Lunar Spider Intrusion Used Tax-Themed JavaScript to Maintain Access for Nearly Two Months

· Original article ↗

Summary

A DFIR investigation details a nearly two-month intrusion that began with a tax-themed JavaScript file and involved multiple malware families, credential theft, lateral movement, and data exfiltration. No ransomware deployment was observed.

Key points

  • The intrusion began when a user executed an obfuscated JavaScript file disguised as a tax form; it downloaded an MSI that deployed Brute Ratel and Latrodectus.
  • The attackers used BackConnect, Brute Ratel, Cobalt Strike, and a custom .NET backdoor for remote access, command and control, persistence, and process injection.
  • They found plaintext domain administrator credentials in a Windows unattend.xml answer file, then used them for privilege escalation and lateral movement across servers, including a domain controller.
  • The attackers harvested credentials from LSASS, browsers, and backup software, and used a Zerologon (CVE-2020-1472) tool in attempted lateral movement.
  • On day 20, they used a renamed Rclone binary to exfiltrate files from a file-share server over FTP for nearly 10 hours.
  • Intermittent activity continued for nearly two months before the attackers were evicted; investigators observed no ransomware deployment.

Article Details

Attack Vectors
  • A user executed an obfuscated JavaScript file disguised as a W-9 tax form. It downloaded an MSI package that ran a Brute Ratel DLL through rundll32.exe.
  • Brute Ratel injected Latrodectus into explorer.exe. The intruder subsequently used BackConnect, Cobalt Strike beacons and a custom .NET backdoor for access.
  • The intruder obtained plaintext domain administrator credentials from an unattend.xml Windows Answer file and used them with runas and RDP.
  • The intruder used PsExec and remote services for lateral movement, and deployed zero.exe, a custom Zerologon exploit targeting CVE-2020-1472, against a second domain controller.
  • On day 20, scripts ran a renamed Rclone binary to transfer file-share data by FTP to a remote host controlled by the intruder.
Defensive Notes
  • Investigate MSI downloads followed by rundll32.exe execution of DLLs, particularly alongside obfuscated JavaScript presented as a tax form.
  • Monitor Registry Run-key changes, scheduled-task creation, suspicious ms-settings protocol-handler changes, and injection into legitimate processes.
  • Protect and review Windows Answer files for retained plaintext credentials; monitor access to unattend.xml, LSASS and backup-software credentials.
  • Monitor unexpected AdFind, PsExec, PowerView, rustscan, RDP and remote-service activity, as well as Rclone-driven FTP transfers from file servers.
  • The report provides network detections, Sigma rules and YARA references for investigating the observed activity. It reports that no ransomware deployment was observed.

Indicators of compromise

TypeIndicatorContext
DOMAINaltynbe[.]comC2 domain used by the initial Brute Ratel DLL.
DOMAINanikvan[.]comC2 domain used by the initial Brute Ratel DLL.
DOMAINavtechupdate[.]comCobalt Strike C2 domain contacted by the sys.dll implant.
DOMAINboriz400[.]comC2 domain used by the initial Brute Ratel DLL.
DOMAINcloudmeri[.]comC2 domain of the lsassa.exe backdoor.
DOMAINdauled[.]comC2 domain used by the replacement Brute Ratel badger.
DOMAINerbolsan[.]comC2 domain used by the replacement Brute Ratel badger.
DOMAINgrasmetral[.]comLatrodectus C2 domain; spelling is preserved as printed in the indicator table.
DOMAINilloskanawer[.]comLatrodectus C2 domain.
DOMAINjarkaairbo[.]comLatrodectus C2 domain.
DOMAINkasym500[.]comC2 domain used by the replacement Brute Ratel badger.
DOMAINkasymdev[.]comC2 domain used by the replacement Brute Ratel badger.
DOMAINsamderat200[.]comC2 domain used by the replacement Brute Ratel badger.
DOMAINscupolasta[.]storeLatrodectus C2 domain.
DOMAINworkspacin[.]cloudLatrodectus C2 domain.
HOSTNAMEresources[.]avtechupdate[.]comHostname in the C2 address of an in-memory Cobalt Strike stager.
HOSTNAMEridiculous-breakpoint-gw[.]aws-use1[.]cloud-ara[.]tyk[.]ioSpecific Tyk.io gateway hostname listed among the initial Brute Ratel C2 destinations.
HOSTNAMEuncertain-kitten-gw[.]aws-euc1[.]cloud-ara[.]tyk[.]ioSpecific Tyk.io gateway hostname listed among the initial Brute Ratel C2 destinations.
IPV4138[.]124[.]183[.]215IP listed for the altynbe[.]com Brute Ratel C2.
IPV4162[.]0[.]209[.]121IP listed for the lsassa.exe backdoor C2.
IPV4173[.]255[.]204[.]62IP listed for the illoskanawer[.]com Latrodectus C2.
IPV4185[.]93[.]221[.]12BackConnect infrastructure listed in the indicator tables.
IPV4193[.]168[.]143[.]196BackConnect infrastructure listed in the indicator tables.
IPV4195[.]123[.]225[.]161IP listed for the dauled[.]com Brute Ratel C2.
IPV4195[.]123[.]225[.]251IP listed for the kasym500[.]com Brute Ratel C2.
IPV4195[.]211[.]98[.]249IP listed for the kasymdev[.]com Brute Ratel C2.
IPV4206[.]206[.]123[.]209IP listed for the sys.dll Cobalt Strike C2.
IPV4217[.]196[.]98[.]61Metasploit C2 IP listed in the indicator tables; the connection was reportedly rejected.
IPV431[.]13[.]248[.]153IP listed as Cobalt Strike C2 infrastructure.
IPV445[.]129[.]199[.]214IP listed for the cron801.dl_ and system.dl_ Cobalt Strike C2.
IPV445[.]135[.]232[.]3FTP host in the intruder's Rclone configuration for data exfiltration.
IPV445[.]150[.]65[.]85IP listed for the samderat200[.]com Brute Ratel C2.
IPV491[.]194[.]11[.]183IP listed for the boriz400[.]com Brute Ratel C2.
IPV491[.]194[.]11[.]64Host listed for delivery of the Latrodectus MSI second stage.
IPV494[.]131[.]108[.]254IP listed for the erbolsan[.]com Brute Ratel C2.
IPV494[.]232[.]249[.]100IP listed for the erbolsan[.]com Brute Ratel C2.
IPV494[.]232[.]249[.]108IP listed for the samderat200[.]com Brute Ratel C2.
IPV495[.]164[.]68[.]73IP listed for the anikvan[.]com Brute Ratel C2.
MD5495363b0262b62dfc38d7bfb7b5541aaComputed hash listed for the system.dl_ or cron801.dl_ Cobalt Strike artifact.
MD54b3e9c9e018659d1cf04daf82abe3b64Computed hash of start.vbs, the data-exfiltration toolkit launcher.
MD550abc42faa70062e20cd5e2a2e2b6633Computed hash of the lsassa.exe backdoor.
MD591889658f1c8e1462f06f019b842f109Computed hash of zero.exe, the intruder's Zerologon exploit artifact.
MD59eaa8464110883a15115b68ffa1ecf7dComputed hash listed for the intruder-used rustscan.exe artifact.
MD5a2b6479a69b51ae555f695b243e4fda1Computed hash listed for the c356468.exe intrusion artifact.
MD5ad3c52316e0059c66bc1dd680cf9edadComputed hash of the sys.dll Cobalt Strike stager.
MD5c8ea31665553cbca19b22863eea6ca2cComputed hash of run.bat, part of the data-exfiltration toolkit.
MD5ccb6d3cb020f56758622911ddd2f1fcbComputed hash of the upfilles.dll Brute Ratel artifact.
MD5d7bd590b6c660716277383aa23cb0aa9Computed hash of the wscadminui.dll Brute Ratel badger.
SHA123fff588e3e5cc6678e1f77fab9318d60f3ac55fComputed hash listed for the c356468.exe intrusion artifact.
SHA12d92890374904b49d3c54314d02b952e1a714e99Computed hash listed for the system.dl_ or cron801.dl_ Cobalt Strike artifact.
SHA1333e1c5967a9a6c881c9573a3222bed6ada911c6Computed hash of start.vbs, the data-exfiltration toolkit launcher.
SHA133a6b39fbe8ec45afab14af88fd6fa8e96885bf1Computed hash of zero.exe, the intruder's Zerologon exploit artifact.
SHA138999890b3a2c743e0abea1122649082a5fa1281Computed hash of the wscadminui.dll Brute Ratel badger.
SHA14a013f752c2bf84ca37e418175e0d9b6f61f636dComputed hash of the upfilles.dll Brute Ratel artifact.
SHA15348970723b378c7cae35bb03d8736f8e5a9f0acComputed hash listed for the intruder-used rustscan.exe artifact.
SHA18dfa63c0bb611e18c8331ed5b89decf433ac394aComputed hash of the sys.dll Cobalt Strike stager.
SHA197d72c8bbcf367be6bd5e80021e3bd3232ac309aComputed hash of the lsassa.exe backdoor.
SHA1ba99cd73b74c64d6b1257b7db99814d1dc7d76b1Computed hash of run.bat, part of the data-exfiltration toolkit.
SHA256100e03eb4e9dcdab6e06b2b26f800d47a21d338885f5dc1b42c56a32429c9168Computed hash of the sys.dll Cobalt Strike stager.
SHA2561a8ebf914ebea34402eecbf0985f05ae413663708d2fcc842fc27057ac5ec4edComputed hash of start.vbs, the data-exfiltration toolkit launcher.
SHA256203eda879dbdb128259cd658b22c9c21c66cbcfa1e2f39879c73b4dafb84c592Computed hash of the lsassa.exe backdoor.
SHA25636bc32becf287402bf0e9c918de22d886a74c501a33aa08dcb9be2f222fa6e24Computed hash of zero.exe, the intruder's Zerologon exploit artifact.
SHA25637471af00673af4080ee21bd248536147e450d2eff45e8701a95d1163a9d62feComputed hash listed for the intruder-used rustscan.exe artifact.
SHA256411dfb067a984a244ff0c41887d4a09fbbcd8d562550f5d32d58a6a6256bd7b2Computed hash of run.bat, part of the data-exfiltration toolkit.
SHA2566c3b2490e99cd8397fb79d84a5638c1a0c4edb516a4b0047aa70b5811483db8fComputed hash of the wscadminui.dll Brute Ratel badger.
SHA25677eede38abdc740f000596e374b6842902653aeafb6c63011388ebb22ec13e28Computed hash listed for the system.dl_ or cron801.dl_ Cobalt Strike artifact.
SHA2568fb5034aedf41f8c8c4c4022fdde7db3c70a5a7c7b5b4dec7f6a57715c18a5bfComputed hash listed for the c356468.exe intrusion artifact.
SHA256f4cb6b684ea097f867d406a978b3422bbf2ecfea39236bf3ab99340996b825deComputed hash of the upfilles.dll Brute Ratel artifact.
URLhxxp[:]//45[.]129[.]199[.]214/vodeo/wg01ck01Cobalt Strike beacon C2 URL observed during the intrusion.
URLhxxp[:]//91[.]194[.]11[.]64/MSI[.]msiURL from which the malicious JavaScript downloaded the second-stage MSI.
URLhxxps[:]//cloudmeri[.]com/comm[.]phpEmbedded C2 endpoint used by the lsassa.exe backdoor.
URLhxxps[:]//illoskanawer[.]com/live/Latrodectus C2 URL in the configuration's decrypted strings.
URLhxxps[:]//workspacin[.]cloud/live/Latrodectus C2 URL in the configuration's decrypted strings.

MITRE ATT&CK

T1003.001 · LSASS MemoryCobalt Strike-injected processes accessed LSASS on multiple devices.T1018 · Remote System DiscoveryThe intruder enumerated domain controllers, servers and other remote systems.T1021.001 · Remote Desktop ProtocolThe intruder used domain administrator credentials to log in to two servers over RDP.T1021.002 · SMB/Windows Admin SharesPsExec remotely deployed Cobalt Strike DLL beacons to a domain controller and other servers.T1027.016 · Junk Code InsertionThe JavaScript concealed a small amount of executable code among extensive filler text.T1033 · System Owner/User DiscoveryThe intruder ran whoami, and the backdoor collected the compromised username.T1046 · Network Service DiscoveryThe intruder used rustscan to scan internal network blocks for SMB on port 445.T1047 · Windows Management InstrumentationThe intruder attempted remote execution of a Cobalt Strike beacon using WMIC.T1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolA renamed Rclone binary transferred file-share data to the intruder's FTP host.T1053.005 · Scheduled TaskThe lsassa.exe backdoor created the SchedulerLsass scheduled task to run at system startup.T1055 · Process InjectionBrute Ratel injected Latrodectus into explorer.exe; Cobalt Strike beacons were injected into legitimate processes.T1059.001 · PowerShellThe intruder executed PowerShell download-and-execute commands and a script to obtain Veeam credentials.T1059.003 · Windows Command ShellThe backdoor executed received commands through cmd.exe, and the intruder used Windows shell commands throughout the intrusion.T1059.007 · JavaScriptThe obfuscated JavaScript initiated download of the malicious MSI package.T1069.002 · Domain GroupsThe intruder queried Domain Admins and enumerated Active Directory groups.T1070.004 · File DeletionThe intruder deleted more than half of the downloaded files and tools after use.T1071.001 · Web ProtocolsLatrodectus, Brute Ratel, the .NET backdoor and Cobalt Strike used HTTP or HTTPS C2 communications.T1078.002 · Domain AccountsThe intruder authenticated with the domain administrator account found in unattend.xml.T1082 · System Information DiscoveryThe intruder ran systeminfo and other commands to inspect compromised systems.T1083 · File and Directory DiscoveryBackConnect was used to browse directories and inspect files, including unattend.xml.T1087.002 · Domain AccountAdFind and net user commands were used to enumerate domain users.T1105 · Ingress Tool TransferThe JavaScript downloaded an MSI, and later activity transferred malware and tools onto compromised hosts.T1135 · Network Share DiscoveryNet view and PowerView Invoke-ShareFinder were used to identify network shares.T1204.002 · Malicious FileA user executed the malicious JavaScript file disguised as a tax form.T1210 · Exploitation of Remote ServicesThe intruder used zero.exe, a custom Zerologon exploit, in attempted lateral movement to a second domain controller.T1218.011 · Rundll32The MSI custom action and subsequent commands used rundll32.exe to execute malicious DLL payloads.T1222.001 · Windows PermissionsThe intruder used icacls to change ownership and reset permissions while trying to read AdFind output.T1482 · Domain Trust DiscoveryThe intruder used nltest to enumerate domain trusts.T1518.001 · Security Software DiscoveryA WMIC command queried installed antivirus products on the beachhead host.T1547.001 · Registry Run Keys / Startup FolderA Registry Run key named Update was created to execute the Brute Ratel badger after restart.T1548.002 · Bypass User Account ControlA Cobalt Strike implant hijacked the ms-settings protocol handler and invoked ComputerDefaults.exe to bypass UAC.T1552.001 · Credentials In FilesThe intruder retrieved unattend.xml and obtained plaintext domain administrator credentials stored in it.T1555.003 · Credentials from Web BrowsersA Latrodectus stealer module collected browser passwords and session data.T1569.002 · Service ExecutionThe intruder attempted to execute a Metasploit reverse shell through a remote service.

CVE

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Related Articles