{"id":5038,"date":"2024-08-27T06:39:29","date_gmt":"2024-08-27T11:39:29","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/threat-group-bling-libra-extortion-cloud-attacks"},"modified":"2024-08-27T06:39:29","modified_gmt":"2024-08-27T11:39:29","slug":"threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/27\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks\/","title":{"rendered":"Threat Group &#8216;Bling Libra&#8217; Pivots to Extortion for Cloud Attacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt304bf67bec1544d1\/66cdbeec5de9965b7f98a2bd\/Cloud-Security_Aleksia_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The threat group behind the infamous Ticketmaster breach earlier this summer is evolving its tactics to go beyond data theft and subsequent sale of stolen data. It&#8217;s now embracing extortion-based attacks as it continues to target cloud environments with legitimate credentials.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers at Palo Alto Networks&#8217; Unit 42 have revealed new details about the operations of the group it calls &#8220;Bling Libra&#8221; (aka ShinyHunters), which is perhaps best known for stealing an impressive 560 million customer records from <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ticketmaster-confirms-cloud-breach-murky-details\" rel=\"noopener\">events giant Ticketmaster<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and putting them up for sale on BreachForums earlier this year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since then, Bling Libra has continued to target cloud environments with a consistent attack pattern, according to a recent <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/shinyhunters-ransomware-extortion\/\" rel=\"noopener\">blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Unit 42&#8217;s Margaret Zimmermann and Chandni Vaya. Since its inception in 2020, the group has been acquiring legitimate credentials in order to target database infrastructure and steal personally identifiable information (PII).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, while a recent shift in tactics uses the same initial-access routine, Bling Libra now has pivoted to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/akira-ransomware-lightning-fast-data-exfiltration-2-hours\" rel=\"noopener\">double-extortion tactics typically associated with ransomware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> gangs \u2014 first stealing data from victims, then threatening to publish it online if a ransom isn&#8217;t paid.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Targeting AWS for Extortion\">Targeting AWS for Extortion<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a recent attack investigated by Unit 42, the group targeted an organization&#8217;s Amazon Web Services (AWS) environment by using stolen credentials to gain access and then proceeded to poke around on the network, the researchers said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While the permissions associated with the compromised credentials limited the impact of the breach, Bling Libra infiltrated the organization\u2019s AWS environment and conducted reconnaissance operations,&#8221; they wrote in the post. The group used tools such as the Amazon Simple Storage Service (S3) Browser and WinSCP to gather information on S3 bucket configurations, access S3 objects, and delete data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Bling Libra lifted AWS credentials from a sensitive file exposed on the Internet that actually contained a variety of credentials, the researchers noted. However, the group &#8220;specifically targeted the exposed AWS access key belonging to an identity and access management (IAM) user and a handful of other exposed credentials,&#8221; they wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The credentials allowed the threat actors to gain access to the AWS account where the IAM user resided, and perform AWS API calls to interact with the S3 bucket in the context of with the AmazonS3FullAccess policy, in which all user permissions are allowed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this case, however, it was enough for attackers to lurk on the network for about a month before launching an attack that exfiltrated data and deleted it from the environment, leaving behind an extortion note that gave the organization one week to pay a ransom. Bling Libra also created new S3 buckets in their wake, presumably &#8220;to mock the organization about the attack,&#8221; the researchers said.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Credentials Remain a Security Hole\">Credentials Remain a Security Hole<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Ticketmaster attack that came to light in June was notable for the sheer amount of data Bling Libra was able to procure in the attack, with the group claiming at the time that the more than half-million records stolen included PII such as names, emails, addresses, and partial payment-card details.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Later that month, the group also claimed responsibility for a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/30m-affected-tickettek-australia-cloud-breach\" rel=\"noopener\">separate attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on a similar company in Australia, Ticketek Entertainment Group (TEG); like Ticketmaster, that attack occurred in May. Indeed, the group has been tied to several notable data breaches affecting <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/shinyhunters-offers-stolen-data-on-dark-web\" rel=\"noopener\">tens of millions of data records<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In many cases, Bling Libra attacks its ultimate targets through a third-party cloud provider. In the case of Ticketmaster and others, that provider was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/snowflake-cloud-accounts-rampant-credential-issues\" rel=\"noopener\">Snowflake<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and attackers used credentials of legitimate cloud accounts that were vulnerable because they did not have multifactor authentication (MFA) activated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/multi-factor-authentication-not-enough-to-protect-cloud-data\" rel=\"noopener\">lack of MFA<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and &#8220;a concerning trend of overly permissive credentials&#8221; are common themes in not only how Bling Libra and other attackers gain access to cloud environments, the researchers wrote. Since more and more organizations are <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/inside-baseball-red-sox-cloud-security-game\" rel=\"noopener\">moving critical operations to the cloud<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, defenders need to resolve basic issues around authentication and permissions to even have a hope of avoiding compromise by savvy actors, they said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unit 42 recommended that organizations always use MFA wherever possible to avoid the initial-access scenario that Bling Libra exploited in the attack. Employing a secure IAM solution that restricts user permissions to only what processes and assets they need (regardless of the individual IAM policies within each account) also could have prevented attackers gaining access to sensitive data, the researchers said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As businesses increasingly embrace cloud technologies, the threat posed by groups like Bling Libra underscores the importance of robust cybersecurity practices,&#8221; they wrote. &#8220;By implementing proactive security measures and monitoring critical log sources, organizations can effectively safeguard their cloud assets and mitigate the impact of cyberthreats.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/threat-group-bling-libra-extortion-cloud-attacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The threat group behind the infamous Ticketmaster breach earlier this<\/p>\n","protected":false},"author":12,"featured_media":5039,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5038","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/threat-group-bling-libra-pivots-to-extortion-for-cloud-attacks.png?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5038","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5038"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5038\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5039"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}