Threat Intelligence

Secureworks Threat Intelligence Summit 2018 overview

Session notes on nation-state threat groups, business email compromise, threat actor tradecraft mistakes, and attribution from the 2018 summit.

Secureworks Threat Intelligence Summit 2018 Overview

Secureworks Threat Intelligence Summit 2018 overview

Alex Tiley (CTU) — GOLD KINGSWOOD, aka Cobalt gang

Covered how a criminal group used a blend of tools to steal millions from banks — demystifying GOLD KINGSWOOD, aka Cobalt gang. The identifiers for this group: targeting, tooling, timing. Attack tools in use include Ratopak, Cobaltstrike.cyst, cobint, WCE, Acehash, Inveigh, listrix and logkatz. Typical APT behaviour methods are: perform spearphish, dump creds, move laterally, locate target, gather intel.

Fsell.info, an underground darkweb forum, was found to be sharing compromised data. Another criminal group referenced was the Lurk group. A case of a forensics investigation was talked over, which (disappointingly, he said) all too commonly resulted in the supplied host turning out to be an Nginx proxy rather than the C&C machine itself. However, it's still worth reviewing the Vim history and SSH root logins as they reveal other running infrastructure such as domains and attack infrastructure. When asked for prevention, the response was: make sure you have good network hygiene (2FA, app whitelisting, LAPS etc.)

Rafe Pilling (CTU) — Redirect to SMB credential stealing

Explained the "Redirect to SMB" credential stealing technique. IRON LIBERTY (RU), aka Energetic Bear, are one group mentioned using this. With NTLM Windows hashing being common for authentication, an SMB redirect hash listener can be dropped to listen for the SMB handshake when a call to SMB is made. Inveigh is a packet sniffer tool that listens for and responds to LLMNR/mDNS/NBNS requests.

An example was shown that indicated this attack using a website running a page that would invoke Microsoft Word to perform an SMB lookup: http://90.10.10.90/template.dotm causes an SMB lookup, with listeners for the handshake set up externally. Advice given: you should already be filtering SMB 445/139/137 at the perimeter! Hillcrest/Leaf Miner was a group mentioned that targets the aerospace industry.

Adam Orton (CTU) — Satellite hijacking (IRON HUNTER)

Explained a very advanced satellite hijacking method for deniable communication used by IRON HUNTER (RU), aka Turla/White Bear. ISP satellite to IP provider used from a local African C2 host. Buckshot Yankee is the name of an identified attacker. IVBB were attacked.

One interesting point was that copied/cloned websites will have a "Doctype=" matching the cloned/copied site in the page code. He also used a web headers/page title Shodan search to discover more detail on copied sites. Also mentioned was a Tims2 (sp?) intel platform used to track attack infrastructure and fill it with passive DNS data.

Chris Taylor (CTU) — BRONZE FIRESTONE domain hiding

Explained how BRONZE FIRESTONE (CH), aka APT29, hide using the same naming convention as Google use on domains — 1e100.net, a Google domain, to hide. They also park their domains on Google DNS 8.8.8.8.

Mark Osborn (CTU) — BRONZE UNION DLL sideload

Had followed BRONZE UNION (CH). He broke down the technique of a malicious DLL sideload search-hijack dropper of a self-extracting RAR file with a signed library. Attack tools listed as used by the attacker were: Plugx, httpbrowser, sysupdate, hyperbro. GetUserSpn was a mentioned script used to search for service accounts. The attack would result in a normal-looking svchost.exe that was in fact running a malicious attached DLL.

Alison Wikoff (CTU) — COBALT DICKENS, Mabna phishing

Iranian group COBALT DICKENS (IR), which performed the Mabna phishing campaign against universities, was explained by Alison Wikoff. Landing pages on newly registered domains such as unit.edu redirect SSO. Intel suggests Iranian sanctions have caused a brain drain; this activity was aimed at gaining course access and intellectual property.

Their original method during 2013–2017 was broad phishing, spear phishing and password spraying, followed by further methods (photo of slide below). The new activity seen matched the previous Iranian activity, so in August 2018 the domain detail was shared and the domains were taken down early.

Slide covering COBALT DICKENS / Mabna phishing timeline
Slide covering the COBALT DICKENS / Mabna phishing timeline, 2013–2018.

Don Smith (Director, CTU) — Real world attacks

Covered a broad section on real world attacks:

  • An example of a fake persona compromise was Mia Ash — a cultivated personality lure, a catfish (wired.com).
  • A term for common scanning malware referenced was 'scan and exploit'.
  • A warning-flag technique used by attackers: IIS forking cmd.exe.
  • An exploit seen in the wild: the Outlook forms exploit used to launch PowerShell.
  • Mention of attackers targeting and stealing NTDS.dit, which holds all Active Directory passwords and requires decryption to reveal them.
  • Secureworks use Redcloak host protection to aid their incident response.
  • BRONZE RIVERSIDE (CH), aka Cloudhopper, was discussed.
  • A download dropper using a .jpg filename which is a renamed PuppyRAT.
  • Attackers now seek OAuth tokens for Gmail and G Suite (Wikipedia: OAuth).
  • Another modern target is AWS keys, stolen from poorly secured code, with attackers then creating VPS instances used for BTC mining. Yet another target is Okta SSO phishing in the USA.
  • One shady activity referenced was Windows KMSpico licensing abuse.
  • When large-scale issues occur in the UK there are alliances between groups such as the NCA, NCSC and SCIG (Strategic Cyber Industry Group) to pool intel and data.
  • During the WannaCry incident the NHS was inordinately affected, more than other firms even those running Windows XP. New thinking is that their N3 network was trusted too much, more than was securely sensible for the NHS (n.b. N3 is now the Health and Social Care Network, HSCN).
  • A term used to describe the initial compromise was: IAV, initial access vector.

Matt Webster (CTU) — Threat actor mistakes

Covering revealing mistakes made by attackers. Pdb file strings show similar patterns. IRON TWILIGHT (RU) performed the DNC hack. An interesting holiday that affects Russian recon is April 15th, a sigint holiday in Russia. BRONZE EXPORT (CH) — DNS tunnelling. BRONZE MOHAWK (CH) / Temp.Periscope / Leviathan. Htran proxy used by attackers (infrastructure picture below).

Htran proxy infrastructure diagram
Htran proxy infrastructure diagram referenced in the Threat Actor Mistakes talk.
The more you learn about threat groups, the better it helps with countermeasures to the learned threat group behaviour. Implement 2FA on all external access points — on-site not required, off-site always required.

Chris Yule (CTU) — Business email compromise, GOLD GALEON

Next talk was business email compromises by Nigerian scammers, covering the GOLD GALEON group and business email scam methods in steps.

Business email compromise methods
Business email compromise methods covered in the GOLD GALEON talk.

GOLD SKYLINE — Nigerian scam group

GOLD SKYLINE, a Nigerian group, uses the iSpy keylogger to gain screenshots. An email address scraper tool is used — simply put in the target sector, scrape websites, send mails.

Buccaneers Confraternity and the confraternities involved in phishing cyberscams (Wikipedia: Confraternities in Nigeria). Pyrate Confraternity, Magnificent Seven — many are sea-themed and have a Facebook page. Ben Bergman covered the history, as they went from a brotherhood in 1972 to today's cults. Naijagists.com covered the buccaneers as cultists; the Premium Times newspaper also covered them in Lagos, calling them "Yahoo boys."

Slide from the GOLD SKYLINE / business email compromise session

Liability and Office 365 logging

When a business mail attack causes a spoofed supplier invoice, who is liable — the supplier whose mail was attacked and not paid, or the receiver who clicked the link and paid? Again the recommendation is external gateway 2FA on webmail etc. A point was made that Office 365 requires a forensic tick log to store the right mail logs. Also, Microsoft TechNet recommends disabling automatic forwarding in the company config. When it comes to these attacks, do senior managers understand that 'emergency' process bypasses are dangerous? What approval processes are in place?

Attribution — Park Jin Hyok / North Korea

Mention of Park Jin Hyok, a North Korean cyber criminal. The FBI indictment document contains many pages of tradecraft, included here: FBI complaint (PDF). Attacks on Sony and a UK media firm are included. The North Korean groups referenced: NICKEL GLADSTONE (NK), NICKEL CAMBIAN (NK).

Attribution — Iranian threat groups

  • COBALT GYPSY (IR)
  • COBALT TRINITY (IR), aka APT33
  • COBALT URSHIN (IR)
  • COBALT DICKENS (IR), aka Mabna
  • COBALT HUEY (IR)

Solving phishing — filtering works to a degree. Blue team phishing. Honeytrap accounts on social media are favoured by North Korea.

Attribution helps understand intent. Focus resources. Cluster of TTPs attribution.