Threat Advisory

The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

Threat: Vulnerability
Threat Actor Name: Night Dragon
Targeted Region: United States, United Kingdom
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A North Korean threat group has been targeting financial institutions. The group uses a variety of tactics to gain initial access, including phishing emails and compromised websites. Once inside the network, they deploy a range of tools to steal sensitive information and disrupt operations. The tools include credential thieves like Mimikatz, registry-hive and LSASS dumping tools, tunneling software such as Chisel and Ligolo-ng, and Potato-family privilege escalation utilities. The group also uses scheduled tasks to download and execute MSI payloads that install EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them.

The group's use of LOLBAS techniques, including a built-in system utility fetching the MSI to remote hosts and a built-in system utility installing it silently, allows them to masquerade their tasks under names like WinSvcUpdate2 and WindowsUpdSvc. This makes it difficult for defenders to detect the implant. Additionally, EtherRAT has no fixed command set, allowing the operator to extend its capabilities without replacing the implant.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A North Korean threat group has been targeting financial institutions. The group uses a variety of tactics to gain initial access, including phishing emails and compromised websites. Once inside the network, they deploy a range of tools to steal sensitive information and disrupt operations. The tools include credential thieves like Mimikatz, registry-hive and LSASS dumping tools, tunneling software such as Chisel and Ligolo-ng, and Potato-family privilege escalation utilities. The group also uses scheduled tasks to download and execute MSI payloads that install EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them.

The group's use of LOLBAS techniques, including a built-in system utility fetching the MSI to remote hosts and a built-in system utility installing it silently, allows them to masquerade their tasks under names like WinSvcUpdate2 and WindowsUpdSvc. This makes it difficult for defenders to detect the implant. Additionally, EtherRAT has no fixed command set, allowing the operator to extend its capabilities without replacing the implant.[emaillocker id="1283"]

The custom X-Bot-Server header is a usable detection point. The group's activities have been linked to several victims, including an American company that was disclosed by The Gentlemen on. The group's use of Ethereum smart contracts for C2 makes it easier for defenders to reconstruct the historical C2 set, which in this case includes five domains. This information can be used to improve detection and mitigation efforts. Overall, the group's tactics are and require a comprehensive approach to defend against.

RECOMMENDATION:

We recommend you to refer below mention link to apply patches: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-032

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Credential access T1003.001 OS Credential Dumping LSASS Memory
Discovery T1082 System Information Discovery -
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu