From KMS Auto to Scareware: Tracking a Multi-Stage Intrusion Linked to APT36?

From KMS Auto to Scareware: Tracking a Multi-Stage Intrusion Linked to APT36?
KMS Auto was abused as an initial entry point in a multi-stage intrusion that led to XMRig mining, ScreenConnect and MeshAgent remote access, and a scareware payload masquerading as ransomware. The incident was tentatively linked to APT36/Transparent Tribe, but the evidence remained inconclusive and the final payload appeared to be a hoax rather than true file-encrypting ransomware. #KMSAuto #XMRig #ScreenConnect #MeshAgent #APT36 #TransparentTribe #SecurityHealthServices.exe

Keypoints

  • KMS Auto was observed as the earliest visible event in the infection chain and is often abused when repackaged by threat actors.
  • The intrusion unfolded in stages over several days, not as a single immediate deployment.
  • XMRig was installed after KMS Auto execution, indicating cryptocurrency mining activity on the compromised system.
  • ScreenConnect and later MeshAgent were deployed to provide persistent remote access and backup control.
  • The final payload impersonated ransomware but functioned as scareware, changing the desktop and displaying threatening messages without encrypting files.
  • The payload used masquerading, hidden files, startup persistence, and dropped components such as batch, VBS, XML, and executable files to maintain execution.
  • Metadata and imagery suggested possible APT36/Transparent Tribe involvement, but the attribution was not conclusive.

MITRE Techniques

  • [T1204.002] User Execution: Malicious File – The chain began when the user executed the KMS Auto file, starting the intrusion (‘the activity began with the execution of KMS Auto on the affected system’).
  • [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – The payload created Run, Run Once, and Startup entries to persist across reboots (‘several Run, Run Once, and Startup Entries are created when executed’).
  • [T1036.005] Masquerading: Match Legitimate Name or Location – The payload disguised itself as a Windows Defender-related process and used a deceptive filename (‘the file is named “SecurityHealthServices.exe” to masquerade as a Windows Defender process’).
  • [T1564.001] Hide Artifacts: Hidden Files and Directories – The malware dropped self-copies into AppData with super hidden attributes to avoid discovery (‘It drops multiple self-copies into the “AppData” folder with a super hidden attribute’).
  • [T1027.009] Obfuscated Files or Information: Embedded Payloads – The executed PE content was embedded into the ransom note, hiding the payload within another file (‘the content of the executed PE was also embedded in it’).
  • [T1105] Ingress Tool Transfer – Additional tools and payloads were dropped onto the host over time (‘the threat actor maintained a presence on the system and introduced additional tooling’).
  • [T1219] Remote Access Software – ScreenConnect and MeshAgent were installed to maintain interactive remote control (‘the installation of ScreenConnect, a legitimate remote access and remote management solution’ and ‘drop redundant RMM tools like MeshAgent’).
  • [T1496] Resource Hijacking – XMRig was deployed to mine cryptocurrency using victim resources (‘the deployment and execution of XMRig, an open-source cryptocurrency mining tool’).
  • [T1491.001] Defacement: Internal Defacement – The desktop wallpaper and overlay were altered to intimidate the victim (‘changes the desktop wallpaper to a Pakistani flag and launches a persistent overlay’).

Indicators of Compromise

  • [File names ] Malware and masquerading artifacts – SecurityHealthServices.exe, RECOVERY_README.txt
  • [File paths ] Remote access and persistence locations – C:ProgramDataHvHostsScreenConnect.WindowsClient.exe, C:ProgramDataOneDriveServerOneDriveServerOneDriveServerScreenConnect.WindowsClient.exe, C:UsersPublicRecovery
  • [Hashes ] Detected samples and components – 6DC495F33D4E1B6BEB27CD418C8ED5AE, D24448EC0257ADFB258846B3317C3B7C, and 3 more hashes
  • [Detection names ] Security product classifications – Trojan (006dad991), CryptoMiner (00516ff51), RemoteTool (005cedd21)


Read more: https://labs.k7computing.com/index.php/from-kms-auto-to-scareware-tracking-a-multi-stage-intrusion-linked-to-apt36/