.@HuntressLabs has validated the vulnerabilities referred to in the latest February 19th #ConnectWise ScreenConnect advisory. For on-premise users, it is our strongest recommendation to patch and update to #ScreenConnect version 23.9.8 immediately.
Excited to kick off #ITNSecure22 today in Orlando, FL! Our own @MaxRogers5 will be presenting on defense evasion this Wednesday starting at 1:30pm. See you there!
I implemented a PoC replicating the exploitation of the #kaseya VSA server as seen in the recent MSP #ransomwareattack.
Can't release more details until the software is fully patched, but this research has helped a lot in understanding the attack.
@HuntressLabs
We haven't confirmed lateral movement, but interesting to see scheduled tasks similar to the "Sapphire Pigeon" tasks on non-Exchange hosts on the same network as a compromised Exchange server.
Not sure what the "Microsoft-Windows-DiskDiagnostic Resolver" scheduled task has to do with TeamViewer, but it was nice enough to clean up all event logs after stopping the service! #CyberSecurity
Attackers used to call PowerShell (in)directly with a single command (using wmic, rundll32, etc.), now they use mshta.exe to read a registry value that contains the PowerShell command. Still looks just as suspicious.
@Ledtech3@KyleHanslovan@HuntressLabs In this case, WMI was another way of persisting the payload discussed here: https://t.co/74ilGS835K (both found on the same host). The encoded data in the Google Sheet decoded to a request very similar to the "stage 2" request from the blog.
I noticed a few odd looking scheduled tasks where the command was something like "c:\users\john". Combining the task's command and args gives a full path, which Windows will run (on 2 of 3 versions I tested). Unfortunately Autoruns only shows the command. https://t.co/Dtn6y6Cl9A
Wanna know how to take a malicious .NET application apart? Check out this blog written by @jdferrell3 from @HuntressLabs. Great read specifically for those who love to see how layers upon layers of obfuscated malware can be torn apart.
https://t.co/wVXiZhNaaU