
admin 2024年3月6日07:55:28评论30 views字数 5559阅读18分31秒阅读模式

U.S. cybersecurity and intelligence agencies have warned of Phobos ransomware attacks targeting government and critical infrastructure entities, outlining the various tactics and techniques the threat actors have adopted to deploy the file-encrypting malware.


"Structured as a ransomware as a service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and county governments, emergency services, education, public healthcare, and critical infrastructure to successfully ransom several million in U.S. dollars," the government said.


The advisory comes from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC).


Active since May 2019, multiple variants of Phobos ransomware have been identified to date, namely Eking, Eight, Elbie, Devos, Faust, and Backmydata. Late last year, Cisco Talos revealed that the threat actors behind the 8Base ransomware are leveraging a Phobos ransomware variant to conduct their financially motivated attacks.


There is evidence to suggest that Phobos is likely closely managed by a central authority, which controls the ransomware's private decryption key.


Attack chains involving the ransomware strain have typically leveraged phishing as an initial access vector to drop stealthy payloads like SmokeLoader. Alternatively, vulnerable networks are breached by hunting for exposed RDP services and exploiting them by means of a brute-force attack.


A successful digital break-in is followed by the threat actors dropping additional remote access tools, taking advantage of process injection techniques to execute malicious code and evade detection, and making Windows Registry modifications to maintain persistence within compromised environments.


"Additionally, Phobos actors have been observed using built-in Windows API functions to steal tokens, bypass access controls, and create new processes to escalate privileges by leveraging the SeDebugPrivilege process," the agencies said. "Phobos actors attempt to authenticate using cached password hashes on victim machines until they reach domain administrator access."

“此外,已经观察到Phobos行动者使用内置的Windows API函数来窃取令牌、绕过访问控制,并使用SeDebugPrivilege进程提升权限来创建新进程,”这些机构表示。“Phobos行动者尝试使用受害机器上的缓存密码哈希进行身份验证,直到获得域管理员访问权限为止。”

The e-crime group is also known to use open-source tools such as Bloodhound and Sharphound to enumerate the active directory. File exfiltration is accomplished via WinSCP and Mega.io, after which volume shadow copies are deleted in an attempt to make recovery harder.


The disclosure comes as Bitdefender detailed a meticulously coordinated ransomware attack impacting two separate companies at the same time. The attack, described as synchronized and multifaceted, has been attributed to a ransomware actor called CACTUS.


"CACTUS continued infiltrating the network of one organization, implanting various types of remote access tools and tunnels across different servers," Martin Zugec, technical solutions director at Bitdefender, said in a report published last week.

“CACTUS继续渗透一个组织的网络,植入各种类型的远程访问工具和隧道到不同的服务器,”Bitdefender的技术解决方案总监Martin Zugec在上周发布的一份报告中表示。

"When they identified an opportunity to move to another company, they momentarily paused their operation to infiltrate the other network. Both companies are part of the same group, but operate independently, maintaining separate networks and domains without any established trust relationship."



The attack is also notable for the targeting of the unnamed company's virtualization infrastructure, indicating that CACTUS actors have broadened their focus beyond Windows hosts to strike Hyper-V and VMware ESXi hosts.

这次攻击还值得注意的是针对未透露名称公司的虚拟化基础设施,表明CACTUS行动者已将焦点扩大到超越Windows主机,打击Hyper-V和VMware ESXi主机。

It also leveraged a critical security flaw (CVE-2023-38035, CVSS score: 9.8) in an internet-exposed Ivanti Sentry server less than 24 hours after its initial disclosure in August 2023, once again highlighting opportunistic and rapid weaponization of newly published vulnerabilities.

它还利用了一个关键的安全漏洞(CVSS评分:9.8)在2023年8月首次披露不到24小时的时间内就在一个暴露在互联网上的Ivanti Sentry服务器上利用,再次突出了对新发布漏洞的机会主义和快速武器化。

Ransomware continues to be a major money spinner for financially motivated threat actors, with initial ransomware demands reaching a median of $600,000 in 2023, a 20% jump from the previous year, according to Arctic Wolf. As of Q4 2023, the average ransom payment stands at $568,705 per victim.

勒索软件继续成为金钱驱动的威胁行为者的主要盈利来源,根据Arctic Wolf的数据,2023年的初步勒索软件要求中值达到60万美元,比前一年增长了20%。截至2023年第四季度,每个受害者的平均赎金支付额达到了568,705美元。

What's more, paying a ransom demand does not amount to future protection. There is no guarantee that a victim's data and systems will be safely recovered and that the attackers won't sell the stolen data on underground forums or attack them again.


Data shared by cybersecurity company Cybereason shows that "a staggering 78% [of organizations] were attacked again after paying the ransom – 82% of them within a year," in some cases by the same threat actor. Of these victims, 63% were "asked to pay more the second time."

网络安全公司Cybereason分享的数据显示,“令人震惊的78%的组织在支付赎金后再次遭受攻击 - 其中82%在一年内被攻击”,在某些情况下是由同一威胁行为者。在这些受害者中,63%“被要求第二次支付赎金。”




  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
  • 本文由 发表于 2024年3月6日07:55:28
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):


匿名网友 填写信息