Summary:[/subscribe_to_unlock_form]
Summary:[emaillocker id="1283"]
AlienFox is a tool framework that targets several web services, with the toolset's essential element being cloud-based and software-as-a-service (SaaS) email hosting providers. Attackers collect API keys and secrets from well-known services including AWS, SES, and Microsoft Office 365 using AlienFox. A modular toolkit called AlienFox is mainly shared on Telegram as source code archives. Any would-be attacker can adopt certain modules by visiting GitHub. Actors gather lists of misconfigured hosts using AlienFox from security scanning tools like LeakIX and SecurityTrails.
Several well-known web frameworks, including Laravel, Drupal, Joomla, Magento, Opencart, Prestashop, and WordPress, have server misconfigurations that the actors depend on. Each script in the toolkits needs a list of targets read from a text file to run; they are designed to check for the services. This "target" file generation is done by a different script. The target generation scripts gather information about potential targets using a combination of web APIs for open-source intelligence platforms and brute force for IPs and subnets. Researchers discovered scripts that used the APIs of the SecurityTrails and LeakIX platforms. When a vulnerable server is located, the actor parses exposed configuration or environment files that include sensitive data, including services that are enabled and the related API keys and secrets.
The AlienFox toolkit illustrates a new development in cloud-based cybercrime. Developers of different skill levels may easily create tooling for cloud services because to their well-documented, robust APIs. The toolset has gradually improved due to better coding techniques, the addition of new modules, and the addition of additional features. Opportunistic cloud attacks are no longer limited to cryptomining, thanks to AlienFox technologies, which enable attacks on basic services without the necessary resources.
Threat Profile:
| Tactic | Technique Id | Technique |
| Initial Access | T1193 | Spearphishing Attachment |
| Persistence | T1053 | Scheduled Task/Job |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1564 | Hide Artifacts | |
| T1140 | Deobfuscate/Decode Files or Information | |
| T1036 | Masquerading | |
| Discovery | T1082 | System Information Discovery |
| T1087 | Account Discovery | |
| T1135 | Network Share Discovery | |
| T1526 | Cloud Service Discovery | |
| T1016 | System Network Configuration Discovery | |
| T1057 | Process Discovery | |
| T1083 | File and Directory Discovery | |
| Collection | T1119 | Automated Collection |
| T1530 | Data from Cloud Storage Object | |
| Exfiltration | T1041 | Exfiltration Over Command-and-Control Channel |
| T1022 | Data Encrypted | |
| T1052 | Exfiltration Over Other Network Medium | |
| Command and Control | T1043 | Commonly Used Port |
| T1071 | Standard Application Layer Protocol | |
| T1219 | Remote Access Software | |
| T1104 | Multi-Stage Channels | |
| T1090 | Connection Proxy |
References:
The following reports contain further technical details:
[/emaillocker]