Invisible thieves in the front yard – from an advanced evasive edge-device attack to potential mitigation methods
Ting-Wei Hsieh (CHT Security Co)
As detection and response toolsets are actively being developed and deployed on common Windows and Linux devices, edge devices remain largely reliant on system configurations and human intervention as their main defence. Nevertheless, nation-state attackers have increasingly been targeting public-facing appliances as initial entry points to gain footholds in victims' environments and their tactics have shown great effectiveness.
In early 2024, we uncovered an attack that lasted several years against a high-tier local cloud service provider. The techniques and novel samples we found show both the efforts attackers have made to understand commercial edge-device systems and the great lengths attackers are willing to go to reduce the chance of being detected. Although the concept of magic packets is nothing new, we discovered that attackers have been moving from static magic signatures and hard-coded C2 configurations to fully dynamic and more versatile magic packets to evade network-based detections.
In this talk, I will share how security appliance mishaps may lead to attacks of such a scale and will focus on the evasion techniques observed in this attack, such as the usage of magic packets with no static signature and utilizing living-off-the-land (LotL) tools to extract sensitive data on compromised edge devices. In addition, the session will present our insights to detect and mitigate persistent installations emerging from this attack and some general recommendations or mitigation methods for both service providers and public-facing appliance suppliers.
For details please visit Virus Bulletin Website.