HomeSecurityHow does the Gold Melody hacking group work?

How does the Gold Melody hacking team work?

Hacking group Gold Melody sells initial access to compromised organizations to other hackers!

See also: Which scams were most popular in the first months of 2023?

golden melody

A financially motivated threat actor has been revealed as an access broker (IAB) that sells access to hacked organizations to other adversaries to carry out subsequent attacks, such as ransomware attacks.

The SecureWorks Counter Threat Unit (CTU) named the cybercrime group Gold Melody, which is also known by the names Prophet Spider (CrowdStrike) and UNC961 (Mandiant).

"This financially motivated group has been active since at least 2017, breaching organizations by exploiting vulnerabilities in unpatched internet-facing servers," the cybersecurity firm said.

See also: FBI and CISA issue joint warning about Snatch Ransomware-as-a-Service

Gold Melody has previously been linked to attacks that exploit security flaws in JBoss Messaging (CVE-2017-7504), Citrix ADC (CVE-2019-19781), Oracle WebLogic (CVE-2020-14750 and CVE-2020-1488), CVE-2021-22205), Citrix ShareFile Storage Zones Controller (CVE-2021-22941), Atlassian Confluence (CVE-2021-26084), ForgeRock AM (CVE-2021-35464), and Apache Log2028 (CVE-4-) servers.

The hacking group is seen expanding its victim footprint, targeting retail, healthcare, energy, financial transactions, and high-tech organizations in North America, Northern Europe, and Western Asia since mid-2020.

Mandiant, in an analysis published in March 2023, said that “in many cases, UNC961 intrusion activity has preceded the development of Maze and Egregor ransomware by different subsequent actors.”.

It further describes the group as “inventive in its opportunistic approach to initial access operations” and notes that it “uses an economical approach to achieve initial access by exploiting recently disclosed vulnerabilities using exploit code that is publicly available.”

In addition to relying on a diverse toolkit that includes the web shell, embedded operating system software, and publicly available utilities, it is known to use proprietary Remote Access Trojans (RATs) and tunneling tools such as GOTROJ (also known as MUTEPUT), BARNWORK, HOLEDOOR, DARKDOOR, AUDITUNNEL, HOLEPUNCH, LIGHTBUNNY, and HOLERUN to execute arbitrary commands, collect system information, and create a reverse tunnel with a predetermined IP address.

See also: Donut ransomware group claims to have attacked Agilitas company

Secureworks, which linked Gold Melody to five breaches from July 2020 to July 2022, said these attacks involved the abuse of a diverse set of flaws, including those affecting Oracle E-Business Suite (CVE-2016-0545), Apache Struts (CVE-2017-5638), Sitecore XP (CVE-2021-42237), and Flexera FlexNet (CVE-2021-4104) to gain initial access.

A successful foundation is achieved by deploying a web shell for persistence, followed by creating directories on the compromised host for staging the tools used in the infection chain.

The identification phase paves the way for credential acquisition, lateral movement, and data extraction. However, all five attacks proved unsuccessful.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS