Security Joes' final report points out that based on this evidence, we conclude that the hackers behind this particular attack are linked to a Russian-speaking ransomware gang, which takes tools used by other groups and adds its own signature.
Security experts have identified an interesting case of a ransomware attack that used tools used by APT (advanced persistent threat) groups. Although there does not appear to be a connection between the groups, the operational tactics, targeting scope, and characteristics of the malware suggest possible connections.
As noted in a report by Security Joes, the ransomware attack observed against a client in the gambling/gaming industry involved a combination of open source tools. Some examples include: a modified version of Ligolo, a reverse tunneling utility that is freely available to users on GitHub, and a tool to dump credentials from LSASS.

According to Security Joes, the ransomware attack unfolded on a weekend night and then rapidly escalated, demonstrating the skill of the individuals running it. Initial access was gained through a compromise of the SSL-VPN credentials of some employees. This was followed by admin scans and RDP brute-force as well as attempts to harvest credentials. The next steps in the attack included gaining access to additional machines with high privileges, deploying a custom proxy tunneling for secure communication, and finally dropping Cobalt Strike.

See also: Rompetrol gas station network hit by Hive ransomware
Although the hackers behind the ransomware attack never had the chance to move on to the next stage, Security Joes believes that the next step would have been the deployment of a ransomware payload, as the tactics used resemble those of classic ransomware gangs. However, this has not been confirmed as researchers were able to stop the payload from executing before the attackers could deploy anything to the compromised network.
The hackers used several open source tools commonly used by many adversaries, such as Mimikatz, SoftPerfect, and Cobalt Strike. One variation worth mentioning is the development of “Sockbot,” a utility written in GoLang based on the open source reverse tunneling tool Ligolo.

The hackers, during their ransomware attack, modified Ligolo by making significant additions that removed the need to use command-line parameters and required several execution checks to prevent the execution of multiple instances.
It is worth noting that a customized Ligolo is not usually a tool for any threat. The only group that used something like this was the Iranian-funded hacking group MuddyWater. The reason we don’t see this tactic often is that Ligolo is not user-friendly enough for malware development, so coding skills are required to make it work.
See also: FBI: Ragnar Locker ransomware has targeted 52 organizations belonging to US critical infrastructure
Another notable tool is lsassDumper, which is also written in GoLang and is used to automatically dump the LSASS process into the transfer.sh service. According to Security Joes, this is the first time a tool like lsassDumper has been spotted, which demonstrates the skill of the hackers. Additionally, directly dumping LSASS credentials is a method often used by ransomware gangs.

Finally, the attackers used ADFind for network reconnaissance, a freely available tool that adversaries use to gather information from Active Directory , also very common in the ransomware space .
Security Joes' final report points out that based on this evidence, we conclude that the hackers behind this particular attack are linked to a Russian-speaking ransomware gang, which takes tools used by other groups and adds its own signature.
Source: bleepingcomputer.com
