Cyber Affairs
No Result
View All Result
  • Login
  • Register
[gtranslate]
  • Home
  • Live Threat Map
  • Books
  • Careers
  • Latest
  • Podcast
  • Popular
  • Press Release
  • Reports
  • Tech Indexes
  • White Papers
  • Contact
Social icon element need JNews Essential plugin to be activated.
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
COMMUNITY
NEWSLETTER
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
NEWSLETTER
No Result
View All Result
Cyber Affairs
No Result
View All Result
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

CISA & FBI Releases TTPs & IOCs Used by Phobos Ransomware Group

admin by admin
Mar 5, 2024
in News
A A
0

The FBI, CISA, and MS-ISAC are urging critical infrastructure organizations to be vigilant against Phobos ransomware. 

This advisory is part of the #StopRansomware initiative, providing defenders with details on Phobos ransomware, including its tactics, indicators of compromise, and mitigation strategies.

This ransomware-as-a-service (RaaS) has been observed targeting various sectors since May 2019, including:

  • Municipal and county governments
  • Emergency services
  • Education
  • Public healthcare

Recent Phobos attacks, reported as of February 2024, highlight the need for heightened awareness and strong security measures.

Technical Details

Phobos actors search for exposed RDP ports or send phishing emails with hidden malware.

They use brute-force tools to crack passwords or establish remote connections. Once inside, they research the victim to understand their network and steal data

Phobos attackers execute files like 1saas.exe or cmd.exe to install additional malware with administrator-level permissions. 

This lets them perform various actions on Windows systems, giving them wide control over the infected machine.

Phobos uses a three-stage process to deploy additional malware through Smokeloader:

  1. Injection: Smokeloader manipulates system functions to inject malicious code into running processes, bypassing security tools.
  2. Obfuscation: It uses a “stealth process” to hide its communication with its control server by masking it as requests to legitimate websites.
  3. Payload Delivery: Finally, it extracts a malicious payload from memory and prepares it for deployment.

This allows attackers to download additional malware onto the compromised system. Also, Phobos actors use commands to shut down the system’s firewall.

They employ tools like Universal Virus Sniffer, Process Hacker, and PowerTool to hide their activities from security software.

Impact:

Phobos actors seek backups after exfiltration. They find and delete Windows volume shadow copies using vssadmin.exe and WMIC. After encryption, victims cannot restore files.

Phobos.exe may encrypt all target host logical disks. Phobos ransomware executables have unique build IDs, affiliate IDs, and embedded ransom notes. Phobos ransomware searches for and encrypts further files once the ransom letter appears.

Email is the primary method of extortion; however, some affiliate organizations phone victims. Phobos actors may name victims and host stolen data on Onion sites. Phobos actors interact using ICQ, Jabber, and QQ. Lists Phobos affiliates Devos, Eight, Elbie, Eking, and Faust’s email providers.

Mitigation Steps Recommended by The FBI, CISA, and MS-ISAC

  • Secure remote access software.
  • Implement application controls.
  • Use intrusion detection systems.
  • Limit RDP usage and enforce best practices.
  • Review accounts and disable unnecessary permissions.
  • Implement backups and recovery plans.
  • Enforce strong password policies and multi-factor authentication.
  • Segment networks and monitor for abnormal activity.
  • Update antivirus software and disable unused ports and protocols.
  • Consider email security measures like banners and disabled hyperlinks.
  • Encrypt and protect backups.

Validate defenses:

  • Test security controls against the MITRE ATT&CK framework.
  • Regularly refine security programs based on the test results.

You cam check the complete IOC here.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are incredibly harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.



Read the full article here

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

[mc4wp_form id=”387″]

Recent News

  • Understanding the Implications & Guarding Privacy- Axios Security Group
  • Hackers Actively Using Pupy RAT to Attack Linux Systems
  • Buckle Up_ BEC and VEC Attacks Target Automotive Industry

Topics

  • AI
  • Books
  • Careers
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • News
  • Podcast
  • Reports
  • Tech Indexes
  • Uncategorized
  • White Papers

Get Informed

[mc4wp_form id=”387″]

Social icon element need JNews Essential plugin to be activated.

Copyright © 2022 Cyber Affairs. All rights reserved.

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

Copyright © 2022 Cyber Affairs. All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.