Crowdstrike Tracks the criminal developer of Nemty
ransomware as TRAVELING SPIDER. The actor has been observed to take advantage
of single-factor authentication to gain access to victim organizations through
Citrix Gateway and send extortion-related emails using the victim’s own
Microsoft Office 365 instance.
(BleepingComputer) A new ransomware has been
spotted over the weekend, carrying references to the Russian president and
antivirus software. The researchers call it Nemty. This is the first version of
Nemty ransomware, named so after the extension it adds to the files following
the encryption process.
Other names-
Gold Mansard,
First seen- 2019
Targets-
Algeria, Argentina, Austria, Belgium, Bhutan, Bolivia, Brazil, Canada, Chile,
China, Czech, Denmark, Ecuador, Egypt, Estonia, France, Germany, Ghana,
Guatemala, Guinea, Hungary, India, Indonesia, Iran, Italy, Japan, Latvia,
Libya, Lithuania, Luxembourg, Malaysia, Morocco, Nepal, Netherlands, Niger,
Pakistan, Philippines, Poland, Portugal, Russia, Slovakia, South Africa, South
Korea, Spain, Sweden, Thailand, Turkey, United Arab Emirates, United Kingdom,
United States, Ukraine, Venezuela, Vietnam,
Tools
7-Zip (category:
Tools)
type: Compression
7-Zip is a file archiver with a high compression ratio.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4b790dff-98c7-4bc7-83aa-87e305485ea4
https://www.7-zip.org/
AdFind (category:
Tools)
type: Info stealer
Command line Active Directory query tool. Mixture of ldapsearch, search.vbs,
ldp, dsquery, and dsget tools with a ton of other cool features thrown in for
good measure. This tool proceeded dsquery/dsget/etc by years though I did adopt
some of the useful stuff from those tools.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4a6285af-8694-43b1-8300-74afd8f0a835
http://www.joeware.net/freetools/tools/adfind/
https://attack.mitre.org/software/S0552/
BloodHound (category:
Tools)
type: Reconnaissance
(PenTestPartners) BloodHound is an application used to visualize active
directory environments. The front-end is built on electron and the back-end is
a Neo4j database, the data leveraged is pulled from a series of data collectors
also referred to as ingestors which come in PowerShell and C# flavours. It can
be used on engagements to identify different attack paths in Active Directory
(AD), this encompasses access control lists (ACLs), users, groups, trust
relationships and unique AD objects. The tool can be leveraged by both blue and
red teams to find different paths to targets. The subsections below explain the
different and how to properly utilize the different ingestors.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2bfed9a7-09bb-469b-a297-c7d6f39a0df7
https://www.pentestpartners.com/security-blog/bloodhound-walkthrough-a-tool-for-many-tradecrafts/
https://github.com/BloodHoundAD/BloodHound
https://attack.mitre.org/software/S0521/
LaZagne (category:
Tools)
type: Credential stealer
LaZagne is a post-exploitation, open-source tool used to recover stored
passwords on a system. It has modules for Windows, Linux, and OSX, but is
mainly focused on Windows systems. LaZagne is publicly available on GitHub.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f2697246-5288-4d3b-94d4-7200c85005e5
https://github.com/AlessandroZ/LaZagne
https://www.trendmicro.com/en_us/research/20/k/weaponizing-open-source-software-for-targeted-attacks.html
https://edu.anarcho-copy.org/Against%20Security%20&%20%20Self%20Security/Group-IB%20RedCurl.pdf
https://unit42.paloaltonetworks.com/lazagne-leverages-d-bus/
https://attack.mitre.org/software/S0349/
https://malpedia.caad.fkie.fraunhofer.de/details/py.lazagne
https://otx.alienvault.com/browse/pulses?q=tag:LazaGne
MEGAsync (category:
Tools)
type: Exfiltration
MEGASync is the official MEGA client for Windows. You can use it to synchronize
your files to the cloud, and upload any file to your personal MEGA account.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=13674826-8ee9-4c1b-8700-6e238a481eb2
https://megasync.en.uptodown.com/windows
Mimikatz (category:
Tools)
type: Credential stealer, Keylogger
(SANS) Mimikatz provides a wealth of tools for collecting and making use of
Windows credentials on target systems, including retrieval of cleartext
passwords, Lan Manager hashes, and NTLM hashes, certificates, and Kerberos
tickets. The tools run with varying success on all versions of Windows from XP
forward, with functionality somewhat limited in Windows 8.1 and later.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8f0da519-c1bc-4add-9e04-2c429e74564f
https://github.com/gentilkiwi/mimikatz
https://www.sans.org/reading-room/whitepapers/intrusion/mimikatz-overview-defenses-detection-36780
https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/
https://www.crowdstrike.com/blog/credential-theft-mimikatz-techniques/
https://attack.mitre.org/software/S0002/
https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz
https://otx.alienvault.com/browse/pulses?q=tag:mimikatz
Nefilim (category:
Malware)
type: Ransomware, Big Game Hunting
(Trend Micro) Nefilim is among the notable ransomware variants that use double
extortion tactics in their campaigns. First discovered in March 2020, Nefilim
threatens to release victims’ stolen data to coerce them into paying the
ransom. Aside from its use of this tactic, another notable characteristic of
Nefilim is its similarity to \'Nemty\'; in fact, it is believed to be an evolved
version of the older ransomware.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3edfaff6-30ec-4abf-85de-56b4192e6a8c
https://www.trendmicro.com/en_us/research/21/b/nefilim-ransomware.html
https://www.sisainfosec.com/blogs/nefilim-ransomware/
https://www.govinfosecurity.com/nephilim-ransomware-gang-tied-to-citrix-gateway-hacks-a-14480
https://labs.sentinelone.com/meet-nemty-successor-nefilim-nephilim-ransomware/
https://malpedia.caad.fkie.fraunhofer.de/details/win.nefilim
https://otx.alienvault.com/browse/pulses?q=tag:nefilim
Nemty (category:
Malware)
type: Ransomware, Big Game Hunting
(BleepingComputer) Nemty ransomware was first spotted in August 2019 and is
known for deleting the shadow copies of all the files it encrypts, making it
impossible for victims who don\'t have separate backups to recover their data.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6907344a-046f-46c1-984a-7ada76c99b7a
https://www.bleepingcomputer.com/news/security/nemty-ransomware-actively-distributed-via-love-letter-spam/
https://www.bleepingcomputer.com/news/security/new-nemty-ransomware-may-spread-via-compromised-rdp-connections/
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/nemty-ransomware-learning-by-doing/
https://www.fortinet.com/blog/threat-research/nemty-ransomware-early-stage-threat
https://malpedia.caad.fkie.fraunhofer.de/details/win.nemty
https://otx.alienvault.com/browse/pulses?q=tag:nemty
https://mdsassets.blob.core.windows.net/downloads/NemtyHowToGuide.pdf
Network
Password Recovery (category: Tools)
type: Credential stealer
When you connect to a network share on your LAN or to your .NET Passport
account, Windows allows you to save your password in order to use it in each
time that you connect the remote server. This utility recovers all network
passwords stored on your system for the current logged-on user. It can also
recover the passwords stored in Credentials file of external drive, as long as
you know the last log-on password.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=84415af1-cc63-4639-aad5-4935751e3e25
https://www.nirsoft.net/utils/network_password_recovery.html
PsExec (category:
Tools)
type: Remote command
PsExec is a free Microsoft tool that can be used to execute a program on
another computer. It is used by IT administrators and attackers and is part of
\'SysInternals\'.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8bfdf3b6-764f-4b42-89e3-ec6c422fcf8a
https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
https://www.bleepingcomputer.com/news/security/new-psexec-spinoff-lets-hackers-bypass-network-security-defenses/
https://attack.mitre.org/software/S0029/
https://otx.alienvault.com/browse/pulses?q=tag:psexec
smbtool (category:
Tools)
type: Exfiltration
Small script for your personal home samba server. Using whiptail or dialog and
acl for manage users / shares / groups.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=dd4c91ab-30ad-454f-845f-7ee7a7fbfb2a
https://github.com/shaftmx/smbtool
