Linchakin

Conti's Ransomware Playbook Includes Recon for Users with Privileged Access

 September 07, 2021     No comments   

Contis Ransomware PlaybookResearchers at Cisco Talos have translated a playbook used by the ransomware-as-a-service group Conti. The playbook contains detailed instructions for how to gain administrator access, including searching social media to find employees to target.

“The adversaries list several ways to hunt for administrator access once on the victim network,” the researchers write. “They use commands such as Net to list users and tools like AdFind to enumerate users with access to Active Directory, and even OSINT, including the use of social media sites like LinkedIn to identify roles and users with privileged access. They note that this hunting process is particularly easy in U.S. and EU networks because of how they are structured and how roles and responsibilities are commonly detailed in comments.”

The researchers note the gang is fairly well-organized and educated on corporate network structures.

“References to team leads, chats and conferences indicate that the group is at least somewhat well-organized,” the researchers write. “They also display a familiarity with corporate network environments, such as where prized assets are located and how to access them. This is particularly true for U.S. and European networks, which they note have enhanced documentation that provides for easier targeting. Of note, the only ‘geographical’ mention by the adversaries was the mention of U.S./EU active directory (AD) structures. Their instructions, which are meticulous and easy to follow, also demonstrate that they are efficient and methodical.”

Talos also stresses that the manual allows less-technical criminals to carry out sophisticated ransomware attacks.

“One of the biggest takeaways during the translation was the overall thoroughness and detail of these playbooks,” the researchers write. “The level of detail provided could allow even amateur adversaries to carry out destructive ransomware attacks, a much lower barrier to entry than other forms of attacks. This lower barrier to entry also may have led to the leak by a disgruntled member who was viewed as less technical (aka ‘a script kiddie’) and less important.”

New-school security awareness training can enable your employees to thwart social engineering attacks.

Cisco Talos has the story.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • PS5 still falls behind Xbox Series X in this one key area PS5 backwards compatibility really should be better by nowIt’s rapidly approaching a year since the PS5 was released, and in that time I’ve had a lot of thoughts about Sony’s new console. I’ve flipped from be… Read More
  • PC Sales Hurt by Chip Deficit: Dell Enjoys Gains, HP SuffersByAnton Shilov Shortages of cheap and small components constrain shipments of PCs.As demand for PCs remains strong, leading PC makers Dell and HP post strong financial results and report growing PC sales. But persistent shortages of… Read More
  • Microsoft Surface Duo 2 Geekbench listing suggests company has listened to its fansSurface Duo 2 benchmarks highlight high-end CPU.The Surface Duo 2 could fix one of the original's biggest flaws. Last fall, Microsoft released its first phone in four years with the Surface Duo – a … Read More
  • 5 ways Samsung Galaxy S22 could steal the iPhone 13’s thunderThe Galaxy S22 has a real chance to overtake the new iPhonesAs we get closer and closer to the rumored iPhone 13 launch, we’re learning more about what Apple probably will (and won't) include this time around. … Read More
  • How to Use Windows Debugger to Fix CrashesByEd Tittel A free app from Microsoft, WinDbg, lets you find out why your computer or any individual app has...The WinDbg (Windows Debugger) tool has been around  and helping users diagnose their BSODs and individual program crashes since the days of Windo… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates