The hacker group known as TA577 has recently changed tactics to use phishing emails to steal Windows NT LAN Manager (NTLM) in order to commit account fraud.
See also: Authorities “slammed” the phishing service BulletProftLink

TA577 is considered an initial access intermediary (IAB), previously associated with Qbot and linked to Black Basta ransomware.
Email security firm Proofpoint reports that while it has seen TA577 favor Pikabot adoption recently , two recent waves of attacks indicate a different tactic.
A series of TA577 attacks launched on February 26 and 27, 2024, distributed thousands of messages to hundreds of organizations worldwide, targeting employees' Windows NTLM hashes.
NTLM hashes are used in Windows for session authentication and security , and can be captured to decrypt the password plaintext offline. Additionally, they can be used in “ pass-the-hash ” attacks that involve no cracking at all, where attackers use the hash as is to authenticate to a remote server or service.
Stolen hashes can, under certain circumstances and depending on the security measures taken, allow attackers to escalate their privileges, “hijack” accounts, access sensitive information, evade security products, and move laterally within a compromised network.
See also: 1265% increase in phishing emails: The role of ChatGPT

TA577 usesphishing to steal NTLM hashes
TA577's new campaign began with phishing emails that appear to be replies to the target's previous discussion, a technique known as thread hijacking.
The emails customize unique (per victim) ZIP files containing HTML files and use HTML META refresh tags to trigger an automatic connection to a text file on an external Server Message Block (SMB) server .
When the Windows device connects to the server, it will automatically attempt to perform an NTLMv2 challenge/response, allowing the remote attacker-controlled server of the TA577 group to steal NTLM hashes.
Proofpoint reports that these URLs did not deliver any malware, so their main goal appears to be capturing NTLM logs.
Proofpoint reports specific files that are present on SMB servers that are not normal, such as the open source tool Impacket, which indicates that these servers are used in phishing attacks.
See also: Phishing emails: Warning signs and protection tips
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What are the best practices for avoiding phishing attacks?
To protect yourself from attacks like the one by the TA577 group that steals Windows NTLM authentication hashes, the first and most important practice is education. Second, always use up-to-date antivirus software and a computer security program. Third, be wary of emails that ask for personal information. Legitimate companies will never ask you to provide your passwords or banking information via email. Finally, use two-factor authentication where possible, since even if someone manages to get your password, they won’t be able to log in to your account without a second piece of authentication, such as a code sent to your mobile phone.
Source: bleepingcomputer
