CISA Warns Against Malicious Use of Legitimate RMM Software

Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory alerting network defenders to the abuse of legitimate remote monitoring and management (RMM) software tools.

The document, published Wednesday jointly with the National Security Agency (NSA) and the Multilateral Intelligence Sharing and Analysis Center (MS-ISAC), also refers to an October 2022 cyber campaign involving the exploitation of RMM solutions.

“Specifically, cybercriminals sent phishing emails to download legitimate RMM software, ScreenConnect (now ConnectWise Control) and AnyDesk. A refund scam was carried out to steal money from the CISA,” CISA wrote.

The campaign appeared to be financially motivated, according to the agency, but could lead to another kind of malicious activity.

“For example, an attacker could sell access to a victim’s account to other cybercriminals or advanced persistent threat (APT) attackers.” Recommendation.

After gaining access to the target network through phishing or other techniques, the attackers (CISA connected to state-sponsored APTs) used legitimate RMM software as a persistence or command and control (C2) backdoor Did.

“By using the RMM software’s portable executable, an attacker can establish local user access without requiring administrator privileges or a full software installation. It effectively avoids many software control and risk management assumptions,” said CISA.

The CISA advisory contains indicators of compromise (IOCs) and mitigations for the aforementioned campaigns to help network defenders protect systems from malicious use of legitimate RMM software.

“The challenge is that this kind of malicious activity is not always obvious to vendors,” he said. action 1.”

“An indication of a threat actor using the tool is setting up an account immediately after creating an associated admin email domain, or regularly removing all endpoints in the account to create a brand new device. It is to replace it with a set.”

Still, security experts said Information security Companies deploy solutions to help hackers detect attempts to exploit them and terminate their activity before they reach their goals.

“I emphasize the need for organizations to implement anti-phishing controls and build strong cybersecurity awareness. This includes fine-tuning spam filters and implementing multi-factor authentication (MFA). This eliminates the possibility of attackers using corporate email domains to distribute phishing emails via stolen credentials.”

CISA advisory comes months after authorities Published the final episode One of a three-section series on how to secure your software supply chain.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *