<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Alchemy Security Consulting</title>
    <link>https://www.alchemysec.com.au/blog</link>
    <description>Explore key insights on offensive and defensive security topics, including OSINT for penetration testers and risks posed by local administrators, from Alchemy Security's latest articles.</description>
    <language>en</language>
    <pubDate>Thu, 01 Oct 2026 06:24:50 GMT</pubDate>
    <dc:date>2026-10-01T06:24:50Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Conti Group - Tooling, Leaks and Russian FSB Ties - Cyber Security Consultants - Alchemy</title>
      <link>https://www.alchemysec.com.au/blog/conti-group-tooling-leaks-and-russian-fsb-ties</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/conti-group-tooling-leaks-and-russian-fsb-ties" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/spider-dealer-01-1024x571-1.jpg" alt="Conti Group - Tooling, Leaks and Russian FSB Ties - Cyber Security Consultants - Alchemy" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The Conti group have been featured across many news outlets lately both inside and outside the cyber security community. It is well known that this specific threat actor is mainly operated from within Russia, and with the recent events within Russia and Ukraine we thought it would be a good idea to do a recap on this treat actor group. In this post we’ll aim to cover some of the tooling utilized by the threat actor as well as their involvement within the recent Russia and Ukraine conflict.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Conti group have been featured across many news outlets lately both inside and outside the cyber security community. It is well known that this specific threat actor is mainly operated from within Russia, and with the recent events within Russia and Ukraine we thought it would be a good idea to do a recap on this treat actor group. In this post we’ll aim to cover some of the tooling utilized by the threat actor as well as their involvement within the recent Russia and Ukraine conflict.&lt;/p&gt; 
&lt;p&gt;We encounter this group on a regular basis through our Managed Detection and Response service, and our incident response engagements. This threat actor behaves much like a business with a broad range of internal resources and departments to leverage as part of their ransomware service.&lt;/p&gt; 
&lt;p&gt;While there are a broad range of publicly available Indicators Of Compromise (IOCs) for this threat actor, we will cover some of the tooling we have seen them used recently which will typically fly under the radar of common security controls.&lt;/p&gt; 
&lt;h2&gt;Conti Group and Critical Infrastructure&lt;/h2&gt; 
&lt;p&gt;As a group Conti makes their money through their ransomware service, once they have gained access to an environment with elevated privileges, they will rapidly look to destroy backups before deploying their ransomware to as many machines as possible. Besides operating more as a business rather than a typical hacker group, they also attempt to ensure their attacks do not impact critical infrastructure. While critical infrastructure typically includes power grids and utilities, Conti are mainly referring to health care infrastructure such as hospitals.&lt;/p&gt; 
&lt;p&gt;However, with the recent conflict in Ukraine Conti have thrown their support behind Russia by publicly stating they will proactively target the critical infrastructure of countries that get involved with the conflict through cyber-attacks against Russia.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="575" height="579" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-Sep-30-2026-10-31-04-8611-AM.png?width=575&amp;amp;height=579&amp;amp;name=image-Sep-30-2026-10-31-04-8611-AM.png" alt="" class="wp-image-493"&gt;  Conti's public announcement around critical infrastructure.   
&lt;/div&gt; 
&lt;p&gt;With this specific threat actor being so successful against targets around the world, especially in Australia, it is important to understand the TTPs associated with this threat actor to better defend against them. This is especially important if your business or environment is considered critical infrastructure.&lt;/p&gt; 
&lt;h2&gt;Russian Federal Security Service (FSB) Ties&lt;/h2&gt; 
&lt;p&gt;It has been long suspected that certain crime groups operating out of Russia have had various levels of support from their government. While there isn’t a lot of publicly available concrete evidence to suggest this is the case, documents have been leaked by a Ukrainian within the Conti group that suggests Conti have ties to the Russian Fedaral Security Service.&lt;/p&gt; 
&lt;p&gt;The below screenshot is from a Conti Jabber conversation where they discuss having gained access to some information detailing correspondence between the victim and the journalism organisation Bellingcat.&lt;/p&gt;  
&lt;img width="940" height="331" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-1-2.png?width=940&amp;amp;height=331&amp;amp;name=image-1-2.png" alt="" class="wp-image-494"&gt;  Translated conversation within the Conti group discussing FSB ties.    
&lt;img width="940" height="108" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-2-2.png?width=940&amp;amp;height=108&amp;amp;name=image-2-2.png" alt="" class="wp-image-495"&gt;  Translated conversation within the Conti group discussing Navalny.   
&lt;p&gt;Of particular interest is the mention of Navalny and FSB within the same chat log, this does seem to suggest that to an extent Conti has a connection or contact at the FSB, how far this relationship goes is yet to be seen.&lt;/p&gt; 
&lt;h2&gt;Tools, Techniques and Processes&lt;/h2&gt; 
&lt;p&gt;The Conti group utilize a broadrange of Tools, Techniques and Processes. We are going to take this opportunity to briefly recap on some of the most common TTPs utilized by the group. As part of this we are also going to touch one some ‘greyware’, legitimate applications utilized by the crew to achieve persistence without raising the suspension of security controls.&lt;/p&gt; 
&lt;h3&gt;Trickbot&lt;/h3&gt; 
&lt;p&gt;Trickbot has been around since 2016, originally only observed being utilized by APT group Wizard Spider. This piece of malware is a feature rich application that provides the threat actor with a huge range of capabilities to facilitate persistence, lateral movement, and enumeration activities.&lt;/p&gt; 
&lt;h3&gt;Emotet&lt;/h3&gt; 
&lt;p&gt;Emotet has been operating since 2014 and was typically classified as a banking trojan and spread through broad phishing campaigns. This malware is typically used by groups as a deployment mechanism. Once the malware has successfully executed on an endpoint, the operator can distribute other malware such as Trickbot and Cobalt Strike.&lt;/p&gt; 
&lt;h3&gt;Cobalt Strike&lt;/h3&gt; 
&lt;p&gt;Cobalt Strike is an Adversary Simulation and Red Team Operations tool built for security teams and penetration testers to easily simulate an advanced threat. Think of this tool as a commercial command and control application. Unfortunately, even though&amp;nbsp; Cobalt Strike perform diligent background checks on all of their customers, the application has been leaked multiple times and is now a staple tool for the Conti group.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-3-2.png?width=501&amp;amp;height=326&amp;amp;name=image-3-2.png" alt="" class="wp-image-496" width="501" height="326"&gt;  Cobalt Strike console screenshot.   
&lt;/div&gt; 
&lt;h2&gt;Greyware&lt;/h2&gt; 
&lt;p&gt;In recent attacks we have noticed a significant shift in Conti’s tradecraft where they have adopted the use of legitimate tooling for both persistence and command and control. This includes utilizing applications that have legitimate real-world purposes such as applications commonly utilized by developers and Managed Service Providers (MSPs).&lt;/p&gt; 
&lt;p&gt;These applications will typically go unnoticed by most security controls purely because they are a legitimate application used by a huge number of legitimate businesses globally. While controls such as Endpoint Detection and Response (EDRs) will likely generate an alert that this is a potential risk, they typically do not prevent the application from executing.&lt;/p&gt; 
&lt;h3&gt;Atera&lt;/h3&gt; 
&lt;p&gt;Atera is a remote management tool developed for MSPs to allow them to easily support their customers through the remote management capabilities of the Atera application. While the technique of using remote access tools for persistence or command and control is not new, the licensing model of Atera resonates with Conti’s processes like no other. Typically, once the group has administrative access within an environment they will register for an Atera instance utilizing a public email address aligned to the internal domain name of the compromised environment. While it is not clear whether the group utilises a free trial for their entire engagement, Atera is licensed per consultant. This means they can essentially deploy the tool across an entire environment without running into any ‘per machine’ licensing issues.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-4-2.png?width=509&amp;amp;height=246&amp;amp;name=image-4-2.png" alt="" class="wp-image-497" width="509" height="246"&gt;  Atera remote management tool screenshot.   
&lt;/div&gt; 
&lt;h3&gt;NGROK&lt;/h3&gt; 
&lt;p&gt;Ngrok is a tool that once installed on a machine can be configured to expose a service on the host to the internet. This is done by tunneling the network traffic over HTTPS to the Ngrok service, where Ngrok then provide a url and port that the user can hit to access the desired service.&lt;/p&gt; 
&lt;p&gt;Conti typically utilize this service to expose remote access protocols such as Remote Desktop Protocol (RDP). This allows them to gain a RDP session on a host that typically is not directly exposed to the internet and makes it easier for them to perform lateral movement.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="940" height="411" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-5-2.png?width=940&amp;amp;height=411&amp;amp;name=image-5-2.png" alt="" class="wp-image-498"&gt;  The process that allows users to tunnel traffic utilising NGROK.   
&lt;/div&gt; 
&lt;h3&gt;Crosstec Remote Control&lt;/h3&gt; 
&lt;p&gt;CrossTec is a tool that is very similar to Atera in that it is typically utilized by an MSP to provide remote support to their customers. CrossTec is not as feature rich as Atera however it does provide the same level of remote access and persistence to the threat actor.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-6-1.png?width=583&amp;amp;height=285&amp;amp;name=image-6-1.png" alt="" class="wp-image-499" width="583" height="285"&gt;  CrossTec Remote Control screenshot.   
&lt;/div&gt; 
&lt;h2&gt;Defending Against Conti&lt;/h2&gt; 
&lt;p&gt;Conti are opportunistic, with most of their successful attacks beginning with a phishing email, password-based attack or exploitation of a 0-Day vulnerability such as LOG4j. If an environment looks to be too mature, they will simply move on to next target to increase the likelihood of a successful attack.&lt;/p&gt; 
&lt;p&gt;Mitigating most threat actors, including Conti can be achieved using fairly common security controls.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Patch Management &lt;/strong&gt;– Ensure that both applications and operating systems are patched on a regular basis. This should also include an out of band patching process for 0-Day vulnerabilities.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Multi-Factor Authentication&lt;/strong&gt; – This single control will make it significantly harder for any threat actor to abuse password based attacks when deployed properly.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;End-Point Detection and Response&lt;/strong&gt; – An industry leading EDR product will detect many of the behaviors exhibited by threat actors. This includes the use of ‘greyware’ and living of the land tooling utilized by groups such as Conti. This also provides your business with a platform to react to incidents on a granular level across all endpoints.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Application Whitelisting&lt;/strong&gt; – This control is extremely effective at reducing the range of tools available for a threat actor to utilize during an incident. Application Control is one of the best ways of ensuring software such as the remote access greyware tools we referred to earlier are not deployed without approval.When configured properly, this control can cripple an attack from even the most advanced threat actors.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Application Level Firewalls&lt;/strong&gt; – The vast majority of application firewall vendors such as PaloAlto and checkpoint provide a categorization for domain and ip addresses. This can be utilized to block an entire application category, for example on a PaloAlto you could block ‘Proxy Avoidance and Anonymizers’ to prevent the use of tools such as NGROK.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;References&lt;/h2&gt; 
&lt;p&gt;&lt;a href="https://www.cyber.gov.au/acsc/view-all-content/advisories/ransomware-profile-conti"&gt;https://www.cyber.gov.au/acsc/view-all-content/advisories/ransomware-profile-conti&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/"&gt;https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/&lt;/a&gt;&lt;/p&gt;  
&lt;div class="wp-block-embed__wrapper"&gt; 
 &lt;div class="twitter-tweet twitter-tweet-rendered" style="display: flex; max-width: 500px; margin-top: 10px; margin-bottom: 10px"&gt; 
  &lt;iframe frameborder="0" allowfullscreen="true" class="" src="https://platform.twitter.com/embed/Tweet.html?dnt=true&amp;amp;embedId=twitter-widget-0&amp;amp;features=eyJ0ZndfdGltZWxpbmVfbGlzdCI6eyJidWNrZXQiOltdLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X2ZvbGxvd2VyX2NvdW50X3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9iYWNrZW5kIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19yZWZzcmNfc2Vzc2lvbiI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfZm9zbnJfc29mdF9pbnRlcnZlbnRpb25zX2VuYWJsZWQiOnsiYnVja2V0Ijoib24iLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X21peGVkX21lZGlhXzE1ODk3Ijp7ImJ1Y2tldCI6InRyZWF0bWVudCIsInZlcnNpb24iOm51bGx9LCJ0ZndfZXhwZXJpbWVudHNfY29va2llX2V4cGlyYXRpb24iOnsiYnVja2V0IjoxMjA5NjAwLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X3Nob3dfYmlyZHdhdGNoX3Bpdm90c19lbmFibGVkIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19kdXBsaWNhdGVfc2NyaWJlc190b19zZXR0aW5ncyI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdXNlX3Byb2ZpbGVfaW1hZ2Vfc2hhcGVfZW5hYmxlZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdmlkZW9faGxzX2R5bmFtaWNfbWFuaWZlc3RzXzE1MDgyIjp7ImJ1Y2tldCI6InRydWVfYml0cmF0ZSIsInZlcnNpb24iOm51bGx9LCJ0ZndfbGVnYWN5X3RpbWVsaW5lX3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9mcm9udGVuZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9fQ%3D%3D&amp;amp;frame=false&amp;amp;hideCard=false&amp;amp;hideThread=false&amp;amp;id=1498386621657493510&amp;amp;lang=en&amp;amp;origin=https%3A%2F%2Fwww.alchemysec.com.au%2Fconti-group-tooling-leaks-and-russian-fsb-ties%2F&amp;amp;sessionId=cebe74013842fe35264e51cbf26be9f4a1aa67c7&amp;amp;theme=light&amp;amp;widgetsVersion=6a3ad42b224df%3A1778106238597&amp;amp;width=500px" style="position: static; visibility: visible; width: 500px; height: 345px; display: block; flex-grow: 1"&gt;&lt;/iframe&gt; 
 &lt;/div&gt;  
&lt;/div&gt;  
&lt;p&gt;&lt;a href="https://attack.mitre.org/groups/G0102/"&gt;https://attack.mitre.org/groups/G0102/&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://attack.mitre.org/software/S0575/"&gt;https://attack.mitre.org/software/S0575/&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fconti-group-tooling-leaks-and-russian-fsb-ties&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Defence</category>
      <pubDate>Fri, 11 Mar 2022 05:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/conti-group-tooling-leaks-and-russian-fsb-ties</guid>
      <dc:date>2022-03-11T05:00:00Z</dc:date>
      <dc:creator>Will</dc:creator>
    </item>
    <item>
      <title>Yes, Local Administrators ARE a Risk</title>
      <link>https://www.alchemysec.com.au/blog/yes-local-administrators-are-a-risk</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/yes-local-administrators-are-a-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Images/Blog/padlock-2400.jpg" alt="Yes, Local Administrators ARE a Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Modern environments are in a constant state of flux; new systems are being commissioned, and old systems decommissioned, to meet new requirements and increase efficiency in all sectors. Managing those changes takes strategy and labour, and every change has an overhead in both of those resources.&lt;br&gt;&lt;br&gt;What do you do when your users want new software, or to be able to update their apps without waiting for the next patch window?&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Modern environments are in a constant state of flux; new systems are being commissioned, and old systems decommissioned, to meet new requirements and increase efficiency in all sectors. Managing those changes takes strategy and labour, and every change has an overhead in both of those resources.&lt;br&gt;&lt;br&gt;What do you do when your users want new software, or to be able to update their apps without waiting for the next patch window?&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Images/Blog/Picture1.png?width=903&amp;amp;height=568&amp;amp;name=Picture1.png" width="903" height="568" alt="Picture1" style="height: auto; max-width: 100%; width: 903px;"&gt;&lt;/p&gt; 
&lt;p&gt;It’s the perfect solution, your users can now:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Install new and updated software&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Change software configurations&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Run repairs on software of there are issues&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Run software that only runs as a local administrator&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;And all this without taking up IT resources for changes that may only affect a single endpoint. Sure, everyone needs email but how many users need software for CAD, tax reconciliation, or even software development?&lt;br&gt;&lt;br&gt;Many businesses decide that the cost to the business, and frustration of users, is too high and provide admin access to users over their own machine. Some may even give functional groups admin to all the endpoints in their team via security groups.&lt;/p&gt; 
&lt;h2&gt;Whatcha Running There, Bud?&lt;/h2&gt; 
&lt;p&gt;&lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Images/Blog/Picture2.png?width=903&amp;amp;height=675&amp;amp;name=Picture2.png" width="903" height="675" alt="Picture2" style="height: auto; max-width: 100%; width: 903px;"&gt;&lt;/p&gt; 
&lt;p&gt;A significant downside of this strategy is loss of both control and visibility over endpoints. You don’t have to patch applications now, but are your users doing it? Maybe they’ve installed chrome and they’re keeping it up to date, or maybe they’re using a portable Firefox on a USB they bring from home – the same one they use to clean up viruses on their parents’ home PC.&lt;br&gt;&lt;br&gt;If you’re letting users install their own software, answering these questions is going to be hard:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;What software do we monitor for updates?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;What software do we have installed in our environment?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Are users using pirated software?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Are users installing software from reputable sources?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;How do we get notified of vulnerabilities in a timely manner?&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;But how do I secure it?&lt;/h2&gt; 
&lt;p&gt;Let’s have a look at ACSC’s Essential Eight Controls to mitigate exploitation. These are the Australian Government’s recommendation for the 8 most important controls to protect your business.&lt;br&gt;&lt;br&gt;Let’s see how they align with allowing:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Application Control – Stringent Application Control is a great control is you have a single application that requires admin execution, but it is impossible for unmanaged endpoints. Application Control can only have an effective implementation if you can manage and restrict the use of the endpoint; local administrator privileges actively work against this control.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Patch Applications – If we are allowing users to install applications, there is no way to effectively implement a patching strategy. We don’t know what we need to patch.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Configure Microsoft Office Macro Settings – This is something we can do, but care should be taken to ensure that users aren’t able to undo group policy settings.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;User Application Hardening – As with Patch Applications, we can’t implement this as we can’t control what applications are installed on an endpoint.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Restrict Administrative Privileges – Users have admin, the best we can do is restrict their scope to machines specifically assigned to them.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Patch Operating Systems – Not affected, though a policy should be enforced configuring the update schedule (disabling update checks is an administrative privilege)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Multi-factor authentication – Local Administrators can add local users to their machines which may bypass this policy&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Regular backups – this is still possible, but backups must be configured centrally to prevent unrecoverable destruction on endpoints via deletion of filesystem checkpoints.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;At this point, allowing Local Administrator access has weakened or invalidated the most effective controls we have.&lt;/p&gt; 
&lt;p&gt;OK, so we’ll get EDR to detect malicious activity. At least this way attackers can’t use tools to exploit other machines.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Images/Blog/Picture3.png?width=366&amp;amp;height=285&amp;amp;name=Picture3.png" width="366" height="285" alt="Picture3" style="height: auto; max-width: 100%; width: 366px; margin-left: auto; margin-right: auto; display: block;"&gt;&lt;/p&gt; 
