Lunar Spider Intrusion Used Tax-Themed JavaScript to Maintain Access for Nearly Two Months

Summary
A DFIR investigation details a nearly two-month intrusion that began with a tax-themed JavaScript file and involved multiple malware families, credential theft, lateral movement, and data exfiltration. No ransomware deployment was observed.
Key points
- The intrusion began when a user executed an obfuscated JavaScript file disguised as a tax form; it downloaded an MSI that deployed Brute Ratel and Latrodectus.
- The attackers used BackConnect, Brute Ratel, Cobalt Strike, and a custom .NET backdoor for remote access, command and control, persistence, and process injection.
- They found plaintext domain administrator credentials in a Windows unattend.xml answer file, then used them for privilege escalation and lateral movement across servers, including a domain controller.
- The attackers harvested credentials from LSASS, browsers, and backup software, and used a Zerologon (CVE-2020-1472) tool in attempted lateral movement.
- On day 20, they used a renamed Rclone binary to exfiltrate files from a file-share server over FTP for nearly 10 hours.
- Intermittent activity continued for nearly two months before the attackers were evicted; investigators observed no ransomware deployment.
Article Details
- Attack Vectors
- A user executed an obfuscated JavaScript file disguised as a W-9 tax form. It downloaded an MSI package that ran a Brute Ratel DLL through rundll32.exe.
- Brute Ratel injected Latrodectus into explorer.exe. The intruder subsequently used BackConnect, Cobalt Strike beacons and a custom .NET backdoor for access.
- The intruder obtained plaintext domain administrator credentials from an unattend.xml Windows Answer file and used them with runas and RDP.
- The intruder used PsExec and remote services for lateral movement, and deployed zero.exe, a custom Zerologon exploit targeting CVE-2020-1472, against a second domain controller.
- On day 20, scripts ran a renamed Rclone binary to transfer file-share data by FTP to a remote host controlled by the intruder.
- Defensive Notes
- Investigate MSI downloads followed by rundll32.exe execution of DLLs, particularly alongside obfuscated JavaScript presented as a tax form.
- Monitor Registry Run-key changes, scheduled-task creation, suspicious ms-settings protocol-handler changes, and injection into legitimate processes.
- Protect and review Windows Answer files for retained plaintext credentials; monitor access to unattend.xml, LSASS and backup-software credentials.
- Monitor unexpected AdFind, PsExec, PowerView, rustscan, RDP and remote-service activity, as well as Rclone-driven FTP transfers from file servers.
- The report provides network detections, Sigma rules and YARA references for investigating the observed activity. It reports that no ransomware deployment was observed.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | altynbe[.]com | C2 domain used by the initial Brute Ratel DLL. |
| DOMAIN | anikvan[.]com | C2 domain used by the initial Brute Ratel DLL. |
| DOMAIN | avtechupdate[.]com | Cobalt Strike C2 domain contacted by the sys.dll implant. |
| DOMAIN | boriz400[.]com | C2 domain used by the initial Brute Ratel DLL. |
| DOMAIN | cloudmeri[.]com | C2 domain of the lsassa.exe backdoor. |
| DOMAIN | dauled[.]com | C2 domain used by the replacement Brute Ratel badger. |
| DOMAIN | erbolsan[.]com | C2 domain used by the replacement Brute Ratel badger. |
| DOMAIN | grasmetral[.]com | Latrodectus C2 domain; spelling is preserved as printed in the indicator table. |
| DOMAIN | illoskanawer[.]com | Latrodectus C2 domain. |
| DOMAIN | jarkaairbo[.]com | Latrodectus C2 domain. |
| DOMAIN | kasym500[.]com | C2 domain used by the replacement Brute Ratel badger. |
| DOMAIN | kasymdev[.]com | C2 domain used by the replacement Brute Ratel badger. |
| DOMAIN | samderat200[.]com | C2 domain used by the replacement Brute Ratel badger. |
| DOMAIN | scupolasta[.]store | Latrodectus C2 domain. |
| DOMAIN | workspacin[.]cloud | Latrodectus C2 domain. |
| HOSTNAME | resources[.]avtechupdate[.]com | Hostname in the C2 address of an in-memory Cobalt Strike stager. |
| HOSTNAME | ridiculous-breakpoint-gw[.]aws-use1[.]cloud-ara[.]tyk[.]io | Specific Tyk.io gateway hostname listed among the initial Brute Ratel C2 destinations. |
| HOSTNAME | uncertain-kitten-gw[.]aws-euc1[.]cloud-ara[.]tyk[.]io | Specific Tyk.io gateway hostname listed among the initial Brute Ratel C2 destinations. |
| IPV4 | 138[.]124[.]183[.]215 | IP listed for the altynbe[.]com Brute Ratel C2. |
| IPV4 | 162[.]0[.]209[.]121 | IP listed for the lsassa.exe backdoor C2. |
| IPV4 | 173[.]255[.]204[.]62 | IP listed for the illoskanawer[.]com Latrodectus C2. |
| IPV4 | 185[.]93[.]221[.]12 | BackConnect infrastructure listed in the indicator tables. |
| IPV4 | 193[.]168[.]143[.]196 | BackConnect infrastructure listed in the indicator tables. |
| IPV4 | 195[.]123[.]225[.]161 | IP listed for the dauled[.]com Brute Ratel C2. |
| IPV4 | 195[.]123[.]225[.]251 | IP listed for the kasym500[.]com Brute Ratel C2. |
| IPV4 | 195[.]211[.]98[.]249 | IP listed for the kasymdev[.]com Brute Ratel C2. |
| IPV4 | 206[.]206[.]123[.]209 | IP listed for the sys.dll Cobalt Strike C2. |
| IPV4 | 217[.]196[.]98[.]61 | Metasploit C2 IP listed in the indicator tables; the connection was reportedly rejected. |
| IPV4 | 31[.]13[.]248[.]153 | IP listed as Cobalt Strike C2 infrastructure. |
| IPV4 | 45[.]129[.]199[.]214 | IP listed for the cron801.dl_ and system.dl_ Cobalt Strike C2. |
| IPV4 | 45[.]135[.]232[.]3 | FTP host in the intruder's Rclone configuration for data exfiltration. |
| IPV4 | 45[.]150[.]65[.]85 | IP listed for the samderat200[.]com Brute Ratel C2. |
| IPV4 | 91[.]194[.]11[.]183 | IP listed for the boriz400[.]com Brute Ratel C2. |
| IPV4 | 91[.]194[.]11[.]64 | Host listed for delivery of the Latrodectus MSI second stage. |
| IPV4 | 94[.]131[.]108[.]254 | IP listed for the erbolsan[.]com Brute Ratel C2. |
| IPV4 | 94[.]232[.]249[.]100 | IP listed for the erbolsan[.]com Brute Ratel C2. |
| IPV4 | 94[.]232[.]249[.]108 | IP listed for the samderat200[.]com Brute Ratel C2. |
| IPV4 | 95[.]164[.]68[.]73 | IP listed for the anikvan[.]com Brute Ratel C2. |
| MD5 | 495363b0262b62dfc38d7bfb7b5541aa | Computed hash listed for the system.dl_ or cron801.dl_ Cobalt Strike artifact. |
| MD5 | 4b3e9c9e018659d1cf04daf82abe3b64 | Computed hash of start.vbs, the data-exfiltration toolkit launcher. |
| MD5 | 50abc42faa70062e20cd5e2a2e2b6633 | Computed hash of the lsassa.exe backdoor. |
| MD5 | 91889658f1c8e1462f06f019b842f109 | Computed hash of zero.exe, the intruder's Zerologon exploit artifact. |
| MD5 | 9eaa8464110883a15115b68ffa1ecf7d | Computed hash listed for the intruder-used rustscan.exe artifact. |
| MD5 | a2b6479a69b51ae555f695b243e4fda1 | Computed hash listed for the c356468.exe intrusion artifact. |
| MD5 | ad3c52316e0059c66bc1dd680cf9edad | Computed hash of the sys.dll Cobalt Strike stager. |
| MD5 | c8ea31665553cbca19b22863eea6ca2c | Computed hash of run.bat, part of the data-exfiltration toolkit. |
| MD5 | ccb6d3cb020f56758622911ddd2f1fcb | Computed hash of the upfilles.dll Brute Ratel artifact. |
| MD5 | d7bd590b6c660716277383aa23cb0aa9 | Computed hash of the wscadminui.dll Brute Ratel badger. |
| SHA1 | 23fff588e3e5cc6678e1f77fab9318d60f3ac55f | Computed hash listed for the c356468.exe intrusion artifact. |
| SHA1 | 2d92890374904b49d3c54314d02b952e1a714e99 | Computed hash listed for the system.dl_ or cron801.dl_ Cobalt Strike artifact. |
| SHA1 | 333e1c5967a9a6c881c9573a3222bed6ada911c6 | Computed hash of start.vbs, the data-exfiltration toolkit launcher. |
| SHA1 | 33a6b39fbe8ec45afab14af88fd6fa8e96885bf1 | Computed hash of zero.exe, the intruder's Zerologon exploit artifact. |
| SHA1 | 38999890b3a2c743e0abea1122649082a5fa1281 | Computed hash of the wscadminui.dll Brute Ratel badger. |
| SHA1 | 4a013f752c2bf84ca37e418175e0d9b6f61f636d | Computed hash of the upfilles.dll Brute Ratel artifact. |
| SHA1 | 5348970723b378c7cae35bb03d8736f8e5a9f0ac | Computed hash listed for the intruder-used rustscan.exe artifact. |
| SHA1 | 8dfa63c0bb611e18c8331ed5b89decf433ac394a | Computed hash of the sys.dll Cobalt Strike stager. |
| SHA1 | 97d72c8bbcf367be6bd5e80021e3bd3232ac309a | Computed hash of the lsassa.exe backdoor. |
| SHA1 | ba99cd73b74c64d6b1257b7db99814d1dc7d76b1 | Computed hash of run.bat, part of the data-exfiltration toolkit. |
| SHA256 | 100e03eb4e9dcdab6e06b2b26f800d47a21d338885f5dc1b42c56a32429c9168 | Computed hash of the sys.dll Cobalt Strike stager. |
| SHA256 | 1a8ebf914ebea34402eecbf0985f05ae413663708d2fcc842fc27057ac5ec4ed | Computed hash of start.vbs, the data-exfiltration toolkit launcher. |
| SHA256 | 203eda879dbdb128259cd658b22c9c21c66cbcfa1e2f39879c73b4dafb84c592 | Computed hash of the lsassa.exe backdoor. |
| SHA256 | 36bc32becf287402bf0e9c918de22d886a74c501a33aa08dcb9be2f222fa6e24 | Computed hash of zero.exe, the intruder's Zerologon exploit artifact. |
| SHA256 | 37471af00673af4080ee21bd248536147e450d2eff45e8701a95d1163a9d62fe | Computed hash listed for the intruder-used rustscan.exe artifact. |
| SHA256 | 411dfb067a984a244ff0c41887d4a09fbbcd8d562550f5d32d58a6a6256bd7b2 | Computed hash of run.bat, part of the data-exfiltration toolkit. |
| SHA256 | 6c3b2490e99cd8397fb79d84a5638c1a0c4edb516a4b0047aa70b5811483db8f | Computed hash of the wscadminui.dll Brute Ratel badger. |
| SHA256 | 77eede38abdc740f000596e374b6842902653aeafb6c63011388ebb22ec13e28 | Computed hash listed for the system.dl_ or cron801.dl_ Cobalt Strike artifact. |
| SHA256 | 8fb5034aedf41f8c8c4c4022fdde7db3c70a5a7c7b5b4dec7f6a57715c18a5bf | Computed hash listed for the c356468.exe intrusion artifact. |
| SHA256 | f4cb6b684ea097f867d406a978b3422bbf2ecfea39236bf3ab99340996b825de | Computed hash of the upfilles.dll Brute Ratel artifact. |
| URL | hxxp[:]//45[.]129[.]199[.]214/vodeo/wg01ck01 | Cobalt Strike beacon C2 URL observed during the intrusion. |
| URL | hxxp[:]//91[.]194[.]11[.]64/MSI[.]msi | URL from which the malicious JavaScript downloaded the second-stage MSI. |
| URL | hxxps[:]//cloudmeri[.]com/comm[.]php | Embedded C2 endpoint used by the lsassa.exe backdoor. |
| URL | hxxps[:]//illoskanawer[.]com/live/ | Latrodectus C2 URL in the configuration's decrypted strings. |
| URL | hxxps[:]//workspacin[.]cloud/live/ | Latrodectus C2 URL in the configuration's decrypted strings. |
MITRE ATT&CK
T1003.001 · LSASS MemoryCobalt Strike-injected processes accessed LSASS on multiple devices.T1018 · Remote System DiscoveryThe intruder enumerated domain controllers, servers and other remote systems.T1021.001 · Remote Desktop ProtocolThe intruder used domain administrator credentials to log in to two servers over RDP.T1021.002 · SMB/Windows Admin SharesPsExec remotely deployed Cobalt Strike DLL beacons to a domain controller and other servers.T1027.016 · Junk Code InsertionThe JavaScript concealed a small amount of executable code among extensive filler text.T1033 · System Owner/User DiscoveryThe intruder ran whoami, and the backdoor collected the compromised username.T1046 · Network Service DiscoveryThe intruder used rustscan to scan internal network blocks for SMB on port 445.T1047 · Windows Management InstrumentationThe intruder attempted remote execution of a Cobalt Strike beacon using WMIC.T1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolA renamed Rclone binary transferred file-share data to the intruder's FTP host.T1053.005 · Scheduled TaskThe lsassa.exe backdoor created the SchedulerLsass scheduled task to run at system startup.T1055 · Process InjectionBrute Ratel injected Latrodectus into explorer.exe; Cobalt Strike beacons were injected into legitimate processes.T1059.001 · PowerShellThe intruder executed PowerShell download-and-execute commands and a script to obtain Veeam credentials.T1059.003 · Windows Command ShellThe backdoor executed received commands through cmd.exe, and the intruder used Windows shell commands throughout the intrusion.T1059.007 · JavaScriptThe obfuscated JavaScript initiated download of the malicious MSI package.T1069.002 · Domain GroupsThe intruder queried Domain Admins and enumerated Active Directory groups.T1070.004 · File DeletionThe intruder deleted more than half of the downloaded files and tools after use.T1071.001 · Web ProtocolsLatrodectus, Brute Ratel, the .NET backdoor and Cobalt Strike used HTTP or HTTPS C2 communications.T1078.002 · Domain AccountsThe intruder authenticated with the domain administrator account found in unattend.xml.T1082 · System Information DiscoveryThe intruder ran systeminfo and other commands to inspect compromised systems.T1083 · File and Directory DiscoveryBackConnect was used to browse directories and inspect files, including unattend.xml.T1087.002 · Domain AccountAdFind and net user commands were used to enumerate domain users.T1105 · Ingress Tool TransferThe JavaScript downloaded an MSI, and later activity transferred malware and tools onto compromised hosts.T1135 · Network Share DiscoveryNet view and PowerView Invoke-ShareFinder were used to identify network shares.T1204.002 · Malicious FileA user executed the malicious JavaScript file disguised as a tax form.T1210 · Exploitation of Remote ServicesThe intruder used zero.exe, a custom Zerologon exploit, in attempted lateral movement to a second domain controller.T1218.011 · Rundll32The MSI custom action and subsequent commands used rundll32.exe to execute malicious DLL payloads.T1222.001 · Windows PermissionsThe intruder used icacls to change ownership and reset permissions while trying to read AdFind output.T1482 · Domain Trust DiscoveryThe intruder used nltest to enumerate domain trusts.T1518.001 · Security Software DiscoveryA WMIC command queried installed antivirus products on the beachhead host.T1547.001 · Registry Run Keys / Startup FolderA Registry Run key named Update was created to execute the Brute Ratel badger after restart.T1548.002 · Bypass User Account ControlA Cobalt Strike implant hijacked the ms-settings protocol handler and invoked ComputerDefaults.exe to bypass UAC.T1552.001 · Credentials In FilesThe intruder retrieved unattend.xml and obtained plaintext domain administrator credentials stored in it.T1555.003 · Credentials from Web BrowsersA Latrodectus stealer module collected browser passwords and session data.T1569.002 · Service ExecutionThe intruder attempted to execute a Metasploit reverse shell through a remote service.
CVE
People
Threat Actors
Malware
BackConnectMultiple types of malware were deployed across the intrusion, including Latrodectus, Brute Ratel C4, Cobalt Strike, BackConnect, and a custom .NET backdoor.IcedIDLatrodectus, a downloader first identified by Proofpoint researchers in November 2023, is attributed to the same threat actors responsible for developing IcedID.LatrodectusMultiple types of malware were deployed across the intrusion, including Latrodectus, Brute Ratel C4, Cobalt Strike, BackConnect, and a custom .NET backdoor.lsassa.exelsassa.exe Backdoor
Vendors
Products
Microsoft WindowsCredentials were harvested from several sources like LSASS, backup software, and browsers, and also a Windows Answer file used for automated provisioning.Veeam Credential ManagerUpon executing the script, the threat actor would have obtained any plaintext usernames and passwords stored in the Veeam Credential Manager.
Tools
AdFindThe threat actor then conducted extensive Active Directory reconnaissance using AdFind.Brute RatelThe intrusion began with a Lunar Spider linked JavaScript file disguised as a tax form that downloaded and executed Brute Ratel via a MSI installer.Cobalt StrikeMultiple types of malware were deployed across the intrusion, including Latrodectus, Brute Ratel C4, Cobalt Strike, BackConnect, and a custom .NET backdoor.MetasploitThreat Feed: Focuses on tracking Command and Control frameworks like Cobalt Strike, Metasploit, Sliver, etc.PowerViewThe threat actor utilized the PowerView module Invoke-ShareFinder twice during the intrusion.PsExecThey used PsExec to remotely deploy Cobalt Strike DLL beacons to several remote hosts including a domain controller as well as file and backup servers.RCloneTwenty days into the intrusion data was exfiltrated using Rclone and FTP.rustscanTwo days later on the backup server they appeared again and dropped a network scanning tool, rustscan, which they used to scan subnets across the environment.Veeam-Get-Creds.ps1On day 26 of the intrusion, the threat actor ran the Veeam-Get-Creds.ps1 script from the injected spoolsv.exe process: