Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le novembre 06, 2020, 20:00:20

Titre: [FireEye]Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser
Posté par: igor51 le novembre 06, 2020, 20:00:20
Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser

[html]

Throughout 2020,     href="/content/fireeye-www/en_US/blog/threat-research/2020/03/they-come-in-the-night-ransomware-deployment-trends.html">ransomware
  activity has become increasingly prolific, relying on an ecosystem
  of distinct but co-enabling operations to gain access to targets of
  interest before conducting extortion. Mandiant Threat Intelligence has
  tracked several loader and backdoor campaigns that lead to the
  post-compromise deployment of ransomware, sometimes within     href="https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/">24
    hours of initial compromise. Effective and fast detection of
  these campaigns is key to     href="/content/fireeye-www/en_US/blog/products-and-services/2020/06/sizing-up-how-mandiant-evaluates-ransomware-defense.html">mitigating
    this threat.


 

The malware families enabling these attacks previously reported by
  Mandiant to intelligence subscribers include KEGTAP/BEERBOT,
  SINGLEMALT/STILLBOT and WINEKEY/CORKBOT. While these malware families
  communicate with the same command and control infrastructure (C2) and
  are close to functional parity, there are minimal code overlaps across
  them. Other security researchers have tracked these malware families
  under the names BazarLoader and   href="https://www.vkremez.com/2020/04/lets-learn-trickbot-bazarbackdoor.html">BazarBackdoor
  or Team9.


 

The operators conducting these campaigns have actively targeted
  hospitals, retirement communities, and medical centers, even in the     href="/content/fireeye-www/en_US/blog/executive-perspective/2020/10/ransomware-the-threat-we-can-no-longer-afford-to-ignore.html">midst
    of a global health crisis, demonstrating a clear disregard for
  human life.


 

Email Campaign TTPs


 

Campaigns distributing KEGTAP, SINGLEMALT and WINEKEY have been sent
  to individuals at organizations across a broad range of industries and
  geographies using a series of shifting delivery tactics, techniques
  and procedures (TTPs). Despite the frequent changes seen across these
  campaigns, the following has remained consistent across recent activity:


 
 

Despite this uniformity, the associated TTPs have otherwise changed
  regularly—both between campaigns and across multiple spam runs seen in
  the same day. Notable ways that these campaigns have varied over time include:


 
 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/botlogger/picture1.png" alt="" />
 
 Figure 1: Email containing internal
    references to target an organization’s name


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/botlogger/picture2.png" alt="" />
 
 Figure 2: Google Docs PDF document
    containing a target organization’s logo


 

Hiding the final payload behind multiple links is a simple yet
  effective way to bypass some email filtering technologies. Various
  technologies have the ability to follow links in an email to try to
  identify malware or malicious domains; however, the number of links
  followed can vary. Additionally, embedding links within a PDF document
  further makes automated detection and link-following difficult.


 

Post-Compromise TTPs


 

Given the possibility that accesses obtained from these campaigns
  may be provided to various operators to monetize, the latter-stage
  TTPs, including ransomware family deployed, may vary across
  intrusions. A notable majority of cases where Mandiant has had
  visibility into these post-compromise TTPs have been attributable to
  UNC1878, a financially motivated actor that monetizes network access
  via the deployment of RYUK ransomware.


 


  Establish Foothold


 

Once the loader and backdoor have been executed on the initial
  victim host, the actors have used this initial backdoor to download
  POWERTRICK and/or Cobalt Strike BEACON payloads to establish a
  foothold. Notably, the respective loader and backdoor as well as
  POWERTRICK have typically been installed on a small number of hosts in
  observed incidents, suggesting these payloads may be reserved for
  establishing a foothold and performing initial network and host
  reconnaissance. However, BEACON is frequently found on a larger number
  of hosts and used throughout various stages of the attack lifecycle.


 


  Maintain Presence


 

Beyond the preliminary phases of each intrusion, we have seen
  variations in how these attackers have