SAP Exploits Used in Active Cyberattack Causing Widespread Infections

Exploits are being used against software-solutions giant SAP in an ongoing cyberattack, causing major disruption in the companies products and services, which could lead to unsecured applications. Hackers are carrying out a coordinated number of attacks on systems, according to a joint report by SAP and security researchers at Onapsis. Some of these attacks include the theft of sensitive data, financial fraud, disruption of mission-critical infrastructure, and the deployment of malware such as ransomware.

SAP is a German multinational corporation based in Baden-Württemberg that develops enterprise software to manage business operations and customer relations. The company is especially known for its enterprise resource planning (ERP) software, customer relationship management (CRM) software, and supply-chain management. SAP is the largest non-American software company by revenue as well as the world’s third-largest publicly-traded software company by revenue.

In their report, SAP noted that the attacks using the exploits could have far-reaching consequences.

“These are the applications that 92 percent of the Forbes Global 2000 have standardized on SAP to power their operations and fuel the global economy,” the alert noted. “With more than 400,000 organizations using SAP, 77 percent of the world’s transactional revenue touches an SAP system. These organizations include the vast majority of pharmaceutical, critical infrastructure and utility companies, food distributors, defense and many more.”

Government agencies should be especially wary of the exploits.

“SAP systems are a prominent attack vector for bad actors,” Kevin Dunne, president at Pathlock stated. “Most federal agencies are running on SAP, as it has become the industry standard for government entities. However, these SAP implementations are often on-premise, and managed by the government entities themselves due to security concerns. These systems then become increasingly vulnerable when updates and patches are not applied in a timely fashion, leaving them wide open for interested hackers.”

Exploits Used in the SAP Cyberattack

The hackers are brute-forcing high-privilege SAP user accounts, as well as exploiting known bugs, including CVE-2020-6287, CVE-2020-6207, CVE-2018-2380, CVE-2016-9563, CVE-2016-3976, and CVE-2010-5326.

Though their identity is not known, Onapsis has stated the hackers are “advanced threat actors,”, given how quickly they’ve been able to develop attacks based on the exploits.

There is “conclusive evidence that cyberattackers are actively targeting and exploiting unsecured SAP applications, through a varied set of techniques, tools and procedures and clear indications of sophisticated knowledge of mission-critical applications,” the alert reads. “The window for defenders is significantly smaller than previously thought, with examples of SAP vulnerabilities being weaponized in less than 72 hours since the release of patches, and new unprotected SAP applications provisioned in cloud (IaaS) environments being discovered and compromised in less than three hours.”

Timeline from Onapsis

The most notable issues are as follows:

CVE-2020-6287 – This exploit is highly critical. It is remotely exploitable, and exploitable through HTTP(s) protocols. No privileges are required (pre-auth) to exploit the vulnerability. CVE-2020-6287 allows for creation of high-privileged application-level SAP users. Because of these characteristics, CISA released an alert on the same day the patch was released. Onapsis was able to record consistent active scanning as well as exploitation (333 instances, coming from 74 distinct IP addresses) for the RECON vulnerability since the public release of the patch and exploits. This activity has increased over time and continues today. Of all exploits, this is the most serious.

CVE-2020-6207 – This exploit affects SAP Solution Manager (SolMan), a central component of every SAP installation. Solution Manager is the equivalent of Microsoft Active Directory for Windows-based platforms: if an organization’s Solution Manager is compromised, an attacker would have complete administrative control over all interconnected SAP applications in the environment.

CVE-2018-2380 – If the SAP application is not properly patched, this vulnerability can be used to escalate privileges and execute OS Commands, eventually accessing the underlying database and moving laterally across other servers. Onapsis researchers identified 34 exploitation attempts sourced from 10 distinct IPs with the intent to execute OS commands in the underlying operating system.

CVE-2016-9563 – This is an exploit affecting the BC-BMT-BPM-DSK component of SAP NetWeaver AS JAVA 7.5 exploitable by remote (low privileged) authenticated attackers. A successful exploit of this vulnerability could result in Denial-of-Service (DoS) type attacks through XML Entity expansion or similar methodology, resulting in loss of availability. Furthermore, this exploit could allow an attacker to gain unauthorized access, resulting in a loss of confidentiality.

CVE-2016-3976 – This vulnerability allows remote attackers to read arbitrary files via directory traversal sequences, resulting in unauthorized disclosure of information. This vulnerability may also allow for arbitrary access to OS resources potentially leading to a privilege escalation situation.

CVE-2010-5326 – This is a critical vulnerability that affected many unsecured SAP applications. By leveraging this vulnerability, threat actors can execute OS commands without authentication and access the application as well as the application’s database, effectively gaining full and unaudited control of the SAP business information and processes.

