EXECUTIVE SUMMARY
A sophisticated and ongoing threat campaign, identified as "VEILDrive," has been actively monitored. The campaign was discovered during an investigation of malicious activity within an affected infrastructure. The attacker leveraged several Microsoft SaaS services, including Microsoft Teams, SharePoint, Quick Assist, and OneDrive, to execute their attack. Notably, the attacker employed a unique OneDrive-based Command & Control method integrated into custom malware within the compromised environments. This novel tactic, using OneDrive for remote communication, complicated detection, and response efforts.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A sophisticated and ongoing threat campaign, identified as "VEILDrive," has been actively monitored. The campaign was discovered during an investigation of malicious activity within an affected infrastructure. The attacker leveraged several Microsoft SaaS services, including Microsoft Teams, SharePoint, Quick Assist, and OneDrive, to execute their attack. Notably, the attacker employed a unique OneDrive-based Command & Control method integrated into custom malware within the compromised environments. This novel tactic, using OneDrive for remote communication, complicated detection, and response efforts.[emaillocker id="1283"]
The attack's techniques were atypical, deviating from standard threat behaviors. The attacker relied primarily on Microsoft's cloud infrastructure, such as Teams and SharePoint, to distribute spear-phishing campaigns and host malicious software. This approach bypassed conventional defense mechanisms and posed significant challenges for detection systems. The malware associated with the campaign was a Java-based .jar file, which was not obfuscated, making it readable yet capable of evading detection by top-tier Endpoint Detection and Response (EDR) tools and all security engines on VirusTotal. This discovery highlights an important risk: even non-obfuscated, straightforward malware can bypass modern detection systems.
Detailed analysis of the attack revealed the use of trusted Microsoft services to conduct the attack, allowing the threat actor to remain undetected by utilizing legitimate infrastructure. The attack included social engineering tactics, such as phishing through Teams and remote access via Quick Assist, which enabled the actor to gain initial access to victim machines. Malware was then delivered through SharePoint, enabling further compromise via remote management tools. Throughout the attack, Microsoft 365 audit logs were used to track the actor’s actions, helping the team understand the methods employed. This analysis provided valuable insights into the vulnerabilities exploited and the necessary steps to strengthen defenses against similar attacks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1078 | Valid Accounts | |
| Execution | T1204 | User Execution |
| T1059 | Command and Scripting Interpreter | |
| Persistence | T1543 | Create or Modify System Process |
| T1136 | Create Account | |
| Defense Evasion | T1562 | Impair Defenses |
| Credential Access | T1555 | Credentials from Web Browsers |
| Discovery | T1082 | System Information Discovery |
| T1057 | Process Discovery | |
| T1016 | System Network Configuration Discovery | |
| Lateral Movement | T1570 | Lateral Tool Transfer |
| Command and Control | T1102 | Web Service |
| T1071 | Application Layer Protocol | |
| T1219 | Remote Access Software | |
| T1573 | Encrypted Channel | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/11/veildrive-attack-exploits-microsoft.html
[/emaillocker]