&lt;p&gt;Oh, yeah that. We can’t stop the tools from running because we can’t get visibility and execution control within a virtual machine. Ok, we’ll get a vulnerability scanner to detect exploitable vulnerabilities – even if we can’t control the applications, we can scan for vulnerable installs to fix.&lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Images/Blog/Picture4-1024x590.png?width=1024&amp;amp;height=590&amp;amp;name=Picture4-1024x590.png" width="1024" height="590" alt="Picture4-1024x590" style="height: auto; max-width: 100%; width: 1024px;"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Images/Blog/Picture5.png?width=903&amp;amp;height=206&amp;amp;name=Picture5.png" width="903" height="206" alt="Picture5" style="height: auto; max-width: 100%; width: 903px;"&gt;&lt;/p&gt; 
&lt;p&gt;Oh, we made the scanner service a domain admin to have one account to scan all our machine. Now we need privileged account management anyway to detect and prevent the scanner account being used outside scanning schedules.&lt;/p&gt; 
&lt;h2&gt;Conclusion&lt;/h2&gt; 
&lt;p&gt;The basic answer here is – administrative privilege is a risk. One of the best ways to prevent exploitation is to limit its usage for administrators, any expansion pollutes your environment.&lt;/p&gt; 
&lt;p&gt;Giving users administrative access is giving away your control, and it’s hard to get that back.&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fyes-local-administrators-are-a-risk&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Defensive</category>
      <category>Blog</category>
      <pubDate>Mon, 01 Nov 2021 16:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/yes-local-administrators-are-a-risk</guid>
      <dc:date>2021-11-01T16:00:00Z</dc:date>
      <dc:creator>Phil</dc:creator>
    </item>
    <item>
      <title>OSINT for Penetration Testers - Cyber Security Consultants - Alchemy</title>
      <link>https://www.alchemysec.com.au/blog/osint-for-penetration-testers</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/osint-for-penetration-testers" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/chris-yang-1tnS_BVy9Jk-unsplash-1024x683-1.jpg" alt="OSINT for Penetration Testers - Cyber Security Consultants - Alchemy" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Part of performing an effective and successful penetration test requires gathering as much information about the target as possible. The more information you have on your target, the more likely you are to discover an exploitable service or land a successful phish.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Part of performing an effective and successful penetration test requires gathering as much information about the target as possible. The more information you have on your target, the more likely you are to discover an exploitable service or land a successful phish.&lt;/p&gt; 
&lt;p&gt;For example, through OSINT you may discover that the target is openly advertising a job position, and invites applicants to send a resume through to HR. You craft a document using template injection to pull a C2 beacon from one of your C2 domains and can achieve a foothold on the internal domain by mimicking a job applicant.&lt;/p&gt; 
&lt;p&gt;Without effective recon, it is likely that this opportunity may be missed resulting in an extended period attempting to gain an internal foothold.&lt;/p&gt; 
&lt;p&gt;So how do you go about effective OSINT/recon?&lt;/p&gt; 
&lt;h2&gt;Breach Data&lt;/h2&gt; 
&lt;p&gt;While breach data may not always contain information on your target, or even recent or up-to-date passwords, it can provide valuable information.&lt;/p&gt; 
&lt;p&gt;For example, it can give an idea of if users practice sensible account hygiene and register for non-work websites using work email addresses. It can also provide an indication of how users structure their passwords. While “Mary1987” may not be the most recent password, it indicates password format in the form of “NameYear” may be suitable for password spraying.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="315" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture7-1.png?width=601&amp;amp;height=315&amp;amp;name=Picture7-1.png" alt="" class="wp-image-455"&gt;  Figure 1 - Checking breach data for potential credentials   
&lt;/div&gt; 
&lt;h2&gt;Social Media&lt;/h2&gt; 
&lt;p&gt;Social media is a good place to identify employees at your target. LinkedIn generally provides a solid list of employee names, along with job titles that can help you land a juicy phish.&lt;/p&gt; 
&lt;p&gt;Creating a list can be done using JavaScript to print employee names to console, or you can use the BurpSuite plug-in GatherContacts.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="329" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture2-2.png?width=601&amp;amp;height=329&amp;amp;name=Picture2-2.png" alt="" class="wp-image-457"&gt;  Figure 2 - Creating a list of employees for phishing and password spraying   
&lt;/div&gt; 
&lt;p&gt;Social media can also be useful for determining what relationships a business might have with other companies in the same industry that could be exploited, or what technology might be in use that may need to be avoided when you gain an internal foothold.&lt;/p&gt; 
&lt;h2&gt;DNS Records&lt;/h2&gt; 
&lt;p&gt;DNS records can also reveal a large amount of information regarding potential targets and remote entry points such as VPN or RDP gateways. In addition, with a lot of organisations moving to cloud platforms it can also help identify issues such as subdomain takeovers (they still very much exist in 2021!)&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="308" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture3-2.png?width=601&amp;amp;height=308&amp;amp;name=Picture3-2.png" alt="" class="wp-image-458"&gt;  Figure 3 - DNS record lookup using the dnsrecon tool (not stealthy)   
&lt;/div&gt; 
&lt;p&gt;One thing you should be wary of with DNS is that it can be noisy if you start querying the organisations DNS servers directly, so depending on how stealthy you need to be, this may need to be done via historical DNS records and/or certificate transparency lookups.&lt;/p&gt; 
&lt;h2&gt;Tools&lt;/h2&gt; 
&lt;p&gt;A number of tools exist that can automate some of this reconnaissance. During a time-limited penetration test these can be quite valuable, as they allow you to work on other tasks while the information is gathered.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;theHarvester - Almost a one-stop shop for reconnaissance and OSINT gathering. The tool can perform lookups using a number of different services, generating employee lists, lists of hosts, interesting files etc. Be aware that a majority of actions performed by theHarvester will touch the target, so may not be suitable for all tests.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;dnsrecon - This tool will do all the DNS reconnaissance required to enumerate subdomains. By default, it will use the target’s own nameservers, but you can specify which to use, and it does have the ability to lookup via certificate transparency logs, check for zone transfers etc.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;Fierce - DNS brute force tool, capable of performing reverse DNS queries. Noisy, so only useful on penetration tests where stealth doesn’t matter.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="334" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture4-2.png?width=601&amp;amp;height=334&amp;amp;name=Picture4-2.png" alt="" class="wp-image-459"&gt;  Figure 4 - fierce in action   
&lt;/div&gt; 
&lt;ul&gt; 
 &lt;li&gt;Hunter.io - Hunter.io is a useful tool for gathering target email addresses from around the Internet. The free tier limits the number of results returned but does give you an idea of how email addresses are formatted to create your own list from people enumerated through other sources. Paid tier does allow full results and the ability to download a CSV file.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;ul&gt; 
 &lt;li&gt;Shodan.io - Shodan can be useful for enumerating open services on target IP addresses without the need for active port scanning. Free tier allows you some use of the API such as domain, CIDR etc. but does have a limited number of daily queries.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="342" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture5-1.png?width=601&amp;amp;height=342&amp;amp;name=Picture5-1.png" alt="" class="wp-image-460"&gt;  Figure 5 - shodan interface   
&lt;/div&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fosint-for-penetration-testers&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Threat Emulation</category>
      <pubDate>Tue, 26 Oct 2021 04:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/osint-for-penetration-testers</guid>
      <dc:date>2021-10-26T04:00:00Z</dc:date>
      <dc:creator>Alex</dc:creator>
    </item>
    <item>
      <title>CONTI Group - The not so advanced APT</title>
      <link>https://www.alchemysec.com.au/blog/conti-group-the-not-so-advanced-apt</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/conti-group-the-not-so-advanced-apt" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/spider-hacker-01-1024x572.jpg" alt="CONTI Group - The not so advanced APT" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Recently in the news it was revealed that a member of an “APT” group that utilises the “Conti” ransomware became disgruntled at the state of their relationship with the group and leaked a large majority of the groups “Tools, Techniques and Procedures” documents.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recently in the news it was revealed that a member of an “APT” group that utilises the “Conti” ransomware became disgruntled at the state of their relationship with the group and leaked a large majority of the groups “Tools, Techniques and Procedures” documents.&lt;/p&gt; 
&lt;p&gt;Conti was first discovered in 2020 and is used primarily by the Russian crime group aliased as “Wizard Spider” (we will assume the leak came from a former member of this group). In addition to the encryption of files seen from historical families of ransomware, Conti also copies files to the attacker’s server before encryption, allowing the group to threaten data leaks if the ransom isn’t paid. &lt;/p&gt; 
&lt;p&gt;As we regularly hear of organisations succumbing to Conti infections or targeted by “Advanced Persistent Threats” such as Wizard Spider, I was curious as to how the group operates so successfully in compromising these organisations and delivering their payloads. In the name of science*, I obtained a copy of the leaked files and to my dismay discovered they really aren’t so “advanced” in the way they operate.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="92" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture1-1.png?width=601&amp;amp;height=92&amp;amp;name=Picture1-1.png" alt="" class="wp-image-427"&gt;  Figure 1 - Downloading the leak "for science"   
&lt;/div&gt;  
&lt;img width="1378" height="377" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture2-1.png?width=1378&amp;amp;height=377&amp;amp;name=Picture2-1.png" alt="" class="wp-image-428"&gt;  Figure 2 - Archive Contents   
&lt;p&gt;From what I can gather based on a Google translate of the leaked documents, activities tend to follow that of a standard penetration test, and they don’t seem to employ any advanced methods such as EDR evasion or attempt to hide their tracks long term which is kind of what you’d expect from a group labelled “advanced”. Organisations can take comfort that they don’t generally seem to utilise 0-day exploits but may jump on easily exploitable vulnerabilities that have recently been disclosed (install those patches!).&lt;/p&gt; 
&lt;h2&gt;Initial Compromise&lt;/h2&gt; 
&lt;p&gt;The group seems to have the most success in gaining an initial foothold through phishing, although have been seen brute forcing RDP end points exposed to the Internet. Often, they will attempt to directly just drop an executable file on a user’s machine via a malicious, disguised email attachment, which will beacon back to a command-and-control server (currently the IcedID malware).&lt;/p&gt; 
&lt;p&gt;This initial beacon then appears to be used to pull down a Cobalt Strike implant that is then used for the rest of the engagement.&lt;/p&gt; 
&lt;h2&gt;Lateral Movement&lt;/h2&gt; 
&lt;p&gt;Once the initial foothold has been gained, and the switch to Cobalt Strike has occurred, internal enumeration activities begin. Activities include enumeration of compromised user privileges on the local machine, identification of domain administrators, and open SMB shares.&lt;/p&gt; 
&lt;p&gt;During this phase, a lot of their activity is detectable if appropriate systems and alerts are in place. The group utilises several additional binaries such as “Adfind”, “Anydesk”, and “putty” which write artifacts to disk. In addition, widely available free scripts are used from projects such as Powerview or Bloodhound.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="374" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture3-1.png?width=601&amp;amp;height=374&amp;amp;name=Picture3-1.png" alt="" class="wp-image-429"&gt;  Figure 3 - Anydesk remote desktop configuration   
&lt;/div&gt; 
&lt;h2&gt;Privilege Escalation&lt;/h2&gt; 
&lt;p&gt;Attackers won’t necessarily perform lateral movement and privilege escalation once gaining an initial foothold, but once they start, they move quickly. Entire environment compromises have been reported in as quickly as 2 hours.&lt;/p&gt; 
&lt;p&gt;Privilege escalation doesn’t follow anything special, simply determining the best route to obtain administrator or higher privileges on the local machine, identifying domain administrator groups and then using well known tools to find where these users are logged in and compromising these systems to obtain their passwords/password hashes.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="601" height="462" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture4-1.png?width=601&amp;amp;height=462&amp;amp;name=Picture4-1.png" alt="" class="wp-image-430"&gt;  Figure 4 - Helpful instruction on hunting down admins   
&lt;/div&gt; 
&lt;p&gt;Once they have domain administrator privileges, they will exfiltrate company data (Office files etc.) offsite for use in blackmail at a later stage. After this they will drop Conti ransomware on the network, encrypting all files on the file share(s) and as many workstations as are reachable.&lt;/p&gt; 
&lt;h2&gt;Detection and Prevention&lt;/h2&gt; 
&lt;p&gt;The primary thread running through the leak is of a few people with &lt;em&gt;a bit more&lt;/em&gt; experience writing basic guides for those &lt;em&gt;not so experienced&lt;/em&gt;, and in performing IR for organisations compromised by Wizard Spider we have discovered that this seems to be the case.&lt;/p&gt; 
&lt;p&gt;Very little is information is provided for advanced exploitation techniques, stealth and remaining out of site or compromising even a semi-mature environment (ie. MFA and EDR or application whitelisting).&lt;/p&gt; 
&lt;p&gt;Organisations can greatly reduce the likelihood of compromise through investment in a couple of key areas. By implementing multi-factor authentication to prevent compromised credentials being re-used. Implementing application whitelisting configured to only allow approved binaries such as Microsoft-signed will prevent the malware from running all together in the event a user clicks on a link or opens an attachment.&lt;/p&gt; 
&lt;p&gt;In addition, implementing an Endpoint Detection and Response (EDR) will prevent “living off the land” style attacks that are consistent with exploitation behaviour.&lt;/p&gt; 
&lt;p&gt;For a long-term approach, organisations can follow the ACSC’s Essential 8 list of recommended security protections.&lt;/p&gt; 
&lt;h2&gt;Disclaimer&lt;/h2&gt; 
&lt;p&gt;I make no promises regarding organisation security when defending against an actual “advanced” threat such as a state-sponsored attacker tasked with infiltrating your organisation with specific goals in mind.&lt;/p&gt; 
&lt;p&gt;&lt;/p&gt; 
&lt;h2&gt;References&lt;/h2&gt; 
&lt;p&gt;https://www.nbcnews.com/tech/security/step-1-google-search-ransomware-hacker-goes-rogue-leaks-gangs-plan-rcna1611&lt;br&gt;https://thedfirreport.com/2021/05/12/conti-ransomware/&lt;br&gt;https://www.cyber.gov.au/acsc/view-all-content/essential-eight&lt;/p&gt; 
&lt;p&gt;&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fconti-group-the-not-so-advanced-apt&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Defence</category>
      <pubDate>Mon, 30 Aug 2021 04:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/conti-group-the-not-so-advanced-apt</guid>
      <dc:date>2021-08-30T04:00:00Z</dc:date>
      <dc:creator>Alex</dc:creator>
    </item>
    <item>
      <title>Hidden Cobra - Uncovering the North Korean APT</title>
      <link>https://www.alchemysec.com.au/blog/hidden-cobras-uncovering-the-north-korean-apt</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/hidden-cobras-uncovering-the-north-korean-apt" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/Alchemis-731x1024.jpg" alt="Hidden Cobra - Uncovering the North Korean APT" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Advanced persistent threats come in many forms ranging from your crime groups, activists all the way through to your state sponsored groups. While some of these threat actors such as crime groups are seen on a regular (if not daily..) basis, state sponsored attacks are less common and more sophisticated. While most state sponsored groups are engaged in similar activity, there is one group specifically that bridges the gap between your typical state sponsored and crime group.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Advanced persistent threats come in many forms ranging from your crime groups, activists all the way through to your state sponsored groups. While some of these threat actors such as crime groups are seen on a regular (if not daily..) basis, state sponsored attacks are less common and more sophisticated. While most state sponsored groups are engaged in similar activity, there is one group specifically that bridges the gap between your typical state sponsored and crime group.&lt;/p&gt; 
&lt;p&gt;Introducing, Hidden Cobra AKA Lazarus Group, the North Korean state sponsored threat actor.&lt;/p&gt; 
&lt;p&gt;Generally, state sponsored APT groups have a similar focus on espionage activities, typically targeting government, critical infrastructure and defence industries. Hidden Cobra however are known for engaging in a broad range of crime-based activity from ransomware all the way through to bank and cryptocurrency exchange heists since roughly 2009. We have listed a few of the better-known attacks Hidden Cobra have conducted below.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;2014 - Sony Breach&lt;/li&gt; 
 &lt;li&gt;2016 - Bangladesh Bank Cyber Heist&lt;/li&gt; 
 &lt;li&gt;2017 - WannaCry&lt;/li&gt; 
 &lt;li&gt;2017 - AppleJeus Cryptocurrency&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;We are going to explore the more recent activity of the AppleJeus campaigns to highlight some of the interesting Tools, Techniques and Processes utilised by Hidden Cobra.&lt;/p&gt; 
&lt;h2&gt;AppleJeus&lt;/h2&gt; 
&lt;p&gt;This specific malware is solely attributed to Hidden Cobra and to date, no other threat actors have been documented using this malware. It has been used in various campaigns to specifically target users of Cryptocurrency trading applications as well as Cryptocurrency exchanges themselves. This malware has been actively deployed and matured since its inception in 2018 across multiple campaigns as documented below from US-CERT.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;2018 Celas Trade Pro&lt;/li&gt; 
 &lt;li&gt;2019 JMT Trading&lt;/li&gt; 
 &lt;li&gt;2019 Union Crypto&lt;/li&gt; 
 &lt;li&gt;2020 Kupay Wallet&lt;/li&gt; 
 &lt;li&gt;2020 ConGoTrade&lt;/li&gt; 
 &lt;li&gt;2020 Dorusio&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AppleJeus is distributed via websites that impersonate a legitimate application or service. Typically these services or applications are related to cryptocurrency, however Hidden Cobra have also been seen impersonating IT administrative tools.&lt;/p&gt; 
&lt;p&gt;The attacker would take the legitimate application and repackage it to include their own malicious code. In some instances the application itself was injected with the malicious code, however in some instances the attacker would simply package a malicious binary along with the application using tools such as Advanced Installer and AutoIT.&lt;/p&gt; 
&lt;p&gt;The threat actor would then host the repackaged/modified application on their impersonated website, before referring users to the malicious website via posts on numerous cryptocurrency forums.&lt;/p&gt; 
&lt;p&gt;Included below are just a few examples of websites and applications that have been impersonated and used by Hidden Cobra as part of their ongoing AppleJeus campaigns to date.&lt;/p&gt; 
&lt;h2 class="has-medium-font-size"&gt;Celas Trade Pro – celasllc[.]com&lt;/h2&gt; 
&lt;p&gt;This AppleJeus campaign was identified in August 2018 and was distributed via a modified and backdoored version of 'Q.T. Bitcoin Trader'. The malware itself was hosted on celasllc[.]com with both Windows and MacOS versions available for download.&lt;/p&gt; 
&lt;div class="wp-block-image is-style-default"&gt;  
 &lt;img width="600" height="321" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/celastrading.png?width=600&amp;amp;height=321&amp;amp;name=celastrading.png" alt="" class="wp-image-387"&gt;  The celasllc[.]com website that was used to distribute AppleJeus in 2018.   
&lt;/div&gt; 
&lt;h2 class="has-medium-font-size"&gt;JMT Trading – jmttrading[.]org&lt;/h2&gt; 
&lt;p&gt;The JMTTrading AppleJeus campaign was identified in 2019, distributed again with a modified version of 'Q.T. Bitcoin Trader'. The malware itself was hosted on GitHub, with both prepackage and 'open-source' versions available for Windows and MacOS.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/JMT-1024x558.jpg?width=768&amp;amp;height=419&amp;amp;name=JMT-1024x558.jpg" alt="" class="wp-image-388" width="768" height="419"&gt;  The jmttrading[.]org website that was used to distribute AppleJeus in 2019.   
&lt;/div&gt; 
&lt;h2 class="has-medium-font-size"&gt;Union Crypto Trader - uninioncrypto[.]vip&lt;/h2&gt; 
&lt;p&gt;Union Crypto was another fake cryptocurrency trading application that was created solely to distribute the AppleJeus malware in 2019.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="600" height="264" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/unioncrp.png?width=600&amp;amp;height=264&amp;amp;name=unioncrp.png" alt="" class="wp-image-389"&gt;  The unioncrypto[.]vip website that as used to distribute the malware in 2019.   
&lt;/div&gt; 
&lt;h2 class="has-medium-font-size"&gt;Bitcoin Find and Recover - btcfindrecover[.]pw&lt;/h2&gt; 
&lt;p&gt;Bitcoin Find and Recover is a legitimate opensource bitcoin password and seed recovery tool. This legitimate tool was utilised to spread AppleJeus via a fake web page. The application itself was hosted prepackaged on the btcfindrecover[.]pw web server with a link back to the actual GitHub repository. &lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="1023" height="928" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/btcfindandrecover.png?width=1023&amp;amp;height=928&amp;amp;name=btcfindandrecover.png" alt="" class="wp-image-390"&gt;  The btcfindrecover[.]pw website that was used to distribute the malware from 2019.   
&lt;/div&gt; 
&lt;h2 class="has-medium-font-size"&gt;Electrum Wallet - electrum-wallet[.]com&lt;/h2&gt; 
&lt;p&gt;Electrum Wallet is a legitimate opensource bitcoin wallet application. The threat actor bundled their malicious code with the application using packaging software such as 'Advanced Installer'. Users were directed to download the backdoored application through forum posts.&lt;/p&gt;  
&lt;img width="690" height="303" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/electrumwaller.jpg?width=690&amp;amp;height=303&amp;amp;name=electrumwaller.jpg" alt="" class="wp-image-391"&gt;  Forum posts utilised by the threat actor to lure users to their webpage hosting the malware.   
&lt;p&gt;AppleJeus malware has a particular focus on cryptocurrency, and it is distributed it in such a way to infect targets through both direct and indirect methods. By simply hosting their malware on their legitimate looking websites and referring target users or organisations to download and utilise the tool, they can compromise both corporate environments and individuals. &lt;/p&gt; 
&lt;p&gt;The malware itself will proactively and re-actively search for crypto currency wallets, usernames and passwords on the target machine before exfiltrating this data to command-and-control infrastructure via https post requests. &lt;/p&gt; 
&lt;h2&gt;Not your typical state sponsored threat actor&lt;/h2&gt; 
&lt;p&gt;While specifically targeting cryptocurrency and banking sectors is not a characteristic unique to Hidden Cobra, it is a unique characteristic for a state sponsored threat actor. While state sponsored attacks are rarer in comparison to crime groups, Hidden Cobra are an example of how even the simplest looking attacks should be taken seriously. The AppleJeus malware itself is not advanced by any means, however as the target audience is broad, these campaigns manage to compromise both individuals and businesses across a vast range of verticals.&lt;/p&gt; 
&lt;p&gt;The graphs below show the geographical spread of infection based on command-and-control traffic to domains that were hijacked during a recent incident response engagement.&lt;/p&gt;  
&lt;img width="1024" height="317" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/applejeusgeomap-1024x317.png?width=1024&amp;amp;height=317&amp;amp;name=applejeusgeomap-1024x317.png" alt="" class="wp-image-392"&gt;  Geographical spread of infections.    
&lt;img width="1024" height="258" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/applejeus-activity-1024x258.png?width=1024&amp;amp;height=258&amp;amp;name=applejeus-activity-1024x258.png" alt="" class="wp-image-393"&gt;  Time chart of infections by country.   
&lt;h2&gt;Defending against these forms of attacks&lt;/h2&gt; 
&lt;p&gt;The TTPs employed by Hidden Cobra are not advanced; technology such as end-point detection response and application whitelisting are extremely effective at detecting and mitigating the TTPs associated with this threat actor. As an individual, secure practices such as hash-based validation are also highly effective practices to ensure that the file you are downloading is legitimate. Most developers will provide a list of hashes (Such as MD5, SHA256 etc..) that can be used to verify that the hash of the file you downloaded matches the hash supplied by the developer.&lt;/p&gt; 
&lt;p&gt;And finally, ensure that you always download applications from a trusted source.&lt;/p&gt; 
&lt;h2&gt;References&lt;/h2&gt; 
&lt;p&gt;&lt;a href="https://us-cert.cisa.gov/ncas/alerts/aa21-048a"&gt;https://us-cert.cisa.gov/ncas/alerts/aa21-048a&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory-hidden-cobra-applejeus-cryptocurrency-threats/"&gt;https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory-hidden-cobra-applejeus-cryptocurrency-threats/&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fhidden-cobras-uncovering-the-north-korean-apt&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Defence</category>
      <pubDate>Tue, 03 Aug 2021 04:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/hidden-cobras-uncovering-the-north-korean-apt</guid>
      <dc:date>2021-08-03T04:00:00Z</dc:date>
      <dc:creator>Will</dc:creator>
    </item>
    <item>
      <title>Please Sign Here - Why NTLM Relaying Is Still a Risk in 2021 - Cyber Security Consultants - Alchemy</title>
      <link>https://www.alchemysec.com.au/blog/please-sign-here-why-ntlm-relaying-is-still-a-risk-in-2021</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/please-sign-here-why-ntlm-relaying-is-still-a-risk-in-2021" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/envelope-01-1024x572.jpg" alt="Please Sign Here - Why NTLM Relaying Is Still a Risk in 2021 - Cyber Security Consultants - Alchemy" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;The&amp;nbsp;Windows&amp;nbsp;Name&amp;nbsp;Resolution&amp;nbsp;Flow&lt;/h2&gt; 
&lt;p&gt;You may be under the impression that turning host names into&amp;nbsp;IP addresses is simple.&lt;/p&gt;</description>
      <content:encoded>&lt;h2&gt;The&amp;nbsp;Windows&amp;nbsp;Name&amp;nbsp;Resolution&amp;nbsp;Flow&lt;/h2&gt; 
&lt;p&gt;You may be under the impression that turning host names into&amp;nbsp;IP addresses is simple.&lt;/p&gt; 
&lt;p&gt;You check:&amp;nbsp;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;The Hosts file; then&amp;nbsp;&lt;/li&gt; 
 &lt;li&gt;Your system’s&amp;nbsp;DNS (Domain Name System)&amp;nbsp;resolver&amp;nbsp;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;That’s it right?&amp;nbsp;If you don’t get a response from your local file or DNS, then the system doesn’t exist. Well,&amp;nbsp;no; the&amp;nbsp;name resolution flow&amp;nbsp;in Windows&amp;nbsp;looks&amp;nbsp;something like this:&amp;nbsp;&lt;/p&gt;  
&lt;img width="1024" height="225" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Windows-Name-Resolution-1024x225.png?width=1024&amp;amp;height=225&amp;amp;name=Windows-Name-Resolution-1024x225.png" alt="" class="wp-image-368"&gt;  Figure 1 - Windows host name resolution flow   
&lt;p&gt;Well, that’s a bit more complicated, isn’t it? And a bit hard to read – feel free to take a minute to look at&amp;nbsp;it zoomed in.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Now I can hear you thinking “WINS? LM Hosts? LLMNR? I don’t remember turning those on. What even are they?”. The more technical people may even be saying “What? We have a domain; we won’t use anything like WINS or NetBIOS. They’re for workgroups.”&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Why&amp;nbsp;Windows Finds Services Via&amp;nbsp;Broadcast&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;Unfortunately, these are all legacy settings that are enabled by default to meet Microsoft’s ever-present backwards-compatible philosophy. You don’t get big in enterprise if your new OS breaks all your old apps and services.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Have you been in the “Network” tab&amp;nbsp;in explorer&amp;nbsp;and wondered&amp;nbsp;how&amp;nbsp;all&amp;nbsp;those laptops and meeting room TVs&amp;nbsp;got there? Has your internet gone out at home and your router redirects you to a webpage to let you know what’s happening? These are&amp;nbsp;all&amp;nbsp;work&amp;nbsp;via broadcast name resolution methods.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;This is especially important for small to medium-sized businesses which might not have an internal domain. How does&amp;nbsp;a new laptop find “WD Cloud Drive” or “BOB-PC” with no Active Directory DNS service&amp;nbsp;to find the file shares?&amp;nbsp;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The same applies to other services as well: WPAD requests are sent out to&amp;nbsp;decide&amp;nbsp;how to proxy web requests in&amp;nbsp;environments&amp;nbsp;that don’t set proxies via DHCP or Group Policy.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Net-NTLMv2&amp;nbsp;Authentication&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;Even back in the&amp;nbsp;Windows NT days, Microsoft knew that that NTLMv1 (DES encryption based on your password hash) was not&amp;nbsp;secure,&amp;nbsp;so they&amp;nbsp;needed a&amp;nbsp;new network authentication mechanism. As such Net-NTLMv2 was introduced in Windows NT4&amp;nbsp;as part of the Security Support Provider framework.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;It goes a little something like this:&amp;nbsp;&lt;/p&gt;  
&lt;img width="1024" height="420" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-2-1024x420.png?width=1024&amp;amp;height=420&amp;amp;name=image-2-1024x420.png" alt="Diagram

Description automatically generated" class="wp-image-352"&gt;  
&lt;em&gt;Figure&amp;nbsp;2&amp;nbsp;- NTLM authentication flow&lt;/em&gt;   
&lt;p&gt;Overall, this is a solid attempt as the user’s password or&amp;nbsp;NT&amp;nbsp;password hash is never sent over the network, but the domain controller can verify the authentication attempt from the NTLMv2 response, server nonce, and the user’s stored NT password hash.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Unfortunately,&amp;nbsp;there is&amp;nbsp;a little&amp;nbsp;idiosyncrasy&amp;nbsp;when using&amp;nbsp;Net-NTLMv2 over SMB (network shares) or LDAP (directory services)&amp;nbsp;- neither the client station&amp;nbsp;nor&amp;nbsp;the server&amp;nbsp;is&amp;nbsp;authenticated&amp;nbsp;in this process, only the connection. This allows a MitM (Man in the Middle)&amp;nbsp;attack to intercept&amp;nbsp;authentication&amp;nbsp;attempts&amp;nbsp;to achieve an authenticated connection.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Relaying&amp;nbsp;Credentials&amp;nbsp;(aka. Pass the Hash)&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;So, let's say we’re a threat actor on the network and we want to be in the middle&amp;nbsp;of one of these connections. We know that Windows clients&amp;nbsp;will&amp;nbsp;sometimes broadcast name requests onto the&amp;nbsp;network,&amp;nbsp;so we just listen;&amp;nbsp;mDNS, WINS, NetBIOS,&amp;nbsp;LLMNR, all of them.&amp;nbsp;Once we get a hit, we&amp;nbsp;impersonate the&amp;nbsp;service, and the connection now looks like this:&amp;nbsp;&lt;/p&gt;  
&lt;img width="761" height="411" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-1-1.png?width=761&amp;amp;height=411&amp;amp;name=image-1-1.png" alt="Timeline

Description automatically generated" class="wp-image-351"&gt;  
&lt;em&gt;Figure&amp;nbsp;3&amp;nbsp;- Intercepted NTLM authentication&lt;/em&gt;&amp;nbsp;   
&lt;p&gt;This is possible because, in the default configuration,&amp;nbsp;this process&amp;nbsp;&lt;em&gt;does not authenticate either the server or client device&amp;nbsp;-&amp;nbsp;&lt;/em&gt;it will only authenticate the credentials sent&amp;nbsp;during negotiation.&amp;nbsp;Unless both the server and client specifically&amp;nbsp;request/require&amp;nbsp;message authentication and encryption (“Sign”&amp;nbsp;and&amp;nbsp;“Seal”&amp;nbsp;in&amp;nbsp;SMB parlance)&amp;nbsp;then it will not occur.&amp;nbsp;This leaves the attacker with a fully authenticated session&amp;nbsp;that the server does not know&amp;nbsp;has been intercepted.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;How to Get More Requests with IPv6&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;OK, so we turn of&amp;nbsp;broadcast&amp;nbsp;name resolution. With that, we’re safe from rogue&amp;nbsp;nameservers on our local network!&amp;nbsp;&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="489" height="487" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-5-1.png?width=489&amp;amp;height=487&amp;amp;name=image-5-1.png" alt="A collage of a person

