Lessons from the Frontlines: Ransomware Attacks, New Techniques, and Old Tricks
Key Takeaways
The SANS Ransomware Summit 2023 discusses lessons from the frontlines of ransomware attacks, including new techniques and old tricks used by threat actors, with a focus on fishing attacks, exploit tactics, and threat actor strategies.
Full Transcript
so we've been reporting on intrusion for quite a while now um unfortunately a bulk of our cases relate to fun andw attacks um so the reality is uh run andw ts are still happening so today uh we're going to be covering the trends and observations from our cases in the last year so by the way we got a article Co what it's like a retrospective year in review so we'll pull out the highlights from that um but we're going to be focusing on initial access Brokers uh that often leads to a ransomware attack and then a breakdown of the attack objectives from an attack point of view and um a little bit of dfir to understand who's on your network and how we can track those some of the attack tooling that we've seen um some common ones and then some new ones and and techniques as well and then finally some useful resources for Defenders so I'll pass you over to my colleague um you'll cover the first few points yep thank you Ryan and thank you Peter first off so through how the year 2022 we witness a multitude of th attacks that can be broadly categorized into two distinct groups fishing and non fishing in threats among the Cyber threats we encountered fishing attacks continue to emerge and these attacks can take on numerous forms but true prevalence methods we witnessed during 2022 involed the use of mariches files the first method frequently employed by cyber criminal was to use zip files containing a malicious link files and for those unfamiliar link files are shortcuts complely only us it in window operating system to access specific programs or files quickly however link files can be embedded with malicious code that when executed can compromise a bing system or steal sensitive information and the second methods involveed the use of an ISO file that also contained a malici string file and we saw the ever green that family to use this technique very often uh by packaging a malicious L file within an ISO file cyber criminal sought to exploit the victims who may have been exploring or opening the contents of such files and Sh groups are the Masters in this case cubot family and the I ID gang and as we all know Microsoft has worked out over the last year to limit the usage of micos inside the office Street these adjustment appear to assistant user first but we are aware that attackers have continued to use this strategy and depending on the situation we discovered that the malicious document either contained exploits for no CVS uh like in the case of finina or attempted to infect use workstation with no malware families such as cubot and otet again and one notable example of using an ISO file for mici go is represented by the Bumblebee malware uh link file has mentioned serve as shortcut to specific programmer file and in fact in this case a malicious sling file is designed to trigger an authorized action when opened and in particular the action is aimed at lancing a CMD XA instance to execute Malu D using run tt2 window commments and again this is instead a real example of Mal Excel document which try to exploit the CV 2022 3010 better known of course as poina and indeed in addition to fishing attacks uh cyber threats continue to exploit specific vulnerabilities and employe bir Force attacks to compromised system and in our case the affected system were mainly Microsoft Exchange and managing support center plus but however I would like to point your attention to a significant growing Trend that we identify in 2022 and I'm referring to C poisoning C poisoning is an emerging technique employed by cyber criminals to manipulate search and giant results in order to redirect and suspecting users to Malicia website and these techniques aims to exploit the trust user place in search engine and their top search results and one prominent criminal groups associated with C poisoning is good loer their activity have been extensively analyzed in our report title so poisoning a good loer story and now we would like to explore the behavior of these groups and their tactics in uh in more details and in particular the user might search for something specific such as o plus player agreement in this case uh the search results are manipulated so that a malicious website or link appears among the top search results and after that the user clicked on the second search results landing on a website that trigger the download and the execution of of a malicious JavaScript file youon execution of the malicious Javas Javascript file good loader employee encoded power shell scrip to load cob strike and this Ena the tractor to establish persistence on the earth and they achiev this through a combination of registry key and schedu Tas ensuring that they presence persist then the tractor use shown for active directory Recon allowing the attacker to discover attack spots within the network and the threat actor collect the results obtained from sh and proceed to P to one host using a cob strike power shell Beacon and after um couple of days doing recon lateral movement the attacker uh leave the network and this is one next slide Peter uh this is one of the most essential slide for me uh not because it describ the attack life cycle which we all know about but because it provide us with an indepth look into where tractors spend their time and while the attack life cycle may follow a similar pattern the specific technique and focus area may vary based on the attacker goals and objective uh so let's delve into to some key points for example in persistence for or better to use uh of schedu task is a fav metor for achieving persistence by creating sched task with malous payload or commments attackers can ensure their presence and additionally creating new user account or machine or domain controller can also serve as a way of maintaining access over the compromised Network or for the Recon phas Recon play of course a crucial role in attacker strategy and all threat actor need to perform some kind of Recon Gathering as much information as possible about the target environment helps them identify potential vulnerability and plan subsequent stages of the attack tools such as ad find or invo sh find ER and others are commonly used for Recon propose this tools helps Al attackers discover information about the network architecture user account Shar resources and so on and so forth uh in any intrusion involving lateral movement Recon has to be done frequently and this could be a key place to detector stop an intrusion PA again the objective of attackers can significantly uh influence their tactics and approach if the call is information extion speed and Ste become crucial attackers will prioritize quick and disection to avoid detection while extracting valuable data instead if the objective is to encrypt the entire infrastructure as for example in runw attacks attackers may take a slower and more deliberate approach they carefully study the target infrastructure compromise M multiple workstation and strategically plan the encryption process to maximize the impact and potential Ransom pain and it is important to note that retractors continuously adapt their ttps to evade detection and maximize their chance of success having said that let's now analyze which compromise was the fastest and which instead was the the slowest the award for quickest compromise goes to Cub we have a look at that the F scenario and in the first one the attackers mostly engaged in Recon operation before being able to access all the data on a file server and as is seen from this Mage the compromise time St is about 1 hour and 30 minutes however in the second distance the compromise happen even more quickly since the malicious actor took control of the system in about 30 minutes escalated to system uh gaed artifact like the LSS process used cob strike Gator the information he was interested in and then made an expession in this circumstances we may categorically state that cubot is unquestionably the fastest entity on Earth H why is this because as we as was already established the main goal of the Cubit family is information thft so their key goal is to do all task as quickly and stealthy as they can but also they seem to opt for spreading in an environment as a a c prior as well and at least our current data set only show that exfiltration on the other side con compromise was the longest uh longest one examined and it run for 19 days everyone is familiar with con I think in particular in this particular instance ICD was used to carry out the first compromise which was followed by I Recon work a lot of lateral movement and the place of cobas beacons we have also seen the download of fresh executable to specific computer as well as lateral transfer using wellknown rmm Technologies and after the ransomware was installed on all of the affected computer were encrypted the compromise one then was then completed uh attackers put a lot of emphasis on the Recon phase as we previously said and while some approach remain the same throughout the time others are be becoming more popular Peter will soon discuss the L but for the time behind it is clear that Adine continued to be one of the most one of the most popular tool for Recon in active directory environments and during our analysis we discovered it as a batch file or as an executable one um the program Ena you to enumerate a large amount of data including people who are members of a domain connected computer object or subnet Etc and so on and so forth uh instead invoke Shi finder that is a component of the Power Sport package is another tool that is frequently used to continue the Recon phase while moving the tension to network files and the share finder components make it possible to list shares on us in the local domain that can be easily combined with other script to enumerate all machine in the domain and the use of more or less less known uh well known Liga Remote Control software for marous reason is another Trend we have noticed but cannot label as new the most common ones seen are clearly any desk and tactical rmm but it's Cru said that using these programs make life easier for attackers since they enable the usage of several function and something that one noice may appear to be entirely legal those these tools are also quite appealing because to the feature built into them such as the cap the capacity to download of course or upload a file or for and uh in recent years protactor have Incorporated L beans into their at chains L beans are legit micet B that attackers exploit to bypass security defense and launch uh attacks without importing additional tools one commonly exploited Ling is window management instrumentation wmi uh which is a subsystem of poal user for standardized data and information management in Windows while wmi is intended for system management attackers leverage it for maritus activity uh such as lateral movement and for persistence and let's explore a couple of this opportunity for example for for defense evasion and Discovery malware authors uses WM integration with popular scripting language to evade security product and detect the virtual environment terminating the malware is detected um lateral movement instead attackers use the window Remote Management winm Service which interact with wmi to perform lateral movement within compromised networks and this involves using command like winm CMD or Powershell to interact with the remote system and now back to Peter thank you so ad enumeration is very common technique that we observe in our cases so this is quite an important post exploitation step for the threat actor because this helps establish situ of awareness of the target environment by identifying resources such as computers user accounts access controls and domain configurations and what's interesting about this technique we see it repeated um throughout an intrusion so especially during lateral movement so if the attacker jumped on another part of a network um so they verify new information such as any local accounts or any uh other domains that they've got on to so we've mentioned ad find so that is very popular tool um in a recent case uh we observed a thre actor using a different tool called ad get so ad get similar to ad find is a Comm online driven Windows application U so there a minimum expect the name of a Target zip file and um this is used then to Save ad collected information to so inside this Z file will be collected artifacts from ad including computers uh user accounts domains trust and controllers so the difference between AD get and ad find ad get has no um L up strings put in a command line or anything it's all built in so this makes detection a little bit harder um there are some commandline promises that can be used but we haven't observed them