Threat Advisory: Telegram Crypto Botnet STRT-TA01

[ad_1]

The Splunk Threat Research Team (STRT) has detected an overhaul of a Crypto Botnet using Telegram, a widely used messaging app that can spawn bots and execute code remotely. STRT has identified sources of attacks from China and Iranian IP addresses specifically targeting the AWS IP address space. The malicious actors behind this botnet specifically target Windows server operating systems with Remote Desktop Protocol.

The Attack: Telegram is a popular messaging app with over 500 million users. In January 2021, Telegram was the most downloaded app on iOS and Android. This app also has a desktop version, which can be linked to a mobile account through the Telegram API. This API can be used to execute commands remotely. This is how malicious actors can turn desktop clients of compromised hosts into bots, as they can issue remote commands, download additional tools and payloads.

In a typical Crypto Botnet attack on Telegram, malicious actors first enter Windows servers and proceed to install several tools found in hacking forums such as NL Brute, KPort Scan, and NLA Checker. All of these tools target Windows servers with weak passwords using RDP brute force tools. And once the threat actor is able to break in and download other exploitation tools as mentioned above, he will install Telegram Desktop, which is used as part of the command infrastructure and control and used to remove cryptomining tools such as minergate and xmrig. These two binaries are identified as monero cryptomining tools (xmr).

STRT was able to identify a monero wallet linked to a previous cryptomining campaign (2018) where similar attack patterns were observed. STRT has now observed the resurfacing of this botnet using Telegram as the C2 infrastructure.

Indicators

The following graphic shows the attack flow associated with this botnet operation.

First, you will see the persistence via lsarpc.exe after intrusion via RDP Brute Force in the following graphic.

Then a self-extracting executable (sfx) file will remove the xmrig payload, along with the removal of update.bat, install.bat, sqlserver.exe (xmrig) and conhost.exe (nssm cli tool). Sqlserver.exe cli is used to perform CPU mining on the compromised machine. A popular XMR mining application, xmrig is frequently used in crypto-based mining campaigns because monero does not need a Graphics Process Unit (GPU) to be mined. In the graphic below, the help menu for the xmrig executable is displayed.

The following graphic shows the update.bat file. This file contains several commands to configure CPU mining and also removes other malware or part miners that may be installed on the machine.

The install.bat file contains a large number of actions focused on defending evasion by killing processes, removing services and adding scheduling tasks using the IFEO registry, removing users, removing users, disabling users, changing file and folder permissions, and removing other malware or active part miners. This is illustrated in the following graphic.

Previous campaign

As shown in the screenshot above, while setting up mining and logging into the mining pool, the attacker needs to enter the hash of the wallet. STRT was able to verify that this portfolio has been observed in previous campaigns dating back to 2018.

Portfolio: 4BrL51JCc9NGQ71kWhnYoDRffsDZy7m1HUU7MRU4nUMXAHNFBEJhkTZV9HdaL4gfuNBxLPc3BeMkLGaPbF5vWtANQru8uJpHSL1Nh1TTWm

This previous campaign also involved the use of cryptomining payloads and very similar mining techniques. The reuse of this portfolio may indicate the presence of similar actors at the origin of the observed exploitation campaign.

Telegram Messenger used as C2 infrastructure

Throughout the STRT investigation, the Telegram Desktop Client executable binary was observed, analyzed, and compared to versions downloaded from the original site; we found no difference between them. Once the Telegram client is installed, it is used as the C2 infrastructure. The following screenshots show examples of how attackers use it for botnet creation purposes.

This screenshot shows how Telegram is used to enumerate local groups on compromised machines.

In the following screenshots, Telegram is used to download masscan and kport scan.

The screenshots above show how Telegram is used to download other botnet exploitation and extension tools such as masscan, kport scan, and NLA Checker. These tools are used for quick internet scan and NLA Checker is a tool used to verify RDP connectivity. The NLA tool needs a python environment to run. The screenshot above also shows how files like IPs.txt are downloaded as well. These files are used for the target input of the scan tools.

In the following screenshot, STRT was able to replicate the use of NLA Checker in the local attack range, this tool allows attackers to quickly grab a large number of IP addresses and determine if they have any remote desktop connectivity. The tool generates IP addresses that verify Network Level Authentication (NLA) and those that do not. Note that enabling NLA in RDP in Windows operating systems generally protects against certain brute force tools and non-Windows RDP clients.

Botnet infrastructure

STRT has found evidence of malicious actors targeting the AWS IP address space, specifically Windows servers with RDP enabled. The STRT also found Iranian IP addresses connecting to zombies and several OSSINT elements indicating the use of Iranian sites and telegram channels for the tool repository and intermediaries. Here are the malicious domains associated with this botnet.

IP address: 218.28.249.14

domain004.gleeze.com test1000.ooguy.com pc0.zz.ha.cn test1003.accesscam.org gamepanel2.theworkpc.com gamepanel.gleeze.com

Mitigation and detections

As we have seen in our research, the best way to prevent these attack vectors is to patch your Windows servers first and apply the latest security updates. Using weak passwords is also a big factor in compromising your servers. Enabling Network Level Authentication (NLA) can also harden your servers and prevent many hacking tools from attempting to use brute force.

Splunk’s Threat Research Team has developed an XMRIG Analytical Story to deal with this threat. The following detection searches are included:

For up-to-date content, please download the latest version of our content from Splunkbase or check out our GitHub.

Sources

1/ https://Google.com/

2/ https://www.splunk.com/en_us/blog/security/threat-advisory-telegram-crypto-botnet-strt-ta01.html

The mention sources can contact us to remove/changing this article

[ad_2]

Related Posts