US and Canadian Authorities in a Joint Advisory Warned of Rising Truebot Activity
In a joint cyber security advisory, the US and Canadian federal authorities warned about an increasing use of a newly identified Truebot malware variant. The malware also known as Silence.Downloader in recent times has garnered attention because of its usage by ransomware groups like CL0P.
The Truebot malware is known to collect and steal information from victims for financial gains by delivering phishing emails with malicious attachments. However, the variant that is currently targeting organizations across the US and Canada is exploiting CVE-2022-31199, a remote code execution (RCA) vulnerability in the Netwrix Auditor software.
The on-premises and cloud-based IT system auditing software’s vulnerability is exploited by threat actors to gain initial access and move laterally within the targeted organization’s network. The advisory further went on to say that the malware once downloaded renames itself and deploys FlawedGrace (RAT) onto the compromised network.
The remote access trojan (RAT) is ‘’able to modify registry and print spooler programs,’’ features it manipulates to escalate privileges and establish persistence onto the host’s network.
After a few hours of the breach, Truebot also executes Cobalt Strike (RAT) payloads for various post-exploitation attacks, including ransomware deployment and data theft. In addition to these RAT variants and tools, Truebot is also associated with the deployment of other delivery vectors and tools like Raspberry Robin and Teleport.
The joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and Canadian Centre for Cyber Security (CCCS) also stressed on the need for immediate mitigation and incident response measures in case of malware detection. It also advised hunting for signs of this malware infection by using the guidelines outlined in the cyber security advisory.
The authorities also advised organizations using Netwrix’s IT system auditing software to apply vendor provided patches to CVE-2022-31199 vulnerability and update it to version 10.5. The advisory also recommended reporting the Truebot hack incident to CISA or the FBI.
Leave a Comment
Cancel