EXECUTIVE SUMMARY
A new ransomware group, known as Mad Liberator, has emerged focusing primarily on data exfiltration. The group has been observed using the legitimate remote-access application, Anydesk, to infiltrate systems without prior contact with the victim. Their tactics involve social engineering techniques to gain access to environments, particularly targeting organizations using remote access tools like Anydesk. While Mad Liberator's primary focus has been data theft, they have also been associated with double extortion, threatening to release stolen data if ransoms are not paid.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new ransomware group, known as Mad Liberator, has emerged focusing primarily on data exfiltration. The group has been observed using the legitimate remote-access application, Anydesk, to infiltrate systems without prior contact with the victim. Their tactics involve social engineering techniques to gain access to environments, particularly targeting organizations using remote access tools like Anydesk. While Mad Liberator's primary focus has been data theft, they have also been associated with double extortion, threatening to release stolen data if ransoms are not paid.[emaillocker id="1283"]
Mad Liberator's attack methodology starts with an unsolicited Anydesk connection request, exploiting the assumption that the request is from the victim's IT department. Upon acceptance, the attacker transfers and executes a binary disguised as a "Microsoft Windows Update," which is detected as Troj/FakeUpd-K. The fake update screen prevents the victim from noticing any malicious activity. The attacker then disables user input and proceeds to access and exfiltrate files from the victim's OneDrive and network shares using Anydesk's FileTransfer feature. The attack concludes with the creation of ransom notes on shared network locations, alerting the victim to the data theft and demanding payment to prevent disclosure.
Mad Liberator represents a significant threat with its effective use of social engineering and abuse of remote access tools. Organizations are advised to implement strict access controls, enforce regular staff training, and review security measures for remote access applications to mitigate the risk of such attacks. The incident underscores the need for vigilance in both technical defenses and user awareness to combat evolving ransomware tactics.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1203 | Exploitation for Client Execution |
| Defense Evasion | T1078 | Valid Accounts |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1046 | Network Service Discovery |
| Collection | T1074 | Data Staged |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1486 | Data Encrypted for Impact |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/new-mad-liberator-gang-uses-fake-windows-update-screen-to-hide-data-theft/