How the AI ​​discovered the Outlaws’ covert crypto-mining operation | Blog

[ad_1]

Oakley Cox, Chief Analysis Officer | Monday, October 11, 2021

Infamy is a paradoxical vocation for cybercriminals. While for some bragging rights are motivation for cybercrime in itself, notoriety is generally not a reasonable goal for those hoping to avoid detection. This is what the threat actors behind the prolific botnet Emotet learned earlier in 2021, for example, when a coordinated effort was launched by eight national law enforcement agencies to end their operation. However, some names pop up over and over in cybersecurity media and consistently avoid detection names like Outlaw.

How Outlaw plans an ambush

Although it has been active since 2018, very little is known about the hacking group Outlaw, which has organized numerous botnet and crypto-jacking attacks in China and abroad. The group is recognized by a variety of business cards, from repeated filenames to a tendency to illegally mine Monero cryptocurrency, but its success ultimately lies in its tendency to adapt and to evolve during months of dormancy between attacks.

Outlaw attacks are marked by constant changes and updates, which they work on in relative silence, before targeting security systems that are too often defeated by ignorance of the threat.

In 2020, Outlaw gained attention when they updated their botnet toolset to find and root out other criminal crypto-jacking software, maximizing their own payment from infected devices. While it’s not surprising that there is no honor among cyber thieves, this update also implemented more disturbing changes that allowed Outlaws malware to evade security defenses. traditional.

By changing disguise between each big robbery and keeping a low profile with the loot, Outlaw ensures that traditional security systems that rely on historical attack data will never be ready for them, no matter how fame it may be. their name. When organizations move beyond these systems rules-based approaches, however, by embracing self-learning AI to protect their digital assets, they can begin to turn the tide on groups like Outlaw.

This blog explores how two pre-infected zombie devices in two very different parts of the world were activated by the Outlaws botnet in the summer of 2021, and how Darktrace was able to detect activity despite the pre-infected devices.

Bounty Hunt: First Signs of Attack

Figure 1: Timeline of the attack.

When a new device was added to a Central American telecommunications company’s network in July, Darktrace detected a series of regular connections to two suspicious endpoints that it identified as markup behavior. The same behavior was seen independently, but almost simultaneously, at a financial company in the APAC region, which was implementing Darktrace for the first time. Darktraces Self-Learning AI was able to identify pre-infected devices by grouping similarly behaving devices into peer groups within local digital domains and therefore recognized that both were acting in unusual ways based on a range of behaviors. .

The first sign that the zombie devices had been activated by Outlaw was the start of cryptocurrency mining. The two devices, despite their geographic distance, turned out to be logged into a single crypto account, illustrating the blind and exponential nature by which a botnet thrives.

Outlaw has in the past limited its business to devices in China in what was supposed to be a show of caution, but recent activities like this show growing confidence.

The botnet recruitment process

The subsequent initiation of Internet Relay Chat (IRC) connections on port 443, a port more often associated with HTTPS activity, was a very characteristic feature of the earlier activity of Outlaw botnets in 2020. IRC is a regularly used tool for communication. communication between botmasters and zombie devices, but using port 443 the attacker was trying to blend in with normal internet traffic.

Shortly after this exchange, the devices downloaded a shell script. Darktraces Cyber ​​AI Analyst was able to intercept and recreate this shell script during its passage over the network, revealing its full function. Oddly enough, the script identified and excluded devices using the botnet’s ARM architecture. Due to its particularly low battery consumption, the ARM architecture is mainly used by portable mobile devices.

This selectivity is proof that malicious crypto-mining remains the main objective of outlaws. Bypassing smaller devices that offer limited crypto-mining capabilities, this shell script focuses the botnet on the most powerful, and therefore most profitable, devices, such as desktops and servers. In this way, it reduces the Indicators of Compromise (IOC) left by the larger botnet without significantly affecting the scale of its crypto-mining operation.

The two devices in question were not using an ARM architecture, and a few minutes later received a secondary payload containing a file named dota3[.]tar[.]gz, a sort of sequel to the Outlaw botnet’s previous incarnation, dota2, which itself referred to a popular video game of the same name. With the arrival of this file, devices appear to have been updated with the latest version of the Outlaws global botnet.

This download was made possible in part by using attackers for a living from land tactics. By using only the common Linux programs already present on the devices (curl and Wget respectively), Outlaw had avoided its activity being reported by traditional security systems. Wget, for example, is ostensibly a reputable program used to retrieve content from web servers and has never been recorded before as part of TTP outlaws (tactics, techniques and procedures).

