Site icon TheCyberThrone

Ransomware groups emerging in using initial access brokers

SSUCv3H4sIAAAAAAAACpxSwW7DIAy9T9o/RJwbCZI0S/Yr1Q4OOA0agQrIpqrqvw+SMNFJk6bd8PN7tp/N7fmpKMgATnLyWtxiFGKp1OK8BS+NDjA77LhFLdAGhCYEhfTGSlA5OIDnk4YZA6gXpSJ8X5PEefCLQ5c1A2EGdN7w9wDWGZeDx3Mo/sBOo562uEiJNRkUIUXIIcPcMqxYgrbi/1Juj7dkE86o+TXOds+mtqgQNoenjUrePz3ae

Advertisements

The FBI has warned that ransomware attackers are targeting third party vendors and services to compromise businesses.

Two emerging initial access techniques are being utilized by threat actors to infect targets with ransomware as of July 2023:

Exploitation of Vulnerabilities in Third Party Vendors

Increasing trend seen with ransomware attacks targeting casinos through third-party gaming vendors between 2022 and 2023. These frequently targeted small and tribal casinos, encrypting servers and the personally identifying information (PII) of employees and patrons.

Advertisements

Targeting of Legitimate System Management Tools

Attackers are targeting manaement tools to elevate their network permissions in the target organization.

The Silent Ransom Group, in one of the campaigns, began by sending phishing messages to victims containing a phone number, which is usually related to pending charges on the victims’ accounts.

Once the target called the phone number, the malicious actors directed them to join a legitimate system management tool via a link provided in a follow-up email. The attackers then used the tool to install other system management tools, which they repurposed for malicious activities. This allowed them to compromise local files and network shared drives, exfiltrate victim data and extort the companies.

Advertisements

Recommendations  for network defenders to protect their organization against these emerging initial access techniques.

Exit mobile version