Cyber Security

Threat Actors Exploiting Legitimate Software For Stealthy Cyber Attacks

Threat actors often exploit legitimate software for malicious purposes as it enables them to evade security measures and gain unauthorized access to systems. 

By using legitimate software, threat actors can avoid detection and blend in with normal network traffic which makes it harder for defenders to detect and mitigate the attack.

Security researchers at ReliaQuest recently identified that threat actors have been actively exploiting legitimate software for stealthy cyber-attacks.

Hackers Exploiting Legitimate Software

ReliaQuest documented an annoying and significant increase in cyber incidents with valid software CAMO (Commercial Applications for Malicious Operations) from January to August 2024.

The tactic was used in 60% of all critical hands-on-keyboard incidents, marking an increase of 16% when compared to 2023.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

However, CAMO actor uses common IT tools PDQ Deploy, Total Software Deployment (TSD), and RMM software like AnyDesk or ScreenConnect.

These tools are most often found with valid code signing certificates that have been used during many phases within the attack kill chain.

⁤For instance, the Medusa ransomware group utilized PDQ Deploy to spread and execute ransomware, while the Inc Ransom group employed SoftPerfect NetScan for network discovery and Restic (disguised as “winupdate.exe”) for data exfiltration. ⁤

PDQ Deploy interface (Source – Reliaquest)

⁤The Black Basta ransomware group launched social engineering campaigns using RMM tools to establish command and control (C2) channels. ⁤

⁤CAMO poses unique challenges as these legitimate tools often evades the security policies, and easily get blend with normal IT operations which helps in complicating the threat detection and incident response.

⁤To mitigate CAMO-based attacks, organizations are advised to implement defense-in-depth strategies including:- ⁤

  • ⁤Network segmentation using VLANs and DMZs. ⁤
  • ⁤Application whitelisting through Windows Defender Application Control (WDAC) or AppLocker. ⁤
  • ⁤Strict controls on RMM tool usage. ⁤

⁤Moreover, researchers also urged to incorporate CAMO awareness into their incident response plans, penetration tests, and risk assessments. ⁤

⁤Not only that, but they also recommended implementing data exfiltration prevention measures like blocking unauthorized cloud services and monitoring access to sensitive data. ⁤

Threat actors will continue leveraging legitimate IT tools like CAMO, AnyDesk, and PDQ Deploy for malicious activities in the long term.

This trend is evidenced by their frequent use in incidents and discussions on cybercriminal forums.

The nation-state groups like “Cozy Bear” are likely to incorporate legitimate behavior into sophisticated custom malware (CloudDuke) using Microsoft OneDrive for data exfiltration.

This persistence is driven by the tools’ effectiveness and the diverse needs of different threat actors.

Simulating Cyberattack Scenarios With All-in-One Cybersecurity Platform – Watch Free Webinar

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago