We just published a report on EVERYTHING that @HuntressLabs SOC is seeing for post-exploitation from #ScreenConnect CVE-2024-1708/CVE-2024-1709.
https://t.co/JVQ7rG7uAt
There's A LOT of it. We're talking:
- Adversaries Deploying Ransomware (LockBit and others)
- Classic LOLbin enumeration and reconnaissance
- Dropping cryptocurrency miners (masquerading as SentinelOne)
- Installing other persistence and backdoors (SimpleHelp C2, SSH, Remote Desktop, new users, reverse shells)
This includes all the technical details and tradecraft for each variety of these attacks. Please go look through this.
If I may be so bold, I think this is seriously the biggest and most-comprehensive release of the active threat intel that we've seen shared publicly so far.
We can confirm, we're seeing the following deployed via the SlashAndGrab (ScreenConnect Vuln)
- Ransomware (Lockbit)
- Cobalt Strike
- SSH Tunnels
- CoinMiners
- Additional RMMs
Victims include Vets Offices, Health Clinics, and local governments (including attacks against systems related to 911 Systems)
Full analysis can be found here: https://t.co/YozTQg3Shf
CVEs:
CVE-2024-1708
CVE-2024-1709
Shoutout @HuntressLabs analysts @f0xtrot_sierra, @xorJosh and the rest of the team for responding to this.
#SlashAndGrab #ScreenConnect #Connectwise
Lotta chatter around #ScreenConnect vulnerabilities now as folks are getting spun up.
Fellow @HuntressLabs researchers and I were up all night to recreate the auth bypass and RCE exploit.
I'm not a huge fan of giving a PoC to threat actors, but I do dig snazzy video demos 😜
.@HuntressLabs now has detection guidance related to the @ConnectWise#ScreenConnect vulnerability. Step 1: PATCH! Step 2: Look for signs of compromise.
CC: Patrick Beggs https://t.co/KIgJyiRYMY
⚠️ Attention, Sysadmins! A newly discovered critical #vulnerability (CVE-2024-21410) in #Microsoft Exchange Server is currently being actively exploited.
Details here → https://t.co/5M0IxD6eTX
Attackers can hijack user accounts & gain admin-level control. Update ASAP!
Microsoft has detected ransomware and extortion campaigns impacting the education sector, particularly in the US, by a threat actor we track as DEV-0832 (aka Vice Society). Get TTPs and protection info via our latest blog post: https://t.co/7p1TpC6pEv
Is a holiday weekend even a holiday weekend without threat actors swooping in to ruin everything? 🙃
Progressive Computing was a victim of the mass attack that ruined many of our Fourth of July weekends last year. They recently covered lessons learned: https://t.co/xVpr34kIyl
Today I got a notification on my phone that YouTube had sent me a copyright report, claiming one of my videos violated copyright and my channel was going to receive a strike.
Except, my video didn't violate copyright. And YouTube didn't really send me a copyright report.
Across ~70,000 businesses that Huntress protects, we see ~195 that have hosts with port 445 open and exposed to the public internet.
With that said, a public port does NOT mean vulnerable to CVE-2022-26809, and external is not the only attack vector. Please patch.
We’re pleased to announce today that Aura Technology and Amicus ITS have combined to create a £10m+ strategic IT solutions group operating in the public and private sectors.
Our two businesses become sister companies under the Aura Technology Group.
https://t.co/xSfD5q8S3s
"I want to bring my own experience in business and sport to the technology world". See @CliveWoodward discussing his new appointment at Aura.
https://t.co/Sp9z5VS0LS
#ITStrategy