Cybersecurity researchers link attackers to the Iranian-backed APT group “Agonizing Serpens,” which has upgraded its capabilities and uses various tools to bypass security measures.
Hackers target and steal sensitive data for various reasons, including:
They may sell the stolen data on the black market, use it for blackmail, or exploit it for fraudulent activities. Unit 42 researchers recently discovered a series of cyberattacks targeting Israeli education and tech sectors, aiming to steal data and render endpoints unusable.
Iranian-linked APT Agonizing Serpens has been active since 2020, using wipers and fake ransomware in attacks targeting Israeli organizations. They aim to steal data and disrupt business continuity, often publishing stolen info on social media.
Here below, we have mentioned the other names of Agonizing Serpens:-
Attackers exploited web servers for initial access, deploying web shells. These shells, similar to past Agonizing Serpens attacks, conducted reconnaissance and network mapping using common scanners that are publicly available.
Basic reconnaissance commands via the web shells (Source – Unit 42)
Here below we have mentioned the scanners:-
The attackers attempted to gain admin credentials, but Cortex XDR blocked their methods. Here below we have mentioned all the attempted methods:-
The attackers employed Plink (as systems.exe) for lateral movement, aimed at data theft and wiper execution. They used tools like WinSCP and Putty, along with a custom sqlextractor (sql.net4.exe) for exfiltration.
Here below we have mentioned the types of data extracted:-
The attackers tried using WinSCP and pscp.exe for file exfiltration, seeking specific file types containing stolen data.
The group tried to bypass EDR, but Cortex XDR blocked their attempts. They used various known techniques not seen in previous attacks, indicating increased sophistication.
The attackers used a custom tool called agmt.exe, likely derived from drvIX based on the PDB path. Agmt.exe is a custom loader for the GMER driver, AGMT.sys. It can terminate a specified target process by registering and starting the AGMT service.
After failing to exploit the GMER driver, the attackers turned to the drvIX tool, leveraging a new vulnerable driver from a public PoC tool called BadRentdrv2.
Cybersecurity researchers at Unit 42 found the following new wipers and tools used by the operators of the Agonizing Serpens group:-
Patch Manager Plus: Automatically Patch over 850 third-party applications quickly – Try Free Trial.
Microsoft has removed two widely-used Visual Studio Code (VS Code) extensions, “Material Theme Free” and…
A new ransomware group, dubbed Anubis, has emerged as a significant threat in the cybersecurity…
A new wave of cyberattacks targeting WordPress websites has been uncovered, with attackers leveraging fake…
A newly identified cybercriminal group, LARVA-208, also known as EncryptHub, has successfully infiltrated 618 organizations…
A new wave of sophisticated cyberattacks targeting macOS systems has been identified, involving two malware…
The modern cybersecurity landscape is witnessing an unprecedented surge in sophisticated attack techniques, with adversaries…