Discover more from f33d by Prelude
TTP Tuesday: Ransomware (Release 3)
MacOS ransomware using custom tools
28 December 2021
Our current theme is ransomware, focusing on scenarios where threats use live off the land (LotL) binaries and custom payloads to accomplish their objectives. The ransomware theme will contain the following kill-chains:
MacOS Ransomware using Custom Tools (Current Release)
Windows Ransomware using Custom Tools
MacOS Ransomware using Custom Tools
This week’s kill chain focuses on a different approach to ransomware for Macs (and Linux in the future). Instead of relying on a typical “discover and encrypt” attack path, our custom chain delivers a (safe) attack that:
Discovers important files within a set directory (Downloads on a Mac).
Once the important directories are located, a custom payload drops on those directories and connects to a unique server (Spiderweb).
That connection exfiltrates each file found within those directories to the web server (Spiderweb).
Once exfiltrated, the contents of each of the files are replaced with a ransom note.
The purpose of this chain is to deliver a ransomware attack without using a traditional encryption method, therefore becoming harder to detect and presenting an alternative method to a current potential “blind spot” in defenses.
We have designed this chain with two paths, one safe and one destructive. The safe path (the default) will copy each file before wiping and apply the wipe to the copy only. Removing the safe flag will allow this attack to run in the wild, and will be destructive.
Check it out on the Prelude chains website.
Watch a demonstration:
Next week, we will be dropping our Windows ransomware using custom tooling.
Staying up to date
Please subscribe and reach out with any feedback. We love to hear from our community!
There are several ways to follow us and learn more about Prelude and our team members:
Get our products
Download Prelude Operator: https://www.prelude.org/download/current
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg
Join our community
Read, watch, and listen
Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org
Watch our live streams: https://www.twitch.tv/preludeorg
Watch our pre-recorded content: https://www.youtube.com/channel/UCZyx-PDZ_k7Vuzyqr4-qK9A