The Evolution of Hacker Tactics: A Case Study
In the ever-evolving world of cybersecurity, it's fascinating to witness the ingenuity of both attackers and defenders. A recent incident involving a French-speaking hacker, codenamed 'Poisson', sheds light on the creative ways intruders are ensuring their access, even when their command-and-control (C2) servers are taken down.
The Unconventional Persistence
What makes this case intriguing is the hacker's use of OpenSSH and Tailscale to create a backdoor, ensuring continued access to the compromised network even after the C2 server went offline. This is a stark reminder that traditional remediation methods, like taking down C2 servers, may not be enough to fully secure a network.
A Young Hacker's Journey
Poisson, as researchers describe, is a junior operator, likely still learning the ropes of the cybercrime world. His schedule, with activity after school hours, and his use of free-tier tools, paint a picture of a novice trying to make their mark. What's surprising is not just the audacity of his actions but also the persistence of his access.
The Art of Staying Hidden
The malware used by Poisson was designed to run in memory, making it harder to detect. The use of a VBScript stager, PowerShell loader, and a .NET loader showcases a multi-layered approach, each stage adding a layer of complexity to the attack. The fact that he failed at roughly half of his attempts but still compromised four machines is a testament to the trial-and-error nature of many cyberattacks.
The Key to Uninterrupted Access
The pivotal moment in this story is Poisson's installation of OpenSSH Server and Tailscale. By joining the victim's machine to his private Tailscale network, he created a covert channel that bypassed the C2 infrastructure entirely. This move, in my opinion, is a game-changer, as it highlights the importance of understanding and monitoring these types of tools in network security.
Beyond the C2
When the Havoc infrastructure went offline, Poisson's access remained intact. This is a crucial lesson for cybersecurity professionals: the C2 server is often just one entry point, and its removal doesn't guarantee network security. The attacker's ability to reconnect automatically when the C2 came back online further emphasizes the resilience of their access.
Targeted Data Theft
Poisson's intentions were clear: stealing banking and email credentials. What's interesting is the specificity of the data targeted. He wasn't after sensitive documents or lateral movement; instead, he focused on direct financial gain. This precision is a reminder that hackers often have specific goals, and understanding these can be key to prevention.
Old Tools, New Tricks
The tools used by Poisson are not groundbreaking, but their application is. China's APT31 and Scattered Spider have previously used Tailscale and legitimate remote-access tools for similar purposes. This trend underscores the importance of behavior-based detection, as these signed and legitimate binaries can easily slip through file-based security measures.
Lessons for Cybersecurity Professionals
Cato Network's research provides valuable insights for defenders. The hunting list they've provided is a practical guide to identifying potential backdoors. However, the real takeaway is the need to think beyond the C2. When a breach is identified, the focus should be on finding and eliminating all potential persistence mechanisms, not just the most obvious entry points.
The Unanswered Questions
The mystery of Thales.zip and its contents remains, leaving room for speculation. What were those executables doing? Why did they run for 32 minutes? These unanswered questions highlight the ongoing challenge of understanding the full scope of an attack, even when you have a detailed playbook.
The Bigger Picture
This case study is a microcosm of the broader cybersecurity landscape. It demonstrates the constant evolution of hacker tactics and the need for equally adaptive defense strategies. As hackers become more creative in ensuring their access, cybersecurity professionals must stay vigilant, constantly updating their playbooks and anticipating new methods of intrusion.