Energetic Bear APT Server Attacks
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Energetic Bear's goal appears to be the collection of Network LAN Manager (NTLM) credentials via SMB; with the first confirmed attacks reported in March 2017, although it is possible the campaign began before this date.
Targeted devices are initially compromised using the Goodor backdoor delivered via spear-phishing emails or watering hole attacks using previously compromised servers. Inveigh spoofed PowerShell scripts are then run to harvest NTLM hashes sent to the compromised device. The group can then crack these hashes to obtain network credentials.
Once Energetic Bear have access to the target network they will enumerate any drives they have write permissions to and place link files (.lnk). Any host that views these links will attempt to load a file from the compromised server, sending their NTLM hash in the process, which is then harvested.
For further information please see the NCSC advisory here.
Remediation advice
To prevent and detect infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:42 pm