If you have anything to do with cyber security, you know it employs its own unique and ever-evolving language. Jargon and acronyms are the enemies of clear writingāand are beloved by cyber security experts. So Morphisec has created a comprehensive cyber security glossary that explains commonly…
Tag: THREAT HUNTING
Gather āround, cyber friends, and Iāll let you in on a little secret: no one knows what the Next Big Thing on the threat landscape will be. But we can look back on 2023, identify notable changes and actor behaviors, and make educated assessments about what 2024 will bring.Ā Ā
This month on the DISCARDED podcast my co-host Crista Giering and I sat down with our Threat Research leaders Daniel Blackford, Alexis Dorais-Joncas, Randy Pargman, and Rich Gonzalez, leaders of the ecrime, advanced persistent threat (APT), threat detection, and Emerging Threats teams, respectively. We discussed what we learned over the last year, and whatās on the horizon for the future. While the discussions touched on different topics and featured different opinions on everything from artificial intelligence (AI) to living off the land binaries (LOLBins) to vulnerability exploitation to ransomware, there were some notable themes that are worth writing down. We canāt say for sure what surprises are in store, but with our cyber crystals balls fully charged ā and a deep knowledge of a yearās worth of threat actor activity based on millions of email threats per day ā we can predict with high confidence whatās going to be impactful in the coming year.Ā Ā
1: Quick response (QR) codes will continue to proliferateĀ
2023 was the year of the QR code. Although not new, QR codes burst on the scene over the last year and were used in many credential phishing and malware campaigns. The use was driven by a confluence of factors, but ultimately boiled down to the fact that people are now way more accustomed to scanning QR codes for everything from instructions to menus. And threat actors are taking advantage. Proofpoint recently launched new in-line sandboxing capabilities to better defend against this threat, and our teams anticipateĀ seeing more of it in 2024. Notably, however, Dorais-Joncas points out that QR codes still just exist in the realm of ecrime ā APT actors have not yet jumped on the QR code bandwagon. (Although, some of those APT actors bring ecrime energy to their campaigns, so itās possible they may start QR code phishing, too.)Ā
2: Zero-day and N-day vulnerability exploitationĀ
A theme that appeared throughout our conversations was the creative use of vulnerabilities ā both known and unreported ā in threat actor activity. APT actors used a wide variety of exploits, from TA473 exploiting publicly-facing webmail servers to espionage actors using a zero-day in an email security gateway appliance that ultimately forced users to rip out and reinstall physical hardware. But ecrime actors also exploited their share of vulnerabilities, including the MOVEit file transfer service vulnerability from the spring of 2023 that had cascading repercussions, and the ScreenConnect flaw announced in the fall of 2023 ā both of which were used by ecrime actors before being officially published. Proofpoint anticipates vulnerability exploitation will continue, driven in part by improved defense making old school techniques ā like macro-enabled documents ā much less useful, as well as the vast financial resources now available to cybercriminals that were once just the domain of APT. Pargman says the creativity from ecrime threat actors is a direct response of defenders imposing cost on our adversaries.Ā Ā
3: Continuing, unexpected behavior changesĀ
Avid listeners of the podcast know I have regularly said the ecrime landscape is extremely chaotic, with TA577 demonstrating the most chaotic vibes of them all. The tactics, techniques, and procedures (TTPs) of some of the most sophisticated actors continue to change. The cost imposed on threat actors that Pargman mentioned ā from law enforcement takedowns of massive botnets like Qbot to improved detections and automated defenses ā have forced threat actors, cybercriminals in particular, to regularly change their behaviors to figure out what is most effective. For example, recently Proofpoint has observed the increased use of: traffic distribution systems (TDSes) such as 404 TDS and Keitaro TDS; unique, infrequently observed filetypes such as URL shortcut (.url) and scalable vector graphic (.svg); multiple new malware loaders and information stealers; and older malware like DarkGate resurfacing as popular payloads. Ecrime threat actors will change their behaviors in direct response to what defenders are doing, and we expect to see a lot more TTP experimentation in 2024.Ā
4: Artificial Intelligence (AI)
