HomeSecurityHacker CRYSTALRAY expands to 1,500 compromised systems

CRYSTALRAY hacker expands to 1,500 compromised systems

A new malicious actor known as CRYSTALRAY has significantly expanded its targeting range with new tactics, now counting over 1,500 victims whose credentials were stolen and used as cryptominers.

See also: Japan: Attacks by Kimsuky hackers

CRYSTALRAY SSH-Snake

This is reported by researchers at Sysdig, who have been tracking the threat actor since February, when they first reported the use of SSH-Snake, which it uses to spread laterally across compromised networks.

SSH-snake is an open-source worm that steals private SSH keys on compromised servers and uses them to move laterally to other servers, while dropping additional payloads on compromised systems

Previously, Sysdig identified around 100 CRYSTALRAY victims affected by SSH-Snake attacks and highlighted the tool's capabilities to map networks, steal private keys, and facilitate covert lateral movement across the network.

Sysdig reports that the threat actor behind these attackshas significantly escalated their activities, counting 1,500 victims.

Sysdig says that CRYSTALRAY uses modified PoC exploits delivered to targets using the Sliver post-exploit toolkit, providing another example of misuse of open source tools.

Before launching exploits, attackers conduct thorough checks to confirm the flaws discovered through the kernels.

See also: Hackers say they breached KFC database

CRYSTALRAY hacker expands to 1,500 compromised systems

The vulnerabilities that CRYSTALRAY targets in its current operations are:

  • CVE-2022-44877: Control Web Panel (CWP) execution error
  • CVE-2021-3129: Arbitrary code execution bug affecting Ignition (Laravel).
  • CVE-2019-18394: Server-side request forgery (SSRF) vulnerability in Ignite Realtime Openfire

Sysdig says Atlassian Confluence products are likely targeted as well, based on observed exploitation patterns.

CRYSTALRAY uses the Platypus web-based administrator to handle multiple reverse shell sessions on compromised systems. At the same time, SSH-Snake continues to be the primary tool used to achieve network propagation.

Once the SSH keys are retrieved, the SSH-Snake worm uses them to connect to new systems, copy itself, and repeat the process on the new hosts.

SSH-Snake not only spreads the infection, but also sends keys and bash histories back to the CRYSTALRAY command and control (C2) server, providing options for greater attack flexibility.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Modern Events Calendar – WordPress: Hackers target vulnerability

Compromised systems pose a significant threat to the integrity and security of an organization’s data. When a system is compromised, unauthorized entities can gain access to sensitive information, potentially leading to data theft, financial loss, and reputational damage. Early detection and response are crucial to mitigating the impact of such breaches, and implementing strong security measures, such as encryption and multi-factor authentication, can help protect against future attacks.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS