July 11, 2022
-
Anomali Threat Research
,

Anomali Cyber Watch: Brute Ratel C4 Framework Abused to Avoid Detection, OrBit Kernel Malware Patches Linux Loader, Hive Ransomware Gets Rewritten, and More

<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>APT, China, Cyberespionage, India, Malspam, Ransomware, Russia, Spearhishing,</b> and <b>Vulnerabilities</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p> <p><img src="https://cdn.filestackcontent.com/jbDi310aRFiqf6hBEYss"/><br/> <b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p> <h2>Trending Cyber News and Threat Intelligence</h2> <div class="trending-threat-article"> <h3><a href="https://www.sentinelone.com/labs/targets-of-interest-russian-organizations-increasingly-under-attack-by-chinese-apts/" target="_blank">Targets of Interest | Russian Organizations Increasingly Under Attack By Chinese APTs</a></h3> <p>(published: July 7, 2022)</p> <p>SentinelLabs researchers detected yet another China-sponsored threat group targeting Russia with a cyberespionage campaign. The attacks start with a spearphishing email containing Microsoft Office maldocs built with the Royal Road malicious document builder. These maldocs were dropping the Bisonal backdoor remote access trojan (RAT). Besides targeted Russian organizations, the same attackers continue targeting other countries such as Pakistan. This China-sponsored activity is attributed with medium confidence to Tonto Team (CactusPete, Earth Akhlut).<br/> <b>Analyst Comment:</b> Defense-in-depth (layering of security mechanisms, redundancy, fail-safe defense processes) is the best way to ensure safety from advanced persistent threats (APTs), including a focus on both network and host-based security. Prevention and detection capabilities should also be in place. Furthermore, all employees should be educated on the risks of spearphishing and how to identify such attempts.<br/> <b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/947244" target="_blank">[MITRE ATT&amp;CK] Exploitation for Client Execution - T1203</a><br/> <b>Tags:</b> China, source-country:CN, Russia, target-country:RU, Ukraine, Pakistan, target-country:PK, Bisonal RAT, Tonto Team, APT, CactusPete, Earth Akhlut, Royal Road, 8.t builder, CVE-2018-0798</p> </div> <div class="trending-threat-article"> <h3><a href="https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat/" target="_blank">OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow</a></h3> <p>(published: July 6, 2022)</p> <p>Intezer researchers describe a new Linux malware dubbed OrBit, that was fully undetected at the time of the discovery. This malware hooks functions and adds itself to all running processes, but it doesn’t use LD_PRELOAD as previously described Linux threats. Instead it achieves persistence by adding the path to the malware into the /etc/ld.so.preload and by patching the binary of the loader itself so it will load the malicious shared object. OrBit establishes an SSH connection, then stages and infiltrates stolen credentials. It avoids detection by multiple functions that show running processes or network connections, as it hooks these functions and filters their output.<br/> <b>Analyst Comment:</b> Defenders are advised to use network telemetry to detect anomalous SSH traffic associated with OrBit exfiltration attempts. Consider network segmentation, storing sensitive data offline, and deploying security solutions as statically linked executables.<br/> <b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905764" target="_blank">[MITRE ATT&amp;CK] Hijack Execution Flow - T1574</a> | <a href="https://ui.threatstream.com/ttp/3905776" target="_blank">[MITRE ATT&amp;CK] Hide Artifacts - T1564</a> | <a href="https://ui.threatstream.com/ttp/947199" target="_blank">[MITRE ATT&amp;CK] Data Staged - T1074</a><br/> <b>Tags:</b> OrBit, Linux, Hooking, detection:Orbit, Shared object, ld.so.preload</p> </div> <div class="trending-threat-article"> <h3><a href="https://www.secuinfra.com/en/techtalk/whatever-floats-your-boat-bitter-apt-continues-to-target-bangladesh/" target="_blank">Whatever Floats Your Boat – Bitter APT Continues to Target Bangladesh</a></h3> <p>(published: July 6, 2022)</p> <p>Bitter (T-APT-17), is a group suspected of being sponsored by the Indian government. Since 2013, Bitter has targeted Bangladesh, China, Pakistan, and Saudi Arabia. Secuinfra researchers describe a new Bitter company that targeted Bangladeshi military organizations in or around May 2022. The observed infection chain included a malicious Excel file, ZxxZ (MuuyDownloader) downloader that the group was seen using earlier in 2022, and a new .Net-based remote access trojan (RAT) dubbed Almond.<br/> <b>Analyst Comment:</b> All users should be informed of the threat phishing poses, and how to safely make use of email. Detection and prevention measures should be taken to ensure that users do not fall victim to phishing.<br/> <b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947244" target="_blank">[MITRE ATT&amp;CK] Exploitation for Client Execution - T1203</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/3904502" target="_blank">[MITRE ATT&amp;CK] Non-Standard Port - T1571</a> | <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a> | <a href="https://ui.threatstream.com/ttp/947253" target="_blank">[MITRE ATT&amp;CK] Data Transfer Size Limits - T1030</a> | <a href="https://ui.threatstream.com/ttp/947195" target="_blank">[MITRE ATT&amp;CK] File and Directory Discovery - T1083</a> | <a href="https://ui.threatstream.com/ttp/2402541" target="_blank">[MITRE ATT&amp;CK] Data Destruction - T1485</a><br/> <b>Tags:</b> Bitter, T-APT-17, Almond RAT, ZxxZ, MuuyDownloader, CVE-2018-0798, Government, Military, APT, Bangladesh, target-country:BD, India, source-country:IN, Cyberespionage, Equation Editor exploits</p> </div> <div class="trending-threat-article"> <h3><a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-187a" target="_blank">Alert (AA22-187A). North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector</a></h3> <p>(published: July 6, 2022, revised: July 07, 2022)</p> <p>US agencies alert that North Korea-sponsored groups have been using Maui ransomware to target Healthcare and Public Health (HPH) sector organizations since at least May 2021. The attackers used unidentified initial access vectors to eventually encrypt servers responsible for healthcare services such as diagnostics services, electronic health records services, imaging services, and intranet services. Maui ransomware is designed for manual execution by a remote actor. It uses a combination of Advanced Encryption Standard (AES), RSA, and XOR encryption.<br/> <b>Analyst Comment:</b> Targeted HPH organizations should try to avoid paying ransoms as doing so does not guarantee data recovery and may pose sanctions risks. Secure personal identifiable information (PII)/patient health information (PHI) and encrypt the data at rest and in transit by using technologies such as Transport Layer Security (TLS). Only store PII and PHI on internal systems that are protected by firewalls, and ensure extensive backups are available if data is ever compromised.<br/> <b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a><br/> <b>Tags:</b> Maui ransomware, Healthcare, USA, target-country:US, Ransomware, HPH, North Korea, source-country:KP, Windows</p> </div> <div class="trending-threat-article"> <h3><a href="https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/" target="_blank">When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors</a></h3> <p>(published: July 5, 2022)</p> <p>Unit 42 researchers discovered an advanced persistent threat (APT) campaign that abused a relatively new, stealthy tool: Brute Ratel C4 (BRc4) pentesting framework. From February 2021 to May 2022, this campaign was mostly targeting large virtual private server (VPS) hosting providers in various countries and regions. BRc4 remote access payload was packaged in a self-contained ISO with a Windows shortcut (LNK) file, a malicious payload DLL and a legitimate Microsoft executable used by the actors for DLL search order hijacking. This packaging is consistent with known Cozy Bear (APT29) techniques, but the attribution is not definitive.<br/> <b>Analyst Comment:</b> Defense-in-depth (layering of security mechanisms, redundancy, fail-safe defense processes) is the best way to ensure safety from APTs, including a focus on both network and host-based security. Anti-phishing employee training should also be in place.