Security researchers have reported an increase in devices infected with the TrueBot malware downloader created by a Russian-speaking hacking group called Silence.
The threat actors have shifted from using malicious emails as their primary attack vector to other techniques. They are also using a new custom data exfiltration tool called Teleport.
The researchers at Cisco Talos analyzed Silence’s attacks over the past months and it was found that the gang delivered Clop ransomware.
Silence hackers have planted their malware on more than 1,500 systems across the world to fetch shellcode, Cobalt Strike beacons, the Grace malware, the Teleport exfiltration tool, and Clop ransomware.
In few attacks between August and September, the hackers infected systems with Truebot (Silence.Downloader) after exploiting a critical vulnerability in Netwrix Auditor servers tracked as CVE-2022-31199.
In October 2022, the gang switched to using USB drives to infect computers with the Raspberry Robin worm, which often delivered IcedID, Bumblebee, and Truebot payloads.
A report from Microsoft in October has linked the worm with the distribution of Clop ransomware by a threat actor they track as DEV-0950, whose malicious activity overlaps with that of FIN11 and TA505 (known for using Clop in extortion attacks).
Cisco Talos notes that the Truebot gang used Raspberry Robin to infect more than 1,000 hosts, many of them desktops not accessible over the public web, mainly in Mexico, Brazil, and Pakistan.
Truebot is a first-stage module that can collect basic information and take screenshots. It also exfiltrates Active Directory trust relations information that helps the threat actor plan post-infection activity.
The command and control (C2) server can then instruct Truebot to load shellcode or DLLs in memory, execute additional modules, uninstall itself, or download DLLs, EXEs, BATs, and PS1 files.
The researchers noticed a set of commands to exfiltrate stolen data through a previously unknown custom tool dubbed Teleport. The analysis of the commands issued via Teleport reveals that the tool is used by the attackers to collect files from OneDrive and Downloads folders, and from the victim’s Outlook email messages.
In some cases, the attackers deploy the Clop ransomware after moving laterally to as many systems as possible with the help of Cobalt Strike.
Image Credits : Cypfer

















Comments