Archive for GuidePoint

Increased Risk Among Immature Threat Actors, Ransomware Operators: Research From GuidePoint Security

Posted in Commentary with tags on April 11, 2024 by itnerd

GuidePoint Security has released new research intelligence that explores the differences between the ransomware groups we “see on TV” – the large, established, and well-resourced RaaS operations – and the smaller, ad hoc, opportunistic, or “immature” ransomware groups that operate more quietly, generally impacting less well-defended victims. 

GuidePoint Security’s researchers highlight the increased risks and behaviors associated with such groups and provide two case studies of immature, high-risk groups – Phobos and DATAF LOCKER – that they observed during recent incident response efforts.

Popular images, depictions, and understanding of modern ransomware groups often focus on the largest and most established groups, maintaining media attention through high-profile attacks and sensationalist extortion tactics. 

While this segment of the ransomware ecosystem exists and remains, relevant, immature ransomware groups operating on the fringe continue to harm smaller and less well-defended organizations, often without a recognizable brand or name to aid in attributing and ascribing deceitful behavior. 

You can read the research here.

New Attack Path Exploits Microsoft SCCM: Researchers Discover Undocumented Way to Compromise Account Privileges

Posted in Commentary with tags on March 28, 2024 by itnerd

GuidePoint Security has unveiled the discovery of an undocumented way to compromise an account and elevate privileges inside an SCCM (System Center Configuration Manager) – aka Microsoft Endpoint Configuration Manager (MECM) – network. 

GuidePoint Security’s Threat & Attack Simulation (TAS) team detected SCCM exploitation for account compromise, finding the conditions that can compromise SCCM client push and machine accounts through automatic site-wide client push installation and Active Directory system discovery. 

Due to the permissions these accounts hold, this can lead to an SCCM site takeover or, in the case of the SCCM push account, administrative privileges over numerous computer objects within the domain.

The TAS researchers are the first to find this novel attack path across the industry in SCCM, an endpoint management tool. 

With certain conditions explained, an attacker may be able to retrieve the hashed credentials for all configured SCCM push accounts, meaning they may be able to access admin privileges.

You can read about this here.

GuidePoint Security Details RaaS Recruitment Efforts Following Law Enforcement Disruption Of Other RaaS Groups

Posted in Commentary with tags on March 20, 2024 by itnerd

GuidePoint Security has revealed that it has discovered three RaaS groups attempting to recruit new members through advertisements on illicit forums on the dark web following Alphv and LockBit law enforcement disruptions, identifying Cloak on UFO Labs and Medusa and RansomHub on the Russian-language RAMP forum for posting ads. 

Each ad had a boilerplate with a short group description, ransom split rates, and contact for TOX. Cloak’s ad was the least remarkable, with few unique features that entice a potential affiliate with options. Medusa was particularly appealing with a sliding payout scale and affiliate/core split dependent on the size of the ransom payment obtained, incentivizing the appearance of high ransom demands. RansomHub was less materialistic, implicitly addressing the crisis of confidence in RaaS groups by declaring that its affiliates could collect ransom payments directly before paying the core group a 10% fee.

GuidePoint Security’s analysis observations include signs of distrust and discontent among RaaS groups and affiliates, indicating that the model is increasingly scrutinized.

You can read the report here.

Novel PowerShell Backdoor Discovered By GuidePoint Security

Posted in Commentary with tags on March 10, 2024 by itnerd

GuidePoint Security has revealed its first encounter with BianLian’s PowerShell backdoor – the first encounter in 2024 to be reported publicly thus far.

GuidePoint Security’s Research and Intelligence Team (GRIT) discovered malicious activity while responding to an incident that began with the exploitation of TeamCity vulnerabilities for initial access, resulting in deploying a novel implementation of a PowerShell backdoor.

Through their analysis, GuidePoint Security ultimately identified the threat actor group behind the attack and provided highly confident attribution to the BianLian ransomware group.

In this technical blog, Drew Schmitt, Practice Lead, GRIT, breaks down BianLian’s use of a novel PowerShell backdoor following the exploitation of TeamCity vulnerabilities.

The research deep dives into BianLian’s exploitation of TeamCity vulnerabilities and post-exploitation behaviors, BianLian’s PowerShell implementation of their GO backdoor, and attribution of the PowerShell backdoor to BianLian.

You can read the details in their new blog, now live at https://www.guidepointsecurity.com/blog/bianlian-gos-for-powershell-after-teamcity-exploitation/.

GuidePoint Security Announces Portfolio of Data Security Governance Services

Posted in Commentary with tags on January 30, 2024 by itnerd

GuidePoint Security today announced the availability of its Data Security Governance services, which are designed to help customers address the challenges of unstructured data and data sprawl through a proven process and program to meet their unique needs.

GuidePoint’s Data Security Governance services consist of policies, standards, and processes leveraging the newest technologies to meet organizations’ data governance goals in both on-prem and cloud environments. Once the right strategy is determined with the customer, GuidePoint Security consultants will review program requirements, assess current policies and controls, perform gap analysis, design and develop/enhance the program, recommend and implement supporting technologies, and create operational processes and metrics.

GuidePoint’s Data Security Governance Services include:

  • Sensitive Data Cataloging: For organizations just getting started in the process of protecting their sensitive data, GuidePoint offers Data Identification workshops to identify sensitive data types in the environment, including trade secrets, intellectual property, and sensitive business communications.
  • Data Security Governance Program Assessment: For organizations with existing Data Security Governance or Data Protection programs, GuidePoint Security experts will assess the program to identify policy non-compliance, gaps in data protection requirements—whether legal, regulatory, contractual, or business—and program maturity levels.
  • Data Security Governance Program Strategy Development: The GuidePoint team will work with an organization’s key stakeholders to design a program strategy aligned with relevant requirements. The outputs of this effort include delivering ongoing sensitive data discovery, automated classification and labeling, the application of required sensitive data protections, restrictions on where sensitive data can be stored and sent, and data retention policy enforcement.
  • Merger and Acquisition Data Identification: This offering provides the ability to identify sensitive data within an M&A target or recent acquisition (including locations, amounts, and access rights) and then perform penetration testing on the storage repositories where that sensitive data exists to determine the risk of data compromise.

For more information on GuidePoint Security’s Data Security Governance services:

GuidePoint Research and Intelligence Team’s (GRIT) Annual Ransomware Report Is Out 

Posted in Commentary with tags on January 25, 2024 by itnerd

GuidePoint Security has announced the release of GuidePoint Research and Intelligence Team’s (GRIT) 2023 Annual Ransomware Report. This report is based on data obtained from publicly available resources, including threat groups themselves, and insight into the ransomware threat landscape. GRIT observed a victim volume nearly doubling year-over-year, driven in part by multiple mass exploitation campaigns impacting hundreds of organizations. In total, GRIT observed 63 distinct ransomware groups leverage encryption, data exfiltration, data extortion, and other novel tactics to compromise and publicly post 4,519 victims across all 30 of GRIT’s tracked industries, and in 120 countries.

GRIT’s Annual Ransomware Report also examines major ransomware events throughout the year including Clop’s MOVEit campaign, Scattered Spider’s attacks on major casinos, LockBit’s new Affiliate Rules regarding ransom negotiations, SEC’s new guidance for incident notifications, law enforcement’s disruption of Alphv operations, and published decryptors impacting ransomware operations for BianLian and Akira. 

Key Highlights of the Report:

  • From an industry perspective, GRIT observed most impacts affecting a limited subset of industries. 62% of all observed victims belong to one of the “top ten” most-impacted industries, with Manufacturing and Technology remaining the two most-impacted industries; Manufacturing and Technology represented 12.9% and 7.9% of all victims, respectively. Among Manufacturing industry victims, the US was impacted five times as much as the next highest country, Germany (265 vs 48 victims). Manufacturing was the most impacted industry for almost every month in 2023, excluding May, when it placed behind Technology by a single observed victim. 
  • The United States was by far the most impacted country in 2023. Among posted victims, 2,199 were US-based organizations, accounting for 49% of all observed ransomware attacks in 2023. Eight out of the ten most impacted countries were within North America and Europe, with Brazil and Australia as the sole outliers. The same “top ten” most impacted countries were home to 76% of all observed victim organizations, of which 27% impacted non-US countries.
  • In line with GRIT’s taxonomy for classifying ransomware groups, long-term Established groups accounted for the overwhelming majority of observed victims (85%), followed by Developing groups (10%). The top three most prolific Established groups—LockBit, Alphv, and Clop—continue to account for not just the lion’s share of victims but also much of the innovation and tactical changes across the ransomware ecosystem. Ephemeral and Emerging groups, as the newest and shortest-term entrants, lagged behind their maturing counterparts but still posed a significant threat to worldwide organizations, exacerbated by less “reliable” actors and frequently recycled malware. 

For more information on GRIT’s 2023 Annual Ransomware Report:

GuidePoint Security Releases Their November Ransomware Report

Posted in Commentary with tags on December 14, 2023 by itnerd

GuidePoint Security has released the GuidePoint Research and Intelligence Team’s (GRIT) November 2023 Ransomware Report, analyzing ransomware by country, industry/threat actor trends, and notable events, including:

  • November Ransomware Trends: Total observed victims increased by 32% and exceeded the calendar year 2023 average by only 16%, while the rolling average increased by only 6%, indicating a relatively consistent pace of operations since Q2.
  • Threat Actor Trends: GRIT also observed a marginal decrease in active ransomware groups. However, this was influenced by the arrival and drop-off of several smaller emerging groups, and 82% of victims were attributed to ransomware groups that have operated for at least six months.
  • Victims by Country: The US accounted for nearly half (48%) of last month’s victims; the Netherlands is in the top 10 again, accounting for 21% of its total victim count in 2023; Canada saw a decrease in victims, typically ranking in the top 3, but fell to #6; Germany saw a spike in attacks, returning to the top 5. 
  • Increased Ransomware Impact: Nearly a quarter of 2023’s ransomware attacks against China took place in November, impacting energy, automotive, legal, and pharmaceutical industries, a departure from the most frequently affected manufacturing industry, further complicating this potential anomaly.
  • Most Targeted Industries: Yet again, Manufacturing was the most targeted industry. Healthcare came in second, followed by Retail and Wholesale, Transportation, and Education to round out the top 5 most targeted sectors in November 2023.

You can read the report here.

GuidePoint Security’s October 2023 Ransomware Report Is Out

Posted in Commentary with tags on November 16, 2023 by itnerd

GuidePoint Security has released the GuidePoint Research and Intelligence Team’s (GRIT) October 2023 Ransomware Report, revealing a 32% decrease in ransomware victims. The report analyzes ransomware by country, industry/threat actor trends, and notable events, including:

  • The US, still the most impacted nation by victim count, experienced an 83% decrease since last month. Germany saw a massive 76% decline. The UK saw 43% more than its average across 2023. Iran stood out this month, with October representing its second-highest monthly total.
  • Once again, manufacturing was the most targeted industry, and retail came in second. Ransomware groups regularly target the sensitive education and healthcare verticals, which saw a slight but notable decrease of 14% yet continue to appear in the top five.
  • LockBit’s ransomware victim count was 24% lower than its average monthly count in 2023. In October, the threat actor spotlight was on NoEscape, whose victims saw an almost 50% increase. In addition, Alphv’s activity decreased by 44%

You can read the full report here.

GuidePoint Research and Intelligence Team’s (GRIT) 2023 Q3 Ransomware Report Is Out

Posted in Commentary with tags on October 19, 2023 by itnerd

GuidePoint Security, a cybersecurity solutions leader enabling organizations to make smarter decisions and minimize risk, today announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q3 2023 Ransomware Report. This report is based on data obtained from publicly available resources, including threat groups themselves, and insight into the ransomware threat landscape. GRIT observed a nearly 15% increase in ransomware activity since Q2 due to an increased number of ransomware groups, including 10 new Emerging groups tracked during this quarter. In the third quarter, GRIT tracked 1,353 publicly posted ransomware victims claimed by 46 different threat groups. Through the first three quarters of 2023, GRIT has tracked a total of 3,385 publicly posted ransomware victims claimed by 57 different threat groups, representing an 83% YoY increase.

GRIT’s latest Ransomware Quarterly Report examines the large-scale ransomware attacks against MGM Resorts and Caesars Entertainment, highlighting possible seasonal targeting of the Entertainment, Hospitality, and Tourism (EHT) industry. Other notable Q3 ransomware events included the end of Clop’s MOVEit campaign, LockBit’s return to a high operational tempo, and Bianlian’s sustained capabilities despite moving to an exfiltration-only model, all of which have contributed to this quarter’s rise in ransomware activity.

Key Highlights of the Report:

  • The Manufacturing and Technology industries were the 1st and 2nd most impacted by ransomware, followed by Retail & Wholesale as the 3rd most impacted. The Retail & Wholesale vertical has experienced a steady quarterly climb in observed victims throughout the year, jumping from 9th place with 38 victims in Q1 to its current spot in the top three with 98 victims. 
  • While US-based organizations saw an increase in total observed victim count in Q3 2023, the percentage of attacks directed against US-based organizations – decreased by 3.3%, reflecting a marked increase in attacks impacting other nations. In particular, United Kingdom-based organizations saw an increase from 59 victims in Q2 to 83 in Q3, an approximate 40.7% quarter-over-quarter increase.
  • The top three most active ransomware groups were Lockbit, Clop, and Alphv. LockBit posted roughly the same number of victims in Q2 as in Q3, totaling 770 victims for the year thus far. Clop activity in Q3 stemmed almost entirely from its mass exploitation of a vulnerability in the MOVEit managed file transfer software, which resulted in a 5% total increase in victims from Q2 to Q3. While Alphv experienced a modest decrease in total victim volume and market share between Q2 and Q3, it retained its position as one of the most impactful ransomware groups, claiming responsibility for more than 10 healthcare victims as well as the MGM resorts breach.
  • Two of the top 10 most active ransomware groups, Bianlian and Akira, have continued to be impactful despite each group having a public decryptor released by security researchers in 2023.

For more information on GRIT’s 2023 Q3 Ransomware Report:

Threat Actors Are Abusing Cloudflare Tunnel in New Effort to Use Legitimate Tools for Attacks

Posted in Commentary with tags on August 3, 2023 by itnerd

Nic Finn, Senior Threat Intel Consultant at GuidePoint Security, released new research, which you can read here identifying a new legitimate tool that threat actors are using to execute attacks – Cloudflare Tunnel, also known by its executable name, Cloudflared. 

Background: Cloudflared is functionally very similar to ngrok, an ingress-as-a-service tool that’s been used by Threat Actors for quite some time now. However, Cloudflared differs from ngrok in that it provides a lot more usability for free, including the ability to host TCP connectivity over Cloudflared. Additionally, Cloudflared provides the full suite of Access controls, Gateway configurations, Team Management, and User Analytics.

Why this Matters: This tool is a legitimate binary, supported on every major operating system, and the initial connection is initiated through an outbound HTTPS connection to Cloudflare-owned infrastructure, followed by data exchanged to tunnel connections over QUIC on port 7844. This means that most firewalls or network-based defenses will allow this traffic, as most firewall rules are far more relaxed toward outbound connections. Threat Actors don’t have to expose any of their infrastructure, except the token assigned to their tunnel, to anyone except Cloudflare prior to a successful connection, and their ability to modify the configuration of the tunnel in real time means post-breach analysis is severely limited if the TA covers their tracks.