<br/> <b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905764" target="_blank">[MITRE ATT&amp;CK] Hijack Execution Flow - T1574</a> | <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/947141" target="_blank">[MITRE ATT&amp;CK] Masquerading - T1036</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a><br/> <b>Tags:</b> Brute Ratel C4, BRc4, APT29, Cozy Bear, Argentina, Mexico, Ukraine, target-region:North America, target-region:South America, DLL search order hijacking, ISO, LNK, Windows</p> </div> <div class="trending-threat-article"> <h3><a href="https://www.microsoft.com/security/blog/2022/07/05/hive-ransomware-gets-upgrades-in-rust/" target="_blank">Hive Ransomware Gets Upgrades in Rust</a></h3> <p>(published: July 5, 2022)</p> <p>In February 2022, a possible trigger for rewriting the Hive ransomware, South Korean researchers defeated the old Hive encryption. Five days after the publication, the new Hive variant was detected by Microsoft with a new, unique encryption approach and other major upgrades. Hive ransomware was fully re-written from Go to Rust programming language, making it harder to reverse-engineer and providing fast and safe encryption. The new Hive variant stores its strings in the .rdata section encrypted by XORing with constants and they are only decrypted during runtime. Hive introduces command-line parameters, including one for supplying the username and the password used to access the Hive ransom payment website. Elliptic Curve Diffie-Hellmann (ECDH) with Curve25519 and XChaCha20-Poly1305 encryption with ChaCha20 symmetric cipher) are used to encrypt strings used to XOR victim files.<br/> <b>Analyst Comment:</b> Defenders should consider requiring MFA from all devices, in all locations, at all times. Implement credential hygiene, update automation, and cloud hardening recommendations.<br/> <b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/2402535" target="_blank">[MITRE ATT&amp;CK] Service Stop - T1489</a> | <a href="https://ui.threatstream.com/ttp/2402534" target="_blank">[MITRE ATT&amp;CK] Inhibit System Recovery - T1490</a><br/> <b>Tags:</b> Ransomware, Hive, Rust, Ransomware-as-a-service, ChaCha20, ECDH, Curve25519, XChaCha20-Poly1305, String encryption, XOR, Healthcare</p> </div> <div class="trending-threat-article"> <h3><a href="https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites" target="_blank">IconBurst NPM Software Supply Chain Attack Grabs Data from Apps Websites</a></h3> <p>(published: July 5, 2022, updated July 6, 2022)</p> <p>ReversingLabs researchers have discovered an extensive supply-chain compromise campaign dubbed IconBurst that was based on malicious NPM modules that are harvesting sensitive data from forms embedded in mobile applications and websites. IconBust used misspelling of popular modules to hide their obfuscated, malicious modules with the jQuery ajax() function to exfiltrate serialized form data to domains controlled by the attacker. Since December 2021, IconBust has affected thousands of downstream mobile and desktop applications as well as websites, exposing their users and visitors to data theft.<br/> <b>Analyst Comment:</b> Developers should be aware of the malicious typosquatting danger due to a library name being misspelled in the code. Organization defensive posture should include consideration for open-source dependencies and associated supply-chain risks.<br/> <b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947137" target="_blank">[MITRE ATT&amp;CK] Supply Chain Compromise - T1195</a> | <a href="https://ui.threatstream.com/ttp/947141" target="_blank">[MITRE ATT&amp;CK] Masquerading - T1036</a><br/> <b>Tags:</b> IconBurst, npm, Supply chain, Malicious library, Typosquatting, jQuery, Javascript, Javascript obfuscator, ionic-io</p> </div> <h2>Observed Threats</h2> <p>Additional information regarding the threats discussed in this week's Anomali Cyber Watch can be found below:</p> <p><a href="https://ui.threatstream.com/vulnerability/99626" target="_blank">CVE-2018-0798</a><br/> Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".</p>

Get the Latest Anomali Updates and Cybersecurity News – Straight To Your Inbox

Become a subscriber to the Anomali Newsletter
Receive a monthly summary of our latest threat intelligence content, research, news, events, and more.