yet and there is little information surrounding this tool um but we were able to determine that the ad enumeration uh was done using our that requests and these requests were sent by the global catalog Port 3268 rather than a typical 389 Port so as mentioned ad get OD codes all the old up search things within the code um so when we did the stut analysis we could see the strings in those um focus in our detect on ad interruptions by L requests uh we can start to inspect the behaviors with these requests so how does the client ad get interrup with the server so if we configure monitoring via Windows of 4662 so which is recorded when an operation was performed on a object so in this case a read property when a request is made for ad objects we can see that over 600 attributes were being requested uh when searching for computer objects so that's a very high number of attributes so this is largely due to the global catalog replica request and also we discovered the use of a new based search um that was implemented in AD gear so effectively this was requesting everything in the ad for us and for computer object less than 30 attributes would sucessfully return so over 600 actually requested but only 30 returned so detailed analysis of the request uh using uh an engineering event 1644 which you can configure for login for troubleshooting L up we could see a high performance impact in query by the pages should being reference and um with a starter know of root directory service entry root DSC instead of of a distinguished name with the apis monitored we could also see the same data so API P where will no the base object and the analysis of the network traffic also confirmed the same so using 4662 is a useful detection opportunity for looking for news or object request so this could be an indication of AD enumeration uh and in to Global catalog out request for entire Forest here are some interesting techniques we've observed in the last year so one case observe the operator query the window security audit event log for specific user accounts and endpoints so this is quite clever so so they compromised an account and they wanted to know what were the resources that account could access so a good way to look at that within the event log um which confirmed if there is sucesses or denies so this was using a passive means rather than active interrogating all resources um a similar technique of been observed by an AP actor known as Earth lka with interesting techniques so instead of bringing their own tools uh the threat actor instead added a built-in Windows feature uh called remote service Administration tool and then use power sh to quer The Domain so this is a very new approach for Tool Ingress so rather than bringing Tools in externally internally they just had to look what was installed and then use the windows um installation monitor to enable certain features and it's not something we've seen before and another similar trick um the threat actor completely uninstalled defend of our Windows features rather than disabling the service or add an exclusion paths and we could see a lot of code views U so this could be from public available resources so we've seen Parell scripts for directory and file Discovery from pentest G of repositories and also Co strike customizations finally we always come across offset Mach mistakes made by the operator so this can be mistakes relating to using the incorrect tool such as NS loal against the username rather than the host other ones happen when they're they're using a C2 framework so for example we saw cobal strike command DC sync and shell keywords being entered within the command shell directly on the endpoint rather than through a beacon test sometimes operators struggle with tools and locals we seen them use power shell get help command in two separate cases the threat actor focus on device drivers so some context on device drivers if a threat aror can exploit a vulnerable driver or Lo their own driver they could poten to achieve system level access so in the usff case the threat actor is part of Discovery collected information about installed drivers then in a separate case involving Emit and Quantum the threat actor installed their own driver called power tool so this was interesting as a driver is provided to keep your computer clean of root kit viruses but operating in a system context this can be abused to kill processes including security tools so threat actors bring in their own device driv is uncommon um but do highlight the vast number of techniques that they've got at their disposal so one of the key actions to prevent that is monitoring instill device drivers and use to cross points and identifying vulnerable drivers or non bad drivers is key secondly correlating end points against unavailable security tooling could indicate underlying issues we see par shell used for a range of purposes from tool inj to security tool tempering multistage delivery and use for Cobo strike Beacon execution and I even recall Ryan recently shared power Shell Code relating to dat exfiltration by Vi City so when we start analyzing par shell commands spe specifically around b64 and coded command we can start to see pattern for example we can see cuse overlapping Tulum and out the box configuration for payload generation then we can start to fingerprint Bas 64 encoded string so this isn't a New Concept and prior work has been done by others and virtually all threat actors were observed using a combination of two basics for and coded strings and starting with JB and sqb and some of these date by years at least to 20120 and little has changed since then even in recent cases we still see um similar fingerprints so R go loader qot Cony all use power shell and share similar indicators power shell Windows events specifically 4104 will record activity relating to suspicious keywords including in memory these will appear as a warning in the event log for example in one case we can see a service start event with a partial encoded command that once decoded references a memory stream keyword this event is logged as a warning and this activity is related to Cobo strike Beacon being loaded other interest in partial activity a threat actor displayed a message box on every compromise endpoint on the network there's been a an increase in the use of remote services such as remote desktop protocol there are several reasons for this one to act to fall coms in the event of if any implants fail due to technical issues or detection plus RDP allows the operator