Crazy Ransomware Gang Exploits Employee Monitoring Tools for Attacks
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Crazy ransomware gang has recently been reported to exploit legitimate employee monitoring software, specifically Net Monitor for Employees Professional, alongside the SimpleHelp remote support tool. This combination allows them to maintain persistence within corporate networks while blending in with normal administrative activities. Researchers from Huntress discovered multiple incidents where these tools were used to facilitate ransomware deployment.
In one notable intrusion, attackers installed Net Monitor for Employees Professional using the Windows Installer utility, msiexec.exe, directly from the developer’s site. This method provided attackers with the ability to remotely view desktops, transfer files, and execute commands, effectively granting them full access to compromised systems.
Additionally, attackers attempted to activate the local administrator account to enhance their control over the network. They also downloaded and installed the SimpleHelp remote access client via PowerShell commands, disguising it with filenames similar to legitimate software, such as Visual Studio’s vshost.exe.
By executing the SimpleHelp payload, attackers ensured they could maintain remote access even if the employee monitoring tool was removed. They often disguised the SimpleHelp binary using filenames that mimicked OneDrive, further complicating detection efforts.
Researchers noted that the attackers monitored system activity in real-time, including cryptocurrency wallet access and remote management tools, as they prepared for ransomware deployment. This included tracking keywords related to popular cryptocurrency services and remote access tools.
While only one incident resulted in the deployment of Crazy ransomware, Huntress suspects that the same threat actor is responsible for both incidents due to overlapping infrastructure and filenames used in the attacks.
This trend of using legitimate remote management tools in ransomware attacks is becoming increasingly common, allowing attackers to blend in with legitimate network traffic. Organizations are advised to monitor for unauthorized installations of such tools and enforce multi-factor authentication (MFA) on all remote access services.
Implications for Organizations
The use of legitimate tools by attackers underscores the need for organizations to enhance their security measures. Monitoring for unauthorized installations and enforcing MFA can significantly reduce the risk of such intrusions.
Key Takeaways
- Regularly audit and monitor for unauthorized installations of remote monitoring and support tools in your organization.
- Enforce multi-factor authentication (MFA) on all remote access services to protect against credential theft.
- Educate employees about the risks of using legitimate software for malicious purposes and encourage reporting suspicious activities.
- Implement robust endpoint protection solutions to detect and respond to unauthorized software installations.
- Review and update security policies to address the use of employee monitoring tools and remote access software.
Key Terms & Concepts
- Net Monitor for Employees Professional: In this article, Net Monitor for Employees Professional refers to software used for monitoring employee activity that was exploited by attackers.
- SimpleHelp: SimpleHelp is a remote support tool that attackers used to maintain access to compromised networks.
- PowerShell: PowerShell is a task automation framework from Microsoft that attackers used to execute commands and install malicious software.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.