Cybersecurity organizations are sounding the alarm over the increasing TrueBot malware attacks.
See also: JumpCloud: Reinstates admin API keys due to an “ongoing incident”

Cybersecurity organizations have warned of the emergence of new variants of the TrueBot malware, which is now targeting companies in the US and Canada with the aim of extracting confidential data from the systems it has infiltrated.
See also: Cisco warns of bug that allows attackers to breach traffic encryption
These sophisticated attacks exploit a critical vulnerability (CVE-2022-31199) in the widely used Netwrix Auditor server and related agents.
This vulnerability allows unauthorized attackers to execute malicious code with the privileges of the SYSTEM user, giving them unrestricted access to the compromised system.
The TrueBot malware, which is associated with the criminal collectives Silence and FIN11, is being developed to steal data and spread ransomware, compromising the security of many infiltrating networks.
Hackers gain their initial foothold by exploiting the reported vulnerability and then proceed to install TrueBot. Once they compromise the networks, they install the FlawedGrace Remote Access Trojan (RAT) in order to escalate privileges , establish persistence on compromised systems , and conduct additional operations.
See also: Rekoobe Malware: Targets vulnerable Linux servers
Hackers launch Cobalt Strike beacons within several hours of the initial intrusion to facilitate post-exploitation tasks, including data theft and installation of ransomware or various malware payloads.
Previous versions of the TrueBot malware were typically spread via malicious email, but the updated versions exploit the CVE-2022-31199 vulnerability to gain initial access.
This strategic shift allows cyber threat actors to carry out attacks on a larger scale within intrusive environments. Importantly, Netwrix Auditor software is used by more than 13,000 organizations worldwide, including notable companies such as Airbus, Allianz, the UK NHS and Virgin.
The advisory does not provide specific information about victims or the number of organizations affected by TrueBot attacks.
The report also highlights the involvement of Raspberry Robin malware in these TrueBot attacks, as well as other post-breach malware such as IcedID and Bumblebee. By using Raspberry Robin as a distribution platform, attackers can reach more potential victims and amplify the impact of their malicious activities.
Given that the Silence and TA505 groups actively infiltrate networks for financial gain, it is vital for organizations to implement the recommended security measures.
To protect themselves from TrueBot malware and similar threats, organizations should consider the following recommendations:
- Install updates: Organizations using Netwrix Auditor should install the necessary updates to mitigate the CVE-2022-31199 vulnerability and update their software to version 10.5 or later.
- Improve security protocols: Deploy multi-factor authentication (MFA) for all employees and services.
- Be alert for infiltration indicators (IOCs): Security teams should actively monitor their networks for signs of TrueBot infection. The joint warning provides guidance to help identify and mitigate the impact of the malware.
- If organizations detect IOC or suspect a TrueBot infiltration, they should act quickly according to the incident response actions outlined in the alert and report the incident to CISA or the FBI.
Information source: thehackernews.com
