
About this episode
Research Saturday is made possible by:
Get every episode summarized
Each time Research Saturday publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
272 searchable segments. Every word is indexed and playable.
Full transcript
Research Saturday — A beast by any other name.. Machine-transcribed; use the interactive transcript above to jump the player to any line.
You're listening to the CyberWire network, powered by N2K. Yes, you can have an enterprise network that's secure and reliable and high performance, and no, you don't need to choose the best two out of three. With meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage. That's because meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network. Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design. You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching firewalls, DNS security, and VPNs. You'll really know what's running on your network down to the most granular client level.
Step off the hardware box upgrade treadmill and switch to meter for a predictable fee, and free up your team to spend time on all the other things that keep your business running. Try it out for yourself and book a demo online at meter.com slash CyberWire. That's M-E-T-E-R dot com slash CyberWire. Hello everyone and welcome to the CyberWire's Research Saturday. I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace. Thanks for joining us. This is like a rather third rebrand that we're aware of.
They have the monster ransomware that they started out with back in 2022, then they rebranded to beast, and now they have goddamn. And also we've seen in some of their code as well, 666. So they seem to have this kind of beast to beastly, I suppose, etheme running through the ransomware names. This Bridgid O'Gorman, senior intelligence analyst on the Sementech threat hunter team. The research we're discussing today is titled GD Ransomware, latest beast rebrand uses malicious driver to disable defenses. I mean, I suppose ransomware are, well, threat actors in general have a bit of a history of trying to be a little bit controversial sometimes with their names or with the mess just of even code and things like that. So I guess they're carrying out a tradition in a way in that sense. Do you suppose there's anything to be read into when a ransomware group continues to
rebrand itself like this? I mean, it's definitely not unusual for ransomware groups to rebrand. I think generally it's in a way I suppose to take, sometimes it's trying to take the heat off of themselves, you know, I mean, beast monster, they would be sort of well known enough names, but they wouldn't be hugely, I suppose, controversial ransomware brands. But in the past, I think we have seen, you know, other, other ransomware families rebrand in the situation where maybe there's a lot of kind of pressure coming under them, maybe from law enforcement, maybe Dave, you know, doing a particularly, a particularly controversial attack that maybe has put a lot of heat on them. And so that's because, you know, I suppose, inspire them to rebrand. I mean, we've seen a few examples of that in the past. We saw the, you know, dark side ransomware, which was used in the colonial pipeline attack
in the US, which disrupts a few supply on the East Cogs back in 2020, 2021 back in COVID times. And I know that was hugely, you know, metal out of headlines, very controversial. And then that led to the group behind us who we track as corries, they then rebranded to Black matter after that. And then they saw squarely rebranded again to the Novores Black House ransomware family, which appears to be shut down at the moment, but, you know, it's very possible they will come around again. So I think rebranding is generally a way to try and maybe take a bit of heat off these ransomware families. And sometimes I think maybe can be driven as well if it's kind of fallouts perhaps between ransomware actors as well. And that maybe there can be kind of a, you know, group that splits off from perhaps rebrands to a different identity as well. Hmm. Well, let's walk through this attack from the beginning here. What are the first signs that something is wrong? So the first sign we saw in this instance was there was suspicious Annie desk activity
on the victim network, I suppose. We didn't see what the vector exactly used was. We don't know if they got in with phishing emails or if they got in by exploiting vulnerabilities. The first kind of suspicious activity we saw was Annie desk being installed on a computer in an unusual location. It was installed under the music folder. So that was kind of the first thing that I suppose sparked a bit of suspicion, I guess, in this attack because it kind of indication you know someone had, because it was in social unusual location that someone had gone in there and kind of manually installed it as well, you know, it wasn't even just kind of automated installation when it did something like that. And then we saw various connections. We made to Annie desk infrastructure. And then we saw the attackers starting to deploy their kind of defense invasion portion of their attack, which was one of the interesting parts of this attack as well. So part of that was that they downloaded onto the computer and defense invasion tool, which they were masquerading as a semantic excuseable.
So they named this tool semantic.exe. And that was also installed in the music folder and tried to impersonate semantic products that it didn't value. You know, there was no legitimate legitimacy to that at all. And then that was used to launch a kernel driver called poison x. So this was one of the interesting parts of this attack. So I suppose BYOVD, as we call it, to bring your own vulnerable driver tactic is something we're seeing so much there in ransomware attacks, like really increasingly seeing and we're seeing attackers use this BYOVD technique to disable security software most of the time. That is what it is being used for. And the poison x driver that was used in this particular attack is relatively kind of new on the scene. I think it was first seen earlier on this year where it was used in about April. It was documented first. And in that case, it was used to disable crowd strike in an attack bush. This is I believe is the first time we've seen that use alongside a ransomware family
as well. Now, one of the things that caught my eye was that driver was signed by Microsoft. What's the significance of that? I mean, it's significance, I suppose, in a few different ways. You know, generally, most modern versions of Windows now drivers have to be signed or they will be loaded. So when a co-editor, so attackers always want, I suppose, to gain access to these signs, drivers. Now, generally, what we see when attackers are using this BYOVD technique is they are basically exploiting of vulnerability in wash is otherwise a legitimate driver and using that then to basically kind of side load or install their malware and their malicious activity onto the victim networks. So, you know, we'd see things like that with ghost driver, like say that's kind of a completely available tool, but that's based on an uniligitimous driver bush. In the case of poison X, it appears to have been developed as a malicious tool from what
we can see. Obviously, the developer says it was developed as a research tool and bush from our analysts can see it's only ever been used for kind of malicious purposes. So it does appear that in this case, the developers of us were able to somehow trick or convince Microsoft to sign the driver. We're not obviously entirely sure how they achieved that, but that obviously just make it quite dangerous. It's also a little bit more unusual because as I say, normally, we do see these legitimate drivers kind of being exploited as opposed to these specifically malicious drivers being used by attackers. I mean, we have seen all the drivers poor try as one that we see frequently being used as well, which similarly also appears to have been a malicious driver. That the developer somehow managed to get signed, but we don't really know how exactly they are they are managing to do this. I want to touch on their attempts to evade detection here. You mentioned that they disguised one of their tools as a semantic product.
What do you suppose the purpose of that was? What did they achieve through that? Well, they're just disguised in the sense of the name of the tool, which was semantic.exe. I suppose they're just trying to disguise their size as a mask or a radius. I suppose alongside other other obviously this, this is one of our customers. They obviously have semantic software on their machines. I guess they were just going to blend in with the legitimate software and trying to make that kind of connections back to their server and all that look like legitimate traffic as much as possible. This is something we see all the time really with attackers that are now a day constantly trying to use even using legitimate cloud services and using legitimate tools in general in order to try and blend into that legitimate traffic that's on machines because that is what obviously makes it makes so much harder to detect when attackers are using legitimate tools that do have legitimate uses, but obviously just using them for malicious purposes.
And then we often see that then as well. For as obviously this was a malicious tool, but they were trying to masquerade an legitimate by giving it the semantic name. And what security tools were they out to disable? So they were basically out to disable whatever security tools were on the system. They would use the poison extriver to basically terminate the termination for their security processes were on the system, including the endpoint detection and response products as well. And they're able to do this because of the nature of drivers because drivers basically have kernel access, which allows them to delete or stop or throttle, I suppose, security products in a way that other tools aren't able to do basically because these drivers have this hurdle level access. They have a level of access and a level of capability to stop other tools that other
tools that are just at the user level can't achieve. So this is why we've seen this growth in BYOVD and why it's such a popular tactic. Now, far ransomware actors and threat actors in general who wants to disable security tools and then, you know, I guess make their, make their activity essentially invisible that on the victim network once those tools are disabled a lot of the time. We'll be right back. A component of this was their lateral movement. Can you walk us through what they were doing there? Yeah, so what is interesting actually with this group, Hyazina, they're very since the start, even since they, I suppose, first came out as monster, and then when they were beast as well, and now we've got them, they're very focused on deploying a lot of password seating, potential harvesting tools. And that seems to be a big part of their attack.
So we see them in this tool using MIMI cats and then also using a whole suite of basically password seating tools that are kind of developed by your staff. So they're kind of these publicly available. It's publicly available too. It really that can kind of harvest credentials from everywhere really, you know, like all your different apps, your browsers, all that. So this is, that's a big part of their operations as well is stealing all those credentials in order to help them move across the system basically and move across the network. So they did that. They, they downloaded a lot of these tools and then they had a little gap of activity probably while they were sort of, I suppose, you know, coordination of these credentials. And then last one movement began across network at that point. And they used, yes, they, again, like, again, using legitimate tools as well for this activity. They use PS exec for last one movement and they also launched admin shares with,
using the so-called credentials as well. They were able to disable Windows, Fender, monitoring as well. And then they use Ani-JS, which they deployed then basically on each, on each post that they were able to reach in order to maintain that kind of persistent access. They registered as an auto-stars service and that they could maintain that persistent access, even if the computers were rebooted. That kind of thing they were still able to maintain that so that was a key part of that was a key part of their activity as well. And I think, you know, it's interesting that certain parts of, I suppose, the group's activity has changed. Obviously, while they're rebranding with the different names and stuff, a lot of their other steps of their attack has remained very similar because they're used sub-Ani-JS, three of these potential harvesting tools. That has kind of remained a fairly consistent step in their attacks that we've seen them carrying out, even since they were carrying out the monster attacks as well. How much of this is actually new compared to the beast
ransomware? I think there are use of poison X is quite interesting. We didn't see them used to be Y-O-V-D elements previously in the attacks. Like in the monster attacks, we saw in the very much kind of exploit using all the kind of living off the lands, probably the available tools, that kind of thing. And similarly with beast, we did see them start to use some other tools. They're reusing the G-Mur tool, which can be kind of used for stopping processes and things like that as well. But they're used to poison X. I think Jaws kind of constitute a bit of a step up, I think, in their sophistication, really. It's quite a new tool, a bit poison X one, like we haven't been used very widely. It's all the relish of the recently newly discovered. So it just seems to be a bit of an escalation in their defensive Asian capability. And even the use obviously of the B-Y-O-V-D technique in general is a bit of an escalation in their defensive Asian capabilities really as well. So I think that is interesting. I think the kind of shows they're
obviously continuing to kind of adapt, continue to kind of develop their skills and develop the effectiveness of their attacks as much as possible. And so that's always something to keep an eye and I think with these groups, you know, that they're obviously, one's, they're continuing to try and make, keep these attacks stealthy and make them as effective as possible on their, on their side of things. I think it's always worth keeping an eye on. What are your recommendations then for the security professionals in our audience to best protect their organizations here? I mean, I think the steps are quite similar really, quite a comes to protecting companies that were from ransomware for all groups really, you know, companies need to have that security software and that's kind of typical mitigation steps in place with that kind of high priority. Out alerts, the trigger on ransomware and pre-m ransomware activity, you know, as those enterprise why the attacks can happen very quickly now. We actually published a blog just last week or the week before as well since we published this blog about a seemingly new ransomware called Spirals. And that went from, you know, the first activity is on the network to the ransomware being
deployed within 24 hours. So that was a very, that escalated very quickly, that attack. I mean, the God's Amitak was stuck basically four days, which is also relatively quickly, quick as well. So I think that, you know, having those alerts for that pre-m ransomware activity is definitely really important as these attacks kind of ease up in lots of ways. And I think obviously though, it wasn't a factor in those particular attacks, as AI becomes increasingly adopted by threat actors and ransomware actors, you know, inevitably, probably the speed of a task is only likely to increase, you know. And I guess then, for general sense, you know, for rural organizations, they need that kind of defense and depth strategy, having those kind of multiple detection protection, different technologies as well to help mitigate risk at different points. It's a behavioral technology is important as well. Now I think because as we say, the use of so many legitimate tools and that kind of thing, you know, so to make sure that all parts of their security, I guess, are enabled in working
together to help detect the attacks more quickly, you know, as well as monitoring things like the use of Julia's tools inside their network and then the kind of basic things of, you know, obviously controlling who has access to administrative accounts, multi-factor authentication, multi-factor authentication, all those kind of basic steps as well that are very important to try and keep that work safe. When you look at this research and you mentioned some of the other recent research that you and your colleagues have done, what do you suppose this is heading? What is the future of ransomware look like in your estimation? It's a big question. I mean, it's hard to know, like, ransomware really, you know, it's been so consistently around for such a long time that, you know, I think we have seen obviously changes and variations. We've seen a lot more of the extortion only attacks as well, becoming very popular, obviously with the attacker, with their groups like shiny hunters and things like that as well. So that ransomware itself is
necessarily being deployed in every attack we see, you know, we are seeing some attacks where the the attackers are just stealing data and then trying to use that to extortion companies. I think that will continue as a trend as well because I just think in lots of ways it's, you know, probably easier for attackers and sometimes just as effective. But I think when it comes to like a really, you know, a really successful ransomware attack for once with a better word, you know, you'll think can kind of compare to that when it comes to disruption that can be caused for the by the attackers and the kind of leverage that can give them, you know, particularly against organizations and, you know, it likes a healthcare or government or, you know, manufacturing where I kind of have that downtime is really going to damage the organization. So I don't think ransomware is going to go anywhere and I do think, you know, inevitably we have really seen, yes, obviously we see they all used for, you know, certain things, you know, for lures, for fishing emails, for certain amount of riding code and that kind of thing. But I'm sure as we go
forward and as the technology continues to develop, we will see ransomware actors, you know, using all I probably trying to speed up these attacks and try to, you know, deploy the ransomware even more quickly across the network, which just make it even more challenging for defenders and for security companies to protect against this kind of behavior. So I think it's hard to know where things are going. But I suppose it's always a bit of a race between, I guess, defenders trying to use new technologies to improve things for people, but then unfortunately attackers also need to use these new technologies to, you know, make their attacks more effective as well. So I think it's an ever-changing landscape, but I definitely think ransomware will be around for the foreseeable future, anyway for sure. Our thanks to Brigitte O'Gorman from Sementek for joining us. The research is titled
GD Ransomware, latest beast rebrand uses malicious driver to disable defenses. We'll have a link in the show notes. And that's research Saturday brought to you by N2K CyberWire. We'd love to know what you think of this podcast, your feedback and shores. We deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire at n2k.com. This episode was produced by Liz Stokes. We're mixed by Elliott Peltzmann and Trey Hester. Our executive producer is Jennifer Ibn. Peter Kielpia's our publisher and I'm Dave Bitner. Thanks for listening. We'll see you back here next time.
More episodes