By evolving and adapting its approach, Outlaw is continually able to outsmart and exceed rules-based security. Darktraces Self-Learning AI, however, kept pace, immediately identifying this Wget connection as suspicious and advising further investigation.

Figure 2: Cyber ​​AI Analyst identifies Wget usage on the morning of July 15 as suspicious and begins investigating potentially linked HTTP connections established on the morning of July 14. This way he builds a complete picture of the attack.

The botnet unleashed

Over the next 36 hours, Darktrace detected over 6 million TCP and SSH connections directed to rare external IP addresses using ports often associated with SSH, such as 22, 2222, and 2022.

What exactly the botnet was doing with these connections can only be speculated. Devices may have been part of a Distributed Denial of Service (DDoS) attack, brute force attempts on targeted SSH accounts, or simply set out to find and infect new targets, thereby expanding the botnet. Darktrace acknowledged that none of the devices had established SSH connections prior to this event and, had Antigena been in active mode, would have taken steps to shut them down.

Figure 3: Device behavior before and after bot activation on July 14, 2021. The large spike in model violations shows a clear deviation from the established life model.

Fortunately, owners of both devices responded to Darktraces detection alerts early enough to avoid serious damage to their own digital domains. If these devices had remained under the influence of the botnet, the ramifications could have been much more serious.

Using the SSH protocol would have allowed Outlaw to engage in a number of activities, potentially further compromising each device’s network and causing loss of data or money to their respective organizations.

Call the Sheriff: Self-Taught AI

Rules-based security solutions work much like the wanted posters of the Old West, hunting down criminals who walked through town last week unprepared for those crossing the hill today. When Black Hats and Outlaws take on a new look and use new techniques with each attack, a new way of responding to threats is needed.

Darktrace doesn’t need to know the Outlaw name or the group’s attack history to stop them. Using its fundamental self-learning approach, Darktrace learns its environment from scratch and identifies subtle deviations indicating a cyber threat. And with the autonomous response, it will even take targeted action to neutralize the threat at machine speed, without human intervention.

Thanks to Darktrace analyst Jun Qi Wong for his insight into uncovering the above threat.

Learn more about how Cyber ​​AI Analyst sheds light on complex attacks

Technical details IoCs: IoCPort (s) Commentdebianpackage[.]center45.9.48[.]5845.9.148[.]11745.9.148[.]12580, 443C2 connections and cryptocurrency mining (port 80) 45.9.148[.]5980, 443C2 connections 45.9.148[.]9980, 443C2 connections and repeated IRC connections (port 443) 45.9.148[.]12980, 443C2 connections 45.9.148[.]23tddwrt7s[.]Downloading the sh80Shell script containing instructions for receiving the secondary dota3 payload[.]tar[.]gz138.68.81[.]16128.199.147[.]38206.189.185[.]16580 Secondary payload, dota3[.]tar[.]gzdota3[.]tar[.]gzBinary containing SSH bruteforce payloadcurl / 7.61.1Wget / 1.17.21 User agents used to download shell script22, 222, 2222, 20222 TCP ports used for external SSH scan Darktrace pattern detections Compliance / CryptoCompromise currency mining activity / Extraction of high priority crypto currencies [Enhanced Monitoring]Abnormal connection / New user agent to IP without hostname Abnormal file / Zip or Gzip from rare external location Abnormal connection / Application protocol on unusual port device / Increased external connectivity TCPMITER ATT & CK port techniques observed Recognition T1595 Active scan T1595 .001 IP Block Analysis Resource Development T1584 Compromise Infrastructure T1588 Obtain Capabilities T1588.001 Obtain Capabilities: Malware T1608 Step Capabilities Defense Evasion T1036.005 Match Legitimate Name or Location Command and Control T1071 Application Layer Protocol T1095107T Layer Protocol T1095107T Layer Protocol ‘applicationT ProtocolT1571 Non-Standard PortImpactT1496 Diversion of resourcesOakley Cox

Oakley Cox is Chief Analytics Officer at Darktrace, based at the Cambridge HQ. He oversees the defense of critical infrastructure and industrial control systems, helping to ensure Darktraces AI stays one step ahead of attackers. Oakley is GIAC Certified in Industrial Defense and Response (GRID) and helps customers integrate Darktrace with existing and new SOC and Incident Response teams. He also holds a doctorate (PhD) from the University of Oxford.

Sources

1/ https://Google.com/

2/ https://www.darktrace.com/en/blog/how-ai-uncovered-outlaws-secret-crypto-mining-operation/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts