Big US election coming up, security is vital and, oh look... a federal agency just got completely pwned for real
- Reference: 1601036105
- News link: https://www.theregister.co.uk/2020/09/25/cisa_agency_hacked/
- Source link:
This is according to Uncle Sam's Cybersecurity and Infrastructure Security Agency (CISA), which on Thursday [1]went into technical detail on how an intruder: broke into staffers' Office 365 accounts; gained access the agency's internal network via its VPN; and installed malware and exfiltrated data.
"CISA became aware – via [2]EINSTEIN , CISA's intrusion detection system that monitors federal civilian networks – of a potential compromise of a federal agency's network," the team wrote. "In coordination with the affected agency, CISA conducted an incident response engagement, confirming malicious activity."
Feeling bad about your last security audit? Check out what just happened to the US Department of Interior [3]READ MORE
We're told the hacker possessed valid login credentials for a bunch of the hacked agency's Microsoft Office 365 accounts as well as domain administrator accounts. CISA suggested these details were obtained by someone exploiting the [4]CVE-2019-11510 vulnerability in Pulse Secure products present in government networks, a hole that can be abused to fetch files and passwords from a vulnerable machine. CISA said it had "observed wide exploitation of CVE-2019-11510 across the federal government," worryingly enough.
Armed with those stolen Office 365 credentials, the attacker logged into one of the agency's O365 accounts, made a beeline for a SharePoint server, and browsed its pages and downloaded a file. Shortly after, the intruder connected to the unnamed agency's VPN, presumably using information gleaned so far from snooping around.
After that, once in the network, the miscreant returned to rifling through one of the Office 365 accounts, "viewing and downloading help desk email attachments with 'Intranet access' and 'VPN passwords' in the subject line, despite already having privileged access," CISA noted. "These emails did not contain any passwords." Nice try but no cigar, then.
Next, the miscreant enumerated the network using standard Windows command-line tools, connected to an external virtual server via SMB, and then, using their administrator credentials, sought to gain a persistent presence on the network by, according to CISA:
Creating a persistent Secure Socket Shell (SSH) tunnel/reverse SOCKS proxy
Running inetinfo.exe (a unique, multi-stage malware used to drop files)
Setting up a locally mounted remote share ... the mounted file share allowed the actor to freely move during its operations while leaving fewer artifacts for forensic analysis.
They then created a local account that allowed them to steal files thus:
Browse directories on a victim file server
Copy a file from a user's home directory to their locally mounted remote share. CISA analysts detected the cyber threat actor interacting with other files on users' home directories but could not confirm whether they were exfiltrated.
Create a reverse SMB SOCKS proxy that allowed connection between an cyber threat actor-controlled VPS and the victim organization's file server
Interact with PowerShell module Invoke-TmpDavFS.psm
Exfiltrate data from an account directory and file server directory using tsclient (tsclient is a Microsoft Windows Terminal Services client)
Create two compressed Zip files with several files and directories on them; it is likely that the cyber threat actor exfiltrated these Zip files, but this cannot be confirmed because the actor masked their activity.
The malware used was non-trivial – it injected decrypted code into itself to fetch and run a payload from a remote server – and was able to avoid detection by hoodwinking the system's antivirus. "The cyber threat actor was able to overcome the agency's anti-malware protection, and inetinfo.exe escaped quarantine," CISA said. Its analysts "determined that the cyber threat actor accessed the anti-malware product's software license key and installation guide and then visited a directory used by the product for temporary file analysis. After accessing this directory, the cyber threat actor was able to run inetinfo.exe."
As we don't know the name of the agency nor what info was stolen, it's hard to say just what the damage was here, though obviously it was important enough for a smart attacker to go through a number of steps to infiltrate and get persistence on the victim network.
As for prevention, CISA recommended organizations follow the usual best practices: monitor for and shut down unusual open ports, eg: port 8100; watch out for large outbound file transfers; and prevent unexpected protocol use, such as SSH, SMB, and RDP. Folks should "deploy an enterprise firewall to control what is allowed in and out of their network" and "conduct a survey of the traffic in and out of their enterprise to determine the ports needed for organizational functions. They should then configure their firewall to block unnecessary ports."
It also published a list of IP addresses, used by the hacker, to look for in logs as a sign of compromise, and to block in case they are reused. CISA declined to comment further. ®
Get our [5]Tech Resources
[1] https://us-cert.cisa.gov/ncas/analysis-reports/ar20-268a
[2] https://www.theregister.com/2016/02/01/us_government_super_firewall_audit/
[3] https://www.theregister.com/2020/09/17/dot_pentesers_expose_wifi/
[4] https://www.theregister.com/2020/01/07/pulse_secure_attacks/
[5] https://whitepapers.theregister.com/
Re: FYI
Especially since this time the federal government attempting to hijack the election is the federal government
Re: FYI
Correct there is no national Election Authority in the US. Also who is the agency? There are a lot of Federal agencies performing many functions. Some of which are more critical than others. It could be anything from the Defense Department to the National Endowment for the Arts.
Re: FYI
Sure, but in the current political environment why is the government agency name being kept secret? Probably because someone in high office would be embarrassed. The description of the methods sound very much like a foreign government attack - nothing new about that.
Re: FYI
Or the recent news of ballots being tossed in Lucerne County, PA this year.
They captured the hackers' IP addresses
I wonder how many of those will be TOR exit nodes or located in countries that do not share information with the US?
Re: They captured the hackers' IP addresses
I wonder how many of those IPs are in the 192.168.x.x range.
Re: They captured the hackers' IP addresses
Charge the owner of the node with aiding and abetting. Simple.
Got them all?
Given the broad ranging and sophisticated attack I do wonder if they have traced everything.
But, but...The internet is perfectly safe and secure. Just as a screen window won't let air pass thru.
When will these goofs realise that a net is just a bunch of holes connected by string and a cloud is a bunch of holes connected with vapor.
before the bean counters took over almost all multi-location data was transmitted over dedicated lines. In the case of many electric companies, over their own power lines. Maybe they should go back to that.
The only rational response to this kind of attack
Is to storm the nearest pizza restaurant armed with automatic weapons
"The cyber threat actor was able to overcome the agency's anti-malware protection"
Maybe the ant-malware protection was disabled by an employee to stop the nagging warnings when running a key generator for their pirated copy of Office 365?
(That story never gets old)
Seems that turning on Multi Factor Authentication for o365 could have stopped the first step. Sure, users don't like MFA but this is the new reality we live in.
Passwords in Email
"'VPN passwords' in the subject line,"
Who ever approved of sending passwords in emails, needs to be tased for a couple months.
That is such a basic no no, no matter what other mistakes were made or not, that is just plain incompetency.
Re: Passwords in Email
But it's OK if you send an encrypted document in one email and the password in a completely separate email - right?
FYI
The election bit makes for an eye-catching headline, but elections of all sorts, including the presidential, are managed by the states and, to some degree, counties. (Remember the "butterfly ballot" in Palm Beach County, Florida, during 2000?) That is not to say that the states are any better at information security, just that there is no immediate link between a hacked federal agency and state agencies of any sort.