Threat Advisory

VEILDrive Campaign Targets Microsoft Services to Exploit C2 Channels

Threat: Malicious Campaign
Targeted Region: U.S.
Targeted Sector: Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A sophisticated and ongoing threat campaign, identified as "VEILDrive," has been actively monitored. The campaign was discovered during an investigation of malicious activity within an affected infrastructure. The attacker leveraged several Microsoft SaaS services, including Microsoft Teams, SharePoint, Quick Assist, and OneDrive, to execute their attack. Notably, the attacker employed a unique OneDrive-based Command & Control method integrated into custom malware within the compromised environments. This novel tactic, using OneDrive for remote communication, complicated detection, and response efforts.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A sophisticated and ongoing threat campaign, identified as "VEILDrive," has been actively monitored. The campaign was discovered during an investigation of malicious activity within an affected infrastructure. The attacker leveraged several Microsoft SaaS services, including Microsoft Teams, SharePoint, Quick Assist, and OneDrive, to execute their attack. Notably, the attacker employed a unique OneDrive-based Command & Control method integrated into custom malware within the compromised environments. This novel tactic, using OneDrive for remote communication, complicated detection, and response efforts.[emaillocker id="1283"]

The attack's techniques were atypical, deviating from standard threat behaviors. The attacker relied primarily on Microsoft's cloud infrastructure, such as Teams and SharePoint, to distribute spear-phishing campaigns and host malicious software. This approach bypassed conventional defense mechanisms and posed significant challenges for detection systems. The malware associated with the campaign was a Java-based .jar file, which was not obfuscated, making it readable yet capable of evading detection by top-tier Endpoint Detection and Response (EDR) tools and all security engines on VirusTotal. This discovery highlights an important risk: even non-obfuscated, straightforward malware can bypass modern detection systems.

Detailed analysis of the attack revealed the use of trusted Microsoft services to conduct the attack, allowing the threat actor to remain undetected by utilizing legitimate infrastructure. The attack included social engineering tactics, such as phishing through Teams and remote access via Quick Assist, which enabled the actor to gain initial access to victim machines. Malware was then delivered through SharePoint, enabling further compromise via remote management tools. Throughout the attack, Microsoft 365 audit logs were used to track the actor’s actions, helping the team understand the methods employed. This analysis provided valuable insights into the vulnerabilities exploited and the necessary steps to strengthen defenses against similar attacks.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
T1078 Valid Accounts
Execution T1204 User Execution
T1059 Command and Scripting Interpreter
Persistence T1543 Create or Modify System Process
T1136 Create Account
Defense Evasion T1562 Impair Defenses
Credential Access T1555 Credentials from Web Browsers
Discovery T1082 System Information Discovery
T1057 Process Discovery
T1016 System Network Configuration Discovery
Lateral Movement T1570 Lateral Tool Transfer
Command and Control T1102 Web Service
T1071 Application Layer Protocol
T1219 Remote Access Software
T1573 Encrypted Channel
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/11/veildrive-attack-exploits-microsoft.html

[/emaillocker]
crossmenu