Description automatically generated with low confidence" class="wp-image-355"&gt;  
 &lt;em&gt;Figure&amp;nbsp;4&amp;nbsp;- Narrator: it was not&lt;/em&gt;&amp;nbsp;   
&lt;/div&gt; 
&lt;p&gt;From Windows Vista&amp;nbsp;and Windows Server 2008, the default configuration&amp;nbsp;will&amp;nbsp;configure&amp;nbsp;IPV6 with DHCPv6 enabled.&amp;nbsp;In keeping with IPv6’s living-network ethos, Windows will periodically send nameserver&amp;nbsp;solicitations to IPv6 multicast addresses to discover new resolvers.&amp;nbsp;&lt;/p&gt;  
&lt;img width="1023" height="340" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-4-1.png?width=1023&amp;amp;height=340&amp;amp;name=image-4-1.png" alt="Graphical user interface, table

Description automatically generated with medium confidence" class="wp-image-354"&gt;  
&lt;em&gt;Figure&amp;nbsp;5&amp;nbsp;- Windows client DHCPv6 solicitation&lt;/em&gt;   
&lt;p&gt;&amp;nbsp;It’s important&amp;nbsp;to note&amp;nbsp;here that with&amp;nbsp;malicious DHCP servers in IPv4 networks,&amp;nbsp;you have to race the real DHCP server to respond to the client as the first answer will be&amp;nbsp;used and any further responses will be ignored.&amp;nbsp;But since IPv6 is designed for clients and routers to communicate and&amp;nbsp;dynamically update&amp;nbsp;network configurations&amp;nbsp;– if we respond to these requests,&amp;nbsp;our&amp;nbsp;IPv6 address&amp;nbsp;will be&amp;nbsp;set as an&amp;nbsp;additional&amp;nbsp;DNS server&amp;nbsp;or router. Windows also prefers IPv6 DNS servers before IPv4 DNS servers, allowing&amp;nbsp;interception&amp;nbsp;traffic&amp;nbsp;from&amp;nbsp;local devices.&amp;nbsp;&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="611" height="283" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image-3-1.png?width=611&amp;amp;height=283&amp;amp;name=image-3-1.png" alt="Text

Description automatically generated with low confidence" class="wp-image-353"&gt;  
 &lt;em&gt;Figure&amp;nbsp;6&amp;nbsp;- Windows client with malicious IPv6 default route&lt;/em&gt;   
&lt;/div&gt; 
&lt;h2&gt;Preventing&amp;nbsp;Credential&amp;nbsp;Relaying&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;As we see in&amp;nbsp;Figure&amp;nbsp;3&amp;nbsp;above, a malicious user is able to forge an authenticated session by&amp;nbsp;intercepting and redirecting the handshake&amp;nbsp;to a controlled target. We were able to do this because there is no&amp;nbsp;authenticity&amp;nbsp;enforcement on the&amp;nbsp;final connection.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The number one way to prevent credential relaying in an enterprise network is to enforce signing of SMB and LDAP traffic (we’ll ignore NTLM authentication over HTTP,&amp;nbsp;transport security provides authenticity for HTTPS connections). When&amp;nbsp;message signing is enforced, the client and&amp;nbsp;server use an&amp;nbsp;agreed session key to&amp;nbsp;include cryptographic signatures for messages in the authenticated session. The session key is&amp;nbsp;derived using the&amp;nbsp;algorithm below:&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;code&gt;sessionKey&amp;nbsp;= HMAC-MD5(v2-Hash, HMAC-MD5(v2-Hash,&amp;nbsp;NTLMv2 Response + Server Challenge))&lt;/code&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;This relies on the user’s&amp;nbsp;password hash which the server doesn’t know, but since the server needs to&amp;nbsp;validate the authentication, the Domain controller can calculate and return the session key in the authentication response.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;By enforcing this signature, MitM attacks are no longer possible as an attacker cannot calculate the authentication code for messages.&amp;nbsp;&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Why&amp;nbsp;Server-Side&amp;nbsp;Signing&amp;nbsp;Enforcement&amp;nbsp;Is Not&amp;nbsp;Enough&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;A common policy in modern networks is to enforce signing on servers only, and this seems reasonable; since enforcement at either side is effectively enforcement at both sides, it should be fine to just set it on servers.&amp;nbsp;Problems arise, however, when we have to deal with non-standard configurations – maybe&amp;nbsp;you require support for an old building management system that doesn’t support authentication with signing… or an HVAC system… or access control.&amp;nbsp;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;If you have systems like this,&amp;nbsp;supporting them means&amp;nbsp;supporting&amp;nbsp;insecure configurations&amp;nbsp;in your environment.&amp;nbsp;Part of remediating these issues&amp;nbsp;can be&amp;nbsp;segmentation and segregation of your environment, but systems are inherently meant to be accessed.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;In these cases, the best way to prevent these attacks is to ensure that client systems are also enforcing secure configurations. Only systems that are explicitly required to having signing disabled should be allowed, to minimize the risk of exploitation.&amp;nbsp;&lt;/p&gt; 
&lt;h2&gt;Conclusion&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;In modern environments, it’s common to see that signing for SMB and LDAP&amp;nbsp;have been enforced on Domain Controllers but with modern tooling that understands those limitations, attackers are still able to&amp;nbsp;exploit this weakness&amp;nbsp;to gain privileges in your environment.&amp;nbsp;Through name resolution poisoning they can collect user password hashes. Through credential&amp;nbsp;relaying,&amp;nbsp;attackers can gain authenticated connections to network shares,&amp;nbsp;extracting&amp;nbsp;or deleting&amp;nbsp;business data&amp;nbsp;and even system backups.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Due to these risks, we recommend the following GPOs to minimize the risk and impact of credential relaying:&amp;nbsp;&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Network security: LDAP client signing requirements&amp;nbsp;– Require Signing&amp;nbsp;(Require signing for LDAP clients)&amp;nbsp;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;ol start="2"&gt; 
 &lt;li&gt;Network&amp;nbsp;security: LDAP server signing requirements – Require Signing (Require signing for LDAP servers)&amp;nbsp;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;ol start="3"&gt; 
 &lt;li&gt;Domain controller: LDAP server channel binding token requirements&amp;nbsp;–&amp;nbsp;Always&amp;nbsp;(Prevent cross-protocol NTLMv2 relaying)&amp;nbsp;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;ol start="4"&gt; 
 &lt;li&gt;Microsoft network client: Digitally sign communications (always)&amp;nbsp;– Enabled&amp;nbsp;(Require signing for SMB&amp;nbsp;clients)&amp;nbsp;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;ol start="5"&gt; 
 &lt;li&gt;Microsoft network server: Digitally sign communications (always)&amp;nbsp;– Enabled&amp;nbsp;(Require signing for SMB servers)&amp;nbsp;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;ol start="6"&gt; 
 &lt;li&gt;Turn off smart multi-homed name resolution&amp;nbsp;– Enabled (Disable LLMNR)&amp;nbsp;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;ol start="7"&gt; 
 &lt;li&gt;Turn off&amp;nbsp;multicast name resolution – Enabled (Disable&amp;nbsp;mDNS)&amp;nbsp;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;In addition, the following PowerShell command can be used to disable NetBIOS on&amp;nbsp;Windows Endpoints:&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;code&gt;Get-ChildItem&amp;nbsp;"HKLM:SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces"&amp;nbsp;|&amp;nbsp;foreach { Set-ItemProperty&amp;nbsp;-Path "$regkey\$($_.pschildname)" -Name&amp;nbsp;NetbiosOptions&amp;nbsp;-Value 2}&amp;nbsp;&lt;/code&gt;&lt;/p&gt; 
&lt;h2&gt;Postscript&lt;/h2&gt; 
&lt;p&gt;In this post,&amp;nbsp;we discussed&amp;nbsp;the risks&amp;nbsp;of not enforcing&amp;nbsp;SMB/LDAP&amp;nbsp;signing and described the process of&amp;nbsp;Net-NTLMv2 authentication. We did not discuss NTLMv1, but the advice&amp;nbsp;you will receive from all sources is clear:&amp;nbsp;&lt;strong&gt;NTLMv1 is not safe, and it should be turned off.&lt;/strong&gt;&amp;nbsp;The network hash itself is&amp;nbsp;salted, but the encryption algorithm is weak. The session key also leaks information as it is calculated without a hash as below:&amp;nbsp;&lt;/p&gt; 
&lt;p class="has-text-align-center"&gt;&lt;code&gt;sessionKey&amp;nbsp;= MD4(NT&amp;nbsp;password&amp;nbsp;hash)&amp;nbsp;&lt;/code&gt;&lt;/p&gt; 
&lt;p&gt;To prevent NTLMv1 use in your environment, the&amp;nbsp;following GPO should be set:&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Network security: LAN Manager authentication level&amp;nbsp;-&amp;nbsp;Send NTLMv2 responses only\refuse LM &amp;amp; NTLM&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fplease-sign-here-why-ntlm-relaying-is-still-a-risk-in-2021&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Threat Emulation</category>
      <pubDate>Mon, 14 Jun 2021 04:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/please-sign-here-why-ntlm-relaying-is-still-a-risk-in-2021</guid>
      <dc:date>2021-06-14T04:00:00Z</dc:date>
      <dc:creator>Phil</dc:creator>
    </item>
    <item>
      <title>The benefits of Red Teaming</title>
      <link>https://www.alchemysec.com.au/blog/the-benefits-of-red-teaming</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/the-benefits-of-red-teaming" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/team-hacker-red-01-1024x571.jpg" alt="The benefits of Red Teaming" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Red teaming is not a new concept within the cyber security community. However in Australia, Red Teaming is a relatively new term for most organisations. In this blog post we'll take a dive into:&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Red teaming is not a new concept within the cyber security community. However in Australia, Red Teaming is a relatively new term for most organisations. In this blog post we'll take a dive into:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;What differentiates a Red Team engagement from a Penetration Test.&lt;/li&gt; 
 &lt;li&gt;Why you shouldn't consider a red team engagement (You totally should.)&lt;/li&gt; 
