Threat Advisory

EXFILTRATOR-22 – An Emerging Post-Exploitation Framework

Threat: Ransomware
Targeted Region: Global
Threat Actor Region: North and Southeast Asia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

Summary:

Exfiltrator-22, often known as EX-22, is a new post-exploitation framework that aims to quietly deliver ransomware into enterprise networks. With such a vast range of capabilities, anyone who buys the tool will find post-exploitation to be a piece of cake. The malware creators are based in North, East, or Southeast Asia and are probably no longer associated with the LockBit ransomware business.[/subscribe_to_unlock_form]

Summary:

Exfiltrator-22, often known as EX-22, is a new post-exploitation framework that aims to quietly deliver ransomware into enterprise networks. With such a vast range of capabilities, anyone who buys the tool will find post-exploitation to be a piece of cake. The malware creators are based in North, East, or Southeast Asia and are probably no longer associated with the LockBit ransomware business.[emaillocker id="1283"]

The malware targets x64-architecture-based devices. The buyers of EX-22 tool would be given a login panel to access the Ex22 server, which is hosted on a secured VPS (Virtual Private Server). Threat actors can use this panel to remotely manage the malware they have installed on affected machines. Reverse shell was elevated so that Exfiltrator-22 may open a network connection from an infected device to a remote server. Exfiltrator-22 can download and upload files once it has taken over a device. It can also trace every entrance log, encrypt the files, and demands ransom. It can collect screenshots and create a live connection to victim's machine. It has the capacity to gain more system privileges and extract sensitive data. The panel also enables threat actors to automate processes like rolling out new malware versions, changing the infection's setup, or developing new campaigns.

With constant upgrades and support, EX-22 becomes a go-to solution for any threat actors seeking to acquire tools for the post exploitation phase but do not want to go with the usual tools due to high detection rates. EX-22 is marketed as completely undetectable.

 

Threat Profile:

Tactic Technique Id Technique
Execution T1129 Shared Modules
Persistence T1547 Boot or Logon AutoStart Execution
Privilege Escalation   T1055 Process Injection
T1134 Access Token Manipulation
Defense Evasion T1497 Virtualization/Sandbox Evasion
T1027 Obfuscated Files or Information
T1112 Modify Registry
T1134 Access Token Manipulation
T1564 Hide Artifacts
T1620 Reflective Code Loading
Credential Access   T1056 Input Capture
Discovery   T1082 System Information Discovery
T1010 Application Window Discovery
  T1057 Process Discovery
T1083 File and Directory Discovery
Collection   T1113 Screen Capture
Impact   T1486 Data Encrypted for Impact

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/02/new-ex-22-tool-empowers-hackers-with.html

[/emaillocker]
crossmenu