ZeroHour
Cisco Talospublished ()ingested

Quarterly Report: Incident Response trends in Spring 2020

criticalRansomwareimportance 60CVE-2019-19781

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-19781
Unauthenticated path traversal RCE in Citrix ADC, Gateway, and SD-WAN WANOP

CVE-2019-19781 is a path-traversal flaw (classified CWE-22, though CISA's description calls it unspecified) in Citrix ADC (formerly NetScaler ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances that lets an unauthenticated remote attacker traverse directories via crafted requests and execute arbitrary commands on the appliance, typically with root privileges. It is triggered by sending specially crafted directory-traversal requests (crafted URLs/requests to the appliance's management or VPN endpoints), which lets the attacker write files and run commands with no credentials. Successful exploitation yields arbitrary code execution on the appliance, enabling theft of VPN/ADC credentials, lateral movement into the corporate network, and installation of persistent backdoors. Any organization running affected ADC, Gateway, or SD-WAN WANOP firmware is affected, with internet-facing gateways used for remote access at the highest risk. Exploitation is confirmed in the wild: the vulnerability is on CISA's KEV (added 2021-11-03) with known ransomware use, EPSS assigns near-certain (100.0%) probability of exploitation within 30 days, and no public PoC is listed despite confirmed abuse.

Do: Upgrade Citrix ADC, Gateway, and SD-WAN WANOP appliances to the fixed firmware builds listed in Citrix advisory CTX267020; if patching cannot be done immediately, apply Citrix's published interim mitigation and restrict internet exposure to the appliance. Because exploitation grants root code execution and persistence, after patching hunt for indicators of compromise (unexpected nsroot account, modified system files, crontab/scheduled entries), kill all active and inactive sessions, and rotate appliance and VPN credentials. Prioritize internet-facing gateways and comply with CISA's required action to apply vendor updates.

9.8100% KEV ransomware
  • Citrix Application Delivery Controller (ADC) Supported ADC firmware lines in effect at disclosure (10.5, 11.0, 11.1, 12.0, 12.1, 13.0) prior to patched builds, per Citrix advisory CTX267020; exact builds n
  • Citrix Gateway Supported Gateway firmware lines (sharing the ADC codebase, same affected releases 10.5-13.0) prior to patched builds, per Citrix advisory; exact builds not spe
  • Citrix SD-WAN WANOP Appliance Affected appliance models (4000, 4100, 5000, 5100) running pre-patch firmware in the 10.2.1-11.4.1 range, per Citrix advisory; exact builds not specified in the
massroughly 80,000-100,000+ internet-exposed Citrix ADC/Gateway appliances at the time of disclosure, with a far larger total installed base (including…
Full article631 words · extracted from blog.talosintelligence.com · click to collapse

Quarterly Report: Incident Response trends in Spring 2020

Monday, April 13, 2020 11:03

By David Liebenberg.
Cisco Talos Incident Response (CTIR) engagements continue to be dominated by ransomware and commodity trojans. As alluded to in last quarter’s report, ransomware actors have begun threatening to release sensitive information from victims as a means of further compelling them to pay. Additionally, DDoS and coinminer threats reemerged in spring 2020 after absences in the previous quarter. Looking at information from November 2019 through January 2020, ransomware maintains its status as the most prevalent threat, and CTIR has observed some changes in the top ransomware offender — Ryuk.

Targeting A wide variety of verticals were once again targeted, including energy and utilities, wholesale and distribution, sports betting, transportation, healthcare, government, manufacturing, real estate, financial services, telecommunications, education, and retail. The top targeted verticals were financial services and government, a change from last quarter when the top targeted vertical was manufacturing.

Threats Although there were some new trends this quarter — including ransomware actors adding extortion to their toolkit, increased observations of the use of red teaming tool Cobalt Strike, and an uptick in the exploitation of a vulnerability in the Citrix Application Delivery Controller (CVE-2019-19781) — this quarter demonstrated the continued threat posed by ransomware, particularly Ryuk, and commodity trojans such as Emotet and Trickbot.

For example, a company in the manufacturing industry became infected with Emotet, likely via email. The adversaries then downloaded and leveraged Trickbot to move laterally throughout the network and elevate privileges. The adversary then used the open-source tool Meterpreter to drop Ryuk onto the victim's environment. CTIR also observed adversaries pushing Ryuk throughout the AD environment as a group policy object (GPO).


Ransomware extortion Ransomware actors have begun exfiltrating sensitive data as another lever to further compel victims to pay the ransom. We observed this in two engagements involving Maze ransomware actors, in which the adversaries exfiltrated sensitive information to an FTP server and threatened to publish it if the ransom was not paid. The Maze team has continued to use this tactic, creating a public website where they release information regarding affected organizations.

We also observed another ransomware incident involving a government organization in which the adversaries published a ransom note and screenshots of compromised critical systems, including the Active Directory (AD) structure, on Twitter. The adversaries threatened to publish more sensitive information if the ransom was not paid.

Other ransomware actors have begun following suit as well, including Sodinokibi, Nemty, DoppelPaymer, Nefilim, CLOP and Sekhmet. This is a particularly dangerous trend since it further compels victims to pay and negates traditional ways of combating ransomware attacks, such as maintaining backups.

Initial vectors For the majority of engagements, definitively identifying an initial vector was difficult due to shortfalls in logging. However, in engagements in which the initial vector could be identified, or reasonably assumed, phishing remained the top infection vector. CTIR also observed continued exploitation of web applications, particularly for Citrix Application Delivery Controller (CVE-2019-19781).

Looking forward Ransomware continues to run rampant in Q3, and Ryuk remains the most common variant. CTIR noticed that Ryuk has undergone some changes this quarter. Contrary to previous quarters, there are fewer engagements where Emotet and Trickbot are the initial dropper for Ryuk. Ryuk attacks are leveraging encoded PowerShell commands to download the initial payload, distributing batch files via GPO to hidden admin shares, and leveraging PowerShell to disable security/AV tools and prevent backups. CTIR has also observed the adversaries using a common network discovery PowerShell script (“Get-DataInfo.ps1”) to scan the entire network and provide an output of online vs. offline hosts.

CTIR also observed a shift from Ryuk actors leveraging PSExec to deploy Ryuk to more use of Windows Management Instrumentation (WMI), BITSAdmin, and the red-teaming framework Cobalt Strike.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/ir-quarterly-threat-report-spring-2020/