Auteur Sujet: [FireEye]Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser  (Lu 3208 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser

[html]

Throughout 2020,     href="/content/fireeye-www/en_US/blog/threat-research/2020/03/they-come-in-the-night-ransomware-deployment-trends.html">ransomware
  activity has become increasingly prolific, relying on an ecosystem
  of distinct but co-enabling operations to gain access to targets of
  interest before conducting extortion. Mandiant Threat Intelligence has
  tracked several loader and backdoor campaigns that lead to the
  post-compromise deployment of ransomware, sometimes within     href="https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/">24
    hours of initial compromise. Effective and fast detection of
  these campaigns is key to     href="/content/fireeye-www/en_US/blog/products-and-services/2020/06/sizing-up-how-mandiant-evaluates-ransomware-defense.html">mitigating
    this threat.


 

The malware families enabling these attacks previously reported by
  Mandiant to intelligence subscribers include KEGTAP/BEERBOT,
  SINGLEMALT/STILLBOT and WINEKEY/CORKBOT. While these malware families
  communicate with the same command and control infrastructure (C2) and
  are close to functional parity, there are minimal code overlaps across
  them. Other security researchers have tracked these malware families
  under the names BazarLoader and   href="https://www.vkremez.com/2020/04/lets-learn-trickbot-bazarbackdoor.html">BazarBackdoor
  or Team9.


 

The operators conducting these campaigns have actively targeted
  hospitals, retirement communities, and medical centers, even in the     href="/content/fireeye-www/en_US/blog/executive-perspective/2020/10/ransomware-the-threat-we-can-no-longer-afford-to-ignore.html">midst
    of a global health crisis, demonstrating a clear disregard for
  human life.


 

Email Campaign TTPs


 

Campaigns distributing KEGTAP, SINGLEMALT and WINEKEY have been sent
  to individuals at organizations across a broad range of industries and
  geographies using a series of shifting delivery tactics, techniques
  and procedures (TTPs). Despite the frequent changes seen across these
  campaigns, the following has remained consistent across recent activity:


 
  • Emails contain an in-line link to an actor-controlled Google
        Docs document, typically a PDF file.
  • This document contains
        an in-line link to a URL hosting a malware payload.
  • Emails
        masquerade as generic corporate communications, including follow-ups
        about documents and phone calls or emails crafted to appear related
        to complaints, terminations, bonuses, contracts, working schedules,
        surveys or queries about business hours.
  • Some email
        communications have included the recipient’s name or employer name
        in the subject line and/or email body.

 

Despite this uniformity, the associated TTPs have otherwise changed
  regularly—both between campaigns and across multiple spam runs seen in
  the same day. Notable ways that these campaigns have varied over time include:


 
  • Early campaigns were delivered via Sendgrid and included
        in-line links to Sendgrid URLs that would redirect users to
        attacker-created Google documents. In contrast, recent campaigns
        have been delivered via attacker-controlled or compromised email
        infrastructure and have commonly contained in-line links to
        attacker-created Google documents, although they have also used
        links associated with the Constant Contact service.
  • The
        documents loaded by these in-line links are crafted to appear
        somewhat relevant to the theme of the email campaign and contain
        additional links along with instructions directing users to click on
        them. When clicked, these links download malware binaries with file
        names masquerading as document files. Across earlier campaigns these
        malware binaries were hosted on compromised infrastructure, however,
        the attackers have shifted to hosting their malware on legitimate
        web services, including Google Drive, Basecamp, Slack, Trello,
        Yougile, and JetBrains.
  • In recent campaigns, the malware
        payloads have been hosted on numerous URLs associated with one or
        more of these legitimate services. In cases where the payloads have
        been taken down, the actors have sometimes updated their Google
        documents to contain new, working links.
  • Some campaigns
        have also incorporated customization, including emails with internal
        references to the recipients’ organizations (Figure 1) and
        organizations’ logos embedded into the Google Docs documents (Figure
      2).

 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/botlogger/picture1.png" alt="" />
 
 Figure 1: Email containing internal
    references to target an organization’s name


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/botlogger/picture2.png" alt="" />
 
 Figure 2: Google Docs PDF document
    containing a target organization’s logo


 

Hiding the final payload behind multiple links is a simple yet
  effective way to bypass some email filtering technologies. Various
  technologies have the ability to follow links in an email to try to
  identify malware or malicious domains; however, the number of links
  followed can vary. Additionally, embedding links within a PDF document
  further makes automated detection and link-following difficult.


 

Post-Compromise TTPs


 

Given the possibility that accesses obtained from these campaigns
  may be provided to various operators to monetize, the latter-stage
  TTPs, including ransomware family deployed, may vary across
  intrusions. A notable majority of cases where Mandiant has had
  visibility into these post-compromise TTPs have been attributable to
  UNC1878, a financially motivated actor that monetizes network access
  via the deployment of RYUK ransomware.


 


  Establish Foothold


 

Once the loader and backdoor have been executed on the initial
  victim host, the actors have used this initial backdoor to download
  POWERTRICK and/or Cobalt Strike BEACON payloads to establish a
  foothold. Notably, the respective loader and backdoor as well as
  POWERTRICK have typically been installed on a small number of hosts in
  observed incidents, suggesting these payloads may be reserved for
  establishing a foothold and performing initial network and host
  reconnaissance. However, BEACON is frequently found on a larger number
  of hosts and used throughout various stages of the attack lifecycle.


 


  Maintain Presence


 

Beyond the preliminary phases of each intrusion, we have seen
  variations in how these attackers have


Tags: