HomeSecurityOcto Tempest: A very dangerous hacking group

Octo Tempest: A very dangerous hacking group

Microsoft has released details about an English-speaking hacking group it is tracking as Octo Tempest . Octo Tempest hackers have advanced social engineering capabilities and are carrying out ransomware attacks and extortion to steal data .

Octo Tempest attacks have been steadily evolving since early 2022, expanding their targeting to organizations that provide telecommunications, email, and technology services. The hackers are also collaborating with the ALPHV/BlackCat ransomware group .

Octo Tempest hackers

Variety of attacks: From account theft to ransomware

Initially, hackers were selling SIM swaps and stealing accounts of high-profile individuals with cryptocurrency assets.

In late 2022, however, the Octo Tempest hackers moved on to phishing, social engineering, mass password resets of targeted organizations' customers, and data theft.

Throughout 2023, the group attacked companies in the gaming, hospitality, retail, manufacturing, technology, and finance sectors, as well as managed service providers (MSPs).

See also: Cyber ​​espionage: YoroTrooper hackers may be related to Kazakhstan

It then became an affiliate of the well-known ransomware gang ALPHV/BlackCat and began using ransomware to both steal and encrypt victims' data.

Microsoft says that the Octo Tempest hackers did not hesitate to resort to direct physical threatsto obtain login credentials that could help them in their attacks.

Octo Tempest: Techniques

Microsoft believes that Octo Tempest is a well-organized group that includes hackers with extensive technical knowledge.

Hackers often gain initial access to systems through social engineering targeting accounts of technical administrators (e.g., support and help desk personnel).

Then, they research the company to identify people who can impersonate them. In effect, they mimic the speech patterns of people on phone calls.

In this way, they trick technical administrators into resetting their password and multi-factor authentication (MFA) methods.

Other methods for initial access include:

  • tricking the target into installing remote monitoring and management software
  • theft of credentials via phishing websites
  • buying credentials from other cybercriminals
  • sending phishing SMS to employees with links leading to fake login portals that record credentials
  • SIM-swapping or call forwarding
  • Direct threats of violence

Once they gain access, Octo Tempest hackers begin the reconnaissance of the attack, monitoring systems and gathering information that would allow legitimate channels to be abused to further the intrusion.

Octo Tempest: A very dangerous hacking group

The team then proceeds to explore the infrastructure, listing access and resources in cloud environments, code repositories, server and backup management systems.

To escalate privileges, the team turns again to social engineering, SIM-swapping, or call forwarding, and initiates a password reset process on the target's account.

See also: Winter Vivern hackers use Roundcube zero-day to steal government emails

During this step, hackers build trust with the victim by using compromised accounts and showing that they understand the company's processes. If they have an administrator account, they approve requests for elevated permissions themselves.

As long as they have access, the Octo Tempest hackers continue to seek additional credentials to gain access to even more systems.

To hide their malicious activity, hackers also target the accounts of security personnel to disable security products and features.

Also, according to Microsoft, Octo Tempest hackers use in their attacks:

  • open source tools: ScreenConnect, FleetDeck, AnyDesk, RustDesk, Splashtop, Pulseway, TightVNC, LummaC2, Level.io, Mesh, TacticalRMM, Tailscale, Ngrok, WsTunnel, Rsocx and Socat
  • deploying Azure virtual machines to enable remote access via RMM installation or modification to existing resources via Azure serial console
  • adding MFA methods to existing users
  • use of the tunneling tool Twingate, which leverages Azure Container instances as a private connection (without exposure to the public network)

The hackers transfer the stolen data to their servers using a unique technique, which involves Azure Data Factory and automated pipelines combined with standard big data operations.

Microsoft notes that identifying the group is difficult due to the techniques it uses, but researchers provide a set of general guidelines that could help detect malicious activity.

Protection

To enhance the security of their digital devices and networks, people can start by implementing strong passwords .Passwords should be long, complex, and include a combination of letters, numbers, and special characters. It is also important to use different passwords for each digital device and service that people use.

See also: Hackers target Russian organizations with backdoor to steal data

Octo Tempest: A very dangerous hacking group

Another way to enhance the security of digital devices is to update software. Software manufacturers often release updates that contain fixes for problems. It is important for people to regularly check for updates and install the latest versions of their software to protect devices from known problems.

Using reliable security software is also crucial to protecting digital devices and networks. People should install a reliable anti-virus and firewall on their devices and keep them updated regularly. This will help them detect and prevent malware.

Paying attention to network security is also important. People should use secure and encrypted Wi-Fi and disable automatic connection to open networks. They should also disable file and printer sharing when not in use, as this can expose their networks to risks.

Finally, awareness and attention to the security of digital devices and networks is vital. Users should be cautious with the emails and messages they receive, avoid clicking on suspicious attachments or links, and not disclose personal information to untrusted sources.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS