Saturday, December 2, 2023

Hackers Using Automated Attack to Exploit Exchange Server and SQL Injection Vulnerabilities

Recently, cybersecurity analysts at Prodraft’s threat intelligence team detected that the hacker group FIN7 was actively exploiting vulnerabilities in Microsoft Exchange and SQL injection through an automated attack system in an attempt to perform the following illicit activities:-

  • Infiltrate corporate networks in order to steal information.
  • Data theft.
  • Adaptive ransomware attacks based on the financial size of the networks.

For years now, this security organization has closely followed the operations of FIN7. There are a number of details revealed by Prodaft about FIN7’s behind-the-scenes:-

  • The hierarchy at the internal level.
  • Affiliations with a variety of ransomware projects.
  • A new SSH backdoor system.

Attack Modes and Auto-attacking

FIN7 is a Russian-speaking threat group that has been active at least since 2012, and its motivations seem to be financial. 

A number of attacks have been linked to this threat group including:-

  • Attacks on ATMs.
  • The use of teddy bears to conceal malware-carrying USB drives.
  • Hiring pentesters to analyze ransomware attacks by setting up a false cybersecurity firm.
Attack Modes

There is a system for automatic attacks called Checkmarks that has been discovered by Prodaft. So, in this scenario Checkmarks works as a scanner that scans for vulnerabilities that could result in remote code execution or privilege elevation in Microsoft Exchange, including:-

Since June 2021 it’s actively using Checkmarks for finding the corporate networks’ vulnerable endpoints and exploiting them by using PowerShell to drop web shells which enabled FIN7 to gain access to corporate networks.

As part of its attack, FIN7 used multiple exploits, including its own custom code and publicly available Proof Of Concepts, to gain access to the target networks.

There are some other vulnerabilities that can be exploited with the Checkmarks attack platform in addition to the MS Exchange flaws. There is also a SQL injection module that uses SQLMap to scan for potential vulnerabilities on a website that may be exploited.

Following the scanning of over 1.8 million targets with FIN7’s Checkmarks platform, 8,147 companies have already been infiltrated. Here the most interesting thing is that all these companies are mainly based in the United States. 

Communications With the C&C Server

Apart from this, from the retrieved Jabber logs, the security analysts also found extensive evidence that multiple ransomware groups were in communication with FIN7, including:-

  • Darkside
  • REvil
  • LockBit

There is one particular detail that is noteworthy in these logs is that FIN7 is fond of keeping an SSH backdoor on the networks of victims who have been extorted by ransomware, even after paying the demanded ransom. 

While this might be done to sell access to other groups or to test a new attack in the future. As part of FIN7’s arsenal of backdoors, this SSH backdoor is an entirely new sophisticated addition.

As a part of the FIN7 group, Checkmarks is one of the sophisticated platforms that demonstrates just how easy it will be for threat actors to take advantage of public exploits to perform wide-scale attacks that could impact the entire world. 

Further, with the help of this type of platform threat actors are also actively industrializing public exploits.

Secure Web Gateway – Web Filter Rules, Activity Tracking & Malware Protection – Download Free E-Book

Website

Latest articles

Active Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns

The CISA announced two known exploited vulnerabilities active attacks targeting Google Chrome & own...

Cactus Ransomware Exploiting Qlik Sense code execution Vulnerability

A new Cactus Ransomware was exploited in the code execution vulnerability to Qlik Sense...

Hackers Bypass Antivirus with ScrubCrypt Tool to Install RedLine Malware

The ScrubCrypt obfuscation tool has been discovered to be utilized in attacks to disseminate the RedLine Stealer...

Hotel’s Booking.com Hacked Logins Let Attacker Steal Guest Credit Cards

According to a recent report by Secureworks, a well-planned and advanced phishing attack was...

Critical Zoom Vulnerability Let Attackers Take Over Meetings

Zoom, the most widely used video conferencing platform has been discovered with a critical...

Hackers Using Weaponized Invoice to Deliver LUMMA Malware

Hackers use weaponized invoices to exploit trust in financial transactions, embedding malware or malicious...

US-Seized Crypto Currency Mixer Used by North Korean Lazarus Hackers

The U.S. Treasury Department sanctioned the famous cryptocurrency mixer Sinbad after it was claimed...

API Attack Simulation Webinar

Live API Attack Simulation

In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how APIs could be hacked.The session will cover:an exploit of OWASP API Top 10 vulnerability, a brute force account take-over (ATO) attack on API, a DDoS attack on an API, how a WAAP could bolster security over an API gateway

Related Articles