HomeSecurityFog ransomware attack uses open source tools

Fog ransomware attack uses open source tools

The hackers behind Fog ransomware use an unusual set of tools, which includes open-source security auditing tools as well as legitimate employee monitoring software, such as Syteca.

See also: Sensata Technologies: Ransomware attack led to data breach

Fog ransomware

The Fog ransomware operation was first observed in May of last year, when it exploited compromised VPN credentials to gain access to victims' networks.

After compromising the system, the attackers used “ pass-the-hash ” attacks to gain administrator privileges, disabled Windows Defender , and encrypted all files, including virtual machines. Later, the threat group was observed exploiting known (n-day) vulnerabilities in Veeam Backup & Replication (VBR) servers, as well as SonicWall SSL VPN endpoints.

Researchers from Symantec and the Carbon Black Threat Hunter discovered this unusual set of tools during an incident response last month at a financial institution in Asia.

See also: Is the Interlock ransomware group behind the attack on Kettering Health?

Symantec was unable to identify with certainty the original method of infection of Fog ransomware, but it recorded the use of several new tools that had not been observed in similar attacks before.

Fog ransomware attack uses open source tools

The most unusual and interesting of these is Syteca (formerly Ekran), a legitimate employee monitoring software that records screen activity and keystrokes. Attackers could use the tool to collect information such as account credentials, which employees typed without knowing they were being monitored remotely.

Syteca was discreetly installed on the system via Stowaway, an open-source tool for stealth communication and file transfer, and executed via SMBExec, the Impacket framework's counterpart to PsExec, which is used for lateral movement within a network. To prepare the data for extraction and transfer to their own infrastructure, the attackers behind Fog ransomware also used the tools 7-Zip, MegaSync, and FreeFileSync.

See also: FBI: Play ransomware has compromised 900 organizations

Based on the above, a crucial conclusion is that the attackers behind Fog ransomware do not rely exclusively on traditional malware, but leverage legitimate tools, which makes their detection particularly difficult. Furthermore, the use of Stowaway and SMBExec indicates that the perpetrators have advanced knowledge of network attacks and lateral movement, which points to organized and targeted attacks with the possible aim of espionage or extortion through data encryption.

Source: bleepingcomputer

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS