HomeSecurityRansomware Still Dominates: New Tactic Emergence

Ransomware Still Reigns: New Tactics Emerge

ransomware

Ransomware attacks often rely on trojans to infect computers and steal data. Such trojans include Emotet and Trickbot, which help criminals infiltrate sensitive data, which they hold hostage in order to demand ransom. But as ransomware dominates the cyber threat landscape, criminals are increasingly carrying out attacks using Cobalt Strike, an otherwise “ethical testing framework.” A new report from Cisco Talos Incident Response (CTIR) describes this new trend.

According to CTIR, ransomware continues to dominate the threat landscape over the past quarter. This means that for five consecutive quarters, it has held this position. Some of the most well-known ransomware include Ryuk, Maze, LockBit, and Netwalker.

One of the tactics that has been increasingly used lately is the use of legal-ethical tools, such as Cobalt Strike, a powerful toolkit designed for simulation and penetration testing.

However, instead of using the tool for ethical purposes (for which it was created), ransomware gangs are using it to infect and compromise systems from which they can then steal and control data. Last quarter, 66% of all ransomware attacks involved Cobalt Strike, the report said.

In one example reported by CTIR, a company was infected with LockBit ransomware. The attackers used Cobalt Strike. Then, using an open source tool called “CrackMapExecWin,” they were able to explore large Active Directory networks and force all systems on the network to perform an update.

The update then created a service to run the ransomware from a compromised server. User accounts were created on the compromised computers, which the attackers used to initiate remote connections. The ransomware gang also used TeamViewer to steal information and erase traces of the breach.

The data extracted from this attack was published on the Maze ransomware leak site.

“One reason we’re seeing so much Cobalt Strike activity right now is because it helps with malware,” said Amy Henderson, a member of CTIR. “Attackers are using it to fill any gaps they have or for quick and efficient construction so they can focus on the more profitable and sophisticated parts of their attack.”

The use of Cobalt Strike is seen not only in ransomware but also in other types of cyberattacks. Also, the use of Cobalt Strike beacons, which can mimic legitimate traffic, may be one reason why the toolkit is attractive to criminals.

In most cases, attackers have already compromised a victim's system and then use the tool.

Cobalt Strike also has a number of features and capabilities that ransomware gangs and other attackers can exploit.

According to CTIR, another ethical toolkit that is also being used for malicious purposes is the Telerik UI framework. It is commonly used for software development, but it was recently discovered to have a vulnerability (CVE-2019-18935) that could allow remote code execution. Such a vulnerability can be particularly dangerous, as many applications may be running older versions of Telerik UI that are vulnerable to the vulnerability, putting users at risk.

In one example, an attacker hit a technology company's server and managed to use the toolkit to execute malicious commands, leading to a ransomware attack.

Ransomware Still Reigns: New Tactics Emerge

How to protect your organization from ransomware attacks?

Use a strong email protection solution: Email is still the first stage of attack (in most cases), so organizations need to have strong email protection programs in place. This includes training employees to detect and report advanced phishing attacks.

Implement the right policies: Implement policies that restrict certain users' access to PowerShell or CMD applications and other critical applications. Such policies should prevent attackers from gaining further privileges so that they cannot spread across networks.

Implement multi-factor authentication: Use authentication methods to put more obstacles in the way of hackers.

Back up critical data: Make sure you have backups of your important data that cannot be modified using domain credentials. This means you should create offline backups or use other methods to protect the copies. Online backups are targeted by hackers before a ransomware attack occurs, so that the victim cannot repair the damage on their own. Having secure backups is essential so that victims can recover their data without paying the ransom.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS