Ongoing Social Engineering Campaign Updates Payloads

Rapid7 identifies ongoing intrusion attempts linked to a social engineering campaign, with threat actors using phone calls and remote access tools to compromise systems. The campaign shows evolving tooling, credential harvesters, and multiple malware payloads, underscoring the need for user awareness and software updates. #SystemBC #AntiSpamExe

Keypoints

  • Date of Report: June 20, 2024
  • Identified Threat: Ongoing social engineering campaign
  • Initial Lure: Email bomb followed by phone calls
  • Remote Access Tool Used: AnyDesk
  • Credential Harvesting Tool: AntiSpam.exe, a .NET executable
  • Malware Payloads: update1.exe, update4.exe, update6.exe (and others) with SystemBC and Golang HTTP beacons
  • Exploitation Attempt: CVE-2022-26923 for privilege escalation
  • Mitigation: Application allowlisting, user awareness training, and regular software updates

MITRE Techniques

  • [T1587.001] Develop Capabilities: Malware – The threat actor is actively developing new malware to distribute. ‘The threat actor is actively developing new malware to distribute.’
  • [T1498] Network Denial of Service – The threat actor overwhelms email protection solutions with spam. ‘The threat actor overwhelms email protection solutions with spam.’
  • [T1566.004] Phishing: Spearphishing Voice – The threat actor calls impacted users and pretends to be a member of their organization’s IT team to gain remote access. ‘The threat actor calls impacted users and pretends to be a member of their organization’s IT team to gain remote access.’
  • [T1059.001] Command and Scripting Interpreter: PowerShell – The threat actor executes a socks proxy PowerShell script. ‘The threat actor executes a socks proxy PowerShell script.’
  • [T1140] Deobfuscate/Decode Files or Information – The threat actor encrypts zip archive payloads with a password. ‘The threat actor encrypts zip archive payloads with a password.’
  • [T1055.002] Process Injection: Portable Executable Injection – Multiple payloads executed by the threat actor utilize local PE injection. ‘Multiple payloads executed by the threat actor utilize local PE injection.’
  • [T1620] Reflective Code Loading – Multiple payloads executed by the threat actor load and execute shellcode. ‘Multiple payloads executed by the threat actor load and execute shellcode.’
  • [T1553.002] Subvert Trust Controls: Code Signing – The threat actor has signed many of their payloads to make them appear legitimate. ‘The threat actor has signed many of their payloads to make them appear legitimate.’
  • [T1068] Exploitation for Privilege Escalation – The threat actor attempts to exploit CVE-2022-26923 to create a machine account. ‘The threat actor attempts to exploit CVE-2022-26923 to create a machine account.’
  • [T1056.001] Input Capture: Keylogging – The threat actor runs an executable that harvests the user’s credentials. ‘The threat actor runs an executable that harvests the user’s credentials.’
  • [T1558.003] Steal or Forge Kerberos Tickets: Kerberoasting – The threat actor requests a large volume of Kerberos service tickets once privileges have been escalated. ‘The threat actor requests a large volume of Kerberos service tickets once privileges have been escalated.’
  • [T1033] System Owner/User Discovery – The threat actor enumerates users within the environment. ‘The threat actor enumerates users within the environment.’
  • [T1570] Lateral Tool Transfer – Anydesk was used to move payloads onto compromised systems. ‘Anydesk was used to move payloads onto compromised systems.’
  • [T1572] Protocol Tunneling – SSH reverse tunnels were used to provide the threat actor with remote access. ‘SSH reverse tunnels were used to provide the threat actor with remote access.’
  • [T1219] Remote Access Software – The threat actor has used Anydesk to gain initial access and Level to move laterally. ‘The threat actor has used Anydesk to gain initial access and Level to move laterally.’

Indicators of Compromise

  • [Network Based Indicators] Domain/IPv4 Address – spamicrosoft[.]com, 37.221.126[.]202, and 12 more items
  • [HBIs] File – AntiSpam.exe ed062c189419bca7d8c816bcdb1a150c7ca7dd1ad6e30e1f46fae0c10ab062ef, AntiSpam.exe d512bf205fb9d1c429a7f11f3b720c74680ea88b62dda83372be8f0de1073a08, and 12 more hashes

Read more: https://blog.rapid7.com/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/