Ransomware Threat Actors Exploit Employee Monitoring Tools for Attacks
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
What Happened
In late January and early February, the Huntress response team detected two separate intrusions involving the misuse of employee monitoring software. The attackers combined Net Monitor for Employees Professional with the remote monitoring and management tool SimpleHelp to gain unauthorized access to corporate networks and attempted to deploy ransomware. Although the attacks were thwarted, they underscore the growing trend of criminals leveraging legitimate software to conceal their activities within enterprise environments.
In the first incident, the attacker installed Net Monitor for Employees on a victim’s machine and manipulated user accounts to reset passwords and create new admin-user accounts. They also attempted to deploy Crazy ransomware linked to VoidCrypt. The second incident involved a compromised third-party SSL VPN account, allowing the attacker to install the monitoring software disguised as Microsoft OneDrive, further demonstrating the sophistication of these attacks.
Implications for Organizations
This misuse of employee monitoring tools reveals significant cybersecurity risks for organizations. The ability of threat actors to blend legitimate software with malicious intent complicates the detection of intrusions. As these tools can perform actions like remote command execution, they effectively become remote access trojans (RATs) in the hands of criminals.
Organizations should be aware that the use of employee monitoring software, while beneficial for data loss prevention, can also pose risks if not properly managed. Regular audits of third-party software and monitoring for unusual process executions are essential to mitigate these risks. Additionally, the financial motivations of attackers may extend beyond ransomware to include direct cryptocurrency theft, as evidenced by the monitoring of keywords related to cryptocurrency platforms.
To safeguard against such threats, implementing multi-factor authentication (MFA) on remote access services and limiting access to essential users can significantly reduce the likelihood of successful intrusions. Organizations must remain vigilant and proactive in their cybersecurity measures to protect against evolving threats.
- Net Monitor for Employees Professional: Used by attackers to gain unauthorized access and manipulate user accounts.
- SimpleHelp: A remote monitoring tool exploited by criminals to deploy ransomware and conduct reconnaissance.
- Crazy ransomware: A variant linked to the attacks, indicating the financial motivations of the threat actors.
- VoidCrypt: The ransomware associated with the attempted deployment in the first incident.
- SSL VPN: A compromised third-party service used to gain initial access in the second incident.
Key Takeaways
- Enable multi-factor authentication (MFA) for all remote access services to enhance security.
- Conduct regular audits of third-party remote monitoring and employee monitoring software to identify potential risks.
- Monitor for unusual process execution chains that may indicate malicious activity.
- Limit remote access to only those users and systems that require it for their job functions.
- Stay informed about the latest cybersecurity threats and adjust security measures accordingly.
Key Terms & Concepts
- Net Monitor for Employees Professional: In this article, Net Monitor for Employees Professional refers to employee monitoring software exploited by attackers to gain unauthorized access.
- SimpleHelp: SimpleHelp is a remote monitoring and management tool that was used by criminals in conjunction with employee monitoring software for malicious purposes.
- Crazy ransomware: Crazy ransomware is a type of malware linked to the attempted attacks described in the article.
- VoidCrypt: VoidCrypt is a variant of ransomware mentioned in connection with the attacks on corporate networks.
- SSL VPN: An SSL VPN is a secure remote access service that was compromised to facilitate one of the attacks discussed.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.