Context

In the wake of the Russian invasion of Ukraine, several multinational companies suffered cyber-attacks by pro-Russian ransomware groups following the suspension of their Russian operations. During this time, a multinational technology company engaged Cyndicate Labs to perform an attack simulation to gain an understanding of their attack surface, and maturity level in the event they closed their Russian offices.

Scenarios and Objectives

Working alongside the client to utilise their budget efficiently, the following scenarios were agreed:

Scenario 1 – External

A motivated attacker attempting to gain access to the internal network. Attacks may include phishing, but no physical intrusion or other social- engineering.

Scenario 2 – Assumed Breach

An assumed breach scenario where a standard employee account had been procured or obtained.

Scenario 1 – External

A motivated attacker attempting to gain access to the internal network. Attacks may include phishing, but no physical intrusion or other social- engineering.

Objective – Compromise the internal network.

Cyndicate Labs initially performed Open-Source Intelligence (OSINT) to collect client related data. This included (but was not limited to) mapping the external attack surface and identifying employees from various regions. The red team then abused the “search external users” functionality of Microsoft Teams to validate emails addresses identified during the OSINT phase. Multiple password sprays were then performed against these valid emails to compromise users with weak, easily guessable passwords. This resulted in four separate credentials being identified.

Whilst most of the external applications identified during the enumeration phase enforced Multi-Factor Authorisation (MFA), it was found that the Exchange Web Services (EWS) API did not. As a result, it was possible to use the compromised credentials to enumerate the global address list, access users’ emails, and any email attachments.

One of the compromised users was found to be a global HR director, whose inbox included a significant amount of sensitive data including portfolio reports detailing upcoming products, and new research. As an HR director, this user was also responsible for overseeing the onboarding of new hires. As part of the onboarding process VPN configuration files and initial credentials were emailed to new employees prior to them receiving their laptops. This left a window of opportunity for the red team to capture these configuration files and complete the onboarding process themselves before the new hire received their laptop.

Once internal access was achieved the client contact was satisfied with external progress and wished to proceed with the second scenario.

Scenario 2 – Assumed Breach

An assumed breach scenario where a standard employee account had been procured or obtained. The objective was to identify the risks associated with a malicious insider and attempt to escalate privileges in order compromise R&D data, and e-commerce applications.

Objective 1 – Escalation of privileges

To gain knowledge about the network and understand how much data was accessible to a low-privilege employee, the red team browsed network file shares and the client intranet. This quickly identified numerous sensitive documents including runbooks belonging to their IT services supplier detailing procedures and operations for managing their estate. Unfortunately, these runbooks also contained clear-text credentials for various applications and service accounts. It was later discovered that one of the passwords identified within these run books was reused for a domain administrator service account.

In addition to the run books, network shares also provided financial documentation, legal data, HR data (including disciplinary letters), R&D, and further cleartext user credentials. After checking with the client point of contact, a subset of less sensitive data was then exfiltrated from the network to test their Data Loss Prevention system.

One of the identified credentials permitted access to the client AWS console. While the credentials did not have significant privileges within AWS, it did permit authentication to the primary SMTP server. As such it was possible for the Cyndicate Labs consultants to send emails from any client email address. As a proof of concept, an email was sent from the company founder to the client point of contact.

Objective 2 – Compromise R&D data

To incorporate additional tooling into the domain whilst simulating a threat actor’s tactics, techniques, and procedures (TTP), the Cyndicate Labs red team used the knowledge gained during the enumeration phase to develop a malicious payload that successfully evades the security tooling in place. This C2 framework was then used for the remainder of the assessment with no activity being detected by the blue team.

Utilising one of the service account credentials identified in the IT provider runbook, it was possible to compromise the companies Privileged Access Management (PAM) solution and gain access to further domain account credentials. One of the accounts within the PAM solutions had administrative access to the main R&D file share. After agreeing with the client, several gigabytes of historical encrypted R&D data was exfiltrated from the file share to an attacker-controlled server.

Objective 3 – Compromise e-commerce applications

During the enumeration phase, it was identified that the e-commerce applications were stored in AWS and managed by the clients’ IT Service Provider. One of the IT Service Provider infrastructure engineers was found to regularly store personal data within a network file share. Throughout the engagement this file share was monitored closely until the employee temporarily stored a PowerShell script containing their clear-text domain credentials. By accessing the companies Citrix from within the internal network, it was found to be possible to evade multi-factor authentication and gain access to the employee’s desktop. The engineer’s desktop folder was found to contain credentials for the backup solution, private keys which resulted in access to almost all Unix hosts within the estate, and AWS credentials which ultimately led to full control of the e-commerce applications.

Additional Testing

As all objectives had been achieved without intervention from the blue team, the client point of contact requested several additional tests to be performed. Firstly, the passwords of high value domain accounts were to be reviewed. Secondly, additional testing around data exfiltration was requested as a significant investment had been made into their Data Loss Prevention (DLP) solution.

A DCSync attack was performed to obtain the password hashes of 150 target accounts believed to be of interest to the Red Team. This included members of Cyber Defence, Infrastructure Engineers, Domain Administrators, and Executives. Once captured, password cracking was performed to obtain the users clear-text credentials. Of the targeted 150 accounts, clear-text credentials were recovered for 37%, unfortunately this included two board members, the founder, and the CEO. Due to the misconfiguration identified at the start of testing and the multi factor authentication bypass, it was possible to access the board members desktops, emails, and email archives, some of which dated back over twenty years.

After performing numerous exfiltration attacks, it became apparent that the DLP solution was not working as expected. After consulting with the vendor, a configuration issue was identified and quickly remediated. Each exfiltration test was then repeated and successfully identified by the DLP software.

The remainder of testing time was then spent working alongside the blue team repeating attacks and writing effective detections for the various tactics, techniques, and procedures performed during the engagement.

Ready to test your defences?

Talk to our team about a red team or threat-led engagement tailored to your organisation.