TA577 has been identified as a notorious threat actor who orchestrated a sophisticated phishing campaign, according to researchers at security firm Proofpoint.
Currently, the group is utilizing a new method of phishing involving ZIP archive attachments.
According to our investigation, this group is utilizing a chain of attacks aimed at stealing authentication information from the NT LAN Manager system.
By using booby-trapped email attachments containing booby-trapped NTLM hashes to steal employees' NTLM hashes, a threat actor that is known for establishing initial access to organizations' computer systems and networks is using these attachments to steal employees' hashes.
The email security company Proofpoint reported today that although it has seen TA577 favouring Pikabot deployment in recent months, two recent attacks indicate that TA577 has taken a different approach to the attack.
A group called TA578, which has been linked with the Qbot malware campaign and the Black Basta ransomware campaign, is one of the first access brokers.
NTLM hashes are a cornerstone of the security of Windows systems for authentication and session management.
Attackers are extremely interested in these hashes as they are potentially useful in offline password cracking and in pass-the-hash attacks, which do not require actual passwords to gain access to services but instead use hashes as shortcuts.
A technique known as thread hijacking, by which the attackers craft phishing emails that seem like legitimate follow-up emails to ongoing conversations, is used by the attackers.
There is a malicious external server that is used to capture NTLM hashes, as these emails contain personalized ZIP files with HTML documents.
When opened, these malicious servers start connecting to a malicious external server that has been set up specifically to capture these hashes.
TA577 likely has the resources, time, and experience to iterate and test new delivery methods at the rate at which it adopts and distributes new tactics, techniques, and procedures.
TA577, along with other IABs, seems to be on top of the threat landscape and understands when and why certain attack chains cease to be effective.
To increase the effectiveness and likelihood of victim engagement with their payload delivery and bypass detections, they will be able to create new methods to bypass detections and make use of them as quickly as possible.
To prevent exploits identified in this campaign, organizations should block outbound SMBs to prevent these sophisticated attacks.
While restricting guest access to SMB servers is a simple security measure, it falls short of preventing these sophisticated attacks.
The company advises that strict email filtering be implemented, outbound SMB connections should not be allowed, and Windows group policies should be activated to minimize the risk.
To combat these types of NTLM-based threats effectively, Microsoft has introduced advanced security features into Windows 11 to help users.
It is important to maintain constant vigilance and take strong security measures to prevent phishing attacks targeting the NTLM authentication protocol.
For organizations to remain safe from sophisticated cybercriminal endeavours, they must stay abreast of emerging threats and adjust their defences to keep up with the rapidly evolving threats.
This Cyber News was published on www.cysecurity.news. Publication date: Sat, 09 Mar 2024 15:43:05 +0000