A North Korean threat group has been targeting financial institutions. The group uses a variety of tactics to gain initial access, including phishing emails and compromised websites. Once inside the network, they deploy a range of tools to steal sensitive information and disrupt operations. The tools include credential thieves like Mimikatz, registry-hive and LSASS dumping tools, tunneling software such as Chisel and Ligolo-ng, and Potato-family privilege escalation utilities. The group also uses scheduled tasks to download and execute MSI payloads that install EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them.
The group's use of LOLBAS techniques, including a built-in system utility fetching the MSI to remote hosts and a built-in system utility installing it silently, allows them to masquerade their tasks under names like WinSvcUpdate2 and WindowsUpdSvc. This makes it difficult for defenders to detect the implant. Additionally, EtherRAT has no fixed command set, allowing the operator to extend its capabilities without replacing the implant.[/subscribe_to_unlock_form]
A North Korean threat group has been targeting financial institutions. The group uses a variety of tactics to gain initial access, including phishing emails and compromised websites. Once inside the network, they deploy a range of tools to steal sensitive information and disrupt operations. The tools include credential thieves like Mimikatz, registry-hive and LSASS dumping tools, tunneling software such as Chisel and Ligolo-ng, and Potato-family privilege escalation utilities. The group also uses scheduled tasks to download and execute MSI payloads that install EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them.
The group's use of LOLBAS techniques, including a built-in system utility fetching the MSI to remote hosts and a built-in system utility installing it silently, allows them to masquerade their tasks under names like WinSvcUpdate2 and WindowsUpdSvc. This makes it difficult for defenders to detect the implant. Additionally, EtherRAT has no fixed command set, allowing the operator to extend its capabilities without replacing the implant.[emaillocker id="1283"]
The custom X-Bot-Server header is a usable detection point. The group's activities have been linked to several victims, including an American company that was disclosed by The Gentlemen on. The group's use of Ethereum smart contracts for C2 makes it easier for defenders to reconstruct the historical C2 set, which in this case includes five domains. This information can be used to improve detection and mitigation efforts. Overall, the group's tactics are and require a comprehensive approach to defend against.
We recommend you to refer below mention link to apply patches: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-032
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Credential access | T1003.001 | OS Credential Dumping | LSASS Memory |
| Discovery | T1082 | System Information Discovery | - |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]