Blog

Funde von Bedrohungen

Krypto

Schnelligkeit der Bewaffnung: Von der Aufdeckung einer Sicherheitslücke bis zur Krypto-Mining-Kampagne in einer Woche

Schnelligkeit der Bewaffnung: Von der Aufdeckung einer Sicherheitslücke bis zur Krypto-Mining-Kampagne in einer WocheStandard-BlogbildStandard-Blogbild
08
Jul 2020
08
Jul 2020

Einführung

The speed with which attackers can weaponize vulnerabilities is steadily increasing. While technology is rapidly evolving and cyber-attacks are becoming more sophisticated, the advantages of exploiting software vulnerabilities over devising a more elaborate and lengthy attack plan have not been overlooked by hackers. These vulnerabilities are also a quick way to gain access into a businesses’ infrastructure. In recent years, attackers have found great benefit and substantial success through quickly weaponizing vulnerabilities in web-facing systems.

Just recently, critical vulnerabilities in Citrix Gateway resulted in a spate of activity targeting Darktrace customers, as reported earlier this year. Without an immediate patch released upon the public announcement of the discovered flaws in Citrix, exploits quickly followed. Similarly, in late April, SaltStack developers reported vulnerabilities in Salt, an open source framework used to monitor and update the state of servers in cloud environments and data centers.

The vulnerabilities found in Salt would allow hackers to bypass authentication and authorization controls and execute code in Salt master servers exposed to the internet. The Salt master is responsible for sending commands to Salt minions and can manage thousands of minions at once. Due to this structure, one exposed Salt master can lead to a compromise of all underlying minions.

On May 2, Darktrace detected successful crypto-miner infections across a number of its customers exploiting the CVE-2020-11651 and CVE-2020-11652 vulnerabilities in SaltStack server management software. In the same weekend, LineageOS — an Android mobile operating system – and Ghost — a blogging platform – both reported suffering a crypto-mining attack due to exposed, unpatched Salt servers. Most notable about these attacks was the sheer speed from a vulnerability being published to a widespread attack campaign.

Timeline

Figure 1: A timeline of events identified by Darktrace on May 3

Technical analysis

Initial compromise

Darktrace initially detected that a number of customer servers running SaltStack were making external connections to endpoints previously not seen on the network. The connections used the curl or wget utilities to download and execute a bash script, which would install a secondary-stage payload containing a cryptocurrency miner.

The systems were targeted directly utilizing 2020-11651 and CVE-2020-11652 vulnerabilities in the ZeroMQ protocol running on SaltStack. These vulnerabilities would allow direct remote code execution as root on the targeted systems, allowing the script to be downloaded and executed successfully with highest system privileges.

The downloader script is almost identical to the one utilized in March in H2Miner infections targeting exposed Docker APIs and Redis instances.

Before downloading the secondary stage payload, the script cleans the target system of a number of pre-existing infections and miners, as well as disabling a number of known security tools and software.

Figure 2: The downloader script

Following the initial clean up, the script would iterate through three functions to download the crypto-miner payload — salt-storer

SHA256 837d768875417578c0b1cab4bd0aa38146147799f643bb7b3c6c6d3d82d7aa2a

— from three different hard-coded servers. An MD5 check for the downloaded executable would be performed prior to execution. The below screenshot illustrates two out of the three downloader functions that would be invoked.

Figure 3: Two of the downloader functions

Second stage payload

Following the cryptographic checks, the downloaded ELF LSB executable kicks into action. No payload analysis was carried out, however it’s execution would result in a crypto-miner being installed and a C2 channel opened.

OSINT indicates that several new versions of the payload were observed carrying additional capabilities, including database dumping and advanced persistence methods. The variants detected by Darktrace’s AI included the more advanced “Version 5” payload purported to have worming capabilities, but in this case they were not observed directly.

Command and control

Upon the execution of an LSB executable, a plaintext HTTP C2 channel would be established, sending basic metadata about the infected host such as processor architecture, available resources, and whether root execution was achieved. This indicates that the C2 mechanisms were likely repurposed from other infections, as this particular infection would execute as root, making the respective component redundant.

Figure 4: A Command and control channel

The complete attack lifecycle was investigated and reported on by Darktrace’s Cyber AI Analyst, which automatically surfaced some crucial details regarding the C2 communication, including other servers that were seen making similar communication patterns, as seen in the bottom right below.

Figure 5: The Cyber AI Analyst automatically generating a natural-language summary of the overall security incident

Figure 6: Further information on the suspicious endpoints

Actions on target

Lastly, devices began mining for cryptocurrency. Cryptocurrency mining demands a substantial proportion of a device’s processing power, such as CPU and GPU, in order to calculate hashes. However, except for the occasional increase in CPU or RAM usage, it can go undetected for months as traditional security products do not normally detect its pattern of behavior as malicious.

Schlussfolgerung

Failing to patch vulnerabilities quickly and decisively can have serious consequences. Sometimes, however, the window of opportunity before an attack hits is too short for patching to be feasible. This example demonstrates how quickly unpatched vulnerabilities can be exploited following an initial public disclosure. And yet, even two months after SaltStack published the updates, many Salt servers remain unpatched and run the risk of becoming compromised.

In the case of Citrix, some exploits led to a ransomware attack. Darktrace’s AI-powered Immune System technology not only detected every stage of these ransomware attacks, but its autonomous response was able to halt any anomalous event and contain further damage.

Because new vulnerabilities are, by nature, unexpected, traditional security tools relying on rules and signatures don’t know to look for malicious activity that arises as a result. However, with its constantly evolving understanding of ‘normal’, Darktrace’s AI detects and investigates any unusual behavior, regardless of its origin or whether an attack has been seen before.

Crypto-mining is still favored among many threat actors due to its ability to generate profits, and a successfully infection can have a serious impact on the confidentiality and integrity of the corporate network. The need for Cyber AI that can detect new vulnerabilities and novel threats, and autonomously respond to stop an attack in its tracks, are critical to ensuring businesses remain secure in the face of cyber-criminals who are mobilizing to exploit vulnerabilities more quickly than ever.

IoCs:

IoCComment144.217.129[.]111Likely C2, URIs: /ms /h /s91.215.152[.]69Likely C2, URI: /h89.223.121[.]139Download of payload sa.sh217.12.210[.]192Download of payload sa.sh45.147.201[.]62Destination for crypto-mining217.12.210[.]245Download of payload salt_storer

Abweichungen von Darktrace Modellen:

  • Device / Initial Breach Chain Compromise
  • Compromise / SSL or HTTP Beacon
  • Device / Large Number of Model Breaches
  • Anomalous Connection / New User Agent to IP Without Hostname
  • Anomalous File / Script from Rare External
  • Compromise / Beaconing Activity To External Rare
  • Anomalous Connection / Multiple Failed Connections to Rare Destination
  • Compromise / Sustained SSL or HTTP Increase
  • Compliance / Crypto Currency Mining Activity

More in this series:

Keine Artikel gefunden.

Sie mögen das und wollen mehr?

Erhalten Sie den neuesten Blog per E-Mail
Vielen Dank! Ihre Anfrage ist eingegangen!
Huch! Beim Absenden des Formulars ist etwas schief gelaufen.
EINBLICKE IN DAS SOC-Team
Darktrace Cyber-Analysten sind erstklassige Experten für Threat Intelligence, Threat Hunting und Incident Response. Sie bieten Tausenden von Darktrace Kunden auf der ganzen Welt rund um die Uhr SOC-Support. Einblicke in das SOC-Team wird ausschließlich von diesen Experten verfasst und bietet Analysen von Cyber-Vorfällen und Bedrohungstrends, die auf praktischen Erfahrungen in diesem Bereich basieren.
AUTOR
ÜBER DEN AUTOR
Max Heinemeyer
Leiter der Produktabteilung

Max ist ein Cybersicherheitsexperte mit mehr als zehn Jahren Erfahrung, der sich auf eine Vielzahl von Bereichen wie Penetrationstests, Red-Teaming, SIEM- und SOC-Beratung sowie die Jagd auf Advanced Persistent Threat (APT)-Gruppen spezialisiert hat. Bei Darktrace ist Max für das globale Threat Hunting zuständig und arbeitet mit strategischen Kunden zusammen, um Cyber-Bedrohungen zu untersuchen und auf sie zu reagieren. Er arbeitet eng mit dem Forschungs- und Entwicklungsteam im britischen Headquarter von Darktrace in Cambridge zusammen. Er leitet die Forschung zu neuen KI-Innovationen und deren verschiedenen defensiven und offensiven Anwendungen. Max' Erkenntnisse werden regelmäßig in internationalen Medien wie der BBC, Forbes und WIRED veröffentlicht. Als er in Deutschland lebte, war er ein aktives Mitglied des Chaos Computer Clubs. Max hat einen MSc von der Universität Duisburg-Essen und einen BSc in internationaler Wirtschaftsinformatik von der Dualen Hochschule Stuttgart in.

share this article
ANWENDUNGSFÄLLE
Keine Artikel gefunden.
PRODUKT-SPOTLIGHT
Keine Artikel gefunden.
COre-Abdeckung
Keine Artikel gefunden.
Dieser Artikel
Schnelligkeit der Bewaffnung: Von der Aufdeckung einer Sicherheitslücke bis zur Krypto-Mining-Kampagne in einer Woche
Teilen
Twitter-LogoLinkedIn-Logo

Verwandte Artikel

Keine Artikel gefunden.

Gute Nachrichten für Ihr Unternehmen.
Schlechte Nachrichten für die Bösewichte.

Starten Sie Ihren kostenlosen Test

Starten Sie Ihren kostenlosen Test

Flexible Lieferung
Sie können es entweder virtuell oder mit Hardware installieren.
Schnelle Installation
Nur 1 Stunde für die Einrichtung - und noch weniger für eine Testversion der E-Mail-Sicherheit.
Wählen Sie Ihre Reise
Testen Sie selbstlernende KI dort, wo Sie sie am meisten brauchen - in der Cloud, im Netzwerk oder für E-Mail.
Keine Verpflichtung
Voller Zugriff auf den Darktrace Threat Visualizer und drei maßgeschneiderte Bedrohungsberichte, ohne Kaufverpflichtung.
For more information, please see our Privacy Notice.
Vielen Dank! Ihre Anfrage ist eingegangen!
Huch! Beim Absenden des Formulars ist etwas schief gelaufen.

Demo anfordern

Flexible Lieferung
Sie können es entweder virtuell oder mit Hardware installieren.
Schnelle Installation
Nur 1 Stunde für die Einrichtung - und noch weniger für eine Testversion der E-Mail-Sicherheit.
Wählen Sie Ihre Reise
Testen Sie selbstlernende KI dort, wo Sie sie am meisten brauchen - in der Cloud, im Netzwerk oder für E-Mail.
Keine Verpflichtung
Voller Zugriff auf den Darktrace Threat Visualizer und drei maßgeschneiderte Bedrohungsberichte, ohne Kaufverpflichtung.
Vielen Dank! Ihre Anfrage ist eingegangen!
Huch! Beim Absenden des Formulars ist etwas schief gelaufen.

Check out this article by Darktrace: Speed of weaponization: From vulnerability disclosure to crypto-mining campaign in a week