HomeSecurityCISA: Cyberattacks exploit legitimate remote monitoring software

CISA: Cyberattacks exploit legitimate remote monitoring software

Today, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) , and the Multi-State Information Sharing and Analysis Center (MS-ISAC) warned of a growing trend in cyberattacks using legitimate software .

CISA

CISA uncovered malicious activity on the networks of several federal agencies through the EINSTEIN, following the release of a report by Silent Push in mid-October 2022.

The malicious activity was linked to an “extensive phishing financially motivated” reported by Silent Push and detected on “multiple other FCEB networks.” It was initially detected on a single FCEB network in mid-September 2022.

See also: Riot Games hack: League of Legends source code up for auction

The attackers behind this campaign began sending emails phishing to the personal and government email addresses of federal personnel, at least since mid-June 2022.

According to CISA and other agencies: “These emails either contain a link to a malicious “first-stage” domain or urge recipients to call the cybercriminals, who then try to convince recipients to visit the malicious first-stage domain.”

Callback phishing attacks , such as those targeting FCEB staff in recent months, have seen huge growth (625%) and have also been adopted by ransomware gangs .

Unlike regular phishing emails , phishing attacks using the Callback method do not include a link to a malicious website. Instead, they try to lure users with topics such as subscription renewals to convince them to call a phone number provided in the email.

When a target calls the number, they will be asked to open a website to download the software required for the refund of the renewal price.

In cases where there was a malicious link in the email, the phishing domains used impersonated high-profile brands, including Microsoft, Amazon, and Paypal.

Clicking on the embedded links led to the opening of the default browser and the automatic download of malware designed to connect to a second-stage domain to download portable versions of AnyDesk and ScreenConnect that connect to the attackers' RMM server.

See also: Windows CryptoAPI: Vulnerable to attacks due to a serious bug

The use of portable remote desktop software executables allows malicious actors to gain access to victims' systems as a local user, without requiring administrator privileges or a full software installation. In this way, criminals gain remote access by bypassing software controls.

FCEB network breach

After gaining access to their targets' devices, attackers attempt to trick victims into logging into their bank accounts to make a supposed refund.

While this particular activity appears to be financially motivated and targeting individuals, access could lead to additional malicious activity against the recipient’s organization—both by other cybercriminals and APT actors,” CISA, NSA, and MS-ISAC report.

Malicious cyber actors could leverage these same techniques to target National Security Systems (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) networks and deploy legitimate RMM software on both work and home devices and accounts,” added .

System and network defenders are encouraged by CISA, NSA, and MS-ISAC to use the breach indicators shared in their public advisories to identify potential exploits or breaches.

CISA encourages network defenders to review the advisories for breach indicators, best practices and recommended mitigations, which highlight the threat of additional types of malicious activity using RMM, including its use as a backdoor for persistence, etc.

A list of measures that have been designed to help mitigate such risks has also been published.

See also: Phishing scam: Australian sentenced to two years in prison

Cyberattack software
CISA: Cyberattacks exploit legitimate remote monitoring software

To protect against potential security breaches, companies and organizations should audit installed remote access and identify authorized RMM software.

It is also recommended to use application control elements to prevent the execution of unauthorized RMM software and to use only authorized RMM software through approved remote access solutions.

To further enhance security, organizations should provide training to their employees so they can recognize the risks and avoid phishing emails. While no one can guarantee complete protection from such threats, training, combined with other measures such as using antivirus software and keeping systems updated, can significantly reduce the risk.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS