Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le juillet 15, 2020, 18:00:18

Titre: [FireEye]Financially Motivated Actors Are Expanding Access Into OT: Analysis of Kill Lists That Include OT Processes Used With Seven Malware Families
Posté par: igor51 le juillet 15, 2020, 18:00:18
Financially Motivated Actors Are Expanding Access Into OT: Analysis of
Kill Lists That Include OT Processes Used With Seven Malware Families


Mandiant Threat Intelligence has researched and written extensively
  on the increasing financially motivated threat activity directly
  impacting operational technology (OT) networks. Some of this research
  is available in our previous blog posts on     href="/content/fireeye-www/en_US/blog/threat-research/2020/02/ransomware-against-machine-learning-to-disrupt-industrial-production.html">industrial
    post-compromise ransomware and     href="/content/fireeye-www/en_US/blog/threat-research/2019/12/fireeye-approach-to-operational-technology-security.html">FireEye's
    approach to OT security. While most of the actors behind this
  activity likely do not differentiate between IT and OT or have a
  particular interest in OT assets, they are driven by the goal of
  making money and have demonstrated the skills needed to operate in
  these networks. For example, the shift to post-compromise ransomware
  deployment highlights the actors’ ability to adapt to more complex environments.


 

In this blog post we look further into this trend by examining two
  different process kill lists containing OT processes which we have
  observed deployed alongside a variety of ransomware samples and
  families. We think it is likely that these lists were the result of
  coincidental asset scanning in victim organizations and not specific
  targeting of OT. While this judgement may initially seem like good
  news to defenders, this activity still indicates that multiple, very
  prolific, financially motivated threat actors are active inside
  organizations’ OT—based on the contents of these process kill
  lists—with the intent of profiting from the ransom of stolen
  information and disrupted services.


 

Two Unique Process Kill Lists Deployed Alongside Seven Ransomware
  Families Include OT Processes


 

Threat actors often deploy process kill lists alongside or as part
  of ransomware to terminate anti-virus products, stop alternative
  detection mechanisms, and remove file locks to ensure critical data is
  encrypted. As a result, the deployment of these lists increases the
  likelihood of a successful attack (MITRE ATT&CK T1489). In post
  compromise ransomware attacks, attackers regularly tailor the lists to
  include processes that are relevant to the victim’s environment. By
  stopping these processes, the attacker makes sure to encrypt data from
  critical systems, which may remain unaffected if the process is
  currently in use. As the likelihood of crippling critical systems
  increases, the target is more likely to suffer impacts on its physical production.


 


  First Process Kill List Has Been Leveraged By At Least Six
    Ransomware Families


 

Mandiant identified samples of at least six ransomware families
  (DoppelPaymer, LockerGoga, Maze, MegaCortex, Nefilim and
  SNAKEHOSE)—all of which have been associated with high-profile
  incidents impacting industrial organizations over the past two
  years—that have leveraged a common process kill list containing 1,000+
  processes. The list, which we briefly discussed in an earlier     href="/content/fireeye-www/en_US/blog/threat-research/2020/02/ransomware-against-machine-learning-to-disrupt-industrial-production.html">blog
    post from February 2020, includes a couple dozen processes
  related to OT executables—mainly from General Electric Proficy, a
  suite used for historians and human-machine interfaces (HMIs). We
  note, that while the inclusion of these processes in this kill list
  could result in limited loss of view of historical process data, it is
  not likely to directly impact the operator’s ability to control the
  physical process itself.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otransomware/Picture1.png" alt="" />
 
 Figure 1: Snippets from “kill.bat”
    deployed alongside LockerGoga (L) and MegaCortex process kill list (R)


 

The earliest iteration we identified of the shared kill list was a
  batch script deployed alongside LockerGoga (MD5:
  34187a34d0a3c5d63016c26346371b54) in January 2019 (Figure 1). Other
  iterations of the list we have observed are also hardcoded directly
  into the ransomware binaries. The different techniques used to deploy
  the process kill list, the use of different malware families, and
  slight variations between each list iteration (mainly typos in the
  processes, e.g.: a2guard.exea2start.exe; nexe;
  proficyclient.exe) indicate that likely more than one actor had
  access to the true source of the process kill list. This source could
  be for example a post of processes shared on a dark web forum, or an
  independent actor sharing the compiled list with other actors.


 

We think it is likely that the OT processes identified in this list
  simply represent the coincidental output of automated process
  collection from victim environment(s) and not a targeted effort to
  impact OT. This is supported by the relatively limited and specific
  selection of OT-related processes, rather than a broader selection of
  many vendors and OT-related processes that would have been suggestive
  of targeted external research. Regardless, this does not downplay the
  significance of the inclusion of OT processes in the list, as it
  suggests that sophisticated financially motivated actors, such as
  FIN6, have had at least some visibility into a victim’s OT network. As
  a result, the actors were able to tailor their malware to impact those
  systems, without the explicit intent to target OT assets.


 

Most types of ransomware attacks in OT environments will result in
  the disruption of services and a temporary loss of view into current
  and historical process data. However, OT environments impacted by a
  ransomware that leverages this kill list and happen to be running one
  or more of the processes used by the initial victim(s)—and therefore
  are included on the list—may face additional impacts. For example,
  historian databases would be more likely to be encrypted, possibly
  resulting in loss of historical data. Other impacts could include gaps
  in the collection of process data corresponding to the duration of the
  outage and temporary loss of access to licensing rights for critical services.


 


  Second List Deployed Alongside CLOP Ransomware Sample Has a Higher
    Chance of Impacting OT Systems


 

Mandiant analyzed a second, entirely unrelated sample of ransomware
  (MD5: 3b980d2af222ec909b948b6bbdd46319) from the CLOP family with a
  hardcoded list for enumeration and termination of processes that
  includes a number of OT strings. The list contains over 1,425
  processes, from which at least 150 belong to OT-related software
  suites (Figure 2 and Appendix).


 

Based on our analysis, the CLOP malware family’s process kill list
  has grown over time possibly as more processes are scanned during
  different compromises. While we do not currently hold enough
  information to describe the exact mechanism used by the actor to grow
  the list, it appears to have resulted from actor reconnaissance across
  multiple victims. We have observed the threat actor employing process
  discovery procedures, including running the tasklist utility. This
  indicates that the actor scanned for processes in at least one
  victim’s OT network(s) before deploying the ransomware.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otransomware/Picture2.png" alt="" />
 
 Figure 2: Subset of processes in observed
    CLOP sample


 

CLOP is also interesting as we have only observed a single unique
  and very prolific financially motivated threat actor leveraging the
  malware family. The group, who has been active since at least 2016 and
  potentially as early as 2014, is known for operating large phishing
  campaigns to distribute malware and typically monetizes intrusions
  through ransomware deployment. As highlighted by their versatility and
  long history in financially motivated intrusions, the actor’s activity
  in OT networks is likely no more than an additional step in the
  process for monetization. However, the financial motivations of the
  actor again do not imply low risk to OT. Instead, our analysis of the
  CLOP sample’s kill list indicates that the included processes actually
  have greater potential to disrupt OT systems than those included in
  the shared list described above.


 

Unlike the first kill list, the CLOP sample includes a list of
  processes that, if stopped, may directly impact the operator’s ability
  to both visualize and control production. This is especially true in
  the case of some included processes that support HMI and PLC
  supervision. Some of the OT processes present in the CLOP sample are
  related to the following products:


 
   
     
   
     
   
              width="119">

TwinCAT


   
                width="0">

Data Acquisition Software (DAQ)

          width="0">

Software used to acquire data from sensors and
          conditioning devices.


   
     
   
              width="119">

N/A


          Vendor


          Product


          Description

Siemens

SIMATIC
        WinCC

SCADA system, common for
          process control and automation.

Beckhoff

Software for
          PC-based process control and automation.

National Instruments

Kepware

KEPServer
        EX

Software platform that collects
          information from industrial devices and sends the output to
          SCADA applications.

OPC Unified Architecture (OPC-UA)

Communication
          protocol for data acquisition and exchange between industrial
          equipment and enterprise systems. 


 


  Table 1: Examples of products related to OT
    processes included in identified CLOP kill list


 

While it is likely the physical processes this software controls
  would continue to operate even if the software processes were
  terminated unexpectedly, stopping the software processes included in
  the CLOP sample’s kill list could result in the loss of view/control
  over those physical processes due to the inability of operators to
  interact with the equipment. This can be caused not only by the
  ransomware’s disruption of intermediary systems, but also by the loss
  of access to relevant files on HMIs/EWS required for the operation of
  process control and monitoring software–for example configurations or
  project files. This could prolong the mean time to recovery (MTTR) of
  impacted environments without offline backups. In the CLOP sample
  list, we also identified specialized processes for software
  application design and testing that may also become corrupted at the
  time of encryption.


 

Process Kill Lists Are Just An Observable Indicating Broader
  Financially Motivated Interest In OT


 

Financially motivated threat actors leverage a large variety of
  tactics and techniques to obtain data that they can later use to
  generate profits. While financial actors have historically posed
  little to no threat to OT systems, the recent uptick in ransomware and
  extortion incidents highlights that industrial operations are
  increasingly at risk. Although we have not observed any financially
  motivated actors explicitly targeting OT systems, our research into
  process kill lists deployed with or alongside ransomware samples shows
  that at least two sophisticated financial actors have expanded their
  access into OT networks during their regular intrusions.


