Cyber Security News

Hackers Used Weaponised Resume to Attack Employee & Gained Org Server Access – Incident Report

A sophisticated cyber attack was detected in March 2024, revealing a complex intrusion that began with a weaponized resume and culminated in the compromise of multiple servers.

This incident highlights the evolving tactics of threat actors and the importance of robust cybersecurity measures.

The attack strated when a threat actor, identified as TA4557 by Proofpoint, submitted a malicious job application.

This group has historical connections to FIN6 and shares tooling similarities with Cobalt Group and Evilnum.

Security analysts at The DFIR Report discovered that the victim, lured by a fake online resume, downloaded and executed a malicious .lnk file from a zip archive named “John Shimkus.zip”.

Fake Resumes (Source – The DFIR Report)

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Infection Chain

The infection process involved several stages:-

  1. Execution of a Windows Shortcut (.lnk) file
  2. Abuse of ie4uinit.exe (a legitimate Microsoft executable)
  3. Deployment of the more_eggs backdoor
  4. Installation of Cobalt Strike beacon

The initial payload used obfuscated commands to create an .inf file and move a legitimate copy of ie4uinit.exe to a custom location.

Infection Chain (Source – The DFIR Report)

This technique, known as LOLBin abuse, allowed the attacker to load and execute COM scriptlets from remote servers.

The more_eggs backdoor was deployed using the msxsl.exe binary, a technique documented in the LOLBAS project.

This malware established persistent communication with the command and control (C2) server using a scheduled task for persistence.

After initial infection, the threat actor:-

  1. Deployed Cobalt Strike on the beachhead host
  2. Exploited CVE-2023-27532 in Veeam software on a backup server
  3. Created new local administrator accounts
  4. Used RDP to connect to compromised servers
  5. Installed Cloudflared for tunneling traffic

The attacker used a modified version of VeeamHax to exploit the Veeam vulnerability, enabling them to execute arbitrary SQL commands and create a local administrator account.

VeeamHax Difference (Source – The DFIR Report)

The threat actor employed various techniques for credential access and network discovery:-

  • Accessed LSASS memory for credentials
  • Used tools like Seatbelt and SharpShares for enumeration
  • Executed adfind.exe for domain reconnaissance
  • Utilized SoftPerfect Network Scanner for network mapping

Two primary C2 channels were observed:-

  1. more_eggs payload communicating with pin.howasit[.]com
  2. Cobalt Strike beacon connecting to shehasgone[.]com

Here below we have mentioned the timeline:-

Timeline (Source – The DFIR Report)

This incident demonstrates the sophisticated tactics employed by modern threat actors, combining social engineering, exploitation of vulnerabilities, and advanced post-exploitation techniques.

Organizations must remain vigilant and implement comprehensive security measures to defend against such multi-stage attacks.

Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago