Healthcare was the most targeted industry vertical by attackers in the second quarter this year, followed by manufacturing and public administration, a just-released report found.

Healthcare accounted for 17 percent of all engagements, with manufacturing and public administration following at 14 percent each, according to the Cisco Talos Incident Response Quarterly Trends report.

A shared characteristic of these top-targeted sectors is a critical lack of downtime tolerance, researchers said in the report. The vast majority of targeted healthcare organizations were entities that directly support clinical operations and/or diagnostic services, where service interruption can result in operational and patient-care consequences.

Additionally, almost all targeted public administration organizations were local governments, which provide essential public services, while the targeted manufacturing entities represented high-value targets within the industrial supply chain, where potential disruptions could create cascading effects across the downstream technology and energy sectors.

When it comes to attacks leading to incidents, phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response engagements. That was an increase from a third of engagements last quarter, according to the report.

Schneider Bold
Delivery Methods

Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms.

Talos also saw a spike in authentication abuse this quarter – observed in 65 percent of engagements compared to 35 percent last quarter – with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods.

Ransomware incidents made up over 20 percent of engagements this quarter, similar to just under 20 percent last quarter. Talos incident response responded to Sinobi ransomware for the first time, as well as previously seen variants Nitrogen and Warlock.

To that end, ransomware operators leveraged legitimate remote monitoring and management (RMM) tools, such as trojanized MeshAgent binary and Zoho Assist, for stealthy access, requiring defenders to prioritize behavior-based monitoring and strict control over administrative binaries.

Q2 incident report

Attackers targeted healthcare the most in Q2, followed by manufacturing and public administration.
Source: Cisco Talos

Trends

In the latest Talos Threat Perspective episode, we explore these trends, and highlight where defenders have the best opportunities to detect attackers:

Starting in April, we observed a persistent QR code phishing campaign targeting primarily Australian organizations that leverages compromised Microsoft 365 accounts to harvest credentials and propagate the attack via internal contact lists.

Phishing-as-a-service (PhaaS) operator platform, ARToken, in an engagement this quarter that closely linked to the EvilTokens platform, Talos said. The ARToken panel exposes 80+ API endpoints for device code phishing, primary refresh token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration – all accessible to operators through a React-based dashboard, researchers said. Our investigation into the platform found phishing lures that impersonate trusted vendors and abuse legitimate Microsoft services, allowing attackers to bypass MFA through the OAuth device authorization flow rather than stealing passwords.

Ransomware and pre-ransomware incidents made up over 20 percent of engagements this quarter, relatively similar to just under 20 percent last quarter.

As mentioned, Talos incident response responded to Sinobi ransomware for the first time, as well as previously seen variants Nitrogen and Warlock. Operators from these groups leveraged tools not previously identified in public reporting, including a trojanized MeshAgent binary and Zoho Assist for remote access.

Talos said it observed threat actors using a trojanized MeshAgent binary as their primary C2 mechanism during this engagement, a tactic not been previously associated with the group in public reporting.

Weaponizing Legit Software

MeshAgent is the open-source agent component of the MeshCentral remote management platform. Here, the actor weaponized it into a covert durable backdoor installed as a SYSTEM-level auto-start service, communicating over encrypted WebSocket (WSS) to an attacker-controlled server, according to the report.

This approach allowed the actor to blend malicious traffic with legitimate remote management activity and maintain undetected access for approximately three days before ransomware deployment, the report said.

Following C2 establishment, the actor moved laterally through the network using RDP and WinRM, leveraging a service account with a weak, easily cracked password obtained from the domain credential store, ntds.dit.

The attacker ultimately deployed the ransomware across the entire domain using a malicious Group Policy Object (GPO) logon script. The incident resulted in the encryption of systems with the .SINOBI file extension, alongside observed data exfiltration staging activity conducted via rclone.exe.

Click here for more on the Cisco Talos Incident Response Quarterly Trends report.

ISSSource

Pin It on Pinterest

Share This