 

This increasing exposure of OT to financially motivated threat
  activity is no surprise, given that TTPs used by cybercriminals
  increasingly resemble those employed by sophisticated actors. We have
  consistently conveyed this message since at least 2018, when we
  publicly discussed the commodity and     href="https://www.fireeye.com/blog/threat-research/2019/04/triton-actor-ttp-profile-custom-attack-tools-detections.html">custom
    IT tools leveraged by the TRITON attacker while traversing
  through its targets’ networks (Figure 3). The likelihood of
  financially motivated actors impacting OT while seeking to monetize
  intrusions will continue to rise for the following reasons:


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otransomware/Picture3.png" alt="" />
 
 Figure 3: TTPs seen across both IT and OT incidents


 
 

Outlook


 

As OT networks continue to become more accessible to threat actors
  of all motivations, security threats that have historically impacted
  primarily IT are becoming more commonplace. This normalization of OT
  as just another network from the threat actor perspective is
  problematic for defenders for many of the reasons discussed above.
  This recent threat activity should be taken as a wake-up call for two
  main reasons: the various security challenges commonly faced by
  organizations to protect OT networks, and the significant consequences
  that may arise from security compromises even when they are not
  explicitly designed to target production systems. Asset owners need to
  look at OT security with the mindset that it is not if you will have a
  breach, but when. This shift in thinking will allow defenders to
  better prepare to respond when an incident does happen, and can help
  reduce the impact of an incident by orders of magnitude.   


 

Appendix: Selection Of OT Processes From CLOP Kill List


 
   
     
   
                width="203">

Atlas Copco


   
              width="203">

Beckhoff


   
              width="203">

Beckhoff


   
              width="203">

Beckhoff


   
              width="203">

GE


   
              width="203">

Honeywell


   
              width="203">

B&R


   
              width="203">

B&R


   
              width="203">

B&R


   
              width="203">

B&R


   
              width="203">

B&R


   
              width="203">

B&R


   
              width="203">

B&R


   
                width="203">

Inray Industriesoftware


   
                width="203">

Inray Industriesoftware


   
              width="203">

Kepware


   
              width="203">

Kepware


   
     
       
   
              width="203">

NiceLabel


   
              width="203">

NiceLabel


   
                width="203">

National Instruments


   
     
   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
     
   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
     
   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
                width="203">

National Instruments


   
              width="203">

OPC


   
              width="203">

OPC


   
              width="203">

AUTEM


   
     
   
              width="203">

PTC


   
              width="203">

Q-Das


   
              width="203">

Q-Das


   
              width="203">

Q-Das


   
              width="203">

Q-Das


   
              width="203">

Q-Das


   
                width="203">

Rockwell Automation or National Instruments


     

   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="462">

SIEMENS.INFORMATIONSERVER.DISCOVERSERVICEINSTALLER.EXE


     

   
              width="462">

SIEMENS.INFORMATIONSERVER.ISREADY.PLUGINSERVICE.EXE


     

   
     
