Blog de Zscaler

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Best Practices

Intelligence Insights: June 2024

image
THE RED CANARY TEAM
June 20, 2024 - 5 min read

Storm-1811 rolls in and JavaScript lures remain popular in this month’s edition of Intelligence Insights

 

Highlights from May

After dropping out of the rankings last month, Atomic Stealer is back on our top 10 most prevalent threat list. It returned at its highest rank so far in our top 10, in a three-way tie for 2nd with SocGholish and this month’s top 10 newcomer, Storm-1811, which we share more about below.

Intelligence insights video thumbnail

 

XMRig activity increased enough to tie for 6th with Mimikatz, making this XMRig’s second appearance on the list after its December 2023 debut. Yellow Cockatoo also returned to the top 10 after a few months of reduced activity.

We had several familiar faces stay on the list in new positions, including Gootloader, which moved up from 8th to 5th, and Scarlet Goldfinch, which dropped from 3rd to 8th. Raspberry Robin, another list regular, fell out of the top 10 altogether in May.

This month’s Top 10 threats

To track pervasiveness over time, we identify the number of unique customer environments in which we observed a given threat and compare it to what we’ve seen in previous months.

Here’s how the numbers shook out for May 2024:

Month's rankThreat nameThreat description

⬆ 1

Impacket

Collection of Python classes to construct/manipulate network protocols

⬆ 2*

Atomic Stealer

Information stealer designed to target data within web browsers and locally stored files on macOS systems, with the goal of accessing sensitive information including credentials, payment card data, keychain details, and cryptocurrency wallets

⬆ 2*

SocGholish

Dropper/downloader that uses compromised WordPress sites to redirect users to adversary infrastructure posing as necessary browser updates to trick users into running malicious code

⬆ 2*

Storm-1811

Financially motivated threat actor and Black Basta affiliate who uses tech support scams and RMM tools, notably Microsoft Quick Assist, for initial access

⬆ 5

Gootloader

JScript dropper/downloader that typically poses as a document containing an 'agreement,” often distributed through search engine redirects

⬇ 6*

Mimikatz

Open source tool that dumps credentials using various techniques

⬇ 6*

XMRig

Monero cryptocurrency miner that is often deployed as a secondary payload

⬇ 8*

Gamarue

Malware family used as part of a botnet. Some variants are worms and frequently spread via infected USB drives

⬆ 8*

PlugX

Malware family capable of a range of behaviors, including DLL side-loading, capturing the screen, and keylogging

⬇ 8*

Scarlet Goldfinch

Activity cluster that uses a distribution scheme similar to SocGholish and uses JScript files to drop NetSupport Manager onto victim systems

⬆ 8*

Yellow Cockatoo

Activity cluster characterized by the delivery of an information stealer and .NET RAT via search engine redirects

⬆ = trending up from previous month ⬇= trending down from previous month ➡ = no change in rank from previous month

*Denotes a tie

 

 

Tracking Storm-1811’s help desk scams

Our newcomer to the list this month is Storm-1811. Beginning in late April 2024 and continuing throughout May, Red Canary saw an activity cluster that we are tracking as Storm-1811. This is Microsoft’s name for a financially motivated threat actor that uses social engineering to gain initial access to environments via remote monitoring and management (RMM) tools—including Microsoft Quick Assist—on victim endpoints.

Storm-1811 leverages different communication methods in ways that increase the effectiveness of their social engineering scams. They use voice phishing (aka vishing) and call users masquerading as tech support, sometimes after reportedly flooding the users’ inboxes with emails. In recent attacks they have also reportedly used Microsoft Teams messages to increase their credibility as IT staff, according to Microsoft. The adversary convinces victims to provide remote access through Microsoft Quick Assist or by downloading and running AnyDesk.

After the adversary gains access, we observed Storm-1811 using curl to download additional tools like OpenSSH, ScreenConnect, and NetSupport Manager. Other reported payloads include Impacket, used for lateral movement, and PsExec, used to deploy Black Basta ransomware

Social engineering attacks are, admittedly, hard to combat. Some mitigation strategies to consider are:

  • Training users to verify the identity of IT staff that call them via trusted internal methods, for example confirming identities with video calls or requiring a shared secret like the endpoint in question’s serial number.
  • QuickAssist is installed by default on Windows machines. If it is not in use in your environment, disable or uninstall it.
  • Inventory the RMMs that are approved for use in your environment. Investigate security alerts for unapproved RMMs and also suspicious activity related to approved RMMs. If possible, block RMMs commonly used in malicious attacks—for example, NetSupport, AnyDesk and ScreenConnect—that aren’t in use in your environment.

Red Canary also saw Storm-1811 use bitsadmin.exe to download follow-on payloads. This gives us a detection opportunity.

Detection opportunity: Executing the Background Intelligent Transfer Service (bitsadmin.exe) to download files

This pseudo detection analytic identifies execution of the Background Intelligent Transfer Service (bitsadmin.exe) with command options to signal file downloads. Adversaries like Storm-1811 use bitsadmin.exe to download malware as a way of bypassing application whitelisting solutions. Note that bitsadmin.exe may be used legitimately by some administration software in your environment.

process == (bitsadmin)

&&

command_line_includes == (download)

&&

deobfuscated_command_line_includes == (bitsadmin, download)

&&

command_line_does_not_include == (*)

Note: * is a placeholder for strings associated with legitimate use of bitsadmin in your environment

 

 

In case you missed it: Open your scripts with Notepad

Many malware families use scripts as part of their intrusions. They have been popular with adversaries for years, a trend that shows no sign of slowing down. These lures can come in the form of multiple script types, including JavaScript, and delivered multiple ways.

If a trusting user opens that malicious script, one way to mitigate script execution is to create a Group Policy Object (GPO) to change the default behavior of commonly misused script extensions, making them behave like benign text files that open in Notepad and do not automatically execute. On May 31, Jeff Felling and Red Canary published a blog about recent prevalent threats like SocGholish and Gootloader that use this technique, and shared specific details on how to create these GPOs to help protect your environment.

 

The 2024 Threat Detection Report is here!

You've read about the top threats of the last month, how about for the entire year? The 2024 Threat Detection Report provides in-depth analysis and actionable guidance.

form submtited
Gracias por leer

¿Este post ha sido útil?

Descargo de responsabilidad: Esta entrada de blog ha sido creada por Zscaler con fines únicamente informativos y se proporciona "tal cual" sin ninguna garantía de exactitud, integridad o fiabilidad. Zscaler no asume ninguna responsabilidad por cualquier error u omisión o por cualquier acción tomada en base a la información proporcionada. Cualquier sitio web de terceros o recursos vinculados en esta entrada del blog se proporcionan solo por conveniencia, y Zscaler no es responsable de su contenido o prácticas. Todo el contenido está sujeto a cambios sin previo aviso. Al acceder a este blog, usted acepta estos términos y reconoce su exclusiva responsabilidad de verificar y utilizar la información según convenga a sus necesidades.

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Al enviar el formulario, acepta nuestra política de privacidad.