{"id":4412,"date":"2024-07-11T09:00:00","date_gmt":"2024-07-11T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/-crystalray-attacks-jump-10x-using-only-oss-steal-credentials"},"modified":"2024-07-11T09:00:00","modified_gmt":"2024-07-11T14:00:00","slug":"crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/11\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials\/","title":{"rendered":"&#8216;Crystalray&#8217; Attacks Jump 10X, Using Only OSS to Steal Credentials"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt498e8af3bf2c8ea1\/668837fd5d11656b571f3973\/Crystal_rain-Nick_Hanna-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A newly discovered threat actor is using an arsenal of open source software (OSS) to scale its credential stealing and cryptomining operations exponentially.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Crystalray&#8221; was first spotted back in February, when it was using a penetration testing program called &#8220;SSH-Snake&#8221; to exploit known vulnerabilities in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/patch-max-critical-atlassian-bug-unauthenticated-rce\" rel=\"noopener\">Atlassian&#8217;s Confluence platform<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. In the time since, researchers from Sysdig have observed it combining a suite of other OSS tools to facilitate nearly every step of its attack chain.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Perhaps thanks to all the time saved not having to write its own malware, Crystalray&#8217;s activity exploded this spring. It has now touched more than 1,800 unique IP addresses worldwide, with hundreds of active infections at any given time. More than half of the attacks have occurred in the US and China.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Crystalray's OSS Attack Chain\">Crystalray&#8217;s OSS Attack Chain<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first tool in Crystalray&#8217;s kit, for performing initial reconnaissance, is called &#8220;ASN.&#8221; This command line tool allows its users to query Shodan for open ports, known vulnerabilities, and many other useful kinds of data about potential targets, such as what software and hardware they might be running. As advertised in its GitHub readme file, ASN does all this and more &#8220;without ever sending a single packet to the target.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attackers then supplement ASN with &#8220;zmap,&#8221; which scans the Web for specific ports running vulnerable services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With the results from zmap in hand, the threat actor runs the HTTP toolkit &#8220;httpx&#8221; to check whether the domain they might target is live.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now that its prey has been squarely identified, Crystalray then uses the vulnerability scanner &#8220;nuclei&#8221; to check which known vulnerabilities the poor victim might be beset by. So far, that process has probably included one or more Confluence bugs, as well as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-44877\" rel=\"noopener\">CVE-2022-44877<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in the CentOS Control Web Panel; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-3129\" rel=\"noopener\">CVE-2021-3129<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in Ignition for Laravel; and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.opencve.io\/cve\/CVE-2019-18394\" rel=\"noopener\">CVE-2019-18394<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in Ignite Realtime Open Fire \u2014 all three of which have earned critical 9.8 out of 10 CVSS scores. nuclei offers the added benefit of allowing its users to scan for potential honeypots.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Crystalray doesn&#8217;t bother to develop any kind of exploit script to compromise these exposed domains. Instead, it uses public <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/stealth-bomber-atlassian-confluence-exploits-drop-web-shells-in-memory\" rel=\"noopener\">proofs-of-concept exploits (PoCs)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to drop its malicious payloads.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"OSS Payloads Both Malicious &amp; Legit\">OSS Payloads Both Malicious &amp; Legit<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The malicious payload might involve Sliver \u2014 a cross-platform red team framework it uses for command-and-control \u2014 or Platypus \u2014 a Go-based tool for managing multiple reverse shells (in Crystalray&#8217;s case, up to 400 at once).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Some of these are not legitimate open source tools,&#8221; notes Michael Clark, director of threat research at Sysdig. Platypus, for example, may be OSS like the others, but &#8220;I don&#8217;t think they pretend to be a legitimate kind of tool. They&#8217;re offering it for bad purposes. But the project discovery tools like nuclei are all meant for defenders, so there&#8217;s a bit of a mix.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One such tool that markets itself to defenders \u2014 though it is almost certainly of more use to attackers \u2014 is SSH-Snake. The program is a worm that enables lateral network movement by gradually accumulating and logging <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/bad-ssh-key-management-leaves-databases-at-risk\" rel=\"noopener\">SSH keys<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> it uses to self-replicate. Crystalray also aims for other sorts of credentials by, for example, using all-bash-history and Linux-smart-enumeration to discover sensitive credentials in bash command history files.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In particular, the group looks for credentials associated with cloud platforms and software-as-a-service (SaaS) email platforms, which it sells in black markets. Its other source of income comes from two cryptominers which, based on the attacker&#8217;s crypto wallet, appear to be earning them a paltry sum \u2014 around $200 per month.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Cost-Benefit of Using OSS Cyberattack Tools\">The Cost-Benefit of Using OSS Cyberattack Tools<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Clark reflects, &#8220;What&#8217;s odd is we see a lot of attacks \u2014 hundreds a year \u2014 and most of them use much simpler scripts they wrote themselves, or tools they bought off of the Dark Web. We rarely see this kind of malicious use of legitimate open source security software.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For all of the time and effort it saves, hackers have one very good reason to avoid OSS: &#8220;Because <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/6-open-source-tools-for-your-security-team\" rel=\"noopener\">defenders can use it too<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which is what&#8217;s great about open source. They can reproduce this exactly to see how it looks in their environment,&#8221; he notes. &#8220;If I&#8217;m a defender, I could go install Sliver \u2014 play with it, see how it works, see how it works against my defensive tools. With a closed source version, it&#8217;s much harder to get your hands on.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On the other hand, he adds, &#8220;These are advanced tools, sometimes. So even if you have it, detection can be difficult, because people put a lot of effort into making these tools very good. Even if they&#8217;re used for defensive purposes, they want defenders being able to replicate advanced attacks.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/-crystalray-attacks-jump-10x-using-only-oss-steal-credentials\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly discovered threat actor is using an arsenal of<\/p>\n","protected":false},"author":12,"featured_media":4413,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4412","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/crystalray-attacks-jump-10x-using-only-oss-to-steal-credentials-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4412"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4412\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4413"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}