HomeSecurityUNC3944: Uses Azure Serial Console for hidden access to VMs

UNC3944: Uses Azure Serial Console for hidden access to VMs

A cybercrime gang with financial motives, identified by Mandiant as “UNC3944”, uses phishing attacks and SIM swapping to take over Microsoft Azure administrator accounts and gain access to virtual machines.

UNC3944: Uses Azure Serial Console for hidden access to VMs

From there onward, the attackers abuse the Azure Serial Console to install remote management software for persistence and abuse Azure Extensions for covert monitoring.

Mandiant reports that UNC3944 has been active at least since May 2022 and its campaign aims to steal data from victim organizations that use Microsoft's cloud computing service.

UNC3944 was previously attributed to the creation of the STONESTOP (loader) and POORTRY (kernel-mode driver) toolkits for terminating security software.

The threat actors used stolen Microsoft hardware developer accounts to sign the kernel drivers.

SIM swapping Azure admins

Initially, access to the Azure administrator account was achieved using stolen credentials that were obtained through a common SMS phishing tactic by UNC3944.

Subsequently, the attackers impersonate the administrator when communicating with support staff in order to trick them into sending a multi-factor reset code via SMS to the target's phone number.

However, the attacker had already changed the administrator's SIM number and had transferred it to his own device, so he received the 2FA token without the victim noticing the breach.

Mandiant has not yet determined how the hackers execute the SIM swapping phase of their operation; however, previous cases have shown that knowledge of the target's phone number and collusion with unscrupulous telecom employees is enough to facilitate illegal number transfers.

Once the attackers establish themselves in the target organization's Azure environment, they use administrator privileges to gather information, modify existing Azure accounts as needed, or create new ones.

UNC3944

In the next phase of the attack, UNC3944 will use Azure extensions to conduct surveillance and gather intelligence, disguise malicious operations as seemingly innocent everyday tasks , and blend in with normal activity.

The Azure Extensions are “additional” features and services that can be integrated into an Azure Virtual Machine (VM) to help expand capabilities and automate tasks.

Because these extensions run inside the VM and are typically used for legitimate purposes, they are both stealthy and less suspicious.

In this case, the threat actor abused the built-in Azure diagnostic extensions, such as “CollectGuestLogs”, which was used to collect log files from the compromised endpoint. Additionally, Mandiant found evidence that the threat actor attempted to abuse other extensions.

UNC3944: Uses Azure Serial Console for hidden access to VMs

VM breach for data theft

UNC3944 then uses the Azure Serial Console to gain administrative access to VMs and execute commands on a command line through the serial port.

Mandiant observed that the “whoami” command is the first command executed by the intruders in order to identify the currently logged‑in user and gather sufficient information for further exploitation.

UNC3944

More information on how to analyze logs for Azure Serial Console can be found in the report's appendix.

Subsequently, the threat actors used PowerShell to enhance their persistence on the VM and installed multiple commercially available remote administration tools that are not named in the report.

The next step for UNC3944 is the creation of a reverse SSH tunnel to the C2 server, in order to maintain hidden and persistent access via a secure channel, as well as to bypass the network's restrictions and security controls.

The attacker sets up a reverse tunnel with port forwarding, facilitating direct connection to the Azure VM via Remote Desktop. For example, any incoming connection on port 12345 of the remote machine will be forwarded to port 3389 of the local host port (Remote Desktop Protocol Service Port).

Finally, the attackers use the credentials of a compromised user account to connect to the compromised Azure VM via the reverse shell and then proceed to expand their control over the compromised environment, stealing data along the way.

The demonstration of the attack by Mandiant reveals that UNC3944 has an advanced level of knowledge regarding Azure and can use the platform's built‑in tools to evade detection.

When this technical expertise is combined with high-level social engineering that help attackers carry out SIM swapping, the risk is amplified.

Simultaneously, the lack of understanding of cloud technologies by organizations that implement inadequate security measures, such as multi-factor authentication via SMS, creates opportunities for these advanced threat actors.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS