216.73.217.22

EDR Bypass Testing Reveals Extortion Actor's Toolkit

· Published 02/11/2024 01:03 · Modified 04/11/2024 11:31

Export JSON

Essential information

Published
02/11/2024 01:03
Modified
04/11/2024 11:31
Tags
2024-11-02 av/edr bypass byovd cobalt strike conti cortex xdr cybercrime forums extortion mimikatz rclone rubeus safetykatz sharphound threat actor profiling
Related entities
8 techniques (mitre), 6 malware, 1 others

Description

Unit 42 investigated an attempt where threat actors tested an tool on rogue systems with installed. The actors purchased network access via Atera RMM and used a technique for the bypass tool. Researchers gained visibility into the actors' systems, uncovering tools, files, and identifying information. The bypass tool was traced to cybercrime forum posts by user KernelMode. Analysis revealed connections to ransomware training materials and overlaps with known TTPs. A Kazakh company and individual were linked to the activity through exposed documents and video artifacts. The incident highlights the growing trend of tools and the monetization of such capabilities in .

External references