HomeSecurityScattered Spider: Attempts to evade detection with Bring-Your-Own-Driver tactics

Scattered Spider: Tries to avoid detection with the Bring-Your-Own-Driver tactic

The financially motivated threat actor, Scattered Spider, was observed attempting to deploy Intel Ethernet diagnostics drivers in a BYOVD (Bring Your Own Vulnerable Driver) attack to evade detection by Endpoint Detection and Response (EDR) security products.

See also: Royal Mail: Suspends its international services due to cyberattack

Scattered Spider

The Bring Your Own Vulnerable Driver (BYOVD) technique leverages a kernel-mode driver with known exploits to gain elevated privileges on Windows systems and launch malicious attacks.

Since device drivers have direct access to the kernel of an operating system, malicious actors can exploit any vulnerabilities to run code with elevated privileges on a Windows.

Shortly after Crowdstrike released its most recent report on Scattered Spider early last month, the company noticed a unique new strategy.

As reported in Crowdstrike's latest report, malicious actors attempted to infiltrate Microsoft Defender for Endpoint, Palo Alto Networks Cortex XDR, and SentinelOne using the Bring Your Own Vulnerability Defense (BYOVD) technique.

See also: Twitter on user email leak: “They were not stolen from our systems”

Disable security products

According to CrowdStrike, the Scattered Spider hacking group was spotted attempting to exploit a high-level vulnerability, CVE-2015-2291, in Intel's Ethernet diagnostics driver. If successfully exploited, this flaw could allow malicious actors to gain kernel privileges and execute arbitrary code on an infected machine.

By exploiting the vulnerability, which was patched in 2015 but still exists on older versions of compromised devices, hackers can bypass any updates that victims have applied to their systems. This allows them to take advantage of this flaw and gain access regardless of the patches that have been installed.

Scattered Spider runs on a lightweight 64-bit kernel driver containing 35 functions, which are digitally signed with certificates stolen from trusted sources such as NVIDIA and Global Software LLC. This way, Windows is able to avoid blocking it .

Hackers exploit these factors to disable endpoint security solutions and minimize defenders' visibility, thus creating an ideal environment for further stages of their attacks on targeted networks.

At startup, the driver decrypts a hard-coded string of targeted security products and fixes the targeted drivers at hard-coded offsets.

See also: Cisco warns of critical vulnerability in EoL routers

The malicious coding injected into the system ensures that security software drivers appear to be working normally, even though they actually fail to protect the device.

Crowdstrike warns against “Bring Your Own Device” (BYOD) attacks, stressing that the ‘Scattered Spider’ has a limited and specific targeting scope but no organization is completely safe from these efforts – therefore, it is important to stay aware of the threat of BYOVD attacks.

Scattered Spider: Tries to avoid detection with the Bring-Your-Own-Driver tactic

An ancient Windows issue that continues to persist

Microsoft recognized the security threats posed by Windows and took steps to improve them in 2021, introducing a new block list feature.

Unfortunately, this issue was not immediately addressed, as Windows does not block these drivers by default unless you are running Windows 11 2022 and later, which were released in September 2022.

Worse still, as ArsTechnica reported in October, Microsoft only updated the driver block list with each major release of Windows, leaving devices vulnerable to these types of attacks. Microsoft has since released updates that fix this service line to properly update the driver block list.

Microsoft recommends that Windows users enable the driver blocklist to protect against these BYOVD attacks. This article provides information about enabling the blocklist using the Windows Memory Integrity feature or Windows Defender Application Control (WDAC).

Unfortunately, enabling Memory Integrity on devices that may not have newer drivers can be difficult.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS