HomeSecurityIgnorant hackers spent months inside a network because they didn't know what...

Ignorant hackers spent months inside a network because they didn't know what to do

Some novice hackers who didn't know what to do spent months inside a government agency network undetected – before more skilled attackers came along and launched a ransomware attack.

hacker

See also: Ransom DDoS attacks hit record levels this year

Analysis of the incident at an unspecified US regional government agency by cybersecurity researchers at Sophos found that the unwitting hackers left plenty of evidence that they were on the network. However, despite leaving a trail, they were not detected by their IT team.

The attackers initially broke into the network using one of the most popular techniques used by cybercriminals – cracking the Windows Remote Desktop Protocol (RDP) password on a firewall. It is not certain how the password itself was cracked, but common methods include brute-force and phishing emails.

They were also lucky, because the compromised RDP account was not only a local admin on the server, but also had domain administrator, which allowed the account to be exploited to create administrator accounts on other servers and desktops.

But despite all this power, the attackers didn't seem to know what to do once they had access to the network. Analysis of the activity logs showed that they were using the servers they controlled within the network to perform Google searches for hacking tools , then followed by pop-up ads for "pirated software downloads."

See also: Police shut down hacking forum RaidForums

Researchers say this allowed the server to become filled with adware and the hackers to inadvertently infect the servers they controlled with malware. The victim didn't notice any of this happening.

Log data suggests that the attackers regularly disappeared for days at a time before returning to look around the network, occasionally creating new accounts to gain access to other machines. This continued for months, with the attackers seemingly learning how to hack networks as they went along, as well as installing cryptomining malware on the compromised servers.

But after four months, the attacks suddenly became more focused and sophisticated. After a three-week lull in activity, the attackers remotely logged in and installed the Mimikatz password-cracking tool to gain access to additional usernames and passwords, saving them all to a text file on the desktop of the admin-level accounts they created.

These hackers also attempted to remove the previously installed coinminer and attempted to uninstall antivirus software on the endpoints. It is possible that the higher sophistication of the attacks means that new attackers had gained access to the network.

At this point, the IT department noticed something strange was happening, taking the servers offline to investigate them – but in doing so, they also disabled some cybersecurity protections – and the attackers took advantage of this.

The attackers repeatedly dumped new account credentials and created new accounts to continue their attacks. The logs were wiped repeatedly, in what could have been an attempt to cover their tracks.

hacker

See also: Only half of organizations reviewed cybersecurity policies due to the pandemic

The new, much more sophisticated attackers also stole a set of sensitive files as they worked toward the apparent end goal of a ransomware attack, which fully encrypted some of the machines on the network with LockBit ransomware. However, the attack did not affect all the machines, and the IT department, with the help of Sophos analysts, was able to “clean up” and restore services.

However, the entire attack could have been avoided if better cybersecurity strategies were in place, as the attackers were able to freely enter and move around the network without being detected.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS