Quarterly Report: Incident Response trends from Winter 2020
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-18935 | Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency. Do: Upgrade to Progress Telerik UI for ASP.NET AJAX 2020.1.114 or later, where a default setting prevents exploitation (or, if staying on 2019.3.1023, enable the non-default hardening setting); per CISA KEV, apply updates per vendor instructions. Because exploitation requires the encryption keys to be known, also patch the older CVE-2017-11317/CVE-2017-11357 key-disclosure flaws or rotate the Telerik upload encryption keys. Check internet-facing IIS/ASP.NET applications for exposed RadAsyncUpload handlers and indicators of compromise, given known ransomware and federal-agency breaches. | 9.8 | 100% | KEV ransomware PoC ×4 |
| largeTens of thousands of internet-exposed ASP.NET/IIS web applications using Telerik controls (order-of-magnitude estimate) | |
| CVE-2020-5902 | Unauthenticated RCE via path traversal in F5 BIG-IP TMUI CVE-2020-5902 is a critical, unauthenticated remote code execution flaw in the F5 BIG-IP Traffic Management User Interface (TMUI), the appliance's web management console, rooted in a directory/path traversal issue (CWE-22) in undisclosed TMUI pages. It is triggered by sending crafted HTTP(S) requests to the management interface — classically path-traversal URLs beneath the TMUI application on the management port — which lets an attacker bypass authentication, read or delete arbitrary files, and execute commands without credentials. Successful exploitation yields full control of the BIG-IP system, which attackers can use to pivot into networks the appliance fronts, maintain persistence, and deploy ransomware. Any organization running an affected F5 BIG-IP appliance or virtual edition whose TMUI is reachable, or whose management network can be reached, is exposed; F5's installed base spans large enterprises and service providers, so the footprint is broad. Exploitation is confirmed in the wild: the flaw was mass-scanned and exploited within days of its July 2020 disclosure, it is listed in CISA KEV with known ransomware use, and EPSS assigns a ~100% probability of exploitation within 30 days. Do: Patch immediately using F5's advisory K52145254 — upgrade BIG-IP to a fixed release per the vendor's version matrix, since CISA's required action is applying vendor updates. Until patched, restrict TMUI/management-interface access to trusted source IPs or a VPN (or disable TMUI if unused) and apply F5's published interim workaround. Because ransomware use is confirmed, hunt for indicators of compromise on both patched and unpatched appliances (unexpected files, webshells, modified login pages, new accounts or scheduled tasks) before treating systems as clean. | 9.8 | 100% | KEV ransomware PoC ×8 |
| mass≈100,000–300,000 internet-exposed BIG-IP TMUI endpoints, with a far larger internal installed base | |
| CVE-2021-26855 | Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon) CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing. Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use. | 9.1 | 100% | KEV ransomware PoC ×4 |
| masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers |
Full article1,552 words · extracted from blog.talosintelligence.com · click to collapse
Quarterly Report: Incident Response trends from Winter 2020-21
Wednesday, March 24, 2021 08:26
For the seventh quarter in a row, Cisco Talos Incident Response (CTIR) observed ransomware dominating the threat landscape. The top variants were Ryuk and Vatet, which is notable given the absence of Ryuk last quarter. We also observed variants of Egregor and WastedLocker continuing to target organizations across the globe.
Unlike last quarter, however, these ransomware attacks overwhelmingly relied on phishes delivering commodity trojan maldocs, such as Zloader, BazarLoader and IcedID. Nearly 70 percent of ransomware attacks relied on commodity trojans this quarter. Adversaries also employ commercially available tools such as Cobalt Strike, open-source post-exploitation tools like Bloodhound, and native tools on the victim’s system, such as PowerShell. For a broader breakdown of these trends, check out our summary here.
CTIR engaged in several incident response engagements in which organizations unknowingly downloaded trojanized updates to the widely deployed SolarWinds' Orion software. Only one of these engagements involved post-compromise activity.
Looking forward, Microsoft recently announced four vulnerabilities in Exchange Server and revealed that a threat actor named Hafnium had been exploiting these vulnerabilities to drop web shells, targeting an array of organizations. Soon other threat actors began leveraging these exploits as well, ranging from APTs to cryptominer groups, with affected organizations estimated in the tens of thousands. CTIR has been responding to a growing number of incidents involving the Microsoft Exchange vulnerabilities.
Targeting
Actors targeted a broad range of verticals, including business management, construction, education, energy and utilities, entertainment, financial, government, health care, industrial distribution, legal, manufacturing and technology. Adversaries most often targeted health care, as we anticipated last quarter given the spate of ransomware attacks targeting health care organizations. It is worth noting there has been an increase in incidents involving Vatet malware, which has been known to target health care organizations. CTIR identified a potential pattern in which regional hospitals associated with a hospital in a given state is initially attacked and may serve as follow-on targets, particularly if they have active VPN connections to the affected organization. There are many reasons why actors are continuing to target the health care industry, including the COVID-19 pandemic incentivizing victims to pay to restore services as quickly as possible.
Threats
Ransomware continued to comprise the majority of threats CTIR observed. As opposed to last quarter, which marked an absence of commodity trojans, the majority of these attacks relied on commodity trojan maldoc phishes as an infection vector. Adversaries are continuing to use commercially available tools as well: Cobalt Strike was observed in half of all ransomware attacks this quarter. There were also numerous ransomware engagements that leveraged open-source reconnaissance tools such as ADFind, ADRecon and Bloodhound. Windows utilities were common, as well. For example, PowerShell was observed in nearly 65 percent of all ransomware attacks, while PsExec usage was observed in more than 30 percent. Other observed tools included dual-use tools such as TightVNC and CCleaner and compression tools such as 7-Zip and WinRAR.
For example, in an incident response engagement involving an education organization in the U.S., the target was initially infected via a phish containing a commodity trojan. In this case, the phish contained a malicious Microsoft Excel attachment that executed the commodity trojan Zloader when if the user enabled macros (CTIR assessed that this Zloader variant was customized for the target based on the fact that its file hash had not been previously observed). An employee at this organization opened the attachment and forwarded it to a colleague. The adversary then pivoted in the environment, leveraging the Group Policy replication mechanism in Windows Active Directory to distribute Ryuk and using PsExec to move laterally and execute remote commands, in line with previous Ryuk behavior. The adversaries obtained domain administrator (DA) credentials and, besides encrypting systems on the network, also wiped backup indexes. More than 1,000 endpoints were encrypted, causing significant damage to the organization, affecting Active Directory, DHCP, DNS and anti-virus software.
In December 2020, Cisco Talos became aware of a sophisticated supply-chain attack in which adversaries gained access to victims' networks via trojanized updates to SolarWinds' Orion software. This attack targeted numerous large enterprises and U.S. government agencies. CTIR engaged in several incident responses in which organizations had unknowingly installed the compromised update. Only one of these engagements involved post-compromise activity, such as malicious PowerUP PowerShell execution. PowerUP appears to be part of PowerSploit, and is a collection of PowerShell modules that are used to assist red teaming activities. While the PowerUP-like PowerShell script did not execute anything at this time, it appeared to be set up as a wrapper or utility, possibly for additional code to be funneled into. CTIR continues to monitor for activity related to the SolarWinds compromise.
Beginning in March, CTIR has been responding to a growing number of incidents involving the Microsoft Exchange vulnerabilities. In one engagement, a customer in the payment processor/technology sector saw no indication that CVE-2021-26855 was exploited. They did, however, observe scanning behavior from a known IP address linked to these attacks, which sent packets to a particular Exchange server beginning February 28. In another engagement, a customer in the healthcare sector saw a CVE-2021-26855 exploit, though we have yet to determine if the activity was just limited to scanning at this time. In one incident response engagement affecting an organization in Germany, we saw a slight deviation from the post-exploitation activity in the aforementioned engagements. The activity started in much the same way, with the adversary installing web shells on the victim environment. However, prior to the deployment of web shells, the customer saw the Domain Admin account password was reset via the presence of the "Password last set" attribute in Active Directory (AD).
Initial vectors
It was difficult to identify an initial infection vector in many engagements last quarter due to shortfalls in logging. However, in engagements in which the initial vector could be identified, or reasonably assumed, phishing remained the top infection vector for the seventh quarter in a row. The vast majority of these were comprised of maldoc phishes as mentioned above. However, there were also engagements involving business email compromise, such as when an employee at an entertainment company received a phish with a spoofed Microsoft Online login page, after which the adversary attempted to authenticate to their Office 365 account from multiple locations. The adversary successfully authenticated and bypassed MFA through use of a legacy application, highlighting the need to disable legacy protocols.
CTIR encourages all organizations to save their logs to make any potential incident response engagements more efficient and effective.
Other notable initial vectors included exploitation of public-facing applications, such as an education organization that had their F5 Load Balancer exploited via CVE-2020-5902 — a remote code execution vulnerability in f5 — in the course of a DDoS attack. There were also several instances of exploitation of a vulnerability in Telerik UI, tracked as CVE-2019-18935. Talos first saw an increase in actors exploiting Telerik UI in summer 2020 — a trend that continues today.
Top-observed MITRE ATT&CK techniques
Below is a list of the most common MITRE ATT&CK techniques observed in this quarter’s IR engagements. Given that some techniques can fall under multiple categories, we grouped them under the most relevant category in which they were leveraged. This represents what CTIR observed most frequently and is not intended to be exhaustive.
Key Findings:
- Phishing with malicious attachments and links accounted for a larger number of the initial access techniques this quarter compared to the previous quarter.
- We observed a variety of execution methods using native Windows utilities, such as “rundll32.exe” and “msiexec.exe”. The use of these utilities may avoid triggering security tools due to them being commonly used in daily operations.
- Engagements involving cryptocurrency mining malware continue to be very low. However, the number of ransomware engagements nearly doubled this quarter.
- Leveraging valid accounts is the most observed lateral movement technique this quarter. RDP usage and remote access services, such as TightVNC, for lateral movement, increased this quarter.
Initial Access (TA0027) — T1078 Valid Accounts: Credentials for a compromised account were leveraged by the adversary Persistence (TA0028) — T1053 Scheduled Task/Job: Adversaries create a scheduled task to run malicious executable every hour Execution (TA0041) — T1204.002 User Execution: Malicious File: Adversary sent phishing emails that contained a malware attachment when clicked, would deploy additional tools to harvest credentials Discovery (TA0007) — T1482 Domain Trust Discovery: Use AdFind (“adfind.bat”) to query for all users, computers, groups, and trusts Credential Access (TA0006) — T1003 OS Credential Dumping: Use tools such as Mimikatz to compromise credentials in the environment. Privilege Escalation (TA0029) — T1484 Group Policy Modification: Force group policy update that creates service to execute ransomware. Lateral Movement (TA0008) — T1021.001 Remote Desktop Protocol: Adversary connects to the system using RDP with valid credentials Collection (TA0035) — T1560.001 Archive Collected Data: Archive via Utility: 7-Zip used to compress a file containing dumped LSASS credentials Defense Evasion (TA0030) — T1070 Indicator Removal on Host: Remove files and artifacts from the infected machine Command and Control (TA0011) — T1132.001 Data Encoding: Standard Encoding: Use Base64 to encode C2 communication Exfiltration (TA0010) — T1567 Exfiltration Over Web Service: Exfiltrated data was located on a file sharing site Impact (TA0034) — T1486 Data Encrypted for Impact: Deploy Ryuk ransomware
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ctir-trends-winter-2020-21/