WEBVTT

1
00:00:01.159 --> 00:00:04.960
<v Speaker 1>Hackers that use siteeca, GC two and adaptics in an

2
00:00:05.080 --> 00:00:10.000
<v Speaker 1>espionage style intrusion against an Asian financial institution. FOG ransomware

3
00:00:10.039 --> 00:00:13.279
<v Speaker 1>hackers known for targeting US educational institutions are now using

4
00:00:13.359 --> 00:00:18.399
<v Speaker 1>legitimate employee monitoring software siteeca and several open source pen

5
00:00:18.480 --> 00:00:23.359
<v Speaker 1>testing tools alongside usual encryption. In a May five attack

6
00:00:23.480 --> 00:00:27.559
<v Speaker 1>on a unnamed financial institution in Asia, Symantec researcher spotted

7
00:00:27.600 --> 00:00:32.520
<v Speaker 1>hackers using siteteca and several pen testers, including GC two

8
00:00:32.560 --> 00:00:35.960
<v Speaker 1>in adaptics. The behavioral they found highly unusual in a

9
00:00:36.039 --> 00:00:39.799
<v Speaker 1>ransomware attack chain. Reflecting on the shift in FOG's attacks,

10
00:00:40.159 --> 00:00:43.799
<v Speaker 1>bug crowd SISO triy Ford said we should expect the

11
00:00:43.880 --> 00:00:46.479
<v Speaker 1>use of ordinary and legitimate corporate software as the norm.

12
00:00:46.479 --> 00:00:49.600
<v Speaker 1>We referred to this as living off the land. Why

13
00:00:49.640 --> 00:00:52.920
<v Speaker 1>would an attacker introduce new software, create more noise and

14
00:00:53.039 --> 00:00:55.960
<v Speaker 1>logs and increase the likelihood detection when the liable software

15
00:00:55.960 --> 00:01:00.759
<v Speaker 1>gets the job done for them well, Simantech identify the

16
00:01:00.799 --> 00:01:04.239
<v Speaker 1>initial infection vector using the attack. FOG ransomware actors have

17
00:01:04.319 --> 00:01:08.799
<v Speaker 1>used critical vulnerabilities in the past. Syteca was likely used

18
00:01:08.799 --> 00:01:12.719
<v Speaker 1>as a stealer. Researchers found attackers using stowaway, the open

19
00:01:12.760 --> 00:01:17.280
<v Speaker 1>source proxy tool designed for secure communication between internal and

20
00:01:17.319 --> 00:01:20.840
<v Speaker 1>external networks. It is not known how the attackers use

21
00:01:20.879 --> 00:01:23.799
<v Speaker 1>the setecha tool during the intrusion, which was distributed as

22
00:01:23.840 --> 00:01:29.239
<v Speaker 1>files under the names like Syteca client dotxe. Still, they

23
00:01:29.239 --> 00:01:32.079
<v Speaker 1>have very serial potential of an employee monitoring tool with

24
00:01:32.120 --> 00:01:35.719
<v Speaker 1>screen recording, a keystroke logging capabilities isn't too hard to guess.

25
00:01:36.239 --> 00:01:39.560
<v Speaker 1>Several libraries are loaded by this executable, suggesting it was

26
00:01:39.599 --> 00:01:44.079
<v Speaker 1>possibly used for information stealing or spying. The real danger

27
00:01:44.079 --> 00:01:46.120
<v Speaker 1>in this case isn't the ransom note, it's how fog

28
00:01:46.159 --> 00:01:49.480
<v Speaker 1>turns a simple screen record into a hidden camera. Software

29
00:01:49.480 --> 00:01:53.200
<v Speaker 1>is an essential driver of growth and innovation for every company. However,

30
00:01:53.319 --> 00:01:56.680
<v Speaker 1>business apps we install an autopilot can suddenly become spy tools.

31
00:01:59.359 --> 00:02:01.560
<v Speaker 1>Security team, you should keep a live map, but where

32
00:02:01.560 --> 00:02:03.719
<v Speaker 1>every monitoring app is allowed to run and flag it

33
00:02:03.760 --> 00:02:09.120
<v Speaker 1>the one moment it pops up somewhere odd. In addition,

34
00:02:09.199 --> 00:02:11.439
<v Speaker 1>another peculiarly observed in the attack was the use of

35
00:02:11.479 --> 00:02:15.919
<v Speaker 1>open source penetration testing tools like GCT and adaptics, rarely

36
00:02:15.919 --> 00:02:19.560
<v Speaker 1>seen with ransomware attacks. Google Command and Controls GC two

37
00:02:19.599 --> 00:02:22.560
<v Speaker 1>is an open source post exploitation tool that allows attackers

38
00:02:22.560 --> 00:02:25.919
<v Speaker 1>to control compromise systems using legitimate cloud services like Google

39
00:02:25.919 --> 00:02:30.000
<v Speaker 1>Sheets and Google Drive. The GC two implant alone potentially

40
00:02:30.039 --> 00:02:33.479
<v Speaker 1>allowed attackers to run discovery commands, transfer files, and load

41
00:02:33.759 --> 00:02:38.759
<v Speaker 1>shell code, hitting a deeper intelligence gathering objectives. Unlike typical

42
00:02:38.800 --> 00:02:41.439
<v Speaker 1>ransomware actors that exit post encryption, the FOG group was

43
00:02:41.439 --> 00:02:44.919
<v Speaker 1>seen establishing persistence even days after deploying the ransomware and

44
00:02:44.960 --> 00:02:50.840
<v Speaker 1>move more common and espionage operations. The attackers establishing persistence

45
00:02:50.840 --> 00:02:53.120
<v Speaker 1>on a victim network having deployed the ransomware is also

46
00:02:53.159 --> 00:02:56.199
<v Speaker 1>not something they would typically see in a ransom ware attack.

47
00:02:59.159 --> 00:03:02.120
<v Speaker 1>And that's your update for now in regards to Fogg

48
00:03:02.159 --> 00:03:04.080
<v Speaker 1>and get the rest of the article if you want

49
00:03:04.120 --> 00:03:08.240
<v Speaker 1>from c s o O CSO online dot com for

50
00:03:08.319 --> 00:03:10.120
<v Speaker 1>the whole article. That's it for now