 &lt;li&gt;The overall benefits of a red team engagement.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p class="has-medium-font-size"&gt;&lt;strong&gt;The Differences&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;There are key differences between a Red Team engagement and a typical penetration test. The first difference to consider is that a Red Team engagement is almost always a 'black box' engagement where very little information outside of clearly defined objectives are supplied by the client. This is also typically the case internally, with very few internal staff members being briefed on both the engagement scope, objectives and timelines. &lt;/p&gt; 
&lt;p&gt;While a Red Team engagement and a penetration test can have very similar objectives, the target scope and approach will differ dramatically. For example, a typical perimeter penetration test will be restricted to targeting an organisation via the internet utilising agreed attack methods. A Red Team engagement however will identify multiple attack surfaces to properly test an organisations overall resilience to an attack from an advanced threat actor. A Red Team engagement will engage in activities such as:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Social Engineering 
  &lt;ul&gt; 
   &lt;li&gt;Phishing&lt;/li&gt; 
   &lt;li&gt;Vishing&lt;/li&gt; 
  &lt;/ul&gt;&lt;/li&gt; 
 &lt;li&gt;Physical Intrusion 
  &lt;ul&gt; 
   &lt;li&gt;Lock Picking&lt;/li&gt; 
   &lt;li&gt;Tail Gating&lt;/li&gt; 
   &lt;li&gt;Physical Implant/Device Placement&lt;/li&gt; 
   &lt;li&gt;Physical Badge Cloning&lt;/li&gt; 
  &lt;/ul&gt;&lt;/li&gt; 
 &lt;li&gt;Wireless Testing&lt;/li&gt; 
 &lt;li&gt;Perimeter Testing&lt;/li&gt; 
 &lt;li&gt;Vulnerability Exploitation&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Another key difference between a typical penetration test and a Red Team engagement is the approach, team size and duration of the assessment. A typical penetration test engagement will generally consist of:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Clearly defined testing process/plan &lt;/li&gt; 
 &lt;li&gt;Duration of five to ten business days&lt;/li&gt; 
 &lt;li&gt;One resource assigned for the duration of the assessment.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;A Red Team engagement differs slightly:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;A Dynamic testing process with a constantly evolving plan.&lt;/li&gt; 
 &lt;li&gt;Duration of ten business days or more.&lt;/li&gt; 
 &lt;li&gt;A minimum of two resources assigned for the duration of the assessment.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Due to the nature of a Red Team engagement, the team will need to create a multi-tiered plan to successfully achieve their target objectives. This involves granular enumeration processes prior to attempting any form of planning or exploitation against a target.&lt;/p&gt; 
&lt;p class="has-medium-font-size"&gt;&lt;strong&gt;Considerations&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Before considering a Red Team engagement over a traditional penetration test, we recommend that customers consider their Cyber Security defensive capabilities. For example if your organisation does not have a cyber security team, strategy or critical security controls in place such as the majority of the ACSC Essential Eight then a Red Team engagement is likely not going to provide more value for you than a traditional penetration test.&lt;/p&gt; 
&lt;p class="has-medium-font-size"&gt;&lt;strong&gt;The Benefits&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;A Red team assessment will target multiple layers of your organization to test their defensive capability against an attack from an Advanced Persistent Threat (APT). While a typical penetration test is limited to a specific service or environment, a Red Team assessment will target your technology, people and physical security to identify the risk posed by an APT (Advanced Persistent Threat) against agreed objectives or scenarios.&lt;/p&gt; 
&lt;p&gt;As part of a red team assessment, you will be able to exercise your defensive technology, incident response and user awareness training to identify and contain an active breach. By working closely with relevant teams, a red team is able to identify advanced vulnerabilities across multiple layers of an organisation and assist them in defending against successful attacks to mature their defensive capabilities.&lt;/p&gt; 
&lt;p&gt;Overall a Red Team engagement is an excellent way for an organisation to test their resilience against an advanced threat actor and to identify vulnerabilities in layers of the organisation they were otherwise not aware of.&lt;/p&gt; 
&lt;p&gt;&lt;/p&gt; 
&lt;p&gt;&lt;/p&gt; 
&lt;p&gt;&lt;br&gt;&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fthe-benefits-of-red-teaming&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Threat Emulation</category>
      <pubDate>Wed, 07 Apr 2021 04:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/the-benefits-of-red-teaming</guid>
      <dc:date>2021-04-07T04:00:00Z</dc:date>
      <dc:creator>Will</dc:creator>
    </item>
    <item>
      <title>Stealing Password Reset Tokens for Fun and Profit - Cyber Security Consultants - Alchemy</title>
      <link>https://www.alchemysec.com.au/blog/stealing-password-reset-tokens-for-fun-and-profit</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/stealing-password-reset-tokens-for-fun-and-profit" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/Hacker-white-background.png" alt="Stealing Password Reset Tokens for Fun and Profit - Cyber Security Consultants - Alchemy" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;When adding a “Password Reset” function to your application it is especially important to ensure this has the same security considerations as any other critical function within the application. Due to the nature of resetting a user’s password, along with many security considerations being overlooked, it is not uncommon for attackers to spend extra time trying to bend these types of functions to their will to try and gain unauthorised access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When adding a “Password Reset” function to your application it is especially important to ensure this has the same security considerations as any other critical function within the application. Due to the nature of resetting a user’s password, along with many security considerations being overlooked, it is not uncommon for attackers to spend extra time trying to bend these types of functions to their will to try and gain unauthorised access.&lt;/p&gt; 
&lt;p&gt;There are some key considerations that must take place when implementing this functionality to ensure it cannot be abused by attackers:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;it should essentially be impossible for an attacker to obtain in any manner a password reset token for another user,&lt;/li&gt; 
 &lt;li&gt;tokens must have a limited time span and be invalidated upon use,&lt;/li&gt; 
 &lt;li&gt;tokens must be authorised to only perform a password reset.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Let’s take a look in the case of an application Alchemy Security tested recently.&lt;/p&gt; 
&lt;p class="has-medium-font-size"&gt;&lt;strong&gt;Problem one – static password reset tokens&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;For each user a password reset token was created at time of account creation and stored in the database as part of the credentials. This meant the account had a single reset token valid for the lifetime of the account, independent of how many times the user forgot their password.&lt;/p&gt; 
&lt;p&gt;As the token was not invalidated after a period of time or once used, this meant that even if the legitimate user reset their password, an attacker still had access to the token and in turn the account, another weakness detailed in problem two. It also appeared likely that the token could not be invalidated without deleting and re-creating the account.&lt;/p&gt; 
&lt;p&gt;The token was returned in a ‘HTTP 200 OK’ response from the API endpoint, so while not visible within the web page itself, was still easily obtainable by an attacker simply using an interception proxy such as Burp Suite. This meant that an attacker could easily write a script to test a list of usernames and obtain the token for each by parsing the resulting response.&lt;/p&gt; 
&lt;p&gt;To make matters worse, all of the above actions do not require any user authentication. Allowing an un-authenticated attacker to easily enumerate both usernames and their associated reset tokens without restriction or valid credentials.&lt;/p&gt;  
&lt;img width="941" height="172" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/leaked-token1.png?width=941&amp;amp;height=172&amp;amp;name=leaked-token1.png" alt="" class="wp-image-301"&gt;  Leaked password reset token.   
&lt;p class="has-medium-font-size"&gt;&lt;strong&gt;Problem two – excessive token permissions &amp;amp; incorrect authorisation checks&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;The biggest problem was the token itself had excessive permissions and was able to perform almost any action for which the user already had permissions. For example, the token could be used to update the user’s profile (which then leaked the user’s password hash, another big issue!) or perform search functions to access data for which the user had access to.&lt;/p&gt; 
&lt;p&gt;These two issues meant that the application was prone to two critical security issues:&lt;/p&gt; 
&lt;ol type="1"&gt; 
 &lt;li&gt;Account takeovers: An attacker able to obtain a reset token now had the ability to change a user’s email address associated with the account and perform an actual password reset (among other changes).&lt;/li&gt; 
 &lt;li&gt;Application takeover: If an attacker targeted an admin account, they could essentially take full control of the application, locking out other administrator accounts and accessing all data within the application. Alternately, they could make changes to any other account of their choice, including escalating privileges of a low privileged account they already had access to.&lt;/li&gt; 
&lt;/ol&gt;  
&lt;img width="941" height="164" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/leaked-token2.png?width=941&amp;amp;height=164&amp;amp;name=leaked-token2.png" alt="" class="wp-image-303"&gt;  Stealing an admin password reset token.    
&lt;img width="941" height="514" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/leaked-token3.png?width=941&amp;amp;height=514&amp;amp;name=leaked-token3.png" alt="" class="wp-image-304"&gt;  Escalating privileges using stolen token.   
&lt;p&gt;These issues can be easily be avoided in the following manner:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;ensure reset tokens are only created once a user runs the “password reset” function,&lt;/li&gt; 
 &lt;li&gt;tokens must only be provided to the user requesting the reset via an email address previously validated and connected to the account and not returned via the web application front end,&lt;/li&gt; 
 &lt;li&gt;tokens must only be authorised to perform a reset and not have permissions for any other purpose,&lt;/li&gt; 
 &lt;li&gt;tokens must not be easily guessed, predictable or able to be brute forced.&lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fstealing-password-reset-tokens-for-fun-and-profit&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Threat Emulation</category>
      <pubDate>Mon, 28 Dec 2020 05:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/stealing-password-reset-tokens-for-fun-and-profit</guid>
      <dc:date>2020-12-28T05:00:00Z</dc:date>
      <dc:creator>Alex</dc:creator>
    </item>
    <item>
      <title>MITRE ATT&amp;CK Framework Primer</title>
      <link>https://www.alchemysec.com.au/blog/mitre-attck-framework-primer</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.alchemysec.com.au/blog/mitre-attck-framework-primer" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/text-figure1-01-1024x571.jpg" alt="MITRE ATT&amp;amp;CK Framework Primer" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The MITRE ATT&amp;amp;CK framework is a fairly familiar term within the Cyber Security industry. It has quickly evolved from a niche framework, to the core of many security operation centers. While the vast majority of security operating centers are familiar with the framework, less mature businesses have trouble understanding where to start and, how to apply the framework effectively.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The MITRE ATT&amp;amp;CK framework is a fairly familiar term within the Cyber Security industry. It has quickly evolved from a niche framework, to the core of many security operation centers. While the vast majority of security operating centers are familiar with the framework, less mature businesses have trouble understanding where to start and, how to apply the framework effectively.&lt;/p&gt; 
&lt;div class="wp-block-image"&gt;  
 &lt;img width="451" height="93" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/image.png?width=451&amp;amp;height=93&amp;amp;name=image.png" alt="" class="wp-image-244"&gt;  
&lt;/div&gt; 
&lt;h2&gt;ATT&amp;amp;CK 1-0-1&lt;/h2&gt; 
&lt;p&gt;ATT&amp;amp;CK is broken up into various categories called ‘Tactics’ starting from ‘Initial Access’ all the way down to ‘Impact’. We liken the order of ATT&amp;amp;CK Tactics from left to right with the Lockheed Martin Cyber Killchain. The Lockheed Martin Cyber Kill Chain visualises the phases a threat actor will have to transition through to meet their objective. &lt;strong&gt;As such, detecting or mitigating a technique in an earlier Tactic allows you to limit the impact the breach will have on your environment by preventing the threat actor from actioning a technique in a later Tactic.&lt;/strong&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;We use this as a general rule, it is possible for some attacks to completely skip various Tactics. However, it is much easier to defend or recover from an attack when you have implemented appropriate mitigation, detection and recovery strategies to better respond to a technique earlier, rather than responding to them in a later Tactic such as ‘Impact’. For example, if you have strategies in place that allow you to detect or prevent potentially malicious remote access events such as a user logging into a VPN service from outside of Australia. You can proactively respond by disabling the account, resetting the users password and preventing the threat actor from actioning techniques from later Tactics. This makes it significantly more difficult for a threat actor to reach their end goal while allowing you to more easily defend your environment.&lt;/p&gt; 
&lt;p&gt;Reconnaissance&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Resource Development&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Initial Access&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Execution&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Persistence&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Privilege Escalation&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Defence Evasion&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Credential Access&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Discovery&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Lateral Movement&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Collection&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Command and Control&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Exfiltration&amp;nbsp;&lt;span class="has-inline-color has-vivid-cyan-blue-color"&gt;&amp;gt;&lt;/span&gt;&amp;nbsp;Impact&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The MITRE ATT&amp;amp;CK framework is built from the perspective of a threat actor, detailing how a threat actor may break into an environment and move laterally.&lt;/strong&gt; Each of these tactics contain multiple techniques, with each technique containing detailed information.&lt;/p&gt; 
&lt;p&gt;The techniques within the framework contain detailed information including:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Methodologies used by threat actors to leverage and exploit the technique.&lt;/li&gt; 
 &lt;li&gt;The systems or services the technique applies to, such as operating systems.&lt;/li&gt; 
 &lt;li&gt;Which threat actors utilise the technique.&lt;/li&gt; 
 &lt;li&gt;How to mitigate or detect the technique in your environment.&lt;/li&gt; 
 &lt;li&gt;Published references to the technique being utilised in the wild.&amp;nbsp;&lt;/li&gt; 
&lt;/ul&gt;  
&lt;img width="1024" height="419" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Screen-Shot-2020-11-10-at-9_45_03-am-1024x419.png?width=1024&amp;amp;height=419&amp;amp;name=Screen-Shot-2020-11-10-at-9_45_03-am-1024x419.png" alt="This image shows a sample of the numerous Tactics and Techniques that make up the MITRE ATT&amp;amp;CK framework." class="wp-image-254"&gt;  This image shows a sample of the numerous Tactics and Techniques that make up the MITRE ATT&amp;amp;CK framework.   
&lt;h2&gt;Using The Framework&lt;/h2&gt; 
&lt;p&gt;So now we understand the basics of ATT&amp;amp;CK, there are various ways of utilising the framework to better defend an environment against a malicious threat actor. Luckily, MITRE have released a tool called ‘ATT&amp;amp;CK Navigator’ that makes this process significantly easier.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The ATT&amp;amp;CK Navigator tool allows cyber security teams to easily navigate and annotate ATT&amp;amp;CK matrices in multiple layers.&lt;/strong&gt; This allows the team to easily plan, measure and visualise both offensive and defensive capabilities through colour coding, numerical values and comments.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;One of the more common use cases for the framework is to regularly measure and mature the defensive capabilities of an organisation. This is done by measuring the effectiveness of various controls and mitigations (Anti-Virus, Email Gateways, Firewalls etc..) against the ATT&amp;amp;CK framework. This can then be used to combine each service matrix into a combined layer, making it simple to identify improvement opportunities. The below image shows how an organisation can easily visualise gaps in their mitigation and detection strategies.&lt;/p&gt;  
&lt;img width="1024" height="349" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Screen-Shot-2020-11-12-at-12_12_36-pm-1024x349.png?width=1024&amp;amp;height=349&amp;amp;name=Screen-Shot-2020-11-12-at-12_12_36-pm-1024x349.png" alt="This image shows multiple product matrices combined to give an overall idea of the detection capabilities. The default navigator legend goes from red through to bright green with red being a combined score of 0." class="wp-image-255"&gt;  
&lt;em&gt;The above image shows multiple product matrices combined to give an overall idea of the detection capabilities. The default navigator legend goes from red through to bright green with red being a combined score of 0.&lt;/em&gt;   
&lt;p&gt;Another excellent use case for the framework, is measuring the effectiveness of a product in mitigating various Techniques and, any potential overlap the product will have with existing products or services in your Cyber Security stack. &lt;strong&gt;It is also quite common for vendors of cyber security products and services to align or measure themselves against the framework.&lt;/strong&gt; MITRE make this even easier by providing pre-evaluation reports of various products against ATT&amp;amp;CK using the Navigator tool. This means an organisiation can simply overlay the MITRE or vendor provided matrices over an overall matrix to identify how effective a product will be alongside existing controls.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The screenshot below (&lt;a href="https://attackevals.mitre-engenuity.org/APT29/results/crowdstrike/matrix.html"&gt;https://attackevals.mitre-engenuity.org/APT29/results/crowdstrike/matrix.html&lt;/a&gt;) shows the effectiveness of CrowdStrike Falcon while detecting Tactics, Techniques and Procedures (TTPs) from the threat actor group Advanced Persistent Threat 29 (APT 29), with a total detection rate of 100%!&lt;/p&gt;  
&lt;img width="1024" height="688" src="https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Screen-Shot-2020-11-10-at-9_39_47-am-1024x688.png?width=1024&amp;amp;height=688&amp;amp;name=Screen-Shot-2020-11-10-at-9_39_47-am-1024x688.png" alt="This image shows a MITRE ATT&amp;amp;CK Evaluation of Crowdstrike Falcon against the Advanced Persistent Threat 29." class="wp-image-256"&gt;  
&lt;em&gt;&lt;em&gt;The above image shows a MITRE ATT&amp;amp;CK Evaluation of Crowdstrike Falcon against the Advanced Persistent Threat 29.&lt;/em&gt;&lt;/em&gt;   
&lt;p&gt;Here at Alchemy Sec, we also utilise the framework when performing incident response for customers. &lt;strong&gt;MITRE keep up to date matrices of a vast range of threat actors that allow cyber security teams to easily identify the known TTPs to look for when dealing with known adversaries.&lt;/strong&gt; Having this information at hand allows cyber security teams to more efficiently detect, mitigate and eradicate the threat actor from the environment.&lt;/p&gt; 
&lt;h2&gt;The Differentiator&lt;/h2&gt; 
&lt;p&gt;Unlike other frameworks, ATT&amp;amp;CK is built around technical tactics, techniques and procedures from the perspective of threat actors. As such, many security teams proactively choose to align their detection, mitigation and incident response processes with the framework to better understand their own strengths and weaknesses. &lt;strong&gt;Integrating MITRE ATT&amp;amp;CK into an organisation’s existing processes does require a degree of technical knowledge.&amp;nbsp;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;In saying that, AlchemySec have guided numerous customers in enhancing their existing processes and leveraging relationships with vendors to have them align their own tools or services against the framework. This allows organisations to utilise the framework without the same degree of technical knowledge and putting all of the heavy lifting back on the vendor to align their product with the framework.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;While the framework is effective from a technical perspective, it can also be used at a management level to easily visualise strengths, weaknesses and opportunities to improve in maturity.&lt;/strong&gt; This process can be pivotal in acquiring buy in from key stakeholders when looking to augment or rationalise existing capabilities with new services.&lt;/p&gt; 
&lt;h2&gt;In Conclusion&lt;/h2&gt; 
&lt;p&gt;The MITRE ATT&amp;amp;CK framework can used as the foundation of a broad range of use cases to allow an organisation to better detect, mitigate and eradicate threats within their environment. To get the most value out of the framework an organisation will require a certain level of maturity from both cyber security processes and technically capable resources. However, the framework contains a wealth of cyber security information that can be utilised for product selection, incident response and threat actor profiling with very little technical knowledge.&lt;/p&gt; 
&lt;p&gt;While some of Alchemy Sec’s example use cases can be niche, we hope the concepts shared resonate and inspire you to generate interesting ones of your own to be used in concert with the framework to the benefit of your own environment.&amp;nbsp;&lt;/p&gt; 
&lt;h3&gt;References&lt;/h3&gt; 
&lt;p&gt;MITRE ATT&amp;amp;CK Framework:&amp;nbsp;&lt;a href="https://attack.mitre.org/"&gt;https://attack.mitre.org&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;MITRE ATT&amp;amp;CK Navigator:&amp;nbsp;&lt;a href="https://mitre-attack.github.io/attack-navigator/"&gt;https://mitre-attack.github.io/attack-navigator/&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;MITRE ATT&amp;amp;CK Evaluations:&amp;nbsp;&lt;a href="https://attackevals.mitre-engenuity.org/"&gt;https://attackevals.mitre-engenuity.org&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;CrowdStrike MITRE ATT&amp;amp;CK Framework Evaluation:&amp;nbsp;&lt;a href="https://www.crowdstrike.com/blog/crowdstrike-falcon-mitre-attack-evaluation-results-second-iteration/"&gt;https://www.crowdstrike.com/blog/crowdstrike-falcon-mitre-attack-evaluation-results-second-iteration/&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;Lockheed Martin Cyber Kill Chain:&amp;nbsp;&lt;a href="https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html"&gt;https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442625516&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fmitre-attck-framework-primer&amp;amp;bu=https%253A%252F%252Fwww.alchemysec.com.au%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Blog</category>
      <category>Defence</category>
      <pubDate>Mon, 16 Nov 2020 05:00:00 GMT</pubDate>
      <guid>https://www.alchemysec.com.au/blog/mitre-attck-framework-primer</guid>
      <dc:date>2020-11-16T05:00:00Z</dc:date>
      <dc:creator>Will</dc:creator>
    </item>
  </channel>
</rss>
