GuidePoint Security has unveiled the discovery of an undocumented way to compromise an account and elevate privileges inside an SCCM (System Center Configuration Manager) – aka Microsoft Endpoint Configuration Manager (MECM) – network.
GuidePoint Security’s Threat & Attack Simulation (TAS) team detected SCCM exploitation for account compromise, finding the conditions that can compromise SCCM client push and machine accounts through automatic site-wide client push installation and Active Directory system discovery.
Due to the permissions these accounts hold, this can lead to an SCCM site takeover or, in the case of the SCCM push account, administrative privileges over numerous computer objects within the domain.
The TAS researchers are the first to find this novel attack path across the industry in SCCM, an endpoint management tool.
With certain conditions explained, an attacker may be able to retrieve the hashed credentials for all configured SCCM push accounts, meaning they may be able to access admin privileges.
You can read about this here.
Increased Risk Among Immature Threat Actors, Ransomware Operators: Research From GuidePoint Security
Posted in Commentary with tags GuidePoint on April 11, 2024 by itnerdGuidePoint Security has released new research intelligence that explores the differences between the ransomware groups we “see on TV” – the large, established, and well-resourced RaaS operations – and the smaller, ad hoc, opportunistic, or “immature” ransomware groups that operate more quietly, generally impacting less well-defended victims.
GuidePoint Security’s researchers highlight the increased risks and behaviors associated with such groups and provide two case studies of immature, high-risk groups – Phobos and DATAF LOCKER – that they observed during recent incident response efforts.
Popular images, depictions, and understanding of modern ransomware groups often focus on the largest and most established groups, maintaining media attention through high-profile attacks and sensationalist extortion tactics.
While this segment of the ransomware ecosystem exists and remains, relevant, immature ransomware groups operating on the fringe continue to harm smaller and less well-defended organizations, often without a recognizable brand or name to aid in attributing and ascribing deceitful behavior.
You can read the research here.
Leave a comment »