Symantec researchers analyzed an exploit tool that abused CVE-2024-26169 in Windows Error Reporting to escalate privileges, potentially as a zero-day in recent ransomware activity. The tools and techniques observed bore strong ties to Black Basta activity, including batch scripts masquerading as software updates, with the threat group reportedly reviving operations using the DarkGate loader. #BlackBasta #Qakbot #DarkGate #WerFault #CVE-2024-26169
Keypoints
- The vulnerability CVE-2024-26169 in Windows Error Reporting could allow privilege escalation if exploited on affected systems.
- An exploit tool associated with the attack was compiled before the patch, suggesting zero-day-like activity by at least one group.
- The attack scenario was linked to Black Basta due to highly similar TTPs, including batch scripts masquerading as software updates.
- In this observed incident, no ransomware payload was deployed, but the techniques aligned with Black Basta campaigns described in recent Microsoft reporting.
- Cardinal founded Black Basta in 2022 and historically linked to Qakbot; after a takedown in 2023, Black Basta reemerged, collaborating with DarkGate loader operators to gain access.
- Mitigation guidance points to the latest protection updates in Symantec’s Protection Bulletin and standard endpoint defenses.
MITRE Techniques
- [T1548.001] Abuse Elevation Privilege – Exploitation of CVE-2024-26169 can permit privilege escalation, described as: “CVE-2024-26169 occurs in the Windows Error Reporting Service. If exploited on affected systems, it can permit an attacker to elevate their privileges.”
- [T1059.003] Batch Scripts – The exploit tool included batch scripts used in the attack context: “the use of batch scripts masquerading as software updates.”
- [T1036] Masquerading – Batch scripts masquerading as software updates to appear legitimate.
- [T1218.005] Image File Execution Options – The exploit uses IFEO to hijack WerFault.exe by creating a specific IFEO registry key and setting the Debugger value to its own executable pathname: “HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution OptionsWerFault.exe” with the “Debugger” value…
- [T1112] Modify Registry – The technique involves registry changes to facilitate execution flow via IFEO, including creating an IFEO registry key with a custom Debugger path (context described above).
Indicators of Compromise
- [Hash] Exploit tool – 4aae231fb5357c0647483181aeae47956ac66e42b6b134f5b90da76d8ec0ac63
- [Hash] Exploit tool – b73a7e25d224778172e394426c98b86215087d815296c71a3f76f738c720c1b0
- [Hash] Batch script – a31e075bd5a2652917f91714fea4d272816c028d7734b36c84899cd583181b3d
- [Hash] Batch script – 3b3bd81232f517ba6d65c7838c205b301b0f27572fcfef9e5b86dd30a1d55a0d
- [Hash] Batch script – 2408be22f6184cdccec7a34e2e79711ff4957e42f1ed7b7ad63f914d37dba625
- [Hash] ScreenConnect – b0903921e666ca3ffd45100a38c11d7e5c53ab38646715eafc6d1851ad41b92e
Read more: https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day