Thursday, February 9, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

TrueBot malware delivery evolution leads to more ransomware

Researcher by Researcher
December 12, 2022
in Cybersecurity
0
TrueBot malware delivery evolution leads to more ransomware
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


botnet.jpg
Image: iStock/bagotaj

Must-read security coverage

According to Cisco Talos, TrueBot malware now collects Active Directory information, which means it targets businesses with larger IT resources. In addition to targeting larger organizations, the malware is experimenting with new delivery methods: Netwrix Auditor bundled with the Raspberry Robin malware.

What is TrueBot?

TrueBot is a downloader malware under active development since 2017. Its goal is to infect systems, collect information on the compromised host to help triage the targets and deploy additional malware. In addition to infecting a host and being able to load and execute files, the new version of the malware has new capabilities: loading and executing additional modules and shellcodes directly in memory, probably to avoid detection.

SEE: The Most Dangerous Ransomware Groups of 2022 (TechRepublic)

The collected information consists of the computer and local network name, the Active Directory trust relations, and a screen capture, all of which is sent to a command-and-control server controlled by the attacker.

The malware is aimed at attacking corporate environments since collecting Active Directory information would not make much sense for individual computers.

TrueBot’s two new delivery techniques

For a long time, TrueBot was delivered mostly via malicious emails. Yet, researchers from Cisco Talos have found and exposed two new delivery and infection methods.

The first one was found when new TrueBot variants were found executed after the exploitation of a vulnerability in Netwrix Auditor (CVE-2022-31199), a legitimate tool used by companies for IT asset management.

The infection rate is low since there are not a lot of instances of this tool exposed directly on the internet. Successful exploitation of the vulnerability allowed the attackers to trigger the BITSAdmin command-line tool via a process from Netwrix Auditor to download and execute the new version of TrueBot (Figure A).

Figure A

Sample commands executed by the Netwrix Auditor process
Image: Cisco Talos. Sample commands executed by the Netwrix Auditor process.

The second one is via another malware, Raspberry Robin, which spreads via infected USB drives. This malware is currently one of the largest malware distribution platforms currently active, according to Microsoft, and delivering several different payloads including TrueBot.

In October 2022, the cumulated use of those two new delivery methods led to the creation of a botnet of over 1,000 infected systems worldwide, according to Talos researchers, with a particular targeting of a few countries: Brazil, Mexico and Pakistan.

SEE: 2022 State of the Threat: Ransomware is still hitting companies hard (TechRepublic)

In November, a second botnet appeared, almost exclusively built of Windows servers offering several services on the internet, such as Remote Desktop Protocol, Server Message Block protocol and Windows Remote Management protocol. None of those servers provided access to any Netwrix Auditor instance, rendering the attack vector unknown for the moment. That said, this second botnet hit 75% of the U.S. (Figure B).

Figure B

botnet infection distribution across the world with countries in North and South America, Europe, and Asia affected
Image: Cisco Talos. Infection distribution for the second TrueBot botnet hitting 75% of the U.S.

TrueBot post-compromise activity

Two payloads are delivered by TrueBot in this campaign.

The first one is Cobalt Strike, which is a framework developed for penetration testing used by both legitimate security professionals and cyber criminals.The second one is the Grace/FlawedGrace malware, which is known to be almost exclusively by threat actor TA505. Once the payload is up and running, the attackers start lateral movements inside the compromised network.

Cisco Talos researchers found an interesting unknown command-line tool dubbed “Teleport” used during this attack stage and aimed at helping data exfiltration in a stealthier way. Teleport enables limiting the upload speed, to help data exfiltration stay undetected and avoid slowing down the corporate network. It also has a feature to limit the file sizes, and the ability to delete itself once used. Finally, it uses a fully custom encryption algorithm made of AES and a hardcoded key.

The Teleport commands used by the attackers reveal they were looking for interesting files such as email files (*.pst, *.ost), files from the users’ OneDrive location or the local download folder from the infected computer.

TrueBot infections end with ransomware

One of the possible outcomes of these attack campaigns is Clop ransomware infections, with double extortion following the infections.

SEE: Ransomware: A cheat sheet for professionals (TechRepublic)

Once the attackers have access to the whole network, they can map it and move laterally inside it to get access to systems of interest. The attackers can browse key servers and desktop file systems, connect to databases, and collect data using Teleport. The attackers can then create scheduled tasks on a large number of systems simultaneously to execute the Clop ransomware and encrypt data, according to Cisco Talos.

Who is behind TrueBot?

TrueBot has been linked to the threat actor Silence Group, which conducts vast high-impact attacks all around the globe. According to several researchers, TrueBot and FlawedGrace would have been developed by the same Russian-speaking person, FlawedGrace being used almost exclusively by threat actor TA505.

It is possible that Silence Group buys access to compromised systems directly from TA505. The appearance of the Clop ransomware, previously spread by TA505, strengthens that link even more.

How to protect from TrueBot’s new malware delivery threat?

It is advised to always have all operating systems and the software they run fully up to date and patched. In this attack campaign, the attackers used an exploit on the Netwrix Auditor vulnerability just a few weeks after the vulnerability was made public. This is just another example showing how fast structured cyber criminals teams might quickly use any new vulnerability.

Second, it is advised to reduce the exposure of software on the internet as much as possible. A software or system that does not need the internet should not be available to it.

It is also advised to deploy multi-factor authentication on every internet-facing system in order to avoid falling for a credential compromise.

Network connections should be carefully monitored. Domains reached by a very low number of connections should be investigated, similar to domains with a high number of connections. Also, direct connections to IP addresses instead of domains should be particularly analyzed.

Finally, security software should be deployed at all levels of incoming data, in particular emails and servers, in addition to endpoints.

Disclosure: I work for Trend Micro, but the views expressed in this article are mine.



Source link

Related articles

New cybersecurity data reveals persistent social engineering vulnerabilities

New cybersecurity data reveals persistent social engineering vulnerabilities

February 9, 2023
New ToddyCat APT Targets Exchange Servers

Fortra Patches Actively Exploited Zero Day in GoAnywhere MFT

February 8, 2023
Tags: deliveryEvolutionLeadsmalwareRansomwareTrueBot
Share76Tweet47

Related Posts

New cybersecurity data reveals persistent social engineering vulnerabilities

New cybersecurity data reveals persistent social engineering vulnerabilities

February 9, 2023
0

Ransomware was down last year, though LockBit led threat actors and employees opened a third of the toxic emails in...

New ToddyCat APT Targets Exchange Servers

Fortra Patches Actively Exploited Zero Day in GoAnywhere MFT

February 8, 2023
0

Several days after news of exploit attempts against a zero day vulnerability in the GoAnywhere MFT secure file transfer tool...

The New Frontier of Data Security: Exploring the Potential of Quantum Random Number Generators (QRNGs) | by Binu Panicker | Feb, 2023

The New Frontier of Data Security: Exploring the Potential of Quantum Random Number Generators (QRNGs) | by Binu Panicker | Feb, 2023

February 8, 2023
0

World’s fastest real-time quantum random number generator with a photonic integrated chip. Credit: Bing Bai and Yao ZhengThe world of...

Sentra Raises $30 Million for DSPM Technology

Germany Appoints Central Bank IT Chief to Head Cybersecurity

February 8, 2023
0

The German government announced the appointment Tuesday of the European Central Bank’s head of IT systems to lead the national...

Metaverse Adds New Dimensions to Web 3.0 Cybersecurity

Metaverse Adds New Dimensions to Web 3.0 Cybersecurity

February 8, 2023
0

With more companies investing in Web 3.0 this year, including blockchain, gaming and the metaverse, the cat and mouse game...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Google’s AI Chatbot Is Out To Rival ChatGPT

Google’s AI Chatbot Is Out To Rival ChatGPT

February 9, 2023
New cybersecurity data reveals persistent social engineering vulnerabilities

New cybersecurity data reveals persistent social engineering vulnerabilities

February 9, 2023
New ToddyCat APT Targets Exchange Servers

Fortra Patches Actively Exploited Zero Day in GoAnywhere MFT

February 8, 2023
“Fintech Right Now is a Boys Club” – How to Close the Gender Gap in Fintech with Stax

Spotlight: How the Isle of Man Became an Insurtech Hub

February 8, 2023

Recent Posts

Google’s AI Chatbot Is Out To Rival ChatGPT

Google’s AI Chatbot Is Out To Rival ChatGPT

February 9, 2023
New cybersecurity data reveals persistent social engineering vulnerabilities

New cybersecurity data reveals persistent social engineering vulnerabilities

February 9, 2023
New ToddyCat APT Targets Exchange Servers

Fortra Patches Actively Exploited Zero Day in GoAnywhere MFT

February 8, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved