home.social

#backconnect — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #backconnect, aggregated by home.social.

  1. Happy Monday everyone!

    Today's #readoftheday is brought to you by Trend Micro and they share their findings related to #BlackBasta and #CactusRansomware adding a piece of malware known as #BackConnect to their toolbox.

    The report states "The BackConnect malware is a tool that cybercriminals use to establish and maintain persistent control over compromised systems. Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute commands on the infected machine. This enables them to steal sensitive data, such as login credentials, financial information, and personal files."

    Behaviors (MITRE ATT&CK):
    Initial Access - TA0001:
    Phishing: Spearphishing Voice - T1566.004 - The attackers conducted an email bombing campaign then contacted the victim posing as "IT Support" or "HelpDesk".

    Command and Control - TA0011:
    Remote Access Software - T1219 -
    The attackers used QuickAssist to access the victim's environment once they were successfully social engineered.

    Lateral Movement - TA0008:
    Remote Services: SMB/ Windows Admin Shares - T1021.002 -
    Remote Services: Windows Remote Management - T1021.006
    The attackers leveraged both SMB, shared folders, and WinRM for lateral movement.

    Go check out the rest of the technical details! Enjoy and Happy Hunting!

    Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
    trendmicro.com/en_us/research/

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting

  2. CapLoader wasn’t designed as an alternative to a traditional NIDS, but the Alerts tab often gives a VERY good overview of the malicious traffic. Here’s a screenshot of CapLoader’s alerts for some recent PCAP files from malware-traffic-analysis.net.

    #Lumma #GootLoader #AgentTesla #RURAT #Remcos #RedLine #BackConnect

  3. Here’s what CapLoader’s Alerts tab looks like after loading 2023-10-16-IcedID-infection.pcap from @malware_traffic. The malicious protocol alerts for GzipLoader, #BackConnect and #IcedID over TLS are obvious indicators of IcedID. But what about the periodic connections made every 5 minutes?
    netresec.com/?b=23B6bcd

  4. Here's the decrypted #IcedID #BackConnect traffic from @malware_traffic latest #PCAP. It was just a bunch of "SLEEP 60 seconds" commands this time 😞​

  5. Attacker launches #BackConnect C2 on #IcedID infected machine and starts a reverse VNC session. The VNC session is used to download #CobaltStrike binary http64.exe from 85.209.11.48 and save it as “http.exe”. Cobalt Strike beacon is then executed from the command line.

    For more details and the original #pcap file, see @malware_traffic’s toot here:
    infosec.exchange/@malware_traf

  6. This #IcedID #BackConnect C2 server keeps telling the bot to sleep for 60 seconds. This goes on for 3 hours. No reverse shell, no VNC, no file manager 😿

    HELLO #TA577, IT’S TIME TO WAKE UP!!

  7. This #IcedID #BackConnect C2 server keeps telling the bot to sleep for 60 seconds. This goes on for 3 hours. No reverse shell, no VNC, no file manager 😿

    HELLO #TA577, IT’S TIME TO WAKE UP!!

  8. This #IcedID #BackConnect C2 server keeps telling the bot to sleep for 60 seconds. This goes on for 3 hours. No reverse shell, no VNC, no file manager 😿

    HELLO #TA577, IT’S TIME TO WAKE UP!!

  9. This #IcedID #BackConnect C2 server keeps telling the bot to sleep for 60 seconds. This goes on for 3 hours. No reverse shell, no VNC, no file manager 😿

    HELLO #TA577, IT’S TIME TO WAKE UP!!

  10. This #IcedID #BackConnect C2 server keeps telling the bot to sleep for 60 seconds. This goes on for 3 hours. No reverse shell, no VNC, no file manager 😿

    HELLO #TA577, IT’S TIME TO WAKE UP!!

  11. NetworkMiner 2.8.1 released today! It now extracts:
    🖥️ #VNC desktop graphics
    🐀 #njRAT transfers and screenshots
    🧊 #IcedID reverse VNC graphics
    ⌨️ #IcedID reverse VNC keylog
    📂 #BackConnect file uploads
    netresec.com/?b=23A41e6

  12. #BazarLoader / #BazarBackdoor also uses the BackConnect protocol do deploy reverse VNC. This screenshot is from @malware_traffic's 2021-11-05 Bazar PCAP. The #BackConnect server was running on 87.120.8.190:9090

  13. Bonjour #IcedID #BackConnect!

    We've spotted a new C2 server being set up on:

    5.196.196.252 (🇫🇷)

    Expect to see this IP in infection chains in the coming days / hours.

    #Recon 👀

    cc @netresec