News Heading

US and Canadian Authorities in a Joint Advisory Warned of Rising Truebot Activity

Reading time: 2 min

In a joint cyber security advisory, the US and Canadian federal authorities warned about an increasing use of a newly identified Truebot malware variant. The malware also known as Silence.Downloader in recent times has garnered attention because of its usage by ransomware groups like CL0P.

The Truebot malware is known to collect and steal information from victims for financial gains by delivering phishing emails with malicious attachments. However, the variant that is currently targeting organizations across the US and Canada is exploiting CVE-2022-31199, a remote code execution (RCA) vulnerability in the Netwrix Auditor software.

The on-premises and cloud-based IT system auditing software’s vulnerability is exploited by threat actors to gain initial access and move laterally within the targeted organization’s network. The advisory further went on to say that the malware once downloaded renames itself and deploys FlawedGrace (RAT) onto the compromised network.

The remote access trojan (RAT) is ‘’able to modify registry and print spooler programs,’’ features it manipulates to escalate privileges and establish persistence onto the host’s network.

After a few hours of the breach, Truebot also executes Cobalt Strike (RAT) payloads for various post-exploitation attacks, including ransomware deployment and data theft. In addition to these RAT variants and tools, Truebot is also associated with the deployment of other delivery vectors and tools like Raspberry Robin and Teleport.

The joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and Canadian Centre for Cyber Security (CCCS) also stressed on the need for immediate mitigation and incident response measures in case of malware detection. It also advised hunting for signs of this malware infection by using the guidelines outlined in the cyber security advisory.

The authorities also advised organizations using Netwrix’s IT system auditing software to apply vendor provided patches to CVE-2022-31199 vulnerability and update it to version 10.5. The advisory also recommended reporting the Truebot hack incident to CISA or the FBI.

Did you like this article? Rate it!
I hated it I don't really like it It was ok Pretty good! Loved it!

We're thrilled you enjoyed our work!

As a valued reader, would you mind giving us a shoutout on Trustpilot? It's quick and means the world to us. Thank you for being amazing!

Rate us on Trustpilot
0 Voted by 0 users
Title
Comment
Thanks for your feedback
Loader
Please wait 5 minutes before posting another comment.
Comment sent for approval.

Leave a Comment

Loader
Loader Show more...