National Cyber Warfare Foundation (NCWF)

TRAVELING SPIDER


0 user ratings
2024-07-26 20:10:33
blscott

 - archive -- 

Crowdstrike Tracks the criminal developer of Nemty
ransomware as TRAVELING SPIDER. The actor has been observed to take advantage
of single-factor authentication to gain access to victim organizations through
Citrix Gateway and send extortion-related emails using the victim’s own
Microsoft Office 365 instance.

(BleepingComputer) A new ransomware has been
spotted over the weekend, carrying references to the Russian president and
antivirus software. The researchers call it Nemty. This is the first version of
Nemty ransomware, named so after the extension it adds to the files following
the encryption process.



 Other names-

Gold Mansard,



 First seen- 2019



 Targets-

Algeria, Argentina, Austria, Belgium, Bhutan, Bolivia, Brazil, Canada, Chile,
China, Czech, Denmark, Ecuador, Egypt, Estonia, France, Germany, Ghana,
Guatemala, Guinea, Hungary, India, Indonesia, Iran, Italy, Japan, Latvia,
Libya, Lithuania, Luxembourg, Malaysia, Morocco, Nepal, Netherlands, Niger,
Pakistan, Philippines, Poland, Portugal, Russia, Slovakia, South Africa, South
Korea, Spain, Sweden, Thailand, Turkey, United Arab Emirates, United Kingdom,
United States, Ukraine, Venezuela, Vietnam,



Tools



7-Zip (category:
Tools)


type: Compression

7-Zip is a file archiver with a high compression ratio.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4b790dff-98c7-4bc7-83aa-87e305485ea4

https://www.7-zip.org/



AdFind (category:
Tools)


type: Info stealer

Command line Active Directory query tool. Mixture of ldapsearch, search.vbs,
ldp, dsquery, and dsget tools with a ton of other cool features thrown in for
good measure. This tool proceeded dsquery/dsget/etc by years though I did adopt
some of the useful stuff from those tools.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4a6285af-8694-43b1-8300-74afd8f0a835

http://www.joeware.net/freetools/tools/adfind/

https://attack.mitre.org/software/S0552/





BloodHound (category:
Tools)


type: Reconnaissance

(PenTestPartners) BloodHound is an application used to visualize active
directory environments. The front-end is built on electron and the back-end is
a Neo4j database, the data leveraged is pulled from a series of data collectors
also referred to as ingestors which come in PowerShell and C# flavours. It can
be used on engagements to identify different attack paths in Active Directory
(AD), this encompasses access control lists (ACLs), users, groups, trust
relationships and unique AD objects. The tool can be leveraged by both blue and
red teams to find different paths to targets. The subsections below explain the
different and how to properly utilize the different ingestors.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2bfed9a7-09bb-469b-a297-c7d6f39a0df7

https://www.pentestpartners.com/security-blog/bloodhound-walkthrough-a-tool-for-many-tradecrafts/

https://github.com/BloodHoundAD/BloodHound

https://attack.mitre.org/software/S0521/





LaZagne (category:
Tools)


type: Credential stealer

LaZagne is a post-exploitation, open-source tool used to recover stored
passwords on a system. It has modules for Windows, Linux, and OSX, but is
mainly focused on Windows systems. LaZagne is publicly available on GitHub.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f2697246-5288-4d3b-94d4-7200c85005e5

https://github.com/AlessandroZ/LaZagne

https://www.trendmicro.com/en_us/research/20/k/weaponizing-open-source-software-for-targeted-attacks.html

https://edu.anarcho-copy.org/Against%20Security%20&%20%20Self%20Security/Group-IB%20RedCurl.pdf

https://unit42.paloaltonetworks.com/lazagne-leverages-d-bus/

https://attack.mitre.org/software/S0349/

https://malpedia.caad.fkie.fraunhofer.de/details/py.lazagne

https://otx.alienvault.com/browse/pulses?q=tag:LazaGne





MEGAsync (category:
Tools)


type: Exfiltration

MEGASync is the official MEGA client for Windows. You can use it to synchronize
your files to the cloud, and upload any file to your personal MEGA account.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=13674826-8ee9-4c1b-8700-6e238a481eb2

https://megasync.en.uptodown.com/windows





Mimikatz (category:
Tools)