to blend our activities however there are some risk quite often we'll see use of RDP established early on in intrusion and then proxy through other processes during the attack life cycle so this is a especially if you have processors don't don't typically use port 3389 so a number of Windows events capture indicators of a activity and despite using proxy processes the operator's client machine can be exposed so this is separate from C2 infrastructure where implants call back to listening post this is exposing the attack box so for example in event 4779 we can see a compromise account being access but the client name is hyperv the IP address shows to compromise mpoint as it was been used as a proxy but the client name wasn't a standed name convention in use on the target Network all threat groups associated with access Brokers and M someware delivery use some form of payload to establish a footlo and to deliver effects sometimes payloads fail to the operator why it's not failed isn't immediately obvious but if the failure is related to a crash then a Windows error reporting can log this event so this can be quite a rich Resource as Crush dumps can be also be collected which can be analyzed so in one case the operator encountered numerous issues deploying cover strip beacons and other tools the operator initially thought it was AV blocking or some kind of software restriction policy so I tried renaming FES to blend in and when this didn't work added extra characters and double extensions the main issue was a defective payload either due to platform or Shell Code being la the NSA provided a useful note um indicating that application crushes could warrant further investigation so these aren't security events so there will be other beny crushes on the network such as Office Word crushing and so on um but if you see spikes in these it can be quite a useful resource kobal St remains a popular C2 framework U we see kobal St use extensively across our cases um one reason why it's still popular is likely due to ease of use operators know to use the framework and learning the new C2 framework in terms of configuring training and upscaling um is quite expensive so another reason despite cover St being fingerprinted and extensively analyzed with detections is still not having an impact to run somewhere intrusion operation so if that does change it's likely groups will adapt by changing the tool and use alternative procedures monitor AV logs um the groups like dropping a lot of tools on endpoints and it's likely something will trip so understand your AV configuration what point you EMB boarded is it an audit or block mode understand what gets prevented and how it works in terms of alerting so assume compromise by emulating the Avers and the atom red team provide some testing resources for this we've talked about how the attacker spend time on your network understanding the environment so as a Defender you should spend time understanding your environment and it's your advantage so try understanding what you can discover what's exposed what needs to be locked down what are your critical resources and how to put monitoring in place there are active measures you can take for detecting the activity early so that is key ear it's spotted the you can respond to it so this includes set up trip wires using honey tokens so this could be like uh privileged accounts um or files on network shares it won't stop attackers but you've got it well tuned and settled for detection it will illuminate their activity if they trip a monitor resource and then finally prepare for an incident um having a world rehearse instant response plan uh how to do that with response containment we assist in knowing what needs to be done from detection remediation through to recovery lastly a big thanks to the DFI report crew for publishing and sharing insight into the intrusions we've mentioned into this presentation
Original Description
SANS Ransomware Summit 2023
Lessons from the Frontlines: Ransomware Attacks, New Techniques, and Old Tricks
Speakers:
Peter O, Cyber Threat Analyst, The DFIR Report
Alessandro Di Carlo, Forensics & Product Manager, Certego Srl
Ransomware attacks are a constant threat faced by many organizations. In 2022 The DFIR Report continued to observe a number of ransomware-related attacks facilitated by a variety of initial access brokers. This talk will provide practical insights into attack lifecycle trends, initial access detections, new techniques observed and the continued use of familiar tools. We'll share detection opportunities for quick wins on identifying attackers on your network. Explore new and emerging discovery tools, and how detecting the adversary early in the attack lifecycle is key to stopping a ransomware attack unfolding. All details are based on 'Real Intrusions by Real Attackers, The Truth Behind the Intrusion.' It will serve as a practical guide for defenders to understand a typical attack. - Initial access by threat actors - Race to compromise, - Attack objectives - Can you detect and respond?, - Who is on your network? - Understanding human behaviours, - Attacker Tooling - New and old discovery techniques
View upcoming Summits: http://www.sans.org/u/DuS
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from SANS Institute · SANS Institute · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
SANS FOR610: Reverse Engineering Malware: Malware Analysis Tools & Techniques
SANS Institute
SANS Institute Cybersecurity Training Customer Stories
SANS Institute
SANS Institute UK Cyber Academy
SANS Institute
SANS Institute UK Cyber Academy
SANS Institute
CISSP® Prep Exam, MGT414, by SANS Institute
SANS Institute
SANS Institute's Rob Lee Discusses The OPM.GOV Hack on CNN
SANS Institute
Information Security Training from SANS Institute - Student Testimonials
SANS Institute
SANS NetWars
SANS Institute
SANS DFIR NetWars
SANS Institute
Hack The Drone - SANS Cyber Academy UK
SANS Institute
SANS VetSuccess Immersion Academy
SANS Institute
SANS Cybersecurity Training, Certifications & Placement for Veterans
SANS Institute
The 2015 SANS Holiday Hack Challenge
SANS Institute
SANS VetSuccess Academy: Hands-on Skills
SANS Institute
SANS VetSuccess Academy Overview
SANS Institute
SANS ICS Security Summit & Training 2017
SANS Institute
Exploring the Unknown Industrial Control System Threat Landscape – SANS ICS Security Summit 2017
SANS Institute
WannaCry recap, patches, and analysis
SANS Institute
If We’re Doing So Well at Cyber Security, Why Are We Still Doing So Poorly?
SANS Institute
Graduation Day - SANS HM Gov Cyber Retraining Academy
SANS Institute
Incentivizing ICS Security: The Case for Cyber Insurance – SANS ICS Security Summit 2017
SANS Institute
SANS Data Breach Summit & Training 2017
SANS Institute
SANS Secure DevOps Summit & Training 2017
SANS Institute
How Threats Are Slipping In the Back Door - SANS ICS Security Summit 2017
SANS Institute
SANS Webcast – Continuous Opportunity: DevOps & Security
SANS Institute
SANS Cybersecurity Programs for the Department of Defense
SANS Institute
SANS Pen Test HackFest Summit & Training 2017
SANS Institute
SANS SIEM & Tactical Analytics Summit & Training
SANS Institute
If We’re Doing So Well, Why Are We Still Doing So Poorly? – SANS ICS Security Summit 2017
SANS Institute
SANS Institute
SANS Institute
ICS515: ICS Active Defense and Incident Response
SANS Institute
SANS Institute
SANS Institute
Introducing the NEW SANS Pen Test Poster
SANS Institute
SANS Institute - An Inside Look at the Newly Updated ICS515 Course
SANS Institute
SANS ICS Security Training, Munich, Germany
SANS Institute
SANS Automotive Summit Webcast
SANS Institute
Privesc Playground - SANS Pen Test HackFest Summit 2017
SANS Institute
Introduction to Reverse Engineering for Penetration Testers – SANS Pen Test HackFest Summit 2017
SANS Institute
Honey, Please Don’t Burn Down Your Office: Fun with Smart Home Automation
SANS Institute
SANS Security Operations Summit & Training 2018
SANS Institute
Sh*t Happens! (But You Still Need to Drink the Water) – SANS ICS Summit 2018
SANS Institute
ICS Threat Intelligence: Moving from the Unknowns to a Defended Landscape – SANS ICS Summit 2018
SANS Institute
You’re Probably Not Red Teaming (And Usually I’m Not, Either) – SANS ICS Summit 2018
SANS Institute
A Sneak Peak at the New ICS410
SANS Institute
Jumping Air Gaps – SANS ICS Summit 2018
SANS Institute
Introduction to Linux
SANS Institute
Introduction to Malware Analysis
SANS Institute
You’re Probably Not Red Teaming (And Usually I’m Not, Either) Webcast by Deviant Ollam
SANS Institute
Hacking your SOEL: SOC Automation and Orchestration – SANS Security Operations Summit 2018
SANS Institute
Hunting for Post-Exploitation Stage Attacks with Elastic Stack and the MITRE ATT&CK Framework
SANS Institute
Apples and Oranges?: A CompariSIEM – SANS Security Operations Summit 2018
SANS Institute
SANS Webcast - Perimeter Security and Why it is Obsolete
SANS Institute
SANS Webcast - Trust No One: Introducing SEC530: Defensible Security Architecture
SANS Institute
The Science of Security: The Psychological Impacts of Security Awareness Programs
SANS Institute
How I Pulled Off an Edgy Security Campaign – SANS Security Awareness Summit 2018
SANS Institute
Practical Advice for Submitting to Speak at a Cybersecurity Conference
SANS Institute
SANS Webcast - Consuming OSINT: Watching You Eat, Drink, and Sleep
SANS Institute
SANS Webcast - Zero Trust Architecture
SANS Institute
SANS STX Cyber Range
SANS Institute
Part 1 – SANS Institute and Tenable talk about cloud security
SANS Institute
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
First take/next take/last take
Seth Godin's Blog
I Was Optimizing Ranking While the Real Problem Was Selection
Dev.to · ValeryKot
What Winning #1 Product of the Day on PeerPush Taught Me as a Solo Developer
Dev.to · GhostPrompter
How I Stopped Dreading OKR Season (with a Kiro Agent)
Dev.to AI
🎓
Tutor Explanation
DeepCamp AI