Threat Group UNC3944 Abusing Azure Serial Console for Total VM Takeover

May 17, 2023Ravi LakshmananSIM exchange/server security

Azure

Financially motivated cyber attackers have been observed exploiting the Microsoft Azure Serial Console on virtual machines (VMs) to install third-party remote management tools within compromised environments.

Mandiant, a Google company, believes this activity is from the threat group it tracks. UNC3944also known as roasted 0ktapus and Scattered Spider.

“This attack method was unique in that it evaded many of the traditional detection methods employed within Azure and gave the attacker full administrative access to the VM,” said the threat intelligence firm. increase.

First revealed late last year, this new adversary has been known to use SIM swapping attacks to infiltrate telecommunications and business process outsourcing (BPO) companies since at least May 2022.

Later, Mandiant also discovered that UNC3944 utilized a loader named STONESTOP to install a maliciously signed driver named POORTRY. This driver is designed to terminate processes and delete files associated with security software as part of a BYOVD attack.

Azure

At this time, it is unclear how the threat actor performs SIM swaps, but the initial access method used SMS phishing messages targeting privileged users to obtain their credentials, followed by two-factor authentication. It is believed to involve performing a SIM swap to receive (2FA). ) puts the token under control on her SIM card.

Attackers with elevated access exploit Azure VM extensions such as Azure Network Watcher, Azure Windows Guest Agent, VMSnapshot, and Azure Policy Guest Configuration to probe the target network.

upcoming webinars

Learn how to stop ransomware with real-time protection

Join our webinar to learn how to stop ransomware attacks using real-time MFA and service account protection.

Reserve your seat!

“Once the attackers complete their reconnaissance, they leverage the serial console functionality to gain an administrative command prompt inside the Azure VM,” said Mandiant, noting that UNC3944 uses PowerShell to deploy legitimate remote management tools. He added that he observed

Group UNC3944

This development is yet another evidence that attackers are leveraging Living-off-the-land (LotL) techniques to sustain and progress their attacks while at the same time evading detection.

“The attacker’s novel use of the serial console is a reminder that these attacks are no longer confined to the operating system layer,” said Mandiant.

“Unfortunately, cloud resources are often misunderstood and can be misconfigured, making these assets vulnerable to attackers. It depends, but one thing is clear: attackers are looking to the cloud.”

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *