Ethical hacking, Securing governments, training U.S. law enforcement, S&P 500 companies, Advance Ai supported Red Teaming led by leading Cyber Warfare experts
Threat Report: SeaShell Blizzard https://t.co/gjJfXjFlft
Continued...
Notable Events
Attacks against Georgian civil society groups
Reported by UK intelligence services and international partners, these attacks consisted of the defacement of web pages belonging to the government of the country/region of Georgia as well as prominent Georgian non-government organizations (NGOs) and media organizations. The attacks against the media caused disruption to the operations of several national broadcasters.
VPNFilter botnet
In May 2018, security researchers disclosed a botnet that affected approximately 500,000 compromised network devices. Analysis of code used in this operation revealed overlaps with a previously used encryption method implemented by Seashell Blizzard (IRIDIUM). The FBI subsequently took over and disrupted this botnet.
PyeongChang Olympic Winter Games
Seashell Blizzard (IRIDIUM) compromised servers used during the 2018 Winter Olympics in PyeongChang, South Korea to deliver a payload that effectively rendered the systems inoperable. The group crafted malware to appear as if originating from another group called "Lazarus," drawing attention away from its true attribution.
BadRabbit ransomware attacks
Towards the end of October 2017, several websites (primarily news and media), were compromised, and then used to deliver a fake Flash Player file containing BadRabbit ransomware through drive-by attacks. Once loaded, the ransomware spread to other endpoints in the network using the EternalBlue and EternalRomance exploits. The campaign primarily impacted systems in Russia, Ukraine, Germany, and Turkey.
NotPetya software supply chain attack
In June 2017, accounting software that is popular in Ukraine was tainted with malicious code that spread through its automatic update process. Using the update process, Seashell Blizzard (IRIDIUM) distributed ransomware that did not provide any recovery options, rendering systems inoperable without recourse. The group used malware that masqueraded as ransomware from previous, unrelated attacks, garnering the name NotPetya from the security community. While Ukraine was the country most impacted, the damage radiated outward due to the global nature of affected companies as well as worm capabilities that used harvested credentials and an SMBv1 exploit.
Ukrainian power grid attacks
In December 2016, a single power transmission substation was impacted by a destructive attack in Kyiv, Ukraine. Customers lost power for approximately one hour. This action might have been a capability test or a show of force. The malware was designed specifically to target electric grids and aptly named Industroyer. Evidence indicates that Seashell Blizzard (IRIDIUM) conducted reconnaissance within the target network for months prior to delivering the destructive payload.
Threat Report: SeaShell Blizzard, continued...
Exploits
The following list has some of the vulnerabilities this group has exploited recently.
CVE-2017-0143-Microsoft Server Message Block 1.0 (SMBv1)
CVE-2017-0145-Microsoft Server Message Block 1.0 (SMBv1)
Malware
The presence of the following malware and hacking tools can indicate an active breach perpetrated by this attack group.
BadRabbit (exclusive)—Self-propagating ransomware detected as Tibbar by Microsoft
Ransom:Win32/Tibbar.A
BlackEnergy (exclusive)—DDoS tool with a specialized ICS plugin
Trojan:Win32/BlackEnergy
CrashOverride or Industroyer (exclusive)—First surfaced in 2016, a modular malware purposely built for specialized attacks against SCADA/ICS systems
Trojan:Win32/CrashOverride.A
FalseCobra (exclusive)—Customized version of Malicious Macro Generator (MMG)
Trojan:O97M/FalseCobra.A!dha
NotPetya (exclusive)—Self-propagating ransomware; Petya variant
Ransom:Win32/Petya
OlympicDestroyer (exclusive)—Malware used in the PyeongChang Winter Olympics attack
Trojan:Win32/Samcrex.A!dha
PowerShell Empire (not exclusive)—Commonly available post-exploitation agent
Behavior:PowerShell/Empire.A
Behavior:Win32/NriPowerShellEmpire
HackTool:PowerShell/EmpireGetClipboardContents
HackTool:PowerShell/EmpireGetScreenshot
Venom RAT (non-exclusive)—An Seashell Blizzard (IRIDIUM)-specific variant of Venom RAT
TrojanDropper:Win32/ViperVenom.A!dha
Trojan:Win32/ViperVenom.A!dha
Threat Report: Seashell Blizzard, continued...
Links to Forest Blizzard (STRONTIUM)
Seashell Blizzard (IRIDIUM) operates with similar sponsorship as the Forest Blizzard (STRONTIUM) activity group, which is attributed to the Unit 26165 of the Russian military service (GRU). In limited circumstances, Microsoft Threat Intelligence has observed similar timeframes in which both activity groups have affected similar verticals and localities. As of March 2022, the country/regions of Georgia and Ukraine have been the most recent. Despite these temporal similarities, both activity groups are considered largely independent and are differentiated at multiple phases of the attack lifecycle.
Infrastrucutre
The infrastructure used by Seashell Blizzard (IRIDIUM) is a combination of shared and dedicated services. Recovered implants have utilized compromised websites as command-and-control servers.
For operational security since at least 2015, Seashell Blizzard (IRIDIUM) has utilized a custom network of Tor relays for command-and-control and egress. The group has used Tor for reconnaissance, attack, and exploitation against Internet-facing assets. Consistent with its OPSEC efforts, Seashell Blizzard (IRIDIUM) has also utilized infrastructure based on domains from free providers, such as Freenom. Seashell Blizzard (IRIDIUM) infrequently utilizes self-signed certificates and instead prefers to opt for SSL certificates from vetted providers, most commonly Let's Encrypt.
The group tends to utilize a combination of dedicated Virtual Private Servers and compromised systems in Eastern Europe for reconnaissance, command-and-control, and watering hole activity. During spear phishing attacks, the group has used accounts in popular webmail providers. Seashell Blizzard (IRIDIUM) has historically established phishing sites for credential harvesting in the .ml, .gq, .ga, and .cf top-level domains.
SeaShell Blizzard threat report continued...
Tools & TTPs
Seashell Blizzard (IRIDIUM) is an evolving activity group whose operations include supply chain attacks and other non-trivial deployment and weaponization methods, alongside more traditional spear phishing and brute force attempts to exploit exposed infrastructure. Although the group is thought to primarily perform espionage against specific verticals, Seashell Blizzard (IRIDIUM) has gained notoriety for enabling particularly destructive cyberattacks.
Seashell Blizzard (IRIDIUM) appears to be primarily responsible for specialized operations that involve disruption and destruction of mission critical systems, including ICS/SCADA systems, for which Seashell Blizzard (IRIDIUM) has previously demonstrated proficiency attacking at an operational or protocol level. With these capabilities, the group demonstrates a distinct level of technical sophistication.
Seashell Blizzard (IRIDIUM) is known to attack targets using a variety of methods, including:
Spear phishing for malware deployment
Drive-by compromises
Credential harvesting
Compromise of third parties for software supply chain attacks
Direct exploitation of devices and systems, often bespoke
Since 2015, Seashell Blizzard (IRIDIUM) has utilized malicious documents that are sometimes weaponized with an exploit. Most often, the documents contained macros that deployed a payload to either the disk or memory.
Between 2014-2015, Seashell Blizzard (IRIDIUM) was chiefly characterized by its use of modified versions of BlackEnergy malware for persistence and command-and-control (C2) communications. Beginning in 2016, in a departure from its traditional methods, Seashell Blizzard (IRIDIUM) began to rely on open-source tools and frameworks to enable early-stage and late-stage operations, complicating both detection and attribution of its activity.
Seashell Blizzard (IRIDIUM) is proficient working with multiple platforms, including Windows, MacOS, and Linux, network infrastructure devices like routers and switches, as well as Industrial Control Systems (ICS).
New threat post: Seashell Blizzard.
Summary:
Seashell Blizzard (IRIDIUM) is high-impact threat actor linked to the Russian Federation and conducts global activities on behalf of Russian Military Intelligence Unit 74455 (GRU). Active since at least 2013, Seashell Blizzard (IRIDIUM)’s prolific operations have led to high-profile incidents frequently leading to sabotage using cyber methods in the form of destructive attacks such as KillDisk (2015) and FoxBlade (2022), supply-chain attacks (MeDoc - 2017), and pseudo-ransomware attacks such as NotPetya (2017) and Prestige (2022). Additionally, operations in 2016 affecting the United States election environment and 2022 Ukraine conflict highlight Seashell Blizzard (IRIDIUM)’s ability to rapidly adapt to diverse environments in support of greater geopolitical objectives. Recognized as a specialized unit with capabilities used to support operations tailored to Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition Systems (SCADA), Seashell Blizzard (IRIDIUM)’s network operations have periodically led to disruptive attacks against critical infrastructure to include energy distribution systems. Seashell Blizzard (IRIDIUM)’s network operations and TTPs are considered diverse and typically leverage a range of common publicly available tools, including Cobalt Strike and DarkCrystalRAT. Network operations linked to the actor have affected multiple tiers of infrastructure, showcasing Seashell Blizzard (IRIDIUM)’s abilities to target end-users, network perimeters, and vertical specific systems leveraging both publicly available and custom exploits and methods. Incidents linked to Seashell Blizzard (IRIDIUM) may indicate an intent to conduct espionage in support of geopolitical objectives, cyber-enabled sabotage, or as preparation for larger campaigns where the targeted organization may enable access or understanding within a greater demographic or industry.
Threat report for CVE-2024-49039 continued....
Detections/Hunting Queries
Microsoft Defender Vulnerability Management
Microsoft Defender Vulnerability Management surfaces devices vulnerable to the following security issues in the Endpoints exposure tab of this report:
CVE-2024-49039
Microsoft Defender Antivirus
Microsoft Defender Antivirus detects threat components as the following:
Exploit:Win32/Tikupom
Microsoft Defender for Endpoint
The following alerts might indicate threat activity associated with this threat. These alerts, however, can be triggered by unrelated threat activity and are not monitored in the status cards provided with this report.
Possible theft of passwords and other sensitive web browser information
Suspicious PowerShell command line
Suspicious process executed PowerShell command
Possible malicious activity from an emerging threat
Threat report for CVE-2024-49039 continued...
Microsoft CTI has the following to say:
Exploitation Activity
Microsoft Threat Intelligence has observed exploitation of this vulnerability in the wild prior to disclosure, including mid-October exploitation activity leading to commodity malware payloads.
Recommendations
Microsoft released security updates for this issue on November 12, 2024. Customers who have not patched are urged to do so as soon as possible for their organization’s security.
Microsoft recommends the following mitigations to reduce the impact of this threat. Check the recommendations card for the deployment status of monitored mitigations.
Turn on cloud-delivered protection in Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attacker tools and techniques. Cloud-based machine learning protections block a huge majority of new and unknown variants.
Turn on the following attack surface reduction rule to block or audit activity associated with this threat:
Block executable files from running unless they meet a prevalence, age, or trusted list criterion
Block execution of potentially obfuscated scripts
Use advanced protection against ransomware
New threat report!
This is what Microsoft CTI has to say about CVE-2024-49039 - Windows Task Scheduler
A Windows sandbox escape vulnerability exists in the Windows Task Scheduler remote procedure call (RPC) interface. A threat actor must have access to a compromised system to exploit this vulnerability, which, if successful, could result in elevation of privileges. Microsoft has observed exploitation of this vulnerability in the wild.
Microsoft released security updates for this issue on November 12, 2024. Organizations can surface vulnerable devices in their environment using Microsoft Defender Vulnerability Management, accessible in the Endpoints exposure tab of this report.
Impacted Technologies
This vulnerability impacts instances of Windows devices updated prior to November 12, 2024.
Description
A threat actor with access to a compromised system could exploit the vulnerability in the Windows Task Scheduler by running a specially crafted application. The exploit could run in a low privileged AppContainer environment that would allow a threat actor to execute RPC functions. Successful exploitation could result in a sandbox escape and elevation of privileges, leading to possible code execution or access to resources at a higher level than the AppContainer environment.
More info to come in a later post....
@KnoetzeGrant new threat report from Microsoft CTI, this is what they have to say about CVE-2024-38217
CVE-2024-38217 is a security feature bypass vulnerability that causes File Explorer on Windows to remove the Mark of the Web (MOTW) from shortcut (LNK) files crafted using certain trailing characters, exempting these files from Windows Smart App Control and Microsoft Defender SmartScreen.
Elastic Security Labs published details of this vulnerability on August 5, 2024. Microsoft released security updates for this issue on September 10, 2024. Microsoft Defender for Endpoint and Microsoft Defender Antivirus provide detections for this threat. Customers should keep antimalware products up to date. Organizations can surface vulnerable devices in their environment using Microsoft Defender Vulnerability Management, accessible in the Endpoints exposure tab of this report.
Impacted Technologies
This vulnerability affects Windows versions updated prior to September 10, 2024.
Description
CVE-2024-38217 stems from how File Explorer handles certain malformed data in LNK files. When a user attempts to open a file with malformed data, File Explorer corrects the data and rewrites the LNK file, which removes the Mark of the Web (MotW) stored in an NTFS alternate data stream named :Zone.Identifier. Because File Explorer takes these actions before checking for the MotW, security features that rely on MotW tagging do not function properly.
To exploit this vulnerability, a threat actor can send a target a malicious, crafted LNK file. After the target downloads the file, the threat actor can achieve remote code execution (RCE) with the target’s privileges.
Elastic Security Labs published details of this vulnerability on August 5, 2024. These details include a proof-of-concept (POC) exploit.
@KnoetzeGrant attacker campaigns continued...Execution:
Execution: User Execution of Malicious Files or Links
The prominence of User Execution as a technique in Q3’s OSINT reports is related to the prevalence of attacks leveraging social engineering to trick users into running malicious code. Phishing and User Execution are consistently intertwined, with attackers regularly relying on user execution as the next step after phishing successfully delivers malicious content. While many organizations implement technical controls like firewalls, intrusion detection systems, and anti-malware, users clicking on malicious files or links can bypass organizations’ defenses.
A significant number of last quarter's reports involve information stealers and ransomware that rely on user interaction to initiate the attack chain, often enticing users to click using themes like AI tools or software updates. For instance, Cyble Research and Intelligence Labs identified that threat actors are exploiting the excitement around unreleased Sora Generative Artificial Intelligence (AI) by creating sophisticated phishing sites to spread information stealers. In this campaign, and several others reported last quarter, social media was used to spread malicious links. For example, researchers at Trend Micro identified a campaign where threat actors hijacked social media pages, renamed them to mimic popular AI photo editors, and posted malicious links to fake websites that ultimately resulted in delivery of payloads like Lumma Stealer.
Another factor fueling the prevalence of User Execution is the prominence of malvertising, which targets users through everyday online activities. For example, researchers at Malwarebytes identified a stealthy malvertising campaign impersonating the popular communication tool Slack. The campaign ultimately duped users into downloading SecTopRAT, a remote access trojan (RAT) with stealer capabilities.
This has led to a diversification of targets and increased the volume of attacks that rely on user actions, reinforcing User Execution as a prominent technique in the threat landscape.
The prevalence of this technique in recent cyber threat reporting underscores the importance of user awareness, effective endpoint protection solutions, and limiting local administrative privileges. In almost all attacks observed by Microsoft where ransomware deployment was successful, threat actors had access to a domain administrator-level account or local administrator passwords that were consistent throughout the environment. Read our article on how organizations can build credential hygiene.
Execution through command and scripting interpreters, particularly PowerShell, appeared as the second most common execution method referenced in OSINT from the last quarter. PowerShell provides a powerful scripting environment that can be exploited for malicious activities. The adoption of PowerShell to run malicious code has been one of the most impactful cybersecurity trends in the past decade. As a result of its widespread use, numerous toolkits have been developed to allow quick deployment for a wide range of attacks.
Kill chain overview:
Initial Access: Phishing remains the most prevalent initial attack vector, featuring in approximately 40% of OSINT reports from Q3. Phishing continues to dominate as an initial access technique, underscoring its perennial effectiveness and emphasizing the ongoing need for comprehensive user education programs and enhanced email security solutions.
Execution: As we reflect on the prominence of phishing, User Execution also remains the most common method of launching attacks, with users often enticed to click on malicious files or links. A notable runner-up was Command and Scripting Interpreter/PowerShell, which was the preceding quarter’s top execution technique.
Persistence: Boot or Logon Autostart Execution, particularly through Registry Run Keys and Startup Folder manipulation, is the most cited persistence technique. This method demonstrates attackers’ continued focus on maintaining persistence across system restarts by embedding themselves in critical system components. As these techniques are frequently used to bypass detection, strengthening endpoint detection and response capabilities around startup processes is essential.
Command and Control: Application Layer Protocols/Web Protocols is the most reported command and control (C2) method reflecting adversaries’ use of legitimate web protocols to mask malicious C2 traffic. Attackers frequently leverage common protocols like HTTP/HTTPS to blend in with normal network traffic, highlighting the need for advanced network traffic analysis.
Impact: Ransomware, specifically Data Encrypted for Impact, remains the most frequently reported impact technique. This reaffirms ransomware’s role as a dominant threat, particularly due to its financial and operational implications. The consistent mention of encryption underscores the importance of data backup strategies and swift incident response capabilities.
Defense Evasion: Obfuscated Files or Information is the most frequently used technique to evade detection, maintaining its top place from previous quarters. Techniques such as Deobfuscate/Decode Files or Information and Indicator Removal/File Deletion followed closely, each being cited in roughly 10% of the reports. The use of these techniques highlights the adaptive strategies attackers use to bypass detection, making the development of robust detection tools and behavior-based analysis critical for defense.
