Threat Advisory

New AlienFox toolkit steals credentials for several cloud services

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

AlienFox is a tool framework that targets several web services, with the toolset's essential element being cloud-based and software-as-a-service (SaaS) email hosting providers. Attackers collect API keys and secrets from well-known services including AWS, SES, and Microsoft Office 365 using AlienFox. A modular toolkit called AlienFox is mainly shared on Telegram as source code archives. Any would-be attacker can adopt certain modules by visiting GitHub. Actors gather lists of misconfigured hosts using AlienFox from security scanning tools like LeakIX and SecurityTrails.

Several well-known web frameworks, including Laravel, Drupal, Joomla, Magento, Opencart, Prestashop, and WordPress, have server misconfigurations that the actors depend on. Each script in the toolkits needs a list of targets read from a text file to run; they are designed to check for the services. This "target" file generation is done by a different script. The target generation scripts gather information about potential targets using a combination of web APIs for open-source intelligence platforms and brute force for IPs and subnets. Researchers discovered scripts that used the APIs of the SecurityTrails and LeakIX platforms. When a vulnerable server is located, the actor parses exposed configuration or environment files that include sensitive data, including services that are enabled and the related API keys and secrets.

The AlienFox toolkit illustrates a new development in cloud-based cybercrime. Developers of different skill levels may easily create tooling for cloud services because to their well-documented, robust APIs. The toolset has gradually improved due to better coding techniques, the addition of new modules, and the addition of additional features. Opportunistic cloud attacks are no longer limited to cryptomining, thanks to AlienFox technologies, which enable attacks on basic services without the necessary resources.

 

Threat Profile:

Tactic Technique Id Technique
Initial Access T1193 Spearphishing Attachment
Persistence T1053 Scheduled Task/Job
Defense Evasion T1027 Obfuscated Files or Information
T1564 Hide Artifacts
T1140 Deobfuscate/Decode Files or Information
T1036 Masquerading
Discovery T1082 System Information Discovery
T1087 Account Discovery
T1135 Network Share Discovery
T1526 Cloud Service Discovery
T1016 System Network Configuration Discovery
T1057 Process Discovery
T1083 File and Directory Discovery
Collection T1119 Automated Collection
T1530 Data from Cloud Storage Object
Exfiltration T1041 Exfiltration Over Command-and-Control Channel
T1022 Data Encrypted
T1052 Exfiltration Over Other Network Medium
Command and Control T1043 Commonly Used Port
T1071 Standard Application Layer Protocol
T1219 Remote Access Software
T1104 Multi-Stage Channels
T1090 Connection Proxy

 

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/new-alienfox-toolkit-steals-credentials-for-18-cloud-services/

[/emaillocker]
crossmenu