type: Credential stealer, Keylogger

(SANS) Mimikatz provides a wealth of tools for collecting and making use of
Windows credentials on target systems, including retrieval of cleartext
passwords, Lan Manager hashes, and NTLM hashes, certificates, and Kerberos
tickets. The tools run with varying success on all versions of Windows from XP
forward, with functionality somewhat limited in Windows 8.1 and later.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8f0da519-c1bc-4add-9e04-2c429e74564f

https://github.com/gentilkiwi/mimikatz

https://www.sans.org/reading-room/whitepapers/intrusion/mimikatz-overview-defenses-detection-36780

https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/

https://www.crowdstrike.com/blog/credential-theft-mimikatz-techniques/

https://attack.mitre.org/software/S0002/

https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz

https://otx.alienvault.com/browse/pulses?q=tag:mimikatz





Nefilim (category:
Malware)


type: Ransomware, Big Game Hunting

(Trend Micro) Nefilim is among the notable ransomware variants that use double
extortion tactics in their campaigns. First discovered in March 2020, Nefilim
threatens to release victims’ stolen data to coerce them into paying the
ransom. Aside from its use of this tactic, another notable characteristic of
Nefilim is its similarity to \'Nemty\'; in fact, it is believed to be an evolved
version of the older ransomware.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3edfaff6-30ec-4abf-85de-56b4192e6a8c

https://www.trendmicro.com/en_us/research/21/b/nefilim-ransomware.html

https://www.sisainfosec.com/blogs/nefilim-ransomware/

https://www.govinfosecurity.com/nephilim-ransomware-gang-tied-to-citrix-gateway-hacks-a-14480

https://labs.sentinelone.com/meet-nemty-successor-nefilim-nephilim-ransomware/

https://malpedia.caad.fkie.fraunhofer.de/details/win.nefilim

https://otx.alienvault.com/browse/pulses?q=tag:nefilim





Nemty (category:
Malware)


type: Ransomware, Big Game Hunting

(BleepingComputer) Nemty ransomware was first spotted in August 2019 and is
known for deleting the shadow copies of all the files it encrypts, making it
impossible for victims who don\'t have separate backups to recover their data.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6907344a-046f-46c1-984a-7ada76c99b7a

https://www.bleepingcomputer.com/news/security/nemty-ransomware-actively-distributed-via-love-letter-spam/

https://www.bleepingcomputer.com/news/security/new-nemty-ransomware-may-spread-via-compromised-rdp-connections/

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/nemty-ransomware-learning-by-doing/

https://www.fortinet.com/blog/threat-research/nemty-ransomware-early-stage-threat

https://malpedia.caad.fkie.fraunhofer.de/details/win.nemty

https://otx.alienvault.com/browse/pulses?q=tag:nemty

https://mdsassets.blob.core.windows.net/downloads/NemtyHowToGuide.pdf





Network
Password Recovery (category: Tools)


type: Credential stealer

When you connect to a network share on your LAN or to your .NET Passport
account, Windows allows you to save your password in order to use it in each
time that you connect the remote server. This utility recovers all network
passwords stored on your system for the current logged-on user. It can also
recover the passwords stored in Credentials file of external drive, as long as
you know the last log-on password.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=84415af1-cc63-4639-aad5-4935751e3e25

https://www.nirsoft.net/utils/network_password_recovery.html





PsExec (category:
Tools)


type: Remote command

PsExec is a free Microsoft tool that can be used to execute a program on
another computer. It is used by IT administrators and attackers and is part of
\'SysInternals\'.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8bfdf3b6-764f-4b42-89e3-ec6c422fcf8a

https://docs.microsoft.com/en-us/sysinternals/downloads/psexec

https://www.bleepingcomputer.com/news/security/new-psexec-spinoff-lets-hackers-bypass-network-security-defenses/

https://attack.mitre.org/software/S0029/

https://otx.alienvault.com/browse/pulses?q=tag:psexec





smbtool (category:
Tools)


type: Exfiltration

Small script for your personal home samba server. Using whiptail or dialog and
acl for manage users / shares / groups.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=dd4c91ab-30ad-454f-845f-7ee7a7fbfb2a

https://github.com/shaftmx/smbtool





Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
a515632e-3374-4602-911e-4f4e259ae0fd
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.