Threat actors will explore ways to incorporate AI into their workflows in similar ways as corporations are currently exploring themselves. While there is much concern about AI-created phishing emails and content in general, the impact of such threats will be negligible because the same tools that detect malicious language, sentiment, tone, subject, etc. are just as effective against robots as humans. What will be impactful is using AI tools to improve overall efficiency, such as scaling information operations or fraud that begins with a benign conversation; using coding assistants to fill knowledge gaps; or creating malicious content faster. At Proofpoint, one of the most effective AI tools in our Threat Research toolbox is Camp Disco, our malware clustering engine. Our data scientists created a custom language model for malware forensics that serves as the backbone for Camp Disco, and the result is hundreds of hours saved while threat hunting. Ā
5: Community sharing is community defenseĀ
One of the best parts of the Emerging Threats team is the incredible support we get from the community sharing information on new malware, TTPs, infrastructure, packet captures (PCAPs), phishing kits, and so much more. The Threat Research blog also serves as a way for our team to share the latest insights gleaned from our vast corpus of data. As the threat landscape continues to change and new threats, exploits, and techniques emerge, the cybersecurity community continues to collectively share and defend against our adversaries. In 2024, this community mindset is going to be more important than ever. And we canāt wait to be a part of it.Ā Ā
Listen to the DISCARDED episodes now:Ā
Phishing, Elections, and Costly Attacks: Part One of Predicting Cyber Threats in 2024Ā
Strategies for Defense and Disruption: Part Two of Predicting Cyber Threats in 2024Ā
Thanks to all our listeners, and until next time, happy hunting!Ā Ā
eSentire’s Threat Response Unit (TRU) detected a .NET backdoor named WorkDevBackdoor delivered via malvertising, employing an NSIS-installer and PowerShell to achieve persistence and data exfiltration. The campaign uses a drive-by download, RC4 encryption, andā¦
Recorded Futureās Insikt Group conducted a study of malicious command-and-control (C2) infrastructure identified using proactive scanning and collection methods throughout 2023.
This article discusses the escalating threat of SMS phishing (smishing) attacks targeting the United States Postal Service (USPS). The rise of these attacks is largely linked to a phishing toolkit available on the dark web, utilized by various threat actors, pā¦
Introduction
DarkGate is a malware family, dating back to 2018, that gained prominence after the demise of Qakbot with a Malware-as-a-Service (MaaS) offering advertised in underground cybercrime forums starting in the summer of 2023. This blog examines DarkGate intrusion trends observed by ThreatLabz between June and October 2023.
Key Takeaways
DarkGate activity surged in late September and early October 2023.
According to our customer telemetry, the technology sector is the most impacted by DarkGate attack campaigns.
Most DarkGate domains are 50 to 60 days old, which may indicate a deliberate approach where threat actors create and rotate domains at specific intervals.
Trend 1: DarkGate activity surges in late September, early October
To better understand DarkGate distribution trends, the ThreatLabz team analyzed hostnames, registration information, IP addresses, website content, and any recent patterns that emerged.
Increase in DarkGate domains
Our analysis revealed that there was a significant rise in the number of active DarkGate domains during the last week of September 2023. This means that more DarkGate websites associated with illegal activities were active during this specific time period.
Uptick in DarkGate transactions
DarkGate transactions increased in late September and into October. Notably, there was a substantial spike in transactions on October 10, 2023. This suggests that the threat actors behind Darkgate were particularly active during this time, possibly executing a series of attacks.
This DarkGate transaction data was compiled by observing the Zscaler cloud. Each time an infected machine made contact with a C2 server was counted as a transaction.
Figure 1: Illustrates spikes in DarkGate command-and-control (C2) activity by date
Trend 2: Technology sector most targeted by DarkGate
Based on analysis of our customer telemetry, the technology industry is the most targeted by DarkGate at 36.7%. Food, beverage, and tobacco come in second at 12.7%.
Figure 2: Industries most targeted by DarkGate
Trend 3: Most DarkGate domains are 50 to 60 days old
ThreatLabz found a concentrated level of activity (such as serving websites, handling transactions, or participating in network communications) among hostnames that have been in existence for 50-60 days. The fact that DarkGate domains follow this pattern could indicate that threat actors are taking a systematic approach where they create and rotate domains at specific intervals. Most likely, this intentional pattern perpetrated by threat actors is a way of evading security measures that target known malicious domains.
Figure 3: Age distribution of DarkGate domains based on transaction volume
Conclusion
The recent surge in DarkGate's activity can be attributed to its use as a replacement for Qakbot. In addition to staying on top of the threat of DarkGate malware, Zscaler's ThreatLabz team continuously monitors for new and emerging threats and shares its findings with the wider security community.
Zscaler Coverage & Indicators of Compromise (IOCs)
Zscaler's multilayered cloud security platform detects indicators related to DarkGate at various levels. Zscaler Sandbox played a particularly crucial role in analyzing the behavior of various files. Through this sandbox analysis, the threat scores and specific MITRE ATT&CK techniques triggered were identified, as illustrated in the screenshot provided below. Zscalerās advanced threat protection capabilities and comprehensive zero trust approach empowers cybersecurity professionals with critical insights into malware behavior, enabling them to effectively detect and counter the threats posed by malicious actors.
Win64.Downloader.DarkGate
Win32.Trojan.DarkGate
Win64.Trojan.DarkGate
LNK.Downloader.DarkGate
VBS.Downloader.DarkGate
JS.Downloader.DarkGate
Figure 4: Zscaler Cloud Sandbox
MITRE ATT&CK TTPās
Tactic
Technique ID
Technique ID
Initial Access
T1566
Phishing
Execution
T1204
T1059
T1569
User Execution
Command and Scripting Interpreter
System Services
Persistence
T1547
Boot or Logon Start Execution
Defense Evasion
T1027
T1070.004
T1202
T1564.001
T1140
Obfuscated Files or Information
File Deletion
Indirect Command Execution
Hidden Files and Directories
Deobfuscate/Decode Files for Information
Credential Access
T1555.003
Credentials from Web Browsers
Discovery
T1016
T1083
T1057
T1082
System Network Configuration Discovery
File and Directory Discovery
Process Discovery
System Information Discovery
Command and Control
T1071
Application Layer Protocol
Indicators of Compromise (IoCs)
Phishing PDF: 55f16d7f0a1683f32b946c03bdda79ca
Malicious DLL: a2fb0b0d34d71073cd037e872d40ea14
Encoded AutoIt Script: 0ea7d1a7ad1b24835ca0b2fc6c51c15a
AutoIt Loader Benign: c56b5f0201a3b3de53e561fe76912bfd
DarkGate Payload: f242ce468771de8c7a23568a3b03a5e2
Malicious ZIP: d2efccdb50c7450e8a99fec37a805ce6
LNK File: 7791017a97289669f5f598646ef6d517
Phishing PDF: 803103fe4b32c86fb3f382ee17dfde44
Malicious ZIP: 0a341353e5311d8f01f582425728e1d7
VBS File: 3df59010997ed2d70c5f7095498b3b3f
Encoded AutoIt Script: 660bc32609a1527c90990158ef449757
AutoIt Loader Benign: c56b5f0201a3b3de53e561fe76912bfd
DarkGate Payload: 9bf2ae2da16e9a975146c213abd7cd4f
Malicious ZIP: 9f93952e425110de34e00ebd6d6daab3
VBS File: c78dfe0f9b4fd732c8e99eb495ed9958
Encoded AutoIt Script: 660bc32609a1527c90990158ef449757
AutoIt Loader Benign: c56b5f0201a3b3de53e561fe76912bfd
DarkGate Payload: 9bf2ae2da16e9a975146c213abd7cd4f
Malicious ZIP: 54e65e96d2591106a2c41168803c77ff
JS File: 57cfc3b0b53e856c78b47867d7013516
Phishing Email: 0a50d4ea1a9d36f0c65de0e78eacbe95
PDF document: 097cbe9af6e66256310023ff2fbadac6
Malicious CAB File: 6ecd98dfd52136cff6ed28ef59b3f760
MSI File: 8ef6bc142843232614b092fac948562d
CAB file dropped from MSI: a169cebb4009ecfb62bb8a1faf09182f
Command-and-control (C2)
āāluxury-event-rentals[.]com
drvidhya[.]in
alianzasuma[.]com
cpm.com[.]py
corialopolova[.]com
skylineprodutora[.]com.br
medsure[.]com.br
humanrecruitasia[.]com
journeotravel[.]com
skylineprodutora.com[.]br
ahantadevnet[.]org
yellowstone[.]com.mm
asiaprofessionals[.]net
