security researchers noticed a surge in devices infected with TrueBot malware downloader, created by a Russian-speaking hacker group called Silence. The Silence organization is known for its massive robbery targeting financial institutions.
Attackers also used a new custom data leakage tool called Teleport. Analysis of Silence attacks over the past few months shows that the gang provides Clop ransomware that is typically deployed by TA505 hackers associated with FIN11 organizations.
Silence 黑客已将他们的恶意软件植入全球 1,500 多个系统,以获取 shellcode、Cobalt Strike 信标、Grace 恶意软件、Teleport 渗漏工具和 Clop 勒索软件。
Cisco Talos researchers analyzed these new activities, and they observed that multiple new attack vectors have been used since August 2022.
在 8 月和 9 月之间的少量攻击中,黑客在利用 Netwrix Auditor 服务器中的一个严重漏洞CVE-2022-31199后,用 Truebot (Silence.Downloader) 感染了系统。
2022 年 10 月,该团伙转而使用 USB 驱动器感染带有 Raspberry Robin 蠕虫的计算机,该蠕虫经常传递 IcedID、Bumblebee 和 Truebot 有效负载。
微软 10 月份的一份报告将该蠕虫与他们追踪为 DEV-0950 的攻击者分发的 Clop 勒索软件联系起来,该攻击者的恶意活动与 FIN11 和 TA505(因在勒索攻击中使用 Clop 而闻名)的行为重叠。
Cisco Talos 指出,Truebot 团伙使用 Raspberry Robin 感染了 1,000 多台主机,其中许多是无法通过公共网络访问的桌面,主要分布在墨西哥、巴西和巴基斯坦。
11, hackers targeted Windows servers, exposing SMB, RDP and WinRM services to the public Internet. Researchers counted more than 500 infection cases, with about 75% of which occurred in the United States.
Truebot is a module in the first stage that can collect basic information and screenshots. It will also leak Active Directory trust relationship information, helping attackers continue to carry out horizontal penetration.
C2 server instructs Truebot to load shellcode or DLL in memory, execute other modules, uninstall itself or download DLL, EXE, BAT, and PS1 files.
Truebot功能图 (思科Talos)
入侵成功后,黑客使用 Truebot 投放 Cobalt Strike 信标或 Grace 恶意软件(FlawedGrace、GraceWire),这已归因于 TA505 网络犯罪集团。 After
, the intruder deploys Teleport, which Cisco describes as a new custom tool built in C++ that helps hackers steal data secretly. Communication between
Teleport and the C2 server is encrypted. Attackers can limit upload speed , filter files by size to steal more files, or delete payloads. All this is to keep a low profile on the victim machine.
传送工具模式 (Cisco Talos)
Teleport 还具有从 OneDrive 文件夹中窃取文件、收集受害者的 Outlook 电子邮件或针对特定文件扩展名的选项。
In some cases, the attacker moved sideways with the help of Cobalt Strike and finally deployed the Clop ransomware.
导致 Clop 部署的感染后活动 (Cisco Talos)
自 2016 年以来,网络安全公司Group-IB 的研究人员一直在跟踪 Silence/Truebot活动,当时黑客偷偷侵入了一家银行,但由于支付订单问题未能窃取资金。
攻击者再次击中同一目标,并开始通过截取受感染系统的屏幕截图和流式视频来监控银行运营商的活动,以了解汇款程序的工作原理。
As far as Group-IB knows, they successfully robbed for the first time in 2017, attacked the ATM system and stole more than $100,000 in one night.
Silence continues to launch attacks, and in the three years between 2016 and 2019, they stole at least $4.2 million from banks in the former Soviet Union, Europe, Latin American and Asia,
Silence/Truebot activity timeline, Source: Group-IB
Group-IB researchers describe Silence hackers as highly skilled, able to reverse engineer malware and modify them for their purposes, or modify vulnerabilities used by Fancy Bear at the assembly instruction level. They are also able to develop their own tools.
Initially, the attackers targeted only Russian companies, but Silence has expanded its reach to a global scale in the past few years.