HomeSecurityWindows devices were attacked by the Blue Mockingbird group

Windows devices were being attacked by the Blue Mockingbird group

Mockingbird

The Blue Mockingbird hacking group is deploying a Moneroon Internet-facing Windows of multiple organizations, as discovered by Red Canary security researchers.

As found, the group has been active since December 2019 and uses many techniques to bypass security.

How did the Blue Mockingbird group operate?

Windows devices were being attacked by the Blue Mockingbird group

Malicious actors exploited web applications that use Telerik UI for ASP.NET AJAXto gain access to machines.

Telerik UI is a user interface suite that helps in the web. Version 2019.3.1023 of the suite, however, has a vulnerability CVE-2019-18935, which was discovered and exploited by the Blue Mockingbird team to gain access to the system and then use the JuicyPotatoto escalate their privileges.

Once he managed to take full control of the device, he deployed a popular version of the Monero mining tool XMRIG as a DLL.

When the COR_PROFILER was configured, every process that loaded the Microsoft .NET Common Language Runtime established persistence.

In some cases, hackers even created a new service to perform the same actions as the COR_PROFILER payload.

Using the JuicyPotato method, the hacking group escalates its privileges from a virtual IIS Application Pool Identity account to the NT Authority \\ SYSTEM account.

Subsequently, the malicious actors use RDP to deploy payloads to remote systems.

How will you avoid such an attack?

To mitigate attacks, it is recommended to update web servers, web applications, and the components that applications. Red Canary has also published a detailed report that presents the Risk Indicators.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS