Cyber Security News

Threat Actors Exploiting Legitimate Software For Stealthy Cyber Attacks

CAMO, or Commercial Applications, Malicious Operations, highlights attackers’ increasing reliance on legitimate IT tools to bypass security defenses, which can be used for various malicious activities like ransomware distribution, network scanning, lateral movement, and C2 establishment.

It can mislead security personnel during investigations, leading to successful compromises. Organizations should use GreyMatter Hunt packages to establish a baseline of existing IT tools, detect malicious activity, and implement appropriate mitigation measures to prevent such attacks.

The Relia Quest report highlights a significant increase in the misuse of commercial applications for malicious operations (CAMO) by threat actors.

These applications, once legitimate tools for IT management and deployment, are now being exploited to advance attacks and evade detection.

It emphasizes the need for organizations to recognize and mitigate the risks associated with CAMO by implementing robust security measures, including policies, controls, and threat detection capabilities.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

By understanding the techniques used by attackers and proactively addressing these threats, organizations can better protect their valuable assets and reduce the likelihood of successful cyberattacks.

CAMO vs. LOLBAS

CAMO, a stealthy attack technique, leverages legitimate software’s intended functions for malicious purposes.

Unlike LOLBAS, which relies on native system utilities, CAMO employs open-source, freely available, or illegally modified tools, which often possess valid code-signing certificates, evading security policies.

Organizations’ incomplete tool inventories and the tools’ legitimate nature hinder detection, which allows attackers to operate undetected, complicating threat response and increasing the risk of successful attacks.

Cybercriminals frequently discuss the use of legitimate tools for malicious purposes on online forums, which found that adversaries commonly employ software deployment tools like PDQ Deploy, cloud storage tools like Rclone, network scanners like SoftPerfect, and remote management tools like AnyDesk for covert operations.

Forum user asks for advice on resolving PDQ Deploy issues

These tools offer advantages like evading detection and reducing the barrier to entry for less skilled attackers, reads the Relia Quest report.

The widespread sharing of cracked versions of these tools further facilitates their abuse, enabling attackers to launch damaging attacks without significant investment.

The threat actors in the analyzed cases employed CAMO techniques to avoid detection and hinder investigations.

By leveraging legitimate tools like PDQ Deploy and Total Software Deployment, they blended malicious actions into routine network operations.

Total Software Deployment user interface

PDQ Deploy was used to spread ransomware, while Total Software Deployment facilitated lateral movement through the installation of ScreenConnect.

These CAMO tools challenged traditional defensive measures, emphasizing the importance of implementing network segmentation and application whitelisting to mitigate such threats.

AnyDesk user interface

The “Inc Ransom” and “Black Basta” ransomware groups exploited legitimate IT tools, SoftPerfect and AnyDesk, to compromise systems and exfiltrate data.

SoftPerfect was used to scan networks and identify vulnerabilities, while AnyDesk provided remote access for malicious activity that was employed to evade detection and blend into legitimate operations.

According to Relia Quest, to mitigate these threats, organizations should block unauthorized cloud services, restrict RMM tools, and monitor suspicious activity.

Simulating Cyberattack Scenarios With All-in-One Cybersecurity Platform – Watch Free Webinar

Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as "GruesomeLarch"…

2 days ago

240+ Domains Used By PhaaS Platform ONNX Seized by Microsoft

Microsoft's Digital Crimes Unit (DCU) has disrupted a significant phishing-as-a-service (PhaaS) operation run by Egypt-based…

2 days ago

Russian TAG-110 Hacked 60+ Users With HTML Loaded & Python Backdoor

The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in Central…

2 days ago

Earth Kasha Upgraded Their Arsenal With New Tactics To Attack Organizations

Earth Kasha, a threat actor linked to APT10, has expanded its targeting scope to India,…

2 days ago

Raspberry Robin Employs TOR Network For C2 Servers Communication

Raspberry Robin, a stealthy malware discovered in 2021, leverages advanced obfuscation techniques to evade detection…

2 days ago

145,000 ICS Systems, Thousands of HMIs Exposed to Cyber Attacks

Critical infrastructure, the lifeblood of modern society, is under increasing threat as a new report…

3 days ago