July 10, 2019 By David Bisson 2 min read

Security researchers observed an Astaroth attack that used only living-off-the-land techniques to run the backdoor directly in memory on Windows machines.

The Microsoft Defender ATP Research Team detected the Astaroth attack after noticing an anomaly from a Windows Defender Antivirus algorithm used for catching fileless campaigns. This led the researchers to an infection chain that relied strictly on living-off-the-land techniques — the use of regular tools already present on the system — to avoid raising any red flags.

The infection chain began with a series of spear phishing emails that contained malicious links to redirect users to a LNK file. When double-clicked, the LNK file executed the Windows Management Instrumentation Command (WMIC) tool with the /Format parameter. The campaign then executed JavaScript code to download payloads using the Bitsadmin tool.

At this point, the attacks used Certutil to decode the payloads and then the Regsvr32 tool to run a series of dynamic link libraries (DLLs). This chain of events eventually led one DLL to load into Userinit and then load Astaroth as its final payload. With Astaroth activated, threat actors could use the backdoor to steal sensitive information and move laterally across the network.

Astaroth Abuses Windows Services and Legitimate Tools

Astaroth attacks often abuse legitimate Windows services. In September 2018, Cofense spotted a campaign that compromised 8,000 machines in one week by exploiting WMIC and Certutil. News of this attack came several months before Cybereason detected a campaign in which threat actors abused legitimate operating system functionality and security-related products to distribute the backdoor to users in Brazil.

Awareness Is the Best Defense Against an Astaroth Attack

Security awareness training to educate employees about phishing campaigns and other digital threats can help defend against an Astaroth attack. Analysts should use this education framework in tandem with a patch management strategy and a deep familiarity with built-in Windows code to spot anomalies that could be indicative of fileless attacks.

More from

White House cements CISA’s role as national coordinator for cybersecurity

2 min read - In 2013, the Obama Administration rolled out "The Presidential Policy Directive (PPD) on Critical Infrastructure Security and Resilience", a forerunner to the Cybersecurity and Infrastructure Security Agency (CISA), created "to strengthen and maintain secure, functioning and resilient critical infrastructure."The directive was groundbreaking in 2013, noting the importance of the rising risk of cyberattacks against critical infrastructure. But as cyber risks are constantly shifting, every cybersecurity program needs to be re-evaluated, and CISA is no exception. That’s why, in April 2024, President…

How a new wave of deepfake-driven cybercrime targets businesses

5 min read - As deepfake attacks on businesses dominate news headlines, detection experts are gathering valuable insights into how these attacks came into being and the vulnerabilities they exploit.Between 2023 and 2024, frequent phishing and social engineering campaigns led to account hijacking and theft of assets and data, identity theft, and reputational damage to businesses across industries.Call centers of major banks and financial institutions are now overwhelmed by an onslaught of deepfake calls using voice cloning technology in efforts to break into customer…

Grandoreiro banking trojan unleashed: X-Force observing emerging global campaigns

16 min read - Since March 2024, IBM X-Force has been tracking several large-scale phishing campaigns distributing the Grandoreiro banking trojan, which is likely operated as a Malware-as-a-Service (MaaS). Analysis of the malware revealed major updates within the string decryption and domain generating algorithm (DGA), as well as the ability to use Microsoft Outlook clients on infected hosts to spread further phishing emails. The latest malware variant also specifically targets over 1500 global banks, enabling attackers to perform banking fraud in over 60 countries…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today