Threat Advisory

Hackers Exploit ConnectWise Flaws to Deploy TODDLERSHARK Malware

Threat: Vulnerability/Malware
Criticality: High
[subscribe_to_unlock_form]
 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

 

Researcher has identified campaign is being run by North Korean threat actor by exploiting exploited recently disclosed security vulnerabilities in ConnectWise ScreenConnect to deploy a new malware dubbed TODDLERSHARK. As per researchers TODDLERSHARK shares similarities with known Kimsuky malware like BabyShark and ReconShark. The campaign initiated with the exploitation of a recently patched authentication bypass vulnerability in ScreenConnect, a remote desktop software developed by ConnectWise. This vulnerability has been exploited by various threat actors due to their ease of exploitation.

 

Threat actors gained access to victim workstations, executing mshta.exe with a URL to the Visual Basic (VB) based malware via cmd.exe. The initial payload, heavily obfuscated with randomized functions, variables, and hexadecimal code, downloads and executes the second stage, whose URL is embedded within the hexadecimal string. The second stage, characterized by three main functionalities, includes modifying Windows registry keys to alter macro execution settings, stealing system information through a series of command-line executions, and setting up a scheduled task to periodically request a unique URL indicative of compromised hosts. The malware's registry modifications aim to allow untrusted and trusted macros to run without notification, potentially increasing susceptibility to future phishing attacks. The system information stealer component spawns cmd.exe instances to capture various system details, including host, user, network, security software information, installed software, and running processes. Notably, recent additions to the malware target security-related information, indicating evolving tactics by threat actors. Furthermore, the malware encodes stolen information into Privacy Enhanced Mail (PEM) certificates using curtail and exfiltrates them to the command and control (C2) server. The scheduled task, hidden within an Alternate Data Stream (ADS), periodically requests a unique URL, potentially serving as a loader for subsequent malware stages based on predefined criteria.

 

Mitigation for organizations include immediate patching of vulnerable systems, consideration of independent threat hunts or compromise assessments, and the implementation of endpoint detection and response (EDR) solutions tailored to detect webshells and malicious behaviors. Additionally, the deployment of web application firewalls (WAFs) or similar monitoring systems can enhance defense-in-depth strategies and provide visibility into potential exploitation attempts. By adopting a proactive and comprehensive approach to cybersecurity, organizations can mitigate the impact of evolving threats and safeguard their critical assets against malicious actors.

 

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2024/03/hackers-exploit-connectwise.html

 

[/emaillocker]
crossmenu