HomeSecurityHackers infiltrate Windows devices through Sliver and BYOVD attacks

Hackers infiltrate Windows devices through Sliver and BYOVD attacks

A malicious hacking group is using Sunlogin exploits to deploy the Sliver post-exploitation toolkit and launch Windows BYOVD attacks to compromise security software. This new campaign represents a serious threat that requires immediate action before it is too late.

See also: Notorious hacker Julius “Zeekill” Kivimäki arrested in France

Hackers infiltrate Windows devices through Sliver and BYOVD attacks

Last summer, Sliver was released by Bishop Fox as an alternative to Cobalt Strike and quickly gained traction among malicious actors for its ability to conduct network surveillance, launch commands and DLLs reflexively, spawn sessions, or manipulate processes.

According to a report by the AhnLab Security Emergency Response Center (ASEC), recently observed attacks target two 2022 vulnerabilities in Sunlogin, a remote control software from a Chinese developer.

See also: Twitter: Top cyber diplomat's account hacked

After exploiting these vulnerabilities to compromise a device, attackers use PowerShell scripts to open reverse shells or install other payloads, such as Sliver, the Gh0st RAT, or the XMRig Monero coin miner.

Sunlogin

Bringing a malicious driver into the attack

The attack begins by exploiting the CNVD-2022-10270 / CNVD-2022-03672 RCE vulnerabilities in Sunlogin version 11.0.0.33 and earlier, using readily available proof of concept (PoC) exploits.

Attackers exploit the flaw to execute an obfuscated PowerShell script to disable security products before deploying backdoors.

The script decodes a portable .NET executable and loads it into memory. This executable is a modified version of the open source tool Mhyprot2DrvControl, which was created to exploit vulnerable Windows drivers to perform malicious actions with kernel-level privileges.

Mhyprot2DrvControl specifically abuses the mhyprot2.sys file, a digitally signed anti-cheat driver for Genshin Impact that Trend Micro observed being used for ransomware since last year.

See also: Android users: Uninstall these 12 apps immediately

After downloading the driver, malicious actors exploit its vulnerability to gain Windows kernel privileges – a power that can be leveraged to stop security processes kept safe by user-mode programs.

Silver

The second part of the PowerShell script downloads Powercat from an external source and uses it to execute a reverse shell that connects to the C2 server, giving the attacker remote access to the compromised device.

In some cases observed by ASEC, Sunlogin attacks were followed by the installation of a Sliver implant (“acl.exe”). Threat actors used the implant created by the Sliver framework in “Session Mode” without the use of wrappers.

Sunlogin Sliver

In some cases, attackers used the Gh0st RAT (remote access trojan) for remote file management, key logging, remote command execution , and data theft

Microsoft recommends that Windows admins enable the vulnerable driver exclusion list to protect against BYOVD attacks.

Microsoft offers detailed guidance on using Windows Memory Integrity or Windows Defender Application Control (WDAC) to enable the block list.

As a means to prevent this attack, you should block the AV killer hash – “f71b0c2f7cd766d9bdc1ef35c5ec1743” and carefully monitor the event logs for any newly installed services named “mhyprot2”.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS