Thursday, February 20, 2025
Homecyber securityHackers Using Remote Admin Tools To Compromise Organizations With Ransomware

Hackers Using Remote Admin Tools To Compromise Organizations With Ransomware

Published on

SIEM as a Service

Follow Us on Google News

Cybercriminals behind the AvosLocker ransomware attack employed a tactic of infecting organizations through Open-Source Remote Administration Tools.

This method allowed the malware to spread rapidly, potentially compromising sensitive data and systems across the affected networks.

The FBI found a new version of AvosLocker in May of 2023 during their investigations.

AvosLocker Ransomware

AvosLocker is a RaaS (ransomware as a service) group that emerged in the middle of 2021. It has since gained notoriety for attacks on U.S. financial institutions, vital factories, and government buildings, all considered part of the country’s “critical infrastructure.”

Members of the AvosLocker group infiltrate corporate networks by masquerading as genuine software installers or by employing freely available remote system administration tools.

Affiliates of AvosLocker engage in extortion by threatening to leak or publicly disclose the stolen information obtained through data exfiltration.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

AvosLocker Affiliates:

  • Remote system administration tools—Splashtop Streamer, Tactical RMM, PuTTy, AnyDesk, PDQ Deploy, and Atera Agent—as backdoor access vectors [T1133]. 
  • Scripts to execute legitimate native Windows tools [T1047], such as PsExec and Nltest. 
  • Open-source networking tunneling tools [T1572] Ligolo[1] and Chisel[2]. 
  • Cobalt Strike and Sliver[3] for command and control (C2).
  • Lazagne and Mimikatz for harvesting credentials [T1555].
  • FileZilla and Rclone for data exfiltration.
  • Notepad++, RDP Scanner, and 7zip

The FBI developed the following YARA rule to detect the signature of a file known to be enabling malware, based on an analysis by a sophisticated digital forensics group.

NetMonitor.exe is a malware masquerading as a legitimate process and it has the appearance of a genuine network monitoring tool.

The network will get a ping from this persistence utility every five minutes. 

The software for NetMonitor is set up to talk to a specific IP address that acts as its command server through TCP port 443.

During an attack, the communication between NetMonitor and the command server is protected, and NetMonitor works like a reverse facilitator that lets attackers connect to the tool from outside the victim’s network.

The FBI and CISA suggest that companies take steps to protect their computer systems from AvosLocker ransomware attacks. This will help to prevent hackers from stealing important information and causing problems.

Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Take advantage of the free trial to ensure 100% security.

Latest articles

Check Point Software to Open First Asia-Pacific R&D Centre in Bengaluru, India

Check Point Software Technologies Ltd. has announced plans to establish its inaugural Asia-Pacific Research...

PoC Exploit Released for Ivanti Endpoint Manager Vulnerabilities

A recent investigation into Ivanti Endpoint Manager (EPM) has uncovered four critical vulnerabilities that...

Ransomware Trends 2025 – What’s new

As of February 2025, ransomware remains a formidable cyber threat, evolving in complexity and...

Hackers Delivering Malware Bundled with Fake Job Interview Challenges

ESET researchers have uncovered a series of malicious activities orchestrated by a North Korea-aligned...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Check Point Software to Open First Asia-Pacific R&D Centre in Bengaluru, India

Check Point Software Technologies Ltd. has announced plans to establish its inaugural Asia-Pacific Research...

PoC Exploit Released for Ivanti Endpoint Manager Vulnerabilities

A recent investigation into Ivanti Endpoint Manager (EPM) has uncovered four critical vulnerabilities that...

Ransomware Trends 2025 – What’s new

As of February 2025, ransomware remains a formidable cyber threat, evolving in complexity and...