A sophisticated cyber attack was detected in March 2024, revealing a complex intrusion that began with a weaponized resume and culminated in the compromise of multiple servers.
This incident highlights the evolving tactics of threat actors and the importance of robust cybersecurity measures.
The attack strated when a threat actor, identified as TA4557 by Proofpoint, submitted a malicious job application.
This group has historical connections to FIN6 and shares tooling similarities with Cobalt Group and Evilnum.
Security analysts at The DFIR Report discovered that the victim, lured by a fake online resume, downloaded and executed a malicious .lnk file from a zip archive named “John Shimkus.zip”.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
The infection process involved several stages:-
The initial payload used obfuscated commands to create an .inf file and move a legitimate copy of ie4uinit.exe to a custom location.
This technique, known as LOLBin abuse, allowed the attacker to load and execute COM scriptlets from remote servers.
The more_eggs backdoor was deployed using the msxsl.exe binary, a technique documented in the LOLBAS project.
This malware established persistent communication with the command and control (C2) server using a scheduled task for persistence.
After initial infection, the threat actor:-
The attacker used a modified version of VeeamHax to exploit the Veeam vulnerability, enabling them to execute arbitrary SQL commands and create a local administrator account.
The threat actor employed various techniques for credential access and network discovery:-
Two primary C2 channels were observed:-
Here below we have mentioned the timeline:-
This incident demonstrates the sophisticated tactics employed by modern threat actors, combining social engineering, exploitation of vulnerabilities, and advanced post-exploitation techniques.
Organizations must remain vigilant and implement comprehensive security measures to defend against such multi-stage attacks.
Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…