News: 1651624310

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cyber-spies target Microsoft Exchange to steal M&A info

(2022/05/04)


A cyber-spy group is targeting Microsoft Exchange deployments to steal data related to mergers and acquisitions and large corporate transactions, according to Mandiant.

The infosec giant's researchers have dubbed the cyber-espionage threat group UNC3524.

And while its techniques overlap with those used by what's said to be "multiple" Russia-based cyber-spies, including the Kremlin-backed gangs accused of meddling in US elections and hijacking SolarWinds' software updates, Mandiant says it can't conclusively link UNC3524 to a previously seen advanced persistent threat group.

[1]

The cyber gang's focus on corporate deals and M&A seem to point to a financial motivation for their misdeeds. However, "their ability to remain undetected for an order of magnitude longer than the average dwell time of 21 days in 2021" indicates espionage, Mandiant researchers Doug Bienstock, Melissa Derr, Josh Madeley, Tyler Mclellan and Chris Gardner [2]wrote in an analysis of UNC3524's tools, tactics and procedures.

[3]

[4]

"Part of the group's success at achieving such a long dwell time can be credited to their choice to install backdoors on appliances within victim environments that do not support security tools, such as anti-virus or endpoint protection," they explained.

The criminals put the "advanced" in advanced persistent threat group, they added, citing the group's high level of operational security, low malware footprint, evasive skills, and having a large Internet-of-Things botnet army at its disposal.

[5]

Plus, each time a victim removed the intruders' access, UNC3524 quickly found a way to break back into the organization's network and "immediately" restarted stealing data.

Making a 'quietexit'

In the analysis, Mandiant's team detailed how the snoops deployed a novel backdoor that the threat hunters dubbed Quietexit; we're told it is based on the open-source Dropbear SSH client-server software.

The threat researchers noted they don't know how the crew gained initial access, though once they had broken in, they deployed the backdoor on opaque network appliances, such as SAN arrays, load balancers, and wireless access point controllers. These types of devices don't typically support security tools, such as antivirus or endpoint detection products, which allowed UNC3524 to remain undetected for at least 18 months.

In some cases, Quietexit renamed itself to look like a legitimate file on the system. The malware then attempts to connect to a hard-coded command and control (C2) address, and Mandiant noted that the criminals also tend to use C2 domains that blend in with legitimate traffic.

For example: if the malware infected a load balancer, the gang used C2 domains that contained a string that could relate to the device vendor and OS name. "This level of planning demonstrates that UNC3524 understands incident response processes and tried to make their C2 traffic appear as legitimate to anyone that might scroll through DNS or session logs," the researchers noted.

[6]

UNC3524 sometimes used a secondary backdoor to gain access: a ReGeorg web shell on a DMZ web server that created a SOCKS proxy.

However, they only used the web shell when the Quietexit backdoors stopped working, and they always used an obscure, "heavily obfuscated" version of ReGeorg that the NSA has linked

[7]PDF

to APT28, also called Fancy Bear, a gang sponsored by Russia's GRU military intelligence service.

[8]Now Mandiant says 2021 was a record year for exploited zero-day security bugs

[9]SolarWinds attacker on the move: Russia's Nobelium crew has trebled attacks targeting MSPs, cloud resellers, says Microsoft

[10]Microsoft dogs Strontium domains to stop attacks on Ukraine

[11]Data-wiper malware strains surge as Ukraine battles ongoing invasion

After deploying backdoors, UNC3524 obtained privileged credentials for the victim's email environment, and then began making Exchange Web Services (EWS) API requests to either Microsoft Exchange or Microsoft 365 Exchange Online.

The gang specifically targets executive teams' mailboxes, or employees that work in corporate development, M&A, or IT security, although Mandiant noted that targeting IT security is likely to determine if their data-theft operation has been detected.

Additionally, the methods that UNC3524 used for EWS impersonation and SPN credential addition are also similar to those used by Russian cyber-espionage gangs including APT29/Cozy Bear, which was the group behind the [12]SolarWinds hack in late 2019. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YnH6a9x80h3Kqn4e23slpgAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.mandiant.com/resources/unc3524-eye-spy-email

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnH6a9x80h3Kqn4e23slpgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnH6a9x80h3Kqn4e23slpgAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnH6a9x80h3Kqn4e23slpgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnH6a9x80h3Kqn4e23slpgAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/1/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF

[8] https://www.theregister.com/2022/04/23/zeroday_exploits_2021/

[9] https://www.theregister.com/2021/10/25/nobelium_russia_svr_msp_warning_microsoft/

[10] https://www.theregister.com/2022/04/08/microsoft-russia-stronium-domains/

[11] https://www.theregister.com/2022/04/29/wiper_attacks_jump_500_percent/

[12] https://www.theregister.com/2021/04/15/solarwinds_hack_russia_apt29_positive_technologies_sanctions/

[13] https://whitepapers.theregister.com/



Hmm?

HildyJ

The techniques seem Russian but the M&A targets don't fit. Russia isn't capable of mergers or acquisitions (in either direction) at this point and gangs looking for a payoff want it in untraceable bitcoin rather than eminently traceable stock and option transactions.

.

Without knowing what companies were targeted or what demands have been made (if any) it is hard to tell what's going on but it seems like corporate espionage between corporate players.

FANG fight anyone?

Re: Hmm?

Clausewitz4.0

Plausible assessment. Either the op was months/years ago, or players are using masks.

Re: Hmm?

sreynolds

Perhaps because the short term gains for the one being acquired is great?

Anyhow, I worry about the world and the proliferation of Exchange and then hosted mail by google and microsoft 360.

Its time the world did a 180 and get back to hosting email on different platforms.

A single flow'r he sent me, since we met.
All tenderly his messenger he chose;
Deep-hearted, pure, with scented dew still wet--
One perfect rose.

I knew the language of the floweret;
"My fragile leaves," it said, "his heart enclose."
Love long has taken for his amulet
One perfect rose.

Why is it no one ever sent me yet
One perfect limousine, do you suppose?
Ah no, it's always just my luck to get
One perfect rose.
-- Dorothy Parker, "One Perfect Rose"