Summary:
During a recent observation, it was noticed that an BlackCat/ALPHV ransomware affiliate used three vulnerabilities in the Veritas Backup product to gain initial access to the targeted network. Former members of Darkside and Blackmatter, which were shutdown to evade law enforcement, are believed to be operating the ALPHV ransomware, which emerged in December 2021. The exploitation of Veritas vulnerabilities in the wild was first observed on October 22, 2022. The vulnerabilities, which were exploited by UNC4466, are considered to be of high severity and have the following CVE numbers: CVE-2021-27876, CVE-2021-27877, CVE-2021-27878. The BlackCat/ALPHV ransomware gang is responsible for a recent cyberattack on NCR, causing an outage on its Aloha point of sale platform.[/subscribe_to_unlock_form]
Summary:
During a recent observation, it was noticed that an BlackCat/ALPHV ransomware affiliate used three vulnerabilities in the Veritas Backup product to gain initial access to the targeted network. Former members of Darkside and Blackmatter, which were shutdown to evade law enforcement, are believed to be operating the ALPHV ransomware, which emerged in December 2021. The exploitation of Veritas vulnerabilities in the wild was first observed on October 22, 2022. The vulnerabilities, which were exploited by UNC4466, are considered to be of high severity and have the following CVE numbers: CVE-2021-27876, CVE-2021-27877, CVE-2021-27878. The BlackCat/ALPHV ransomware gang is responsible for a recent cyberattack on NCR, causing an outage on its Aloha point of sale platform.[emaillocker id="1283"]
According to recent observations, an attacker group known as UNC4466 can compromise a Windows server running Veritas Backup Exec through a publicly available Metasploit module and maintain access to the host. The threat actor utilized Advanced IP Scanner and ADRecon utilities to gather information about the victim's environment after the initial compromise. Following that, the threat actor proceeded to download several tools on the compromised host, including LAZAGNE, LIGOLO, WINSW, RCLONE, and finally the ALPHV ransomware encryptor via the Background Intelligent Transfer Service (BITS). To communicate with the command-and-control server (C2), the threat actor employed SOCKS5 tunneling. According to the researchers, the threat actor utilized BITS transfers to obtain SOCKS5 tunneling tools and then delivered the ransomware payload by creating immediate tasks in the default domain policy, disabling security software, and executing the encryptor. They also steal valid user credentials using Mimikatz, LaZagne, and Nanodump to escalate privileges. The threat actor concludes the attack by disabling real-time monitoring capability of Microsoft Defender and clearing event logs to evade detection.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]