HomeSecurityIranian hackers encrypt Windows systems via BitLocker

Iranian hackers encrypt Windows systems via BitLocker

According to Microsoft, Iranian hackers tracked as DEV-0270 (also known as Nemesis Kitten) are abusing the BitLocker Windows feature to encrypt victims' systems.

Iranian BitLocker hackers

The company's researchers discovered that the group is rapidly exploiting disclosed vulnerabilities and extensively using living-off-the-land binaries (LOLBINs) in attacks .

See also: How to install Session Messenger on Windows?

This aligns with Microsoft 's findings that Iranian hackers are using BitLocker, a data protection feature that provides encryption on devices running Windows 10, Windows 11, or Windows Server 2016 and later .

“ DEV-0270 uses setup.bat commands for BitLocker encryption, which leads to hosts not working ,” Microsoft researchers explained .

“For workstations, the team uses DiskCryptor, an open-source full disk encryption system for Windows that allows encryption of a device's entire hard drive.“.

Access to the compromised network is achieved by establishing persistence via a scheduled task. DEV-0270 then escalates privileges to the system level, and can do things like disable Microsoft Defender Antivirus to avoid detection, lateral movement, and file encryption.

See also: Cisco will not fix vulnerability found in EoL routers

Windows BitLocker

Iranian hackers appear to be demanding ransoms two days after initial access. On average, they ask victims to pay $8,000 for decryption keys.

Microsoft claims that the Iranian hackers exploiting BitLocker to encrypt Windows systems are a subgroup of the Iranian cyberespionage group Phosphorus (also known as Charming Kitten and APT35). This group is known for targeting and collecting information from victims associated with governments, NGOs, and defense organizations worldwide.

DEV-0270, however, appears to be carrying out attacks “for personal gain,” according to Microsoft, although it is not entirely certain yet.

Based on some infrastructure evidence, Microsoft says the group is operated by an Iranian company known by two aliases: Secnerd (secnerd[.]ir) and Lifeweb (lifeweb[.]it).

“These organizations are also affiliated with Najee Technology Hooshmand (ناجی تحقیم هوشمند), located in Karaj, Iran,” the company added.

See also: HP: Fixes bug in pre-installed Support Assistant tool

“The group usually targets randomly: it scans the Internet to find vulnerable servers and devices, making organizations with vulnerable and detectable servers and devices susceptible to these attacks.“.

Given that many of the DEV-0270 attacks have exploited known Exchange (ProxyLogon) or Fortinet (CVE-2018-13379) vulnerabilities, companies are urged to take the necessary measures (updates, etc.) to prevent exploitation attempts and subsequent ransomware attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS