TA551 a Threat Actor every MSP Needs to know About
In this video, Ryan, Wes, and Gary discuss the critical security threats posed by phishing attacks, particularly focusing on the infamous threat actor group TA551. They delve into the importance of understanding and mitigating risks associated with Cobalt Strike beacons, which can lead to severe network compromises if not promptly addressed. The conversation also explores practical strategies for MSPs to enhance their cybersecurity measures, including implementing restrictive macro policies and fostering security awareness training.<ul><li>Phishing accounts for 43% of all breaches, highlighting the need for robust email security and user training.</li><li>Cobalt Strike is a critical threat when detected in a network, as it indicates a high likelihood of a network compromise and potential ransomware attack.</li><li>Implementing restrictive macro policies can neutralize up to two-thirds of malicious documents, making it a crucial step in defending against attacks like those from TA551.</li></ul>
Guests
Video Transcript
All right, we're live episode 62. I don't have a propeller over my head, if any of you those, no. Notice. This is, uh, live from Wade Kilgore's office at Access Tech and No, no Santa Hat on the tv. Yeah, exactly. New thing. Um, but we have an action pack show today and a phenomenal guest, uh, who I'm gonna introduce shortly. Let me get a little bit of the housekeeping out of the way.
Number one, you're gonna be, uh, in good hands probably in about 10 minutes with, uh, Ryan West and Gary as, um, I'm gonna exit because of what I have going on here. But, uh, a few things I want to kick off. Number one, um, by the way, we talked last week about the training that, um, initiative that we're doing with Black Hills John and Anti Siphon John Strand. I'm gonna put it in again and I'm gonna be very clear. It's in chat. Okay?
So, as you know, John has a pay what you can, it's not pay what you want. Ms. Teams can pay 4 95. We have the cyber call code discount of a hundred off. So this is sand style training at 3 95. With that, you have to register 4 95 and get the a hundred off. You will get a year of the cyber range, which isn't standard. And what isn't standard is Ask John anything Post-event, which we will schedule based on those that put in the cyber call code. You will be invited and there will be Ms.
P specific topics. Stay tuned. There's gonna be a big press release coming this week from MSSP alert. There's a lot of stuff coming out about this. Uh, next thing, real quick, uh, and the reason I'm giving props to this is 'cause Jonathan Crow has helped me a ton in this initiative, and I just want to thank him for all his help. He's doing this is kind of timely. He's doing his MSP chats on Thursday, which is in the call to action, gone fishing.
He's gonna have, uh, conce, which is literally the who's who in enterprise, um, uh, security for phishing. And, uh, he's gonna want to have them on as well as, um, and I'm drawing a blank on the other ones. I'm sorry, Jonathan, but I just wanted to call you out and thank you, Gary. I can tell you wanna say something a little sarcastic? I can't imagine. What is it, Gary? No, no. Just keep going. Alright, let's go. Alright. Yeah, yeah. I, I'm losing focus. That's all. All right. Okay.
Well, we're gonna get on with it now. Alright, so right on into it. Um, so only, um, let's see. See, according to Verizon data breach report and setting the stage here, 43% of all breaches involve phishing. Um, it is the, obviously social engineering is in like the 90% range of attacks. Phishing being the top one. We really haven't covered it on the cyber call.
So, with that, um, we, so Andrew, can I just say real quick, real time today, everyone at True Methods got an email saying that they have been assigned cybersecurity training. Click here to get to your course. And it was a Phish. Was it a Phish? Yeah. Yeah. Nice. Yes. Was it an Phish or was it a, uh, phishing test? It was a fish. Yeah. This is not a test. Nah, I don't even wanna know what the click rate was on that. I'm assuming it was probably, Yeah. Gimme some feedback from the audience.
Am I, are we frozen? Here You are, Andrew. Yeah, I thought you were just looking in, uh, stern disapproval of the rest of us, but, uh, You, uh, It was just a wouldn't the First time. All right, Ryan. Oh, sorry about that. I hear you apologize. I don't know what happened to, um, am I, am I, can you hear me guys? You're good. Yes. I Apologize. My, my internet just hung up, so, okay. Um, In interest of time, we brought on Brad Duncan.
So Brad, I'm gonna give you a, a touch of overview, but Ryan found your article. You do a ton of research only what over 1800 blogs, uh, on your site, which, um, is, is phenomenal. I'm gonna let, um, you tell a little bit about that. But background, a a veteran retired from the Air Force. I'm gonna let you tell about yourself. But one thing, Ryan, at some point, Brad, when you guys say, Hey, what is, you know, ta five, five one's emails look like Brad will share his screen just for a moment.
'cause he's got the actual data sitting at his fingertips. Yeah. Brad, a little bit about yourself. And again, thanks so much for coming on. This is a really important topic for the, Uh, well, I'm, uh, I'm, uh, definitely happy to be here. I'm always, um, I'm, I'm always, uh, uh, I always enjoy talking with, uh, other industry professionals, and especially when I can bring, uh, um, security related, uh, uh, details to, uh, not necessarily a security related audience, right?
Because when we're talking MSB, we're talking, uh, we're talking the whole, uh, uh, gma the whole round of, uh, IT services in many cases, right? And, uh, uh, security may not be the top priority. Uh, but, uh, uh, uh, I can get into that, uh, uh, later in my personal philosophy on, uh, on, uh, you know, when we're talking about IT versus security just in general, not even talking about MSP, but, uh, just it.
Um, so, uh, I spent, uh, I spent, uh, about 21 and a half years in the, uh, US Air Force as a listed person, um, doing, uh, uh, as a crypto logic linguist. I was, uh, working, uh, in, uh, Korea, spent 13 of my years in, uh, South Korea, had Osan air base. And, uh, I did, uh, classified intelligence work.
And, uh, when I retired, uh, back in, uh, 2010, I really needed to, uh, um, here in the San Antonio or area, that's where I ended up and was trying to find a way to, uh, uh, you know, use those skills that I'd learned in Intelligence Analyst into something that I found, uh, uh, personally fulfilling. And, uh, I got my, uh, foot in the door because, uh, the Air Force cert was hiring, uh, people that had security clearances.
Uh, and they, they were telling us, we'll, we'll train you, we'll train you how to do this IT security type job. And, uh, so, uh, uh, um, I got, uh, uh, was a security plus, uh, the comp TIA security plus certification. And, uh, uh, then I had, uh, once I got hired on, I had to, at the time, uh, get the, uh, SANS GCIA certification.
Right now, I think there are, uh, for the Department of Defense Regulations, uh, governing that people are able to get certified Ethical Hacker, which, uh, I'm glad I got the GCIA because that was a much more really hands-on, definitely focused on blue team type defense activity, which is, uh, which is where I live. And then, uh, eventually, um, I went commercial, uh, started over, uh, at, uh, Rackspace when they were building up their security operations center.
And then, um, one of the, one of the perks I had at Rackspace at the time was, uh, up to $200 of, uh, free web hosting each month. And, uh, all employees had that. So I, uh, I, uh, started using it. I registered the name malware traffic analysis.net, and I started posting stuff, uh, first as a vanity project to say, Hey, uh, I, I have some idea that I know what I'm doing, but that also helped build, uh, my skills.
And, um, uh, by the time I left Rackspace a few years later, um, they were a much, uh, more secure environment. It wasn't, uh, it was a little more of a wild west, uh, type thing where I was much more likely to find interesting stuff that may have slipped, uh, past the security monitoring that was then currently in place. So it was, uh, very much an educational experience. And then, uh, when the opportunity at Palo Alto Networks, uh, opened up, um, uh, I would've been a fool.
I would've kicked myself if I didn't, uh, take it. So, uh, really my time at Rackspace.
And, uh, I think this goes for a lot of, uh, security professionals where, where it's a matter of opportunity, a matter of, uh, just taking that chance and jumping in, uh, because certainly, uh, when I started doing cybersecurity, it, uh, um, when I retired from the Air Force, I definitely took a noticeable, uh, I wouldn't say how much of a percent, but I took a noticeable pay cut, uh, which, uh, my air force pension kind of made up for.
But, uh, my wife wasn't too happy about the fact that I was making, uh, um, you know, less than I was making in the military. But, uh, uh, I wasn't after it for the money. I was after it to, to find a, uh, a long-term, uh, career in something I was very, that I could be passionate about. And that's, uh, uh, that's, uh, blue team defensive, uh, operations for information security, InfoSec, cybersecurity, whatever you wanna call it. Awesome, Brad. So, um, so, um, I'm getting some feedback.
You again, chance was, So I don't know why you're saying back, Andrew. Andrew. Oh, it sounds like we all are. Yeah. Um, somebody's got their, it was, we, we, so Wes is muted. It's Wes. Hey, Andrew. Can I ask a quick question? Yeah, of course. I, I wanna get behind the curtains on the five people who said they didn't wanna know how to better defend against phishing attacks. You, I know you always look at the poll In our call. Yeah. Yes. I would like to know less about phishing, please. Yeah.
Yeah, because it's not that u it's not used that often in, in attacks. So, um, and I know Ryan's gonna be touching on things like cobalt strike and, and things like that. So, Ryan, let me hand over the controls to you. This is one of your favorite threat actors. I've heard you say, one of the most important and why, Ryan, just high level, should this threat actor be in every MSP's threat profile?
Yeah, I mean, it's a great, I mean, yes, my favorite threat actor and, and the, the reasons are varied. Um, TA 5 51 leads to many of the types of threats that MSPs and their SMBs experience on a daily basis. Um, and phishing, you know, outside of credential theft and vulnerability exploitation, phishing is one of the top, if not the top mechanisms for attackers to gain a foothold. And TA 5 51 has made it their business at being very successful at doing this.
And so they've delivered, as Brad will talk about a number of threats through their, uh, through their platform, um, in the past two years. And, uh, that ranges anywhere from info stealing malware to bank, and, uh, you know, financial Trojans exploit kits, um, and now, um, droppers and downloaders. So a lot of that can lead to ransomware as well. Um, and so, you know, TA 5 51 has just this incredible power to spider into a bunch of different areas.
Um, and it's kind of like, you know, peeling the onion analogy or peeling the artichoke. Like every layer you peel back, the deeper and deeper you go, the more and the more you learn. And like, it's actually a really great threat actor to learn cyber defense from because of the layers of, uh, of what they do and how quickly they change. I mean, this year alone, Brad, I think they've changed, uh, what they're delivering four or five times. Is that right? You're muted. Uh, I got you off.
I got you off. You're fine. Uh, thank you. Thank you. Yeah. Uh, sorry about that. Yes. Um, they started out, uh, last year they were doing, uh, iced id and then, uh, in January, CAC Bott in, uh, uh, they were doing, uh, some, uh, URS Ngozi ice FB uh, back in March and April. Uh, they were doing Trick Bot briefly, uh, uh, last month. And now they're doing, uh, bizarre Loader, right? So yeah, five Delete, right?
And as we'll as we'll talk about more Trick Bot and Bizarre Loader can actually be intermediate steps to Conti and Rio Ransomware. So again, if, if Rio Ransomware threat actor, I believe that's Wizard Spider, right? Um, and, um, what, I don't know what the threat actor behind Conti is, uh, off the top of my head, but if those are in your profile, TA 5 51 is in your profile. Right?
So, um, again, so I I, earlier in the chat, scroll up, I posted a link to the Mitre attack, um, profile, as well as the Red Canary profile. I actually love the Red Canary profile because it actually talks about detection opportunities. Um, and that's where one of the poll questions comes from is, do you have macro policies? So, um, maybe be before I just like give away the whole thing.
Um, Brad, can you, can you give us an overview of one of the, um, that, that most recent Sands diary you wrote on that came out on Friday, and kind of what we should be taking away from that Sure thing here. Uh, I will post that link in the chat. So there's a, there's a link to it.
Uh, basically what I did was I took an example of an email, uh, showed what it looked like, and, uh, uh, showed, uh, what the enclosed, uh, the attached zip archive looks like, and then, uh, uh, what the Word document does and, uh, show some of the traffic. My focus has always been more on, uh, uh, traffic characteristics of, uh, these types of infections, because I believe that can tell a lot.
And that generally, uh, when we're talking about it, security in general, uh, network traffic monitoring is not, uh, as pervasive as I personally think it should be. Uh, it's costly to implement, and the, um, uh, the benefits, uh, from a business sense may not, uh, may not make as much, uh, uh, sense, uh, financially when you're talking about the bottom line, uh, compared to endpoint security and, uh, some other things that you can do, uh, uh, to secure your networks.
But, um, understanding the traffic is, uh, very much a gateway to better understanding the, uh, campaign or the actor behind it. Perfect. And, um, so in, in your article, you mentioned, if I'm not mistaken, cobalt Strike. Um, yes.
And I think we've, we've referred to Cobalt Strike a couple times, um, but I don't know that we've ever really discussed for our MSP audience is really what it is and what it means, um, and how critical it could be for an MSP if their MDR provider says, Hey, we see a Cobalt Strike Beacon in your, your network. Um, talk to us a little bit about Cobalt Strike, what it is, you know, is it inherently bad or could it be in, you know, and just, you know, just riff on it a little bit for me.
Uh, what I will say is Cobalt Strike is not inherently malicious, but it is, it's a red team tool to, uh, that was developed.
Uh, I forget what the, uh, what the name of the actual company is, but, uh, it's a commercially available tool for people, uh, in, uh, uh, red team type operations where you're trying to do penetration tests or probe networks, or, uh, I shouldn't say probe networks, but once you establish a telehealth in a network, cobalt Strike is, uh, the way that you establish that, uh, that back door into that compromised host where you have that to hold in your network. Right?
And we usually call that a C two right. Command and control. Yes. And that command Control has a beacon, it's a frequency with which it checks in with the C two server. Cobalt Strike mimics that beacon of that check-in to that server, or it can actually be facilitate the actual beaconing and the C two server itself, right? Yes. Uh, what I find is, uh, a lot of times when you see Cobalt Strike initially, right?
So you have something like, uh, uh, through TA 5 51, you've got Bizarre Loader or Trick Bot, and then, uh, uh, you start seeing, uh, a, a known IP address or a known domain used by Cobalt Strike, and it beacons out, it, it, it's maintaining contact, and it's establishing it once, like every minute or two, right? So you'll see a TCP connection, you'll see, uh, uh, some web traffic, and it'll happen once every minute or two, but Cobalt Strike is, uh, it's a C two, but it's also a backdoor.
So I've had a host in my lab that's been infected by Cobalt Strike, and then you start seeing it several times every minute, where you start seeing new TCP connections, such as one after another. And it's just filling up, uh, uh, the, the network traffic, uh, the space in the P cap is growing and growing and growing, and meanwhile, I've had infected Windows hosts that have had Cobalt Strike.
And you can see somebody that has used it as kinda like a remote access tool, and they're playing around on your desktop. They're going to any shared drives that you have on that infected Windows host, if you're part of, uh, an active directory network.
So yeah, it's a C two, you're sending, uh, back and forth information from the infected Windows host, but it also acts as a channel for people to, uh, use it as a remote access tool to actually just play around on your host and jump to other parts of the network. You can use it to download, and I've seen this before, where you've download Network Enumeration tools, and then you start seeing Ping scans trying to find out other active hosts on the network.
And then you see, uh, where the one infected host is trying to remote log on to other hosts in the network, whether or not it's successful. Whenever he had the Print Nightmare, when that was, uh, uh, big a couple of weeks back, uh, that I saw an exploit for that, um, actually sent through, it was a PowerShell script, and they just stored it, they literally stored it in the downloads folder of that infected user on that Windows House. This is in my lab environment.
So normally in my lab environment, uh, I don't have that many, uh, uh, windows clients, right? I cannot, uh, simulate, uh, a very, um, attractive looking environment to somebody that's using Cobalt Strike to get in there, because I, you know, I'm not gonna be able to have a hundred, 200, 300, uh, client to where it looks like, Hey, this is a, a big company.
I'm gonna try and, uh, look for some servers and see if there's any, uh, uh, data servers, anything that we can, uh, that we can exploit, we can crack, um, you know, people using Cobalt Strike as that tool can use Mimi Cats or any tool really to get in and, uh, use that infected Windows host as a point to spread across the network. Gonna go to we for this next one. Wes talked about this a little bit on Friday.
So the, the, the, the, the chain of this attack, right, is TA 5 5 1 sends an email, be head's gonna show us what that looks like in a minute. I then do something that leads to Bizarre Loader. Bizarre Loader, can then deliver Cobalt Strike, cobalt strike equals host and network compromise, and then that can lead to data exfiltration, data breach, ransomware, et cetera, et cetera. So, cobalt Strike is kind of your last step before game over.
So your perch, you see a Cobalt Strike Beacon or some indicator of Cobalt Strike in an MSP's environment. You send them a ticket. What do you think the response from an Ms P should be if you escalate a Cobalt straight beacon to them? And what are you, what are you seeing and what do you think they should be doing? Why don't, why don't we act this out a little bit, Ryan?
Uh, so what I normally see is, you know, hey, I see this email from Perch, I, I shouldn't say normally on occasion, what we'll see is we see this email from Purge suspected Beacon, recommend that you take a look and, and jump on the phone and give us some confirmation of what you're seeing, and it'll go into Monday. Uh, what it should be is, hold on, I gotta like, get this cam. I gotta, I gotta take care of this. I gotta jump off the call now.
It needs to be a drop everything you're doing, and immediately, uh, go take care of it, right? Because, um, we're not always saying we, we've sent Falses before. Um, but it needs to be something that's a drop all because it's typically one of the last stages of an attack before you look at like the, the cyber kill chain, where you see active, active, um, on object actions, on objectives. Like they're right there at that stage, at that point, yeah. Yeah.
We're, if you see Cobalt strike to, to steal from the Avengers, we're in the end game now, right? We're, um, I believe there was a, an article I was reading on Friday, one estimate that from the time of a Cobalt Strike Beacon to the time your network is completely owned, and ransom could be as little as one to two hours. So you get a Cobalt Strike Beacon that is a stop. Everything your network is about to be completely compromised type of event, right?
And so, while, while TA 5 51 is not all about Cobalt Strike, increasingly we are seeing a lot of different threat actors use Cobalt Strike. I mean, if you just look at Cobalt Strike and Mitre Attack Framework and the groups that are using it, it is very large. And if you're getting an alert on Cobalt Strike, they're very far along into their network and their foothold.
That's a, that's a get off the phone call your cyber insurance carrier, get your IR provider in there, like start cleaning, start mitigating, start containing right now. Do, do you have anything to add on that, Brad? Uh, yeah. I mean, uh, what I would say is, uh, yes, it can happen very quickly. It can happen within an hour. Uh, keep in mind also that it could happen, uh, days or weeks later.
Uh, one of the first, uh, reports that, uh, FireEye put out on, uh, ransomware from a trick bot infection, uh, where I think there was Cobalt Strike being used. They, they said, uh, they can, uh, they can see a week or a month later. Uh, it just depends on the network, right? So if you've got proper security monitoring in place, you should be able to detect a, uh, cobalt Strike Beacon relatively early.
If you do, that's good, because you can get that as soon as possible, um, uh, because there's a chance, there's a chance that that Cobalt Strike told that Beacon, uh, uh, you know, may not be used right away. And I've, for me, it's about 50 50 from what I've seen in the lab environments and the tests that are run where I set up these fake, uh, uh, active directory environments, and I have, uh, um, uh, you know, these, uh, windows clients that are logged in.
Sometimes it happens really, really quick, um, to where you go from just a, a minute or two, uh, beaconing to where it's like several times a minute, and, uh, you know that they're in there and they're actually, uh, uh, they're actually poking around. Yeah. But it, it, it, uh, so regardless of whether they do it sooner or later, you want to get that taken care of as soon as possible, get that host offline, if at all possible. Yep. Yeah.
If we have time, too, towards the end of the call, I wanna, I wanna talk about, uh, things we can do offensively against, uh, cobalt Strike C two servers. There's a tool released last week called Cobalt Spam, which I think is actually really cool. Um, and there was actually a vulnerability just discovered in the, the beaconing component of, um, cobalt strike, that it can actually knock a cobalt strike C two server offline.
Um, and of course, it was fixed because Cobalt Strike is a valid piece of software that is used maliciously by threat actors. But I think it's an interesting conversation to think about whether or not there should be some sort of kill switch built into a piece of software that companies know are being used for illicit gains. So, we'll see if we have time at the end, but we don't, you show us what a normal TA 5 5 1 email looks like, and how an MSP can go about spotting it.
And then from there, I really wanna work through things we can do to, um, really disrupt the, or implement a kill chain for the TA 5 51 type emails, and hopefully get to the point where we're, we're never even inviting bazaar loader or whatever malware of the day. It's dropping into our environment from ever gaining a I gotcha. Lemme go ahead and share my screen real quick. All right. Uh, what I have here is I've got a, uh, um, VM that I've got set up. I've got some examples.
Uh, here's an email. I open it in Thunderbird. I've, uh, kind of sanitized it because, uh, what happens here is, uh, these are, this is, um, a legitimate email chain that was probably stolen from someone that had it, uh, whether it was this person here, or, uh, somebody that had that as, uh, uh, a recipient in a, uh, email that had multiple recipients. So you're seeing a subject line and a sender.
This, this, uh, person in the, uh, I believe Argentine, uh, government, but, uh, this is all English. So, um, the attachments are mostly named request zip, but sometimes they could be named info zip, and you would have to, uh, you would have to open it using the password. So right there, there's two indicators to look for. Yes. One is an email that contains a password in the body. Another is contains an attachment info or request zip.
If you see those two things together, that is a very strong indication. This is a potentially malicious email. Definitely, definitely. Uh, yeah, anytime I see any zip attachments with, uh, password protection, that's a, that's a big red flag right there.
Um, And as an MSP, right, that doesn't mean all password protected zips are malicious, but if you quarantined them instead of deleting them, your, your end user can escalate to you and say, Hey, I was expecting the zip file from so and so, I didn't get it. You can go into the quarantine and release it, but that prevents you from letting all the bad in with the one good thing that's gonna come once every three months.
Uh, yeah, definitely, I should say, um, I should probably say definitely suspicious as opposed to malicious, because, uh, yeah, a password protected zip archive, uh, from my perspective as a, uh, security, uh, and threat researcher, I love seeing those things because my assumption is that it's probably malicious, but if you have to deal as an MSP with supporting an organization, you cannot afford to, uh, make that base assumption.
Now you've got a, uh, word document, and in this case, here's an example of what those Word documents look like. This is from Friday where I've extracted a bunch of Word documents to kinda show the patterns that they, uh, that they, uh, reveal, right? So you'll see ordained docs, uh, specifics, oh eight point 21, or in this case on Friday the 13th, it was oh eight 13 point 2021 doc. So they follow specific naming patterns and the document templates.
Uh, when you've got a campaign that's using, uh, English, uh, language templates, it, uh, currently it looks like this, and it's, uh, always an enabled macro situation. It's telling you to enable macros. This is a common tactic. The, um, uh, password protected zip attachment is also a common tactic, uh, probably not as common as the, the Microsoft Office document with macros. Now, if I enable this, What will happen is That's another, that's another detection point, right?
So, so you didn't block the zip. If you're seeing a Word document execute with macros, that's another potential indicator on the system. Now, because we've gotten past blocking the email, now we're talking about system activity. That's an indication. Something weird is happening on the system. Yes. Now, what I've got here, you can see, uh, the command shall pop up, uh, uh, for this, uh, HTA file.
Um, now what's happening is, because this is from last Friday, those, uh, the domains, uh, uh, that these documents are calling out to these, uh, document macros, or this code is calling out to hosting them out, where they're, they usually don't last more than 24 hours before they're, uh, just taken offline. And the, uh, threat actor, in this case, TA 5 51, moves on to setting up, uh, completely different domains.
But, uh, what they're doing is it's going to users public, and there's it, it didn't download it, so it wasn't able to save it here. So if you see, for example, uh, reg Server 32 or, uh, run DLL 32, uh, uh, a process that's trying to run something in your public folder or something in your, uh, program data folder, right? And that'll also work on the system, like when word 30, when Worde is interacting with Reg 32, right? You talk about parent-child relationships between processes. Yes.
And good EDR an MDR provider would say it is very bizarre for when Word e XE to be interacting with Reg Serve 32, that is almost guaranteed a malicious process. Yeah. And, you know, it's interesting because, um, uh, a lot of times, uh, I generally have to set up, uh, these, um, I'll stop sharing now. There we go. I generally set up these, uh, uh, these test environments as vulnerable as possible, right?
So I'm gonna have the latest updates and patches, but I'm going to, uh, disable certain things, uh, like, uh, real-time protection and, uh, uh, put some exclusions in, uh, cancel the firewalls, uh, disable those, do all sorts of things that would, uh, ensure that the malware runs, right?
So, uh, but, uh, default settings for Windows ten's, uh, uh, uh, host, and especially enabling something like tamper protection in Windows 10 is something that would do a lot to prevent this stuff from happening in the first place, right? Um, the, uh, macros are, uh, I, I generally have to go through and set up Microsoft, uh, office, word, Excel, uh, whatever, to allow macros to automatically run, take it out of protected mode.
Because if you got protected mode, the end user's not going to, uh, be able to even run those macros unless they're technically savvy enough and have the permissions to go in and disable protected mode, in this case, in Microsoft Word. Yeah. If that makes sense, right? So there, there's a lot that can be done now, uh, depending on the organization and MSPs, uh, uh, providing the services for, there could be requests on the way things are set up.
My, um, uh, uh, my limited experience in the field along those lines is that there's a lot more, uh, exceptions, uh, that are used in, uh, workplace environments that allow people to, you know, say, be able to enable back rows or bypass protected mode. A lot of stuff that, uh, e executives within a company would say, Hey, we need to be able to do this.
Not realizing, or possibly even realizing they're just balancing the risk on, you know, how bad this could be if something malicious is involved. Yeah. Yeah. Ryan, I was gonna say, in the real world, very few MSPs have gotten to this point of relationship with every one of their customers to be able to, this is just one of 10 other conversations they need to have and to change like 30 or 40 customers, uh, behaviors on how they do this and how they interact with their customers and vendors.
Like, this is not an easy, this is not an easy thing. It's, it's critical, but it's not easy for, like, I, you know, I sit in the peer group meetings and I listen to the struggles people are having as they're trying to build that relationship with every customer to be able to have these conversations and have the, you know, their customers understand it quickly and be willing to change the way they do things. Yeah.
I mean, as, as you were talking, I was kind of paying attention to the chat, and I, I love what Felicia is saying out out there. She's saying, we, we block it wholesale, right? You can't do zips and macro policies are enabled, but what she's done is, she said, I understand that you have a valid business need for some of these things.
So I'm gonna work with you to set up an alternate collaboration workflow that isn't as open and as susceptible to some of these attack techniques that still allow you to collaborate. And that's more of a yes but attitude. Oh, you need to do this. Okay, yes, I can help you do that, but we're not gonna do that through email. We're gonna do that through secure file sharing. We're gonna do that through, that's like a true VCIO vcso type of collaboration.
That's the type of solution that we need to bring to some of these problems. So, um, this is why, I'm sorry, Wes has been asking, I'm sorry, I'm Sorry. Real quick before we move on from that, 'cause I was reading what Felicia was saying too, and, um, what prompted me right to, to say that, and it assumes two things. It assumes, you know, number one, that you have gotten to where she, you know, she has with these conversations.
And then two, that you have the resources to develop the alternate solution to take the time to train them and move them over to it. 'cause all of that takes time and planning pre-conversation and post conversation. Yeah, definitely. So this is why we just wanna drive home the macro policies. Wes was hitting on this in the LinkedIn post on Friday. Um, and, uh, you know, uh, Brad just talked about it, macro policies.
If you have a restrictive macro policy in place, it's estimated that up to two thirds of all of the malicious documents that come through TA 5 51 are actually neutralized by just having a restrictive macro policy. So we, it's really interesting. We, we think of TA 5 51 is on this pedestal. They're one of the most capable email based threat actors in the world, but there are very simple things that we can do to neutralize their effectiveness. Um, and so that, I wanted to hand it over to Gary.
I know, I know Gary might have wanted to dig into that a little bit more. So, over to you, Gary. Muted, bud. What I want to do with Zoom out a little here, uh, Brad, and talk about like, if a user engages in one of these emails, we talked about some of the end result where they get to, but what are some of the points along the way that they can look for detection? Uh, that's a good, uh, that's a good question.
I already said that, uh, you know, when we're talking about password protected, uh, uh, email attachments, uh, that's a suspicious point, right? Um, not necessarily malicious, but it is something like, uh, felicia's, uh, method of being able to, uh, you know, stop people from, uh, or, or to, to, to give options to people instead of just automatically clicking and opening those.
But if those can be detected and, uh, um, you know, depending on the, the security, uh, uh, infrastructure of an MSP, that might be something that could be detected, uh, uh, you know, uh, where you're at. But, uh, you know, so the password protected zip archive, the, um, the, uh, the, uh, uh, word macros, uh, it's not often that people need to use macros, uh, in a general sense, but they definitely, uh, are use cases where they do have to be used.
So, uh, but those macros causing word to actually call up, uh, you know, red server 32 or run DLL 32, uh, or causing a PowerShell script to, uh, appear.
And, uh, when you're talking about a PowerShell script that happens after a word macro is enabled, and, uh, it's, uh, running in the, uh, c program data directory, or the C user's public directory, or the C user's username, app data, local temp directory, uh, or sometimes, uh, you know, anywhere along that path, uh, for that, uh, uh, potential victim, right?
Anywhere under c users in their Windows user account name anywhere under there is someplace that malware could conceivably store a, uh, malicious binary to run on that system. Yeah. And depending on the nature of that binary, it could, uh, it, it, uh, it could cause administrative access, but it doesn't even need administrative access to establish that toll hold on that Windows client. Yeah. Um, but yeah, so it's, it's macros. It's those, uh, parent child processes.
It's, uh, for TA 5 51 is the password protected zip archives that contain word, uh, word documents or files that in, in dot dock as contained within those password protected zip archives. Yeah. If you see something that says request zip as an attachment to an email that looks like it's a reply, that's a, that's another re flag. Doesn't necessarily need to be blocked, but it needs to be looked into. Yep. So, um, I wanna talk for a minute about, um, security awareness training.
And a lot of MSPs now are, right, obviously there's a bunch of vendors and they're, they're implementing this phishing simulations. I wanted to get your opinion on how effective they are, um, just in general, what your take is on this. Uh, in general, my take is that they are, uh, they can be very effective. Uh, when I was working at Rackspace, uh, for example, at, at the, at a hosting provider in their security operations center for the corporate network, right?
So we're talking about employees of Rackspace, and, uh, I can say with, uh, with the conviction that their phishing training actually got people to notify us in the SOC whenever they received, uh, these suspicious emails that we may not have caught otherwise, right? So, uh, and then people would say, Hey, I got this through my Gmail account, is this malicious? And, uh, we can take a quick look and, uh, uh, say, uh, either yes it is, or no, it isn't.
Um, uh, my wife is, uh, I like to say is a good example of user training. I've got her somewhat paranoid. She's not the most technical person in the world, um, sometimes to the point where it kind of drives me a little, a little batty, uh, when she's asking me to say, you know, how do I do this? And, uh, I said, I explained that to you, you know, four separate occasions during the past year, but she doesn't use it, so she's not familiar with it.
So she's a good target audience for what I like to say is, uh, uh, security awareness training. And I've got her, um, uh, the one thing I never get annoyed at is when she says, Hey, I got this email. Can you take a look at it? And, uh, um, uh, it's about a 50 50 shot as to whether or not it's actually malicious or not, which in my book is a good result, right?
Because she's recognizing even the good stuff that looks suspicious, but not so much to where she would be like, bugging me for every, uh, little piece of just garden variety spam that comes through.
Uh, but my professional experience, Rackspace, uh, you know, being in an environment where as I was a member of the soc, we were getting notifications from people that were, uh, that had that security awareness training, and they were better able to spot these emails that we may or may not have caught, uh, in our soc. And from the, uh, personal perspective with my wife, who is now recognizing, uh, uh, stuff in a way that I am actually very pleased with, uh, as a security professional.
Is there anything else that you haven't hit on that you think should be part of every MSP's email security? Uh, some way to get across the idea that the internet is like building a multimillion dollar mansion in the worst part of town, because the internet is a great equalizer, and it puts not only that, uh, you know, the, the good people that you want, right within poking distance of you.
It also puts all the bad people, uh, that could possibly be on the internet within poking and touching distance of you. And, uh, so if you're gonna build that multimillion dollar mansion in this metaphorical, uh, bad neighborhood with tons of criminals and people walking by constantly chucking rocks at your windows and stuff, uh, you know, you better have some steel, metaphorical steel bars on those windows. You better have locks on your door. You better have an alarm system, right?
You cannot just assume that all the good stuff of the internet is, which is helping your business is the only thing about the internet. So I just say, you know, I just say your internet presence, your public facing servers, uh, your email addresses that are out there publicly, they are in an extremely bad neighborhood. Uh, uh, look at it that way. If there's some way in security training to kind of get that idea across, if, if that makes sense. Yeah, Absolutely.
Uh, so with the time we have left, I want it, Wes, I wanted to send things over to you. Cool, Gary, thank you. And, um, No, we do. Can you hear me? Yeah. Okay. And Brad, heartfelt thank you for joining us today before you joined last week, when Andrew was able to secure you for this.
Um, man, I got kind of excited because I didn't know you, but I've known all about you because we use malware traffic analysis all the time in our QA processes, and, uh, it's a privilege to have you on today, and thank you for what you do. You know, you are the epitome of exactly what we look for in the security industry, somebody that's providing the community all kinds of rich data and makes the world a better place.
So, just wanted to say thank you to you, to Palo Alto, unit 42, um, for what you guys are doing. Um, let me just start with this. I want to go a little different from where we've been going in the conversation. You know, we've talked about adversary simulation just a little recently on the cyber call and introducing that concept to MSPs. What are your thoughts on it?
Do you think MSPs that are small and, and midsize that typically have 40 to 60 employees or somewhere around there and, you know, a hundred clients, you, can they, can they get involved in that? Or is there ways that they can sort of mimic some of the best practices from adversary simulation in their own defenses? What you think? Uh, that's a good question because, uh, realistically you need some sort of expertise, right?
Whether it's, uh, you know, uh, a a professionally educated, uh, fully certified, uh, uh, person that's, uh, uh, uh, part of the MSP environment, or somebody who is taking the reins and finds that stuff interesting.
You have to have, even in a small MSPI say, you have to have, you should have, uh, from a security standpoint, at least one person in that small MSP that is interested and has, uh, uh, some, uh, uh, capability or, uh, uh, reach and, uh, most of all interest and passion in it, uh, in order to be able to, uh, do anything with that.
So realistically, you know, and they're the ones that are going to go through and, uh, start to kind of gently poking and prodding and seeing, you know, where the weak points are, and they're the ones that, uh, that may do it. Now, if you've got the money, if you've got the resources, uh, sure hire that security person. But if you don't have that, you still need that role, whether it's formal or informal.
Um, if it's informal, you're, you're kind of taking a big risk because that person wants to get, uh, some skills under their belt. They'll probably, uh, move on to bigger and better opportunities, because security is a very, um, uh, uh, it's one of those fields where the supply, uh, the demand far outstrips the supply. So, uh, that's really the, uh, the only problem that you're talking about.
Whether it's an MSP of whatever size or any organization that needs, uh, uh, security to, uh, protect its assets. Um, you have to have a function within your organization to focus on security. If you don't have that with the internet being a bad neighborhood and all you're, uh, you're playing with fire it Personally, very much agree. Very much agree. And one of the things I want to say, oh, I've gotten some feedback. Let me, me, I don't know if that fixed it, fixed it.
Lemme just, these guys, I'm, didn't I noticed your camera over? I did wanna say, uh, so I thank you for saying that we Oh, you're fading out. Yeah, we're losing you. Wes, You, it looks like your mic is on mute right now. See? Can we unmute him Here? Lemme give it a shot, Ryan. You might be able to, Yeah, I can't do it. Ah, Oh, Wes. Oh, both, both of them. It looks like, it looks like we're both, uh, the only two. Uh, okay, Wes is, There we go. How about now? There we go. Hey, There we go.
Yeah, so wonderful hotel wifi I'm dealing with here. Um, I love that you said it because we've been saying this for quite a while on the cyber call now, Brad, that every MSP needs to have at least one person that, that has some ownership and understanding and expertise and commitment to security for the org. I mean, we just have to, so that, and it might end up being An expert, right, to start with, because that's Not only, It's not a matter of just paying people.
We can't really, not every M ms P can attract someone with all the skillset. So I think, you know, that's a really good point. I, I very much agree. Um, so let's, let's talk about this for a minute, Brad. We've mentioned like detection opportunities. You mentioned like, you know, certain user directories, like system 32 and temp directories is like detection capabilities. You've mentioned, you know, Microsoft Word doing odd things like talking to the registry.
What are some other detection capabilities that MSPs or really anybody should be looking for in terms of how malware typically classically likes to operate rate? Uh, realistically, uh, the, the stuff that I run across is, uh, my focus is on the Windows client. So pretty much what I told you is, uh, pretty much the, the types of things I look for, um, really also, I should say, updates, the Windows registry that, uh, uh, that are unusual, right? Anything, uh, in the, uh, what is it?
The, uh, HKCU, let's see, I got a, I gotta double check here. Uh, red edits, right? So if you go on your registry editor and you go, uh, to the hq, current user software, Microsoft Windows current version run, right? If there's, uh, uh, anything that's in that folder, uh, that's not approved by your organization, uh, you know, that's a big red flag right there. Any scheduled task, right? Any scheduled task that pops up that's not, you know, like Adobe update or Microsoft Edge updating.
There are certain things that are in there, anything that looks outta place. And, uh, usually you can see these things because they'll sometimes try and mimic, uh, words and phrases, uh, that seem like they might be legitimate, but they, to me, they stick out like a sore thumb. And then finally in the, uh, uh, window start menu, program menu, the startup folder, sometimes you'll see a shortcut dropped in there, right?
And that shortcut will, uh, will, uh, you know, it, it will pull something up like either a Windows executable file or, you know, run DLL 32, um, for a, uh, particular file that's stored in some odd, unusual place. Um, realistically, you know, under that program data folder under that c uh, uh, users, uh, username folder, uh, anywhere under those two branches, uh, or public, uh, you can, you find unusually named, uh, folders that don't seem like they should be there.
Those things are, uh, artifacts, uh, that I commonly see from Windows-based malware infections, uh, those types of, you know, all track what I term commodity malware, which is stuff that hits everybody, right? You're not gonna see it targeting specifically any one, uh, group or people or person. It's generally gonna be sent out to anybody they can get their hands on.
So if you're looking at that stuff, stuff that MSPs would, uh, likely encounter on a day-to-day basis, whether or not it's caught by the spam filters or not, um, that sort of thing. Those sort of artifacts is stuff, uh, you know, that you can look for. I love it. Thank you. Maybe my, my final question question, Matt, feedback is still here, let me just do this. Okay. I've got way down.
So maybe my final question for you, Brad, um, in, in sake of time is you kind of like spoil us a little bit when it comes to malware traffic analysis. We love in, in the CRU at, at perch to, um, grab your P caps and TCP replay them, and they're so clean and precise and perfect. Uh, you know, and it's fun to see what detections come about.
And sometimes we'll see some very interesting detections that come back from the TCP replay, but I have to imagine a lot of real infections are not so clean and clear. Probably things like encrypted outbound traffic. I don't think a lot of MSPs do decryption.
Um, you know, can you talk to us a little bit about, you know, while your, your captures are very clean and perfect, what's the real world look like for most defenders when we would typically see an infection leading to whatever your Pcap would produce like in the real world? I hope that makes sense. Uh, uh, perfectly.
I mean, uh, uh, my goodness, it, the stuff, you're right, the stuff that I, uh, post I'm trying to cut down on, and this is just Windows 10, I'm trying to cut down on any, uh, just species traffic, and you still get a lot of that stuff. Now, add to that a person that's on the web looking up stuff in the course of doing their job. So you've got hundreds of thousands of URLs and IP addresses and domains that are popping up in that traffic.
If you get an alert and it's like, okay, well I'm gonna pull a five to 10 minute window of when that alert began and stopped to see if I can find something, you're digging through a haystack, right? And, uh, uh, you know, that's why some sort of intrusion detection is, uh, is, uh, uh, critical in order to be able to catch this sort of stuff that we're talking about.
And even then, when we're talking about something like Cobalt Strike and other malicious related H-T-T-P-S traffic or encrypted traffic, you know, odds are you're not gonna see it because you're not gonna have the HT TPS decryption or the TLS or SSL decryption that you would need, right? That's, that's still in this day and age a, uh, luxury as opposed to, uh, something that people think, uh, critical and necessary.
Even in my lab environment, I don't, uh, you know, I don't have a setup to where I can decrypt, uh, H-D-T-P-S traffic. I have to, I have to work around it, right? Because I don't have a quick and easy way to do it, uh, or, or a, uh, technically feasible way that I can do it, uh, yet. So who knows, you know, in the next few years, maybe we can, uh, um, you know, it, it's, uh, you know, whether it's my employer or any security vendor, uh, HT TPS description is an addition, right?
It's not part of a base package. Uh, and it's definitely not free. So, uh, but that's the state of the industry right now.
So basically you're having to, um, somehow have a repository of information that's security related that is shows, uh, suspicious domains that are coming up because these domains and that H-T-T-P-S traffic, even if they're using something like Lessen Crypt as a certificate authority for their, uh, traffic that may ping alert on, hey, they're using Lessen crypt, but plenty of valid, uh, sites used, lets and Crypt. So that's a, that's like an informational tag.
It's not anything, uh, uh, and it could very well be malicious because criminals use that. Um, self-signed certificates. Yeah, that's definitely, uh, something you want to keep an eye out for.
But, uh, uh, so if you've got detection, um, you know, as an MS uh, p, if you've got detection where you can detect self-signed certificates, 'cause they won't work in web browsers, but they very well will work when malware is using a self-signed certificate on a website to establish that H-D-T-P-S or TLS or SSL uh, channel.
So, uh, yeah, that's another thing I forgot to mention before, self-signed certificates, any unusual certificate data, uh, that you're seeing for the issuer, uh, for a certificate used in H-D-D-P-S-T-L-S-S-S, all traffic. Um, but, uh, uh, realistically I would have to say, you know, and this is where you have that, uh, uh, dedicated security function, and I think we're kinda running close on time here.
I don't want spend much more time, but to have that information repository, whether it's a MISP or something like Jira or something where you can collect data on weird or suspicious or malicious stuff you've seen in your network and have that for people to look at and reference unique to your networks. Yeah. So let's do some calls to action one. Brad has an awesome blog. Uh, and Brad, if you want to put, drop the link in the chat, drop it in there.
Now follow that blog, you're gonna get a daily dose of, uh, of threatened intelligence, um, which will be amazing. Stans diary. It's where I found this. That's how Brad ultimately came to us, follow the Sands Diaries on a daily basis. Um, spend some time in the Mitre attack threat framework, looking at TA 5 51, working through LEC ice, id, bizarre loader, trick bot, cobalt strike, learning those things.
And then working your way back to the ransomware families, you are gonna learn a lot about, uh, hardening of your servers. And as Felicia said, a lot of things you can do without buying additional tools, which is really what we like to hear. We don't wanna hit to buy new stuff to secure your environment. There are a lot of things you can do with the base tools that already exist. Um, and then Wes, I don't want wanted to give you the, the closing word.
Anything from PERCH and CRU with regard to TA 5 51 or indicators or threats that you wanna share. He might have his volume down still. I don't know. Yeah, he has his volume down. He can't, okay. So, um, yeah, we'll maybe we'll hit that on the next call, but Gary, any parting thoughts? You're muted. I was gonna say, uh, tell rest to white, uh, write it down and hold it up on a sign is an, is an answer. No, just interesting. And listen, we have different people on, we covered different topics.
Um, but it always seems Ryan to end up, like some of this is more sophisticated, but a lot of it is some things that everybody can be doing. And, and, and that seems to be the common theme, right? Uh, through this, uh, on a weekly basis as we have people here are talking about different threats, vectors, it's, it's, it's the common thread Okay. Awesome. Thanks so much for joining us for episode 62, uh, and we look forward to seeing you again next week. Have a great one, folks. Thanks, Brad.
Thank you, Brad.


