Threat Advisory

BlackCat Ransomware Deploys New Signed Kernel Driver

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

In late December 2022, several security firms discovered that malicious kernel drivers were being signed using Microsoft hardware developer accounts. These drivers were used in various cyberattacks, including ransomware incidents. Microsoft took action by revoking the compromised accounts. The use of signed kernel drivers by malicious actors is achieved through various means, such as abusing Microsoft signing portals, exploiting leaked or stolen certificates, or utilizing underground services. In this case, the attackers attempted to deploy an old driver that had already been detected by security researchers. To bypass detection, they used a different kernel driver signed with a stolen or leaked cross-signing certificate.[/subscribe_to_unlock_form]

Summary:

In late December 2022, several security firms discovered that malicious kernel drivers were being signed using Microsoft hardware developer accounts. These drivers were used in various cyberattacks, including ransomware incidents. Microsoft took action by revoking the compromised accounts. The use of signed kernel drivers by malicious actors is achieved through various means, such as abusing Microsoft signing portals, exploiting leaked or stolen certificates, or utilizing underground services. In this case, the attackers attempted to deploy an old driver that had already been detected by security researchers. To bypass detection, they used a different kernel driver signed with a stolen or leaked cross-signing certificate.[emaillocker id="1283"]

The ransomware attack that was detected in February demonstrates the ransomware operators' desire to get privileged access to their targets. After releasing the final payloads, they use ransomware families with low-level components to avoid security software. Attacks using ransomware frequently meet Microsoft's standards for code-signing, enabling attackers to create kernel modules for particular purposes, mostly defence evasion. Attackers can use either stolen or leaked code-signing certificates, or they can obtain new certificates by pretending to be reputable organisations and manipulating Microsoft's signature procedures or grey markets.

Execution Flow

Researchers examine a signed driver (ktgn.sys) used in the BlackCat attacks. It is dropped by the User Agent tjr.exe in the user temporary directory and installed as a kernel driver with the ability to kill security agent processes. The driver is signed with a currently revoked digital signature from "BopSoft" and obfuscated using Safengine Protector v2.4.0.0. Attempts to analyze the driver's functionality are hindered by its obfuscation.

The use of signed kernel drivers by attackers highlights the evolving tactics employed by ransomware operators and their affiliates. These actors are continually adapting their techniques to evade detection and gain privileged access. Rootkits and code-signing certificates play a crucial role in their ability to hide and launch sophisticated attacks. As a result, it is essential for organizations to remain vigilant and implement robust security measures to mitigate such threats effectively.

Threat Profile:

References:

The following reports contain further technical details:

https://www.trendmicro.com/en_us/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver.html

[/emaillocker]
crossmenu