{"id":5064,"date":"2024-08-28T15:40:08","date_gmt":"2024-08-28T20:40:08","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/blackbyte-targets-esxi-bug-with-ransomeware-to-access-virtual-assets"},"modified":"2024-08-28T15:40:08","modified_gmt":"2024-08-28T20:40:08","slug":"blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/28\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets\/","title":{"rendered":"BlackByte Targets ESXi Bug With Ransomware to Access Virtual Assets"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd27800e8299319d5\/66cf7d68e20e4a91a0037ca6\/ransomware_mayam_studio_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Threat actors using the infamous BlackByte ransomware strain have joined the rapidly growing number of cybercriminals targeting a recent authentication bypass vulnerability in VMware ESXi to compromise the core infrastructure of enterprise networks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The bug, tracked as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24505\" rel=\"noopener\">CVE-2024-37085<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, allows an attacker with sufficient access on Active Directory (AD) to gain full access to an ESXi host <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/ransomware-gangs-exploit-esxi-bug-for-instant-mass-encryption-of-vms\" rel=\"noopener\">if that host uses AD for user management<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Popular Target\">A Popular Target<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/07\/29\/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption\/\" rel=\"noopener\">Microsoft<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and other security vendors previously identified ransomware outfits such as Black Basta (aka Storm-0506), Manatee Tempest, Scattered Spider (aka Octo Tempest), and Storm-1175 leveraging CVE-2024-37085 to deploy ransomware strains such as Akira and Black Basta. In these attacks, the adversaries used their AD privileges to create or rename a group called &#8220;ESX Admins&#8221; and then use the group to access the ESXi hypervisor as a fully privileged user.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BlackByte&#8217;s use of the vulnerability represents a pivot from the threat group&#8217;s usual practice of scanning for and exploiting public-facing vulnerabilities \u2014 like the ProxyShell flaw in Microsoft Exchange \u2014 to gain an initial foothold. Researchers at Cisco Talos who observed BlackByte threat actors target CVE-2024-37085 in recent attacks described the tactic as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.talosintelligence.com\/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks\/\" rel=\"noopener\">one of several changes<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> they made recently to stay ahead of defenders. Other changes include the use of BlackByteNT, a new BlackByte encryptor written in C\/C++, dropping as many as four vulnerable drivers, compared to three previously, on compromised systems and using the victim organization&#8217;s AD credentials to self-propagate.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Talos&#8217;s investigation showed that organizations in the professional, scientific, and technical services sectors are most vulnerable to attacks involving the use of legitimate but vulnerable drivers to bypass security mechanisms \u2014 a technique researchers refer to as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/ransomhub-rolls-out-brand-new-edr-killing-byovd-binary\" rel=\"noopener\">Bring Your Own Vulnerable Driver<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (BYOVD).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;BlackByte\u2019s progression in programming languages from C# to Go and subsequently to C\/C++ in the latest version of its encryptor \u2014 BlackByteNT \u2014 represents a deliberate effort to increase the malware&#8217;s resilience against detection and analysis,&#8221; Talos researchers James Nutland, Craig Jackson, and Terryn Valikodath wrote in a blog post this week. &#8220;The self-propagating nature of the BlackByte encryptor creates additional challenges for defenders. The use of the BYOVD technique compounds these challenges since it may limit the effectiveness of security controls during containment and eradication effort.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Constant Change\">Constant Change<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BackByte&#8217;s pivot to vulnerabilities such as CVE-2024-37085 in ESXi is a manifestation of how attackers constantly evolve their tactics, techniques, and procedures to stay ahead of defenders, says Darren Guccione, CEO and co-founder of Keeper Security. &#8220;The exploitation of vulnerabilities in ESXi by BlackByte and similar threat actors indicates a focused effort to compromise the core infrastructure of enterprise networks,&#8221; Guccione says. &#8220;Given that ESXi servers often host multiple virtual machines, a single successful attack can cause widespread disruption, making them a prime target for ransomware groups.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sygnia, which investigated numerous ransomware attacks against VMWare ESXi and other virtualized environments earlier this year, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sygnia.co\/blog\/esxi-ransomware-attacks\/?blaid=6088911https:\/\/news.sophos.com\/en-us\/2023\/12\/21\/akira-again-the-ransomware-that-keeps-on-taking\/\" rel=\"noopener\">described the attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as unfolding in a specific pattern in most instances. The attack chain begins with the adversary gaining initial access to a target environment via a phishing attack, vulnerability exploit, or malicious file download. Once on a network, attackers tend to use tactics like altering domain group memberships for domain-connected VMware instances, or via RDP hijacking, to obtain credentials for ESXi hosts or vCenter. They then validate their credentials and use them to execute their ransomware on the ESXi hosts, compromise backup systems, or change passwords to them and then exfiltrate data.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Increased Enterprise Pressure\">Increased Enterprise Pressure<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attacks on ESXi environments increase the pressure on organizations and their security teams to maintain a versatile security program, according to the researchers. &#8220;This includes practices like strong vulnerability management, threat intelligence sharing, and incident response policies and procedures to keep pace with evolving adversary TTPs,&#8221; the Cisco Talos researchers said. &#8220;In this case, vulnerability management and threat intel sharing will help to identify lesser-known or novel avenues that adversaries may take during an attack such as the ESXi vulnerability.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Heath Renfrow, cofounder of disaster recovery firm Fenix24, says with CVE-2024-37085, organizations face an addition challenge because of perceived difficulties in implementing mitigations for it. &#8220;These mitigations include disconnecting ESXi from AD, removing any previously used groups in AD that managed ESXi, and patching ESXi to 8.0 U3, where the vulnerability is fixed,&#8221; Renfrow says. &#8220;VMware is the most widely used virtual solution globally, and the attack footprint is broad and easily exploitable. This makes it an easy win for threat actors to access the crown jewels and cause significant damage quickly.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/blackbyte-targets-esxi-bug-with-ransomeware-to-access-virtual-assets\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors using the infamous BlackByte ransomware strain have joined<\/p>\n","protected":false},"author":12,"featured_media":5065,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5064","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/blackbyte-targets-esxi-bug-with-ransomware-to-access-virtual-assets.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5064"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5064\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5065"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}