ASEC found Larva-26009 targeting MS-SQL servers to deploy VShell, GotoHTTP, SoftEther, and XMRig, using remote control and proxy tools to maintain access and mine cryptocurrency. The attack also involved web shells, credential theft attempts, privilege escalation utilities, and cloud-based infrastructure to obscure command-and-control activity. #Larva26009 #VShell #GotoHTTP #SoftEther #XMRig
Keypoints
- ASEC observed Larva-26009 in attacks against MS-SQL servers and identified an instance where XMRig CoinMiner was installed.
- The attacker used command execution on the MS-SQL server to download and install additional payloads, with only ping-related activity found in logs.
- Web shells were installed on IIS web servers for persistence and control, including ASPX web shells such as Sharp4WebCmd and Suo5.
- The threat actor attempted credential theft by dumping registry hives and used tools like HackBrowserData for browser credential, history, and cookie theft.
- Multiple privilege escalation and reconnaissance tools were staged, including JuicyPotatoNG, SigmaPotato, BadPotato, RustPotato, and Fscan.
- The attacker used remote control and backdoor mechanisms such as GotoHTTP, Chrome Remote Desktop, backdoor accounts, VShell, and Cloudflared to maintain access.
- Final payloads included XMRig for mining and SoftEther VPN to build a concealed C&C-related infrastructure and hinder attribution.
MITRE Techniques
- [T1059 ] Command and Scripting Interpreter – The attacker executed commands through MS-SQL and PowerShell to download and run payloads (‘the attacker installed malware by executing download commands’).
- [T1105 ] Ingress Tool Transfer – Additional tools and payloads were downloaded from remote servers, including web shells, GotoHTTP, XMRig, and SoftEther (‘downloaded additional payloads’).
- [T1505.003 ] Server Software Component: Web Shell – A web shell was installed on an IIS web server to maintain persistence and control (‘a web shell was additionally installed on systems with a web server’).
- [T1003 ] OS Credential Dumping – The attacker attempted to dump registry hives associated with credentials (‘dump HKLMSYSTEM… dumping HKLMSAM and HKLMSECURITY’).
- [T1217 ] Browser Session Cookie – HackBrowserData was present to steal browser cookies, history, and credentials (‘stealing credentials, history, and cookies stored in web browsers’).
- [T1068 ] Exploitation for Privilege Escalation – Multiple Potatoes and related tools were used to elevate privileges (‘JuicyPotatoNG, SigmaPotato, BadPotato, and RustPotato’).
- [T1018 ] Remote System Discovery – Fscan was uploaded to identify internal targets for lateral movement (‘scan internal networks as needed to identify Attack Targets’).
- [T1021.001 ] Remote Services: Remote Desktop Protocol – Newly created accounts were likely used for remote control via RDP (‘exercise remote control over the infected system through RDP’).
- [T1090.001 ] Proxy: Internal Proxy – Cloudflared exposed local ports externally to relay access (‘run Cloudflared to expose available local ports to the outside’).
- [T1106 ] Native API – The attacker used built-in Windows utilities and APIs such as certutil and bitsadmin to fetch and decode payloads (‘Certutil.Exe -decode…’; ‘Bitsadmin /transfer’).
- [T1027 ] Obfuscated Files or Information – Encrypted data files and shellcode were decrypted at runtime to evade detection (‘encrypted data files to bypass detection’).
- [T1140 ] Deobfuscate/Decode Files or Information – Payloads were decrypted using routines such as DJB2 or certutil decode before execution (‘decrypts the shellcode using the DJB2 algorithm’).
- [T1055 ] Process Injection – Shellcode was executed in memory after decryption (‘decrypts it in memory, and executes it’).
- [T1102 ] Web Service – Download servers hosted malware and tools on cloud/web services and were used for C&C-related activity (‘download server’, ‘Cloudflare’).
Indicators of Compromise
- [MD5 ] Sample hashes associated with the campaign – 03bbee2c93c8b78bba321396a92bf026, 0429b9f291f570db0945282aa77c2d98, and 3 more hashes
- [URL ] Download and staging locations for payloads – https[:]//ams-pub-dev[.]s3[.]dualstack[.]eu-west-1[.]amazonaws[.]com/test/hub/update[.]zip, https[:]//imagefiles-backup[.]oss-ap-southeast-7[.]aliyuncs[.]com/GotoHTTP_x64[.]exe, and 3 more URLs
- [FQDN ] Infrastructure used for delivery and staging – microsftapiedge[.]com, update[.]microsftapiedge[.]com
- [IP Address ] Infrastructure used by the threat actor – 159[.]223[.]46[.]140, 38[.]60[.]253[.]35
- [File Name ] Payloads and components referenced in the attack – xmr-1.Zip, GotoHTTP_x64[.]exe, apaches[.]aspx, batt[.]exe, browser[.]exe
- [File Name ] Additional tools and loaders used on the victim system – homename.Aspx, main.Txt, gojoke.Png, edgeico.Ico
Read more: https://asec.ahnlab.com/en/94685/