New threat report from Microsoft, focusing on the attack lifecycle in general:
This report presents an analysis of recent trends in cyber threats based on 242 articles published by threat researchers across the security community between July and September 2024 (Q3). These articles are curated by Microsoft Threat Intelligence from over one hundred trusted sources and are included in Microsoft Defender Threat Intelligence as open-source intelligence (OSINT) articles. The analysis focuses on over 2,000 MITRE ATT&CK framework tags correlated to the content in each article. By distilling insights from these tags and the related intelligence, we can highlight prevalent tactics, techniques, and procedures (TTPs) observed in the cyber security landscape over the past quarter. This dataset is not exhaustive but represents a curated set of the most high-profile cyber threat intelligence reporting from across the security community.
Mitre Attack TTP's observed for the .RDP file abuse for initial access threat report:
MITRE ATT&CK Techniques observed
Initial Access
T1566.001 Phishing: Spear phishing Attachment | RDP file attachments are used in spear phishing emails
Execution
T1204.002 User Execution: Malicious File | The threat actor relies on the targeted user to open the malicious RDP file
Credential access
T1187 Forced Authentication
T1539 Steal Web Session Cookie
T1552 Unsecured Credentials
T1083 File and Directory Discovery
T1135 Network Share Discovery
T1120 Peripheral Device Discovery
Check https://t.co/F7Nui1DXUu for more details.
CTI gathered from Microsoft Defender XDR
@KnoetzeGrant Threat report! We are using multiple sources for threat intelligence, and we will be bringing you regular posts on what we find....
Right now .RDP files in spear phishing and phishing campaigns are being observed, this is what @microsoft CTI has to say about it:
Threat actors have recently been observed using Remote Desktop Protocol (RDP) configuration files as file attachments in phishing campaigns as an initial access vector. This technique allows an attacker to gain access to resources on the target system including hard disks, clipboard contents, printers, connected peripheral devices, audio, and authentication features and facilities of the Windows operating system—including smart cards.
INVESTEC - cybercrime is expected to cost the world $10.5 trillion annually by 2025 https://t.co/PgISthPUbB via @investec We are one step ahead, are you stuck in last year or last decade? #CyberSecurity#Stuxnet#RedTeam#APT#ThreatIntelligence#CyberDefense#cyberWarfare #MalwareAnalysis #CyberAttack #Infosec #ZeroDay #IncidentResponse #Ransomware #AI #Phishing #AdvancedPersistentThreat #DDoS #MalwareIncidentResponse #PowerShell #IDPS #SIEM #Humint #Sigint #SOC #Israel #NorthKorea #SouthAfrica #Kenya #DRC #Ethiopia #Zambia #Zimbabwe #USA #Sweden
Check out this article: https://t.co/sjfOL4S8vA If a US President can be hacked, how easy are you hacked? We uncovered the worm that almost stopped Iran's nuclear, we know how to protect you. #CyberSecurity#Stuxnet#RedTeam#APT#ThreatIntelligence#CyberDefense#cyberWarfare #MalwareAnalysis #CyberAttack #Infosec #ZeroDay #IncidentResponse #Ransomware #GovernmentSecurity #ZeroTrust #RedTeaming #PenetrationTesting #CyberThreatIntelligence #AI #Phishing #AdvancedPersistentThreat #DDoS #MalwareIncidentResponse #PowerShell #IDPS #SIEM #Humint #Sigint #SOC #Israel #NorthKorea #SouthAfrica #Kenya #DRC #Ethiopia #Zambia #Zimbabwe #USA #Sweden
Exclusive: Stay ahead or get hacked – Dangote Group’s CIO warns of mounting cyber threats in Africa https://t.co/dVz3qO2n2s When will you fulfill your responsibility as CEO or President to protect the integrity of your organization? #StateSecurityRS#PresidencyZA #SAPoliceService #CyberSecurity #Stuxnet #RedTeam #APT #ThreatIntelligence #CyberDefense #cyberWarfare #GovernmentSecurity #ZeroTrust #RedTeaming #PenetrationTesting #CyberThreatIntelligence #AI #Phishing #AdvancedPersistentThreat #DDoS #MalwareIncidentResponse #PowerShell #IDPS #SIEM #Humint #Sigint #SOC #Israel #NorthKorea #SouthAfrica #Kenya #DRC #Ethiopia #Zambia #Zimbabwe #USA #Sweden #china #war #iran #hti @CISACyber