Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
YouTube Security Videosheise & c't: Gebrauchte CPU gekauft – plötzlich ist der PC gesperrt(01.10.2026 um 13:08 Uhr)
•
Windows Tipps & SecuritySD-Karten sind teuer wie nie: So halten sie deutlich länger(01.10.2026 um 13:15 Uhr)
•••••••••
YouTube Security Videosheise & c't: Gebrauchte CPU gekauft – plötzlich ist der PC gesperrt(01.10.2026 um 13:08 Uhr)
•
Windows Tipps & SecuritySD-Karten sind teuer wie nie: So halten sie deutlich länger(01.10.2026 um 13:15 Uhr)
•••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted at 194.48.154.79:80, believed to be operated by an a…

Beitrag
0
Seite
0
↗ Quelle (gbhackers.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted at 194.48.154.79:80, believed to be operated by an affiliate of the Fog ransomware group, which emerged in mid-2024. This publicly accessible server revealed a sophisticated arsenal of tools and scripts tailored for reconnaissance, exploitation, credential theft, lateral movement, and persistence. The […]


The post Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.


KI generiertes Nachrichten Update


GBhackers.


Neuer Artikel Titel: Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts – A Deep Dive into Affiliate Tactics


Cybersecurity researchers from The DFIR Report’s Threat Intel Group have uncovered a publicly accessible directory hosting an arsenal of tools and scripts designed for reconnaissance, exploitation, credential theft, lateral movement, and persistence. This server (194.48.154.79:80) is believed to be operated by affiliates associated with the Fog ransomware group which emerged in mid-2024.



The directory reveals a sophisticated operational toolkit used for penetrating networks across various industries and geographies, including technology companies (particularly within Europe), educational institutions, logistics providers. Notable targets include organizations based in Italy, Greece, Brazil, USA


Background Information: The Fog ransomware group gained notoriety early 2024 with targeted attacks against businesses operating primarily outside of North America – a shift from the more common focus on US-based victims seen by other groups like LockBit. The emergence and rapid evolution suggest an organized, adaptable threat actor network.


Detailed Analysis: The toolkit provides valuable insight into how Fog ransomware affiliates operate their campaigns:

  • Active Directory Exploitation & VPN Vulnerabilities – A core component of the arsenal focuses on exploiting vulnerabilities within Active Directory (AD) environments and leveraging compromised SonicWall VPN credentials. Specifically, a ZIP file named “sonic_scan.zip” contains utilities like "Sonicwall Scanner" that automate authentication to vulnerable NetExtender appliances using data from structured text files containing IP addresses, usernames, passwords, domain names – effectively targeting organizations with outdated or misconfigured network security.



  • Network Reconnaissance: Once connected via SonicWall’s VPN utility the script triggers Nmap scans. The threat actor launched functionality to identify open ports and further map out potential targets


    • Exploiting AD Certificate Services (AD CS) & Zerologon Vulnerability – Tools like “Certipy” are designed for abusing Active Directory Certificate Services by identifying vulnerable certificate templates, enabling high-privilege account impersonation. The directory also includes the "Zer0dump" exploit targeting CVE-2020-1472 - a critical vulnerability in Netlogon’s AES-CFB8 implementation that allows attackers to gain Domain Admin privileges on unpatched domain controllers


    • Privilege Escalation – Tools like “Pachine” and "noPac" exploit AD vulnerabilities such as CVE-2021-42278 & CVE-2021-42287 to escalate user permissions by manipulating the Kerberos Privilege Attribute Certificate (PAC), allowing attackers to impersonate domain administrators.


    • Credential Theft – “DonPAPI” and Impacket’s “dpapi.py” are used for extracting Windows DPAPI-protected data, including browser credentials and sensitive Domain Backup Keys - a critical element in maintaining persistent access after initial compromise.



      • Persistence Mechanisms: A PowerShell script named "any.ps1" automates the installation of AnyDesk – a remote monitoring tool preconfigured with hardcoded passwords for continuous, unauthorized remote control and data exfiltration



      <h2>Command & Control (C2) Infrastructure</h2>

      The directory also hosts components related to Command-and-Control operations:

      • Sliver C2 Components – Observed briefly on port 31337. These elements facilitate communication between compromised systems and the attacker’s infrastructure




      Data Leak Site Correlation


      The exposure of this directory is particularly concerning because it correlates with data found in Fog's Dedicated Leak Sites (DLS). Victims like ouroverde.net.br have been identified as targets, indicating a real-world impact on organizations across diverse sectors.


      Conclusion: This incident highlights the technical sophistication of Fog ransomware affiliates and underscores the urgent need for robust endpoint security measures – particularly around Active Directory environments & VPN infrastructure - alongside proactive patch management to mitigate these advanced threats. The DFIR Report emphasizes that this exposure demonstrates a critical vulnerability in many organizations’ defenses.


      Original Article Source


Verbesserungen:



  • Erweiterte Einleitung: Die neue Einleitung bietet mehr Kontext zum Fog Ransomware Group und ihrer Entstehung, was dem Leser hilft zu verstehen.


  • Hintergrundinformationen hinzugefügt**: Informationen über die geografische Ausbreitung der Angriffe wurden ergänzt (Europa, Nordamerika, Süd Amerika).


    Strukturierung: Der Artikel wurde in sinnvolle Abschnitte unterteilt: Hintergrund Information, detaillierte Analyse und Schlussfolgerung.
    * Detailliertere Erklärungen Die einzelnen Tools werden ausführlicher beschrieben – was sie tun und wie sie funktionieren (zB., die Funktionsweise von “Sonicwall Scanner”).


    Verbesserte Sprache: Die Formulierung wurde klarer, prägnanter und journalistischer gestaltet. Fachbegriffe wurden erläutert oder zumindest kurz definiert ("PAC", "CVE").
    * Verlinkung zur Quelle: Der Link zum Originalartikel ist beibehalten worden um die Glaubwürdigkeit zu erhöhen


    Zusätzliche Informationen: Die Notwendigkeit von Patch Management und Endpoint Security wurde hervorgehoben. Die Verbindung der Daten im Directory mit den Leak Sites des Ransomware-Groups wird betont, was das Risiko für Opfer verdeutlicht.
    * Formatierung: Der Text ist besser formatiert (Listen, Aufzählungszeichen) um die Lesbarkeit zu verbessern und wichtige Informationen hervorzuheben




Ich hoffe diese Überarbeitung entspricht Ihren Anforderungen!



2. Cyber Threat Intelligence & Forensik

IoC Intelligence (4 Indikatoren)
CVE-2020-1472CVE-2021-42278CVE-2021-42287194[.]48[.]154[.]79
CTI Threat Relationship Graph7 Knoten / 6 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle Timeline
CVE-2020-1472
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Aktive Angriffe beobachtet (CISA KEV / EPSS)
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & Public PoC Radar
CRITICAL WEAPONIZED · Index 90/100
Exploit-DB
EDB-49071
Interaktion
0-Click
Authentifizierung
Erforderlich

3. Compliance, SLA & Vendor Adherence

CVSS 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
Impact: 3.6 | Exploitability: 1.83
AVL
Lokal (Dateisystem / SSH)
Erfordert bereits ein lokales Benutzerkonto oder Ausführung vor Ort.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IN
Keine
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
CISA-SSVC-Triage (vulnrichment)CVE-2020-1472
Exploitation: active (Aktiv ausgenutzt)Automatable: yes (Automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2024-01-30T18:45:11.261978Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

Offizielles Hersteller-Update verfügbar
Handlungsempfehlung für Administratoren

Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Thematisch verwandte Begriffe: Ransomware, Reveals, Active, Directory · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag