{"id":3785,"date":"2024-05-29T09:43:22","date_gmt":"2024-05-29T14:43:22","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/blacksuit-dozens-victims-curated-ransomware"},"modified":"2024-05-29T09:43:22","modified_gmt":"2024-05-29T14:43:22","slug":"blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/29\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware\/","title":{"rendered":"BlackSuit Claims Dozens of Victims With Carefully Curated Ransomware"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd70e24a4b281681f\/66573231d632e3c94cfc4618\/cards-William_Scott-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The BlackSuit ransomware gang has leaked stolen data from attacks against 53 organizations spanning a year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers from ReliaQuest analyzed in-depth an attack that took place in April from the ransomware group, which has been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/fresh-ransomware-gangs-emerge-victims-decline-market-leaders\" rel=\"noopener\">active since May 2023.<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> The group \u2014 believed to be spun off from the Royal ransomware gang \u2014 primarily targets US-based companies in critical sectors such as education and industrial goods, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.reliaquest.com\/blog\/blacksuit-attack-analysis\/\" rel=\"noopener\">choosing targets carefully<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to maximize financial gain, according to a blog post published yesterday.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This targeting pattern strongly suggests a financial motivation with a focus on critical sectors that either have smaller cybersecurity budgets or a low tolerance for downtime, thereby increasing the likelihood of a successful attack or a speedy ransom payment,&#8221; according to the Reliaquest Threat Research Team post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BlackSuit uses a double-extortion method and other tactics, techniques, and procedures (TTPs) that reflect a maturity atypical of a group that&#8217;s only been around for a year. This reflects its origin <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/royal-ransom-demands-exceed-275m-rebrand-in-offing\" rel=\"noopener\">in Royal<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which in turn was comprised of members of the formidable and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/breakup-conti-ransomware-members-dangerous\" rel=\"noopener\">now-defunct<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/what-the-conti-ransomware-group-data-leak-tells-us\" rel=\"noopener\">Conti ransomware gang<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The group&#8217;s pedigree, varied malware deployment methods, and advanced encryption and system-recovery processes indicate that BlackSuit&#8217;s operators are likely experienced and technically proficient,&#8221; the team wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attack investigated by ReliaQuest shows BlackSuit using an array of of &#8220;straightforward TTPs&#8221; that begin including <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/cybersecurity-101\/kerberoasting\/\" rel=\"noopener\">Kerberoasting<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and leveraging <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/leveraging-behavioral-analysis-to-catch-living-off-the-land-attacks\" rel=\"noopener\">PsExec for lateral movment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, FTP for exfiltration, brute forcing, and the ultimate deployment of ransomware from a virtual machine.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"In-Depth Attack Sequence\">In-Depth Attack Sequence<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The BlackSuit attack observed in April began when a threat actor gained VPN access to the customer&#8217;s environment through a valid account, likely using credentials that were brute-forced or accessed in a password dump. The VPN was an easy target for initial access because it was &#8220;a non-primary VPN gateway at a disaster recovery site and was not configured to enforce multifactor authentication or certificate requirements,&#8221; the team noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Over the next week, the attacker moved laterally across several Windows workstations, primarily using PsExec, a remote administration tool that was already in use in the customer environment.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After a three-day pause in the action \u2014 likely because the attack was done by an initial-access broker who then sold BlackSuit or one of its affiliates access to the environment \u2014 the attack resumed with the attacker authenticating to a Windows server and then downloading a custom payload that allowed loading of Rubeus, a toolkit for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/abusing-kerberos-for-local-privilege-escalation\" rel=\"noopener\">Kerberos abuse<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, into PowerShell.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It then compromised more than 20 users through <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ryuk-s-rampage-has-lessons-for-the-enterprise\" rel=\"noopener\">Kerberoasting<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.qomplx.com\/blog\/qomplx-knowledge-kerberoasting-attacks-explained\/\" rel=\"noopener\">post-exploitation attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that extracts service account credential hashes from Active Directory for offline cracking, according to security firm Qomplx \u2014 as well as an additional account via AS-REP roasting.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacker used an unmonitored Windows server to initiate FTP connections to an external IP address to send more than 100 gigabytes of data over the next six hours, then set up a malicious Windows VM likely used &#8220;to obfuscate the ransomware deployment from endpoint security tools,&#8221; according to Reliaquest researchers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The threat actor used PsExec from their VM to copy the ransomware payload \u2014 which was hosted on a network share \u2014 to hundreds of hosts through Server Message Block (SMB),&#8221; the team wrote. &#8220;Following this, WMIC was used to load the ransomware payload as a library, thus executing the encrypter.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once the attack was detected, the impacted organization took immediate action to roll passwords across the domain and isolate the compromised site from other global locations to limit the impact. It ultimately focused on remediation through hash banning and host isolation using endpoint security solutions, according to Reliaquest.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The customer worked to detect potential data leakage and monitor its digital assets, as well as deployed &#8220;various detection rules \u2026 to strengthen the organization&#8217;s defensive posture, including those to identify malware, suspicious DNS requests, and lateral movement activities,&#8221; according to the post.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Mitigating Various Ransomware Attack Stages\">Mitigating Various Ransomware Attack Stages<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ReliaQuest revealed several mitigation tactics that organizations can take for each of the attack steps it observed. For instance, to avoid the initial <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/attackers-target-check-point-vpns-access-corporate-networks\" rel=\"noopener\">misconfiguration of the VPN <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">that allowed for initial access, the team suggested that organizations use centralized change management and version control to deploy network device configurations instead of managing devices individually.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This &#8220;will cut down on misconfigurations, and, when paired with an automated inventory mapping solution, will help to ensure there are no hidden misconfigured or legacy devices,&#8221; according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations also can better track lateral movements by monitoring Windows event logs and deploying a robust endpoint detection and response (EDR) tool, neither of which the customer did.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Many organizations choose not to forward Windows logs from workstations because of ingest restrictions on existing <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/generative-ai-takes-on-siem\" rel=\"noopener\">SIEM licenses<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; the team noted. &#8220;It&#8217;s important for organizations to be aware of the risks when making this decision and to compensate if possible.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While Kerberoasting is difficult to mitigate entirely, &#8220;because anyone can request a ticket-granting service (TGS) ticket for any service principal name (SPN) to crack offline,&#8221; the researchers noted that organizations can take steps &#8220;to put the burden on the adversary and make it an unattractive option.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of those is to disable the ability to request weak encryption types to strengthen passwords, &#8220;which is often more straightforward than retroactively enforcing password complexity,&#8221; the ReliaQuest team suggested.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/blacksuit-dozens-victims-curated-ransomware\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The BlackSuit ransomware gang has leaked stolen data from attacks<\/p>\n","protected":false},"author":12,"featured_media":3786,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=2560%2C1669&ssl=1",2560,1669,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=300%2C196&ssl=1",300,196,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=640%2C418&ssl=1",640,418,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=640%2C418&ssl=1",640,418,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=1536%2C1001&ssl=1",1536,1001,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=2048%2C1335&ssl=1",2048,1335,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=1024%2C668&ssl=1",1024,668,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/blacksuit-claims-dozens-of-victims-with-carefully-curated-ransomware-scaled.jpg?fit=2560%2C1669&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3785"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3786"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}