Cybersecurity Agencies Sound Alarm on Rising TrueBot Malware Attacks

July 7, 2023swati kanderwalCyber ​​Attack/Malware

TrueBot malware attack

Cybersecurity agencies have warned of the emergence of a new variant of TrueBot malware. This enhanced threat now targets companies in the United States and Canada with the aim of extracting sensitive data from compromised systems.

These advanced attacks exploit a critical vulnerability (CVE-2022-31199) in the popular Netwrix Auditor server and its associated agents.

This vulnerability allows an unauthorized attacker to execute malicious code with the privileges of the SYSTEM user, granting unrestricted access to a compromised system.

Working with cybercrime groups Silence and FIN11, TrueBot malware siphons data to spread ransomware and compromise the safety of numerous intrusive networks.

Cybercriminals exploit the cited vulnerability to gain an initial foothold and begin installing TrueBot. Once inside the network, it installs the FlawedGrace Remote Access Trojan (RAT) to elevate its privileges, establish persistence on the compromised system, and perform additional operations.

“During FlawedGrace’s execution phase, the RAT stores an encrypted payload in its registry. The tool can create a scheduled task and inject the payload into msiexec.”[.]exe and svchost[.]The exe is a command process that allows FlawedGrace to establish a command and control (C2) connection to 92.118.36.[.]For example, in addition to running 199, it loads a dynamic-link library (DLL) to achieve privilege escalation,” the advisory reads.

Cybercriminals initiate Cobalt Strike beacons within hours of the initial intrusion. These beacons facilitate post-exploitation tasks such as exfiltrating data and installing ransomware and various malware payloads.

While previous versions of TrueBot malware were typically spread through malicious email attachments, the updated version leverages the CVE-2022-31199 vulnerability to gain initial access.

This strategic shift will enable cyber threat actors to carry out larger-scale attacks within the intrusion environment. Importantly, Netwrix Auditor software is employed by more than 13,000 of his organizations worldwide, including prominent companies such as Airbus, Allianz, his NHS in the UK, and Virgin.

The advisory does not provide specific information on the number of victims or affected organizations for TrueBot attacks.

The report also highlights the involvement of Raspberry Robin malware and other post-compromise malware such as IcedID and Bumblebee in these TrueBot attacks. By using Raspberry Robin as a distribution platform, attackers can reach more potential victims and amplify the impact of their malicious activity.

upcoming webinars

🔐 Privileged Access Management: Learn How to Overcome Key Challenges

Discover different approaches to overcoming the challenges of privileged account management (PAM) and leveling up your privileged access security strategy.

reserve a spot

Given that the Silence and TA505 groups are actively infiltrating networks for financial gain, it is important that organizations implement the proposed security measures.

To protect themselves from TrueBot malware and similar threats, organizations should consider the following recommendations.

  • Install updates. Organizations using Netwrix Auditor should install the necessary updates to mitigate the CVE-2022-31199 vulnerability and update their software to version 10.5 or later.
  • Enhanced security protocols: Implement multi-factor authentication (MFA) for all employees and services.
  • Beware of Intrusion Indicators (IOCs): Security teams should proactively probe networks for signs of TrueBot compromise. Joint Alert provides guidelines to help you discover and mitigate the impact of malware.
  • Please report any incidents: If your organization detects an IOC, or suspects a TrueBot intrusion, you should act promptly according to the incident response actions listed in the alert and report the incident to CISA or the FBI.

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *