﻿{"id":2525,"date":"2018-03-27T22:00:56","date_gmt":"2018-03-27T15:00:56","guid":{"rendered":"https:\/\/humanit.asia\/?p=2525"},"modified":"2019-07-22T14:54:49","modified_gmt":"2019-07-22T07:54:49","slug":"ta18-086a","status":"publish","type":"post","link":"https:\/\/old.humanit.asia\/th\/ta18-086a\/","title":{"rendered":"TA18-086A: Brute Force Attacks Conducted by Cyber Actors"},"content":{"rendered":"<div>\n<p>Original release date: March 27, 2018<\/p>\n<h3>Systems Affected<\/h3>\n<p>Networked systems<\/p>\n<h3>Overview<\/h3>\n<p>According to information derived from FBI investigations, malicious cyber actors are increasingly using a style of brute force attack known as password spraying against organizations in the United States and abroad.<\/p>\n<p>On February 2018, the Department of Justice in the Southern District of New York, indicted nine Iranian nationals who were associated with the Mabna Institute for computer intrusion offenses related to activity described in this report. The techniques and activity described herein, while characteristic of Mabna actors, are not limited solely to use by this group.<\/p>\n<p>The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) are releasing this Alert to provide further information on this activity.<\/p>\n<h3>Description<\/h3>\n<p>In a traditional brute-force attack, a malicious actor attempts to gain unauthorized access to a single account by guessing the password. This can quickly result in a targeted account getting locked-out, as commonly used account-lockout policies allow 3-to-5 bad attempts during a set period of time. During a password-spray attack (also known as the \u201clow-and-slow\u201d method), the malicious actor attempts a single password against many accounts before moving on to attempt a second password, and so on. This technique allows the actor to remain undetected by avoiding rapid or frequent account lockouts.<\/p>\n<p>Password spray campaigns typically target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols.&nbsp; An actor may target this specific protocol because federated authentication can help mask malicious traffic.&nbsp; Additionally, by targeting SSO applications, malicious actors hope to maximize access to intellectual property during a successful compromise.<\/p>\n<p>Email applications are also a target.&nbsp; In those instances, malicious actors would have the ability to utilize inbox synchronization to (1) obtain unauthorized access to the organization&#8217;s email directly from the cloud, (2) subsequently download user mail to locally stored email files, (3) identify the entire company\u2019s email address list, and\/or (4) surreptitiously implements inbox rules for the forwarding of sent and received messages.<\/p>\n<h3>Technical Details<\/h3>\n<p>Traditional tactics, techniques, and procedures (TTP\u2019s) for conducting the password-spray attacks are as follows:<\/p>\n<ul>\n<li>Use social engineering tactics to perform online research (i.e., Google search, LinkedIn, etc.) to identify target organizations and specific user accounts for initial password spray<\/li>\n<li>Using easy-to-guess passwords (e.g., \u201cWinter2018\u201d, \u201cPassword123!\u201d) and publicly available tools, execute a password spray attack against targeted accounts by utilizing the identified SSO or web-based application and federated authentication method<\/li>\n<li>Leveraging the initial group of compromised accounts, download the Global Address List (GAL) from a target\u2019s email client, and perform a larger password spray against legitimate accounts<\/li>\n<li>Using the compromised access, malicious actors attempt to expand laterally (e.g., via Remote Desktop Protocol) within the network, and perform mass data exfiltration using File Transfer Protocol tools such as FileZilla<\/li>\n<\/ul>\n<p>Indicators of a password spray attack include:<\/p>\n<ul>\n<li>A massive spike in attempted logons against the enterprise SSO Portal or web-based application. Using automated tools, malicious actors attempt thousands of logons, in rapid succession, against multiple user accounts at a victim enterprise, originating from a single IP address and computer (e.g., a common User Agent String). Attacks have been seen to run for over two hours<\/li>\n<li>Employee logons from IP addresses resolving to locations inconsistent with their normal locations<\/li>\n<\/ul>\n<h3>Typical Victim Environment<\/h3>\n<p>The vast majority of known password spray victims share some of the following characteristics <a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST04-002\">[1]<\/a><a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST05-012\">[2]<\/a>:<\/p>\n<ul>\n<li>Use SSO or web-based applications with federated authentication method<\/li>\n<li>Lack multifactor authentication (MFA)<\/li>\n<li>Allow easy-to-guess passwords (e.g., \u201cWinter2018\u201d, \u201cPassword123!\u201d)<\/li>\n<li>Use inbox synchronization allowing email to be pulled from cloud environments to remote devices<\/li>\n<li>Allow email forwarding to be setup at the user level<\/li>\n<li>Limited logging setup creating difficulty during post-event investigations<\/li>\n<\/ul>\n<h3>Impact<\/h3>\n<p>A successful network intrusion can have severe impacts, particularly if the compromise becomes public and sensitive information is exposed. Possible impacts include:<\/p>\n<ul>\n<li>Temporary or permanent loss of sensitive or proprietary information<\/li>\n<li>Disruption to regular operations<\/li>\n<li>Financial losses incurred to restore systems and files<\/li>\n<li>Potential harm to an organization\u2019s reputation<\/li>\n<\/ul>\n<h3>Solution<\/h3>\n<h4>Recommended Mitigations<\/h4>\n<p>To help deter this style of attack, the following steps should be taken:<\/p>\n<ul>\n<li>Enable MFA and review MFA settings to ensure coverage over all active, internet facing protocols<\/li>\n<li>Review password policies to ensure they align with the latest NIST guidelines <a href=\"https:\/\/pages.nist.gov\/800-63-3\/\">[3]<\/a> and deter the use of easy-to-guess passwords<\/li>\n<li>Review IT Helpdesk password management related to initial passwords, password resets for user lockouts, and shared accounts. IT Helpdesk password procedures may not align to company policy, creating an exploitable security gap<\/li>\n<li>In addition, many companies offer additional assistance and tools the can help detect and prevent password spray attacks, such as the Microsoft blog released on March 5, 2018 (link below):<\/li>\n<\/ul>\n<p><a href=\"https:\/\/cloudblogs.microsoft.com\/enterprisemobility\/2018\/03\/05\/azure-ad-and-adfs-best-practices-defending-against-password-spray-attacks\/\">https:\/\/cloudblogs.microsoft.com\/enterprisemobility\/2018\/03\/05\/azure-ad-and-adfs-best-practices-defending-against-password-spray-attacks\/<\/a><\/p>\n<h4>Reporting Notice<\/h4>\n<p>The FBI encourages recipients of this document to report information concerning suspicious or criminal activity to their local FBI field office or the FBI\u2019s 24\/7 Cyber Watch (CyWatch). Field office contacts can be identified at www.fbi.gov\/contact-us\/field. CyWatch can be contacted by phone at (855) 292-3937 or by e-mail at CyWatch@ic.fbi.gov. When available, each report submitted should include the date, time, location, type of activity, number of people, and type of equipment used for the activity, the name of the submitting company or organization, and a designated point of contact. Press inquiries should be directed to the FBI\u2019s national Press Office at npo@ic.fbi.gov or (202) 324-3691.<\/p>\n<h3>References<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST04-002\">[1] NCCIC\/US-CERT Tip ST04-002 \u2013 Choosing and Protecting Passwords <\/a><\/li>\n<li><a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST05-012\">[2] NCCIC\/US-CERT Tip ST05-12 \u2013 Supplementing Passwords<\/a><\/li>\n<li><a href=\"https:\/\/pages.nist.gov\/800-63-3\/\">[3] NIST Special Publication 800-63 \u2013 Digital Identity Guidelines<\/a><\/li>\n<\/ul>\n<h3>Revision History<\/h3>\n<ul>\n<li>March 27, 2018: Initial Version<\/li>\n<\/ul>\n<hr>\n<p>This product is provided subject to this <a href=\"http:\/\/www.us-cert.gov\/privacy\/notification\">Notification<\/a> and this <a href=\"http:\/\/www.us-cert.gov\/privacy\/\">Privacy &amp; Use<\/a> policy.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original release date: March 27, 2018 Systems Affected  [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[106],"tags":[],"class_list":["post-2525","post","type-post","status-publish","format-standard","hentry","category-alerts-th"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TA18-086A: Brute Force Attacks Conducted by Cyber Actors - humanit managed services<\/title>\n<meta name=\"description\" content=\"In a traditional brute-force attack, a malicious actor attempts to gain unauthorized access to a single account by guessing the password.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/old.humanit.asia\/ta18-086a\/\" \/>\n<meta property=\"og:locale\" content=\"th_TH\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TA18-086A: Brute Force Attacks Conducted by Cyber Actors - humanit managed services\" \/>\n<meta property=\"og:description\" content=\"In a traditional brute-force attack, a malicious actor attempts to gain unauthorized access to a single account by guessing the password.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/old.humanit.asia\/ta18-086a\/\" \/>\n<meta property=\"og:site_name\" content=\"humanit managed services\" \/>\n<meta property=\"article:published_time\" content=\"2018-03-27T15:00:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-22T07:54:49+00:00\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 \u0e19\u0e32\u0e17\u0e35\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"headline\":\"TA18-086A: Brute Force Attacks Conducted by Cyber Actors\",\"datePublished\":\"2018-03-27T15:00:56+00:00\",\"dateModified\":\"2019-07-22T07:54:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/\"},\"wordCount\":948,\"articleSection\":[\"Alerts\"],\"inLanguage\":\"th\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/\",\"url\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/\",\"name\":\"TA18-086A: Brute Force Attacks Conducted by Cyber Actors - humanit managed services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\"},\"datePublished\":\"2018-03-27T15:00:56+00:00\",\"dateModified\":\"2019-07-22T07:54:49+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"description\":\"In a traditional brute-force attack, a malicious actor attempts to gain unauthorized access to a single account by guessing the password.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/#breadcrumb\"},\"inLanguage\":\"th\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-086a\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/old.humanit.asia\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TA18-086A: Brute Force Attacks Conducted by Cyber Actors\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\",\"url\":\"https:\\\/\\\/old.old.humanit.asia\\\/\",\"name\":\"humanit managed services\",\"description\":\"making technology easy\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/old.old.humanit.asia\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"th\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"caption\":\"Admin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TA18-086A: Brute Force Attacks Conducted by Cyber Actors - humanit managed services","description":"In a traditional brute-force attack, a malicious actor attempts to gain unauthorized access to a single account by guessing the password.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/old.humanit.asia\/ta18-086a\/","og_locale":"th_TH","og_type":"article","og_title":"TA18-086A: Brute Force Attacks Conducted by Cyber Actors - humanit managed services","og_description":"In a traditional brute-force attack, a malicious actor attempts to gain unauthorized access to a single account by guessing the password.","og_url":"https:\/\/old.humanit.asia\/ta18-086a\/","og_site_name":"humanit managed services","article_published_time":"2018-03-27T15:00:56+00:00","article_modified_time":"2019-07-22T07:54:49+00:00","author":"Admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Admin","Est. reading time":"5 \u0e19\u0e32\u0e17\u0e35"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/old.humanit.asia\/ta18-086a\/#article","isPartOf":{"@id":"https:\/\/old.humanit.asia\/ta18-086a\/"},"author":{"name":"Admin","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"headline":"TA18-086A: Brute Force Attacks Conducted by Cyber Actors","datePublished":"2018-03-27T15:00:56+00:00","dateModified":"2019-07-22T07:54:49+00:00","mainEntityOfPage":{"@id":"https:\/\/old.humanit.asia\/ta18-086a\/"},"wordCount":948,"articleSection":["Alerts"],"inLanguage":"th"},{"@type":"WebPage","@id":"https:\/\/old.humanit.asia\/ta18-086a\/","url":"https:\/\/old.humanit.asia\/ta18-086a\/","name":"TA18-086A: Brute Force Attacks Conducted by Cyber Actors - humanit managed services","isPartOf":{"@id":"https:\/\/old.old.humanit.asia\/#website"},"datePublished":"2018-03-27T15:00:56+00:00","dateModified":"2019-07-22T07:54:49+00:00","author":{"@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"description":"In a traditional brute-force attack, a malicious actor attempts to gain unauthorized access to a single account by guessing the password.","breadcrumb":{"@id":"https:\/\/old.humanit.asia\/ta18-086a\/#breadcrumb"},"inLanguage":"th","potentialAction":[{"@type":"ReadAction","target":["https:\/\/old.humanit.asia\/ta18-086a\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/old.humanit.asia\/ta18-086a\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/old.humanit.asia\/"},{"@type":"ListItem","position":2,"name":"TA18-086A: Brute Force Attacks Conducted by Cyber Actors"}]},{"@type":"WebSite","@id":"https:\/\/old.old.humanit.asia\/#website","url":"https:\/\/old.old.humanit.asia\/","name":"humanit managed services","description":"making technology easy","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/old.old.humanit.asia\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"th"},{"@type":"Person","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c","name":"Admin","image":{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","caption":"Admin"}}]}},"_links":{"self":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/comments?post=2525"}],"version-history":[{"count":1,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2525\/revisions"}],"predecessor-version":[{"id":2530,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2525\/revisions\/2530"}],"wp:attachment":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/media?parent=2525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/categories?post=2525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/tags?post=2525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}