Remote Control" The same can be said about file creation events in the tool-related folders: event_type: "filecreate" AND file_path: "SupremoRemoteDesktop" What other interesting RMMs used by ransomware affiliates you saw? See you tomorrow!

119. RustDesk: An RMM You May Not Heard About

Image
Hello everyone! I'm sure you are well-informed about various RMMs abused by adversaries. But have you heard about this one - RustDesk ? For example, it was used ITW by Akira ransomware affiliates. The tool is available for various platforms, here's a Windows version . Let's look at some detection opportunities, and start from the binary itself: event_type: "processcreatewin" AND proc_file_productname: "rustdesk" You may also hunt for file or folder creation events related to RustDesk: event_type: "filecreate" AND file_path: "rustdesk" Make sure you checked non-Windows binaries as well! See you tomorrow!

073. Detecting RMMs from Ransomware Affiliate's Toolkit: FleetDeck

Image
Hello everyone! Yes, ransomware. Again. Let's look at another RMM abused by adversaries -  FleetDeck . I don't see it very often, but there're even public reports showing it's leveraged by by ransomware affiliates, for example,  ALPHV . By the way, this legitimate remote access tool has a very interesting slogan on its website - "Command and Control". Let's start from DNS requests to fleetdeck[.]io: event_type: "dnsreq" AND dns_rname: "fleetdeck.io" The tool isn't very common, we can hunt for processes executed from default installation location: event_type: "processcreatewin" AND proc_file_path: "FleetDeck Agent" The installer also uses PowerShell (yes, again) to create a new firewall rule: powershell.exe -Command "New-NetFirewallRule -DisplayName 'FleetDeck Agent Service' -Name 'FleetDeck Agent Service' -Direction Inbound -Program 'C:\Program Files (x86)\FleetDeck Agent\fleetdeck_agent...