axecapital[.]ro
semquedagotas[.]com.br
reverasuplementos[.]fun
tikwave[.]site
grupec[.]com.co
chatpipoca[.]net
ncsinternationalcollege[.]com
gatraders.com[.]pk
ibuytech[.]pk
winstonandfriendz[.]ca
skincaremulher[.]fun
adam-xii-rpl.my[.]id
mycopier.com[.]my
japaaesthetics[.]com
msteamseyeappstore[.]com
youth[.]digital
roundstransports[.]com
mfleader.com[.]ar
fefasa[.]hn
nile-cruiise-egypt[.]com
flyforeducation[.]com
expertaitalia[.]eu
plataformaemrede[.]com.br
runnerspacegifts[.]com/umn/
kiwifare[.]net
getldrrgoodgame[.]com
hmas[.]mx
darkgate[.]com
5.188.87.58
5.42.77.33
45.144.28.244
94.228.169.123
94.228.169[.]143[:]2351/
94.228.169[.]143[:]8080/
66.42.110.147
94.131.106.78
88.119.175.245
45.32.222.253
grupowcm[.]com[.]br
thekhancept[.]com
eelontech[.]com
bligevale[.]co[.]zw
dhtech[.]ae
techs[.]com
gsrhrservices[.]com
glowriters[.]com
a2zfortextile[.]com
alpileannn[.]com
boutiquedhev[.]com
hypothequeswestisland[.]com
onetabmusic[.]com
sirishareddy[.]info
appapi[.]store
sictalks[.]com
nia-dbrowntestserver[.]com[.]ng
ofc[.]ai
unasd[.]org
plusmag[.]ro
beautifullike[.]com
gsrglobal[.]org
winstonandfriendz[.]ca
divinfosystem[.]com
supershuttles[.]co[.]za
ziaintegracion[.]com
themarijuanashow[.]com
blackshine[.]lk
deroze[.]net
vtektv[.]com
dna-do-gamer[.]com
kalismprivateltd[.]co[.]uk
arshany[.]com
kelotecnologia[.]com
millennialradio[.]es
phomecare.co.uk
In a new report, Recorded Futureās Insikt Group examines North Koreaās success in its cybercriminal operations targeting the cryptocurrency industry.
Security Joes describes a large-scale data-wiping campaign targeting Israeli organizations, led by hacktivist groups Karma and Moses Staff, featuring BiBi-Linux Wiper and the Windows variant bibi.exe. The investigation links pro-Palestinian motives to the attaā¦
AhnLab ASEC detected malware distributed through breached legitimate websites using LNK files that prompt users to run them, illustrating a distribution chain that involves HTML and VBScript executed via mshta and PowerShell. The article also covers how AhnLabā¦
Threat hunting today blends structured methodologies, real-time data analysis, and adaptive automation to uncover anomalies, threats, and attacker activity across logs, networks, and endpoints. The article showcases traditional approaches, a modern futuristic ā¦
Introduction In this blog post, we will provide an update on our continued analysis and tracking of infrastructure associated with…
Brand impersonation has surged as a core concern, with attackers impersonating trusted brands to steal credentials and deliver malware across platforms. The piece highlights new tooling (VirusTotal NetIoc) and practical hunting approaches to detect and track tā¦
Mallox is a ransomware operation targeting Windows systems, leveraging unsecured MS-SQL servers as an entry point and using brute-force techniques to gain access. It employs a double-extortion model, steals data before encryption, and is expanding via affiliatā¦
This article examines threat hunting for business email compromise (BEC) in Microsoft 365 by analyzing anomalous user agents in telemetry. It details how Huntress identified and validated malicious authentications linked to a rare AZURECLI/Azsdk-python user agā¦
ReliaQuestās Threat Hunting Team traced a May 2023 incident to Gootloader, a JavaScript-based initial-access malware that can seed second-stage remote access tools and enable ransomware deployments. The assessment details Gootloaderās infection chain, the Systā¦