   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Siemens


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Ansys


   
              width="203">

Tani


   
              width="203">

Tani


   
              width="203">

Tani


          Process Name


          Vendor

ACTLICENSESERVER.EXE

TCATSYSSRV.EXE

TCEVENTLOGGER.EXE

TCR.EXE

ALARMMANAGER.EXE

S2.EXE

BR.ADI.DISPLAY.BRIGHTNESS.EXE

BR.ADI.SERVICE.EXE

BR.ADI.UPS.MANAGER.EXE

BR.ADI.UPS.SERVICE.EXE

BR.AS.UPGRADESERVICE.EXE

BRAUTHORIZATIONSVC.EXE

BRTOUCHSVC.EXE

OPCROUTER4SERVICE.EXE

OPCROUTERCONFIG.EXE

SERVER_EVENTLOG.EXE

SERVER_RUNTIME.EXE

NICELABELAUTOMATIONSERVICE2017.EXE

NiceLabel

NICELABELPROXY.EXE

NICELABELPROXYSERVICE2017.EXE

APPLICATIONWEBSERVER.EXE

CWDSS.EXE

National
        Instruments

NIAUTH_DAEMON.EXE

NIDEVMON.EXE

NIDISCSVC.EXE

NIDMSRV.EXE

NIERSERVER.EXE

NILXIDISCOVERY.EXE

NIMDNSRESPONDER.EXE

NIMXS.EXE

National
        Instruments

NIPXICMS.EXE

NIROCO.EXE

NISDS.EXE

National
        Instruments

NISVCLOC.EXE

NIWEBSERVICECONTAINER.EXE

SYSTEMWEBSERVER.EXE

OPC.UA.DISCOVERYSERVER.EXE

OPCUALDS.EXE

ANAWIN.EXE

ASM.EXE

Possibly
        Siemens

PARAMETRIC.EXE

QDAS_O-QIS.EXE

QDAS_PROCELLA.EXE

QDAS_QS-STAT.EXE

QDASIDI_SRV.EXE

SPCPROCESSLINK.EXE

TAGSRV.EXE

_SIMPCMON.EXE

ALMPANELPLUGIN.EXE

ALMSRV64X.EXE

ALMSRVBUBBLE64X.EXE

CC.TUNNELSERVICEHOST.EXE

CCAEPROVIDER.EXE

CCAGENT.EXE

CCALGRTSERVER.EXE

CCARCHIVEMANAGER.EXE

CCCAPHSERVER.EXE

CCCSIGRTSERVER.EXE

CCDBUTILS.EXE

CCDELTALOADER.EXE

CCDMRUNTIMEPERSISTENCE.EXE

CCECLIENT_X64.EXE

CCECLIENT.EXE

CCESERVER_X64.EXE

CCESERVER.EXE

CCKEYBOARDHOOK.EXE

CCLICENSESERVICE.EXE

CCNSINFO2PROVIDER.EXE

CCPACKAGEMGR.EXE

CCPERFMON.EXE

CCPROFILESERVER.EXE

CCPROJECTMGR.EXE

CCPTMRTSERVER.EXE

CCREDUNDANCYAGENT.EXE

CCREMOTESERVICE.EXE

CCRT2XML.EXE

CCRTSLOADER_X64.EXE

CCSSMRTSERVER.EXE

CCSYSTEMDIAGNOSTICSHOST.EXE

CCTEXTSERVER.EXE

CCTLGSERVER.EXE

CCTMTIMESYNC.EXE

CCTMTIMESYNCSERVER.EXE

CCUCSURROGATE.EXE

CCWATCHOPC.EXE

CCWRITEARCHIVESERVER.EXE

DA2XML.EXE

GSCRT.EXE

HMIES.EXE

HMIRTM.EXE

HMISMARTSTART.EXE

HMRT.EXE

IPCSECCOM.EXE

OPCUASERVERWINCC.EXE

PASSDBRT.EXE

PDLRT.EXE

PMEXP.EXE

PNIOMGR.EXE

REDUNDANCYCONTROL.EXE

REDUNDANCYSTATE.EXE

S7ACMGRX.EXE

S7AHHLPX.EXE

S7ASYSVX.EXE

S7EPASRV64X.EXE

S7HSPSVX.EXE

S7KAFAPX.EXE

S7O.TUNNELSERVICEHOST.EXE

S7OIEHSX64.EXE

S7OPNDISCOVERYX64.EXE

S7SYMAPX.EXE

S7TGTOPX.EXE

S7TRACESERVICE64X.EXE

S7UBTOOX.EXE

S7UBTSTX.EXE

S7WNRMSX.EXE

S7WNSMGX.EXE

S7WNSMSX.EXE

S7XUDIAX.EXE

S7XUTAPX.EXE

SCORECFG.EXE

SCOREDP.EXE

SCOREPNIO.EXE

SCORES7.EXE

SCORESR.EXE

SCSDISTSERVICEX.EXE

SCSFSX.EXE

SCSMX.EXE

SDIAGRT.EXE

Siemens

Siemens

SIEMENS.INFORMATIONSERVER.SCHEDULER.EXE


     

Siemens

SIM9SYNC.EXE

SIMNETPNPMAN.EXE

SMARTSERVER.EXE

SSERVCFG.EXE

TOUCHINPUTPC.EXE

TRACECONCEPTX.EXE

TRACESERVER.EXE

UM.RIS.EXE

UM.SSO.EXE

WEBNAVIGATORRT.EXE

WINCCEXPLORER.EXE

CCDMRTCHANNELHOST.EXE

ANSYS.ACT.BROWSER.EXE

ANSYS.EXE

ANSYS192.EXE

ANSYSFWW.EXE

ANSYSLI_CLIENT.EXE

ANSYSLI_MONITOR.EXE

ANSYSLI_SERVER.EXE

ANSYSLMD.EXE

ANSYSWBU.EXE

CONFIGSERVERI64.EXE

ENGINELOGGERI64.EXE

PLCENGINEI64.EXE


Source: Financially Motivated Actors Are Expanding Access Into OT: Analysis of
Kill Lists That Include OT Processes Used With Seven Malware Families (http://)