HomeCyber BalkansNo EDR, No Problem: How Huntress Reconstructed an Akira Ransomware Attack from...

No EDR, No Problem: How Huntress Reconstructed an Akira Ransomware Attack from Forensic Evidence

Published on

spot_img

In the realm of cybersecurity, incident responders often find themselves confronting the aftermath of attacks rather than witnessing their unfoldings in real-time. Such was the case for Huntress, a cybersecurity firm, in September when they were summoned to a situation involving Akira ransomware that had already compromised an organization. The unfortunate aspect of this scenario was that Huntress’s endpoint detection and response (EDR) tools were deployed post-attack, providing limited visibility into the initial intrusion, reconnaissance, credential theft, and subsequent moves made by the attackers.

A post-compromise installation complicates investigations significantly, as the EDR telemetry typically vital for tracing the attacker’s steps is absent. However, in a recent analysis by Huntress researcher Harlan Carvey and his colleagues, it became evident that while certain data streams are missing, this does not equate to a lack of evidence. The team adeptly demonstrated that remnants of the attack could still be pieced together from residual artifacts left on the system.

The Initial Signs of Compromise

The alarm was raised almost immediately after the Huntress agent went live. An EDR signal was triggered on a domain controller, revealing the presence of an executable named svchost.exe, running under the SYSTEM account from a temporary directory, specifically C:\PerfLogs\Temp. This executable was later identified as a binary associated with GOST (Go Simple Tunnel), an open-source tool renowned for creating proxies and tunnels and previously linked with activities by Akira affiliates.

As the investigation unfolded, it became clear that reconstructing the details of the attack would rely on a painstaking review of what remained on the disk: Windows Event Logs, Registry artifacts, and logs generated by the ransomware itself. This forensic detour was necessary to build a timeline of the attack sequence.

Deconstructing the Kill Chain

The evidence gleaned from event logs indicated that the attacker had gained access to the environment via a Remote Desktop Protocol (RDP) connection from a workstation that was not part of the organization’s network, identified by the hostname C1IFRYXI. Shortly thereafter, the attackers accessed the Bitdefender console and disabled four critical Bitdefender services, with each stoppage recorded in the Service Control Manager’s events.

This marked the beginning of a sequence that aligns with familiar ransomware tactics:

  1. Credential Access: The svchost.exe was likely employed to dump Local Security Authority Subsystem Service (LSASS) memory, facilitating credential gathering.
  2. Persistence: The GOST tunnel was established, establishing a communication channel with an external IP address, specifically 64.227.4[.]134.
  3. Exfiltration: In the same directory, Rclone—a tool known for syncing data—was run, indicative of data being sent to cloud storage.
  4. Impact: Following these exploitative actions, Akira was unleashed on the organization’s file shares, culminating the attack cycle.

The Challenge of Evidence Collection

Due to the absence of process telemetry, no recorded command lines related to the ransomware execution were available. Instead, the researchers had to depend on what they termed ‘toolmarks’: the distinct side effects left behind by the tools in use. Notably, shellbags revealed the attacker’s navigation through subfolders designated for sharing. Concurrently, PowerShell event logs documented commands that deleted volume shadow copies—an established tactic employed by Akira to inhibit recovery options.

Remarkably, as encryption progressed, the shellbags displayed an attacker opening one of the now-encrypted subfolders within Windows Explorer, seemingly confirming that the encryption had been successfully executed. This cycle of access, deletion of shadow copies, logging activity, and visual confirmation occurred repeatedly. Approximately four hours post-initial encryption, the GOST tunnel was finalized, ensuring the intruders maintained access.

Recommendations for Defenders

In light of these findings, Huntress provided practical recommendations aimed at empowering organizations in the face of potential threats:

  • Maintain a detailed inventory of both physical and virtual systems as well as applications.
  • Actively work to reduce the attack surface, minimizing entry points and enhancing overall security.
  • Implement multifactor authentication (MFA) for any remote access that must be made available.
  • Monitor for logins originating from unknown or suspicious workstations.
  • Scrutinize directories such as C:\PerfLogs for the creation and execution of new executables.

This comprehensive analysis, inclusive of indicators of compromise and file hashes pertinent to both the Akira payload and the GOST binary, is extensively documented on the Huntress blog. By shedding light on the incident, Huntress underscores the critical nature of vigilance and proactive measures in the ever-evolving landscape of cybersecurity.

The original article can be located on IT Security Guru, highlighting a methodical approach to understanding and responding to ransomware attacks, even in the absence of traditional detection tools.

Source link

Latest articles

GhostAction Hackers Compromise Over 500 GitHub Accounts to Steal Cloud and AI API Credentials

Recent GhostAction Campaign Compromises Over 500 GitHub Accounts: A Comprehensive Analysis In a troubling development...

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools, and 12 Additional Stories

The realm of cybersecurity is continually evolving, revealing a striking juxtaposition between the blunders...

Danish CPR Breach Sheds Light on Supply Chain Risk Challenges

Major Cyber Breach in Denmark Exposes Personal Data of Millions A significant cybersecurity breach has...

US Disrupts China-Linked Integrity Technology Cyber Espionage Tool

Significant Disruption in Cybersecurity: U.S. Authorities Seize Hacking Tools Linked to Chinese Contractor In a...

More like this

GhostAction Hackers Compromise Over 500 GitHub Accounts to Steal Cloud and AI API Credentials

Recent GhostAction Campaign Compromises Over 500 GitHub Accounts: A Comprehensive Analysis In a troubling development...

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools, and 12 Additional Stories

The realm of cybersecurity is continually evolving, revealing a striking juxtaposition between the blunders...

Danish CPR Breach Sheds Light on Supply Chain Risk Challenges

Major Cyber Breach in Denmark Exposes Personal Data of Millions A significant cybersecurity breach has...