Throughout 2020, href="/content/fireeye-www/en_US/blog/threat-research/2020/03/they-come-in-the-night-ransomware-deployment-trends.html">ransomware
activity has become increasingly prolific, relying on an ecosystem
of distinct but co-enabling operations to gain access to targets of
interest before conducting extortion. Mandiant Threat Intelligence has
tracked several loader and backdoor campaigns that lead to the
post-compromise deployment of ransomware, sometimes within href="https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/">24
hours of initial compromise. Effective and fast detection of
these campaigns is key to href="/content/fireeye-www/en_US/blog/products-and-services/2020/06/sizing-up-how-mandiant-evaluates-ransomware-defense.html">mitigating
this threat.
The malware families enabling these attacks previously reported by
Mandiant to intelligence subscribers include KEGTAP/BEERBOT,
SINGLEMALT/STILLBOT and WINEKEY/CORKBOT. While these malware families
communicate with the same command and control infrastructure (C2) and
are close to functional parity, there are minimal code overlaps across
them. Other security researchers have tracked these malware families
under the names BazarLoader and href="https://www.vkremez.com/2020/04/lets-learn-trickbot-bazarbackdoor.html">BazarBackdoor
or Team9.
The operators conducting these campaigns have actively targeted
hospitals, retirement communities, and medical centers, even in the href="/content/fireeye-www/en_US/blog/executive-perspective/2020/10/ransomware-the-threat-we-can-no-longer-afford-to-ignore.html">midst
of a global health crisis, demonstrating a clear disregard for
human life.
Campaigns distributing KEGTAP, SINGLEMALT and WINEKEY have been sent
to individuals at organizations across a broad range of industries and
geographies using a series of shifting delivery tactics, techniques
and procedures (TTPs). Despite the frequent changes seen across these
campaigns, the following has remained consistent across recent activity:
Despite this uniformity, the associated TTPs have otherwise changed
regularly—both between campaigns and across multiple spam runs seen in
the same day. Notable ways that these campaigns have varied over time include:
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/botlogger/picture1.png" alt="" />
Figure 1: Email containing internal
references to target an organization’s name
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/botlogger/picture2.png" alt="" />
Figure 2: Google Docs PDF document
containing a target organization’s logo
Hiding the final payload behind multiple links is a simple yet
effective way to bypass some email filtering technologies. Various
technologies have the ability to follow links in an email to try to
identify malware or malicious domains; however, the number of links
followed can vary. Additionally, embedding links within a PDF document
further makes automated detection and link-following difficult.
Given the possibility that accesses obtained from these campaigns
may be provided to various operators to monetize, the latter-stage
TTPs, including ransomware family deployed, may vary across
intrusions. A notable majority of cases where Mandiant has had
visibility into these post-compromise TTPs have been attributable to
UNC1878, a financially motivated actor that monetizes network access
via the deployment of RYUK ransomware.
Establish Foothold
Once the loader and backdoor have been executed on the initial
victim host, the actors have used this initial backdoor to download
POWERTRICK and/or Cobalt Strike BEACON payloads to establish a
foothold. Notably, the respective loader and backdoor as well as
POWERTRICK have typically been installed on a small number of hosts in
observed incidents, suggesting these payloads may be reserved for
establishing a foothold and performing initial network and host
reconnaissance. However, BEACON is frequently found on a larger number
of hosts and used throughout various stages of the attack lifecycle.
Maintain Presence
Beyond the preliminary phases of each intrusion, we have seen
variations in how these attackers have