After initial access, Onapsis observed threat actors using the exploits to establish persistence, for privilege escalation, evasion and, ultimately, complete control of SAP systems, including financial, human capital management and supply-chain applications.

“Additionally, attempts at chaining vulnerabilities to achieve privilege escalation for OS-level access were observed, expanding potential impact beyond SAP systems and applications,” according to the analysis.

The exploits in their assigned groups

According to the report, on a number of occasions, threat actors were observed combining exploits from Group 1 and Group 2 to achieve access to the SAP application and to gain access to the operating system. Additionally, exploits in Group 4 were seen in combination with an initial access that could be obtained through exploits in Group 1 (Application Level access) or Group 3 (OS Level access).

Exploit Chaining Analysis from Onapsis

Interestingly, the cyberattackers in some cases are patching the exploited vulnerabilities after they’ve gained access to a victim’s environment, Onapsis said.

“This action illustrates the threat actors’ advanced domain knowledge of SAP applications, access to the manufacturer’s patches and their ability to reconfigure these systems,” according to the firm. “This technique is often used by threat actors to deploy backdoors on seemingly patched systems to maintain persistence or to evade detection.”

Protection

Against vulnerabilities like the SAP exploits, the first action in securing systems should always be to patch them. Unpatched systems are the root cause of many cyberattacks, especially against businesses.

Beyond patching, business owners should have proactive attitude with regards to cybersecurity, which includes using the best tools for the job. One of the these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

More_Eggs Trojan Spreads Among LinkedIn Job Seekers

Aback-door trojan is infecting hopeful job-seekers on LinkedIn through a spear-phishing campaign, according to a new report by eSentire. The phishing email will attempt to get the job-seeker to click a malicious .zip file, which is the first step in deploying the More_Eggs trojan onto their device. The malicious files are tailored and will have “position” at the end of the file name, which helps them appear legitimate.

“For example, if the LinkedIn member’s job is listed as ‘Senior Account Executive—International Freight,’ the malicious .ZIP file would be titled ‘Senior Account Executive—International Freight position’ (note the ‘position’ added to the end),” according to the eSentire report. “Upon opening the fake job offer, the victim unwittingly initiates the stealthy installation of the fileless backdoor, more_eggs.”

As a back-door Trojan, More_Eggs allows hackers to access a user’s system from a remote location. This includes sending and receiving files and so can function as a malware loader for other virus strains.

While many groups have been found to use More_Eggs, it is developed by The Golden Chickens threat group. The group sells the trojan under a Malware-as-as-Service (MaaS) subscription.

Researchers at eSentire have noted 3 aspects of More_Eggs that makes it a “formidable threat to business and business professionals.”

Firstly, the trojan bypasses most antivirus defenses by abusing Windows processes. Secondly, it uses personalized spear-phishing to increase its chance of success. Lastly, more_eggs has been deployed at a time when job hunters are desperate to find work in the midst of a global pandemic.

The motivation behind the attacks are not yet known. There is little to gain from the devices on individuals who are unemployed; their devices are not connected to any corporate network. Some researchers have pointed out the attacks may lay dormant, and could activate at a point at the future when the victim does have access to business systems through the infected device.

In the report, eSentire follows the more_eggs LinkedIn attack on someone in the health care technology sector. Chris Hazelton with mobile security provider Lookout statedthat the victim that said was likely chosen so that cybercriminals could gain “access to an organization’s cloud infrastructure, with a potential goal of exfiltrating sensitive data related to intellectual property or even infrastructure-controlling medical devices. He added, “Connected devices, particularly medical devices, could be a treasure trove for cybercriminals.”

Morales added that to avoid compromise, all users on LinkedIn should be on the lookout for spear-phishing scams.

“Targeting LinkedIn is not rocket science,” he added. “It is social media for the corporate world with a description of the key players in every industry. I assume that I am a target too and always look for that.”

Potential Threat Actors Deploying More_Eggs Trojan

It is currently unknown which group is behind this campaign. It is unlikely to be The Golden Chickens themselves, as in the past, they have mostly been responsible for developing and selling the trojan. In their report, eSentire outlined 3 likely threat actor groups behind the campaign. These groups have used More_Eggs in the past, using the same methods as found in the current LinkedIn campaign.

FIN6 – FIN6 is a financial cybercrime group that primarily steals payment card data and sells it on underground marketplaces. The FIN6 group first gained notoriety in 2014 for their attacks against point-of-sale (POS) machines in retail outlets and hospitality companies. Continuing their quest for credit and debit card data, they later moved on to targeting e-Commerce companies and stole their credit card data via online skimming. The FIN6 threat group has also been known to infect some of their victims with ransomware.

Researchers reported in Feb. 2019 that FIN6 was specifically targeting numerous e-Commerce companies and using malicious documents to infect their targets with the more_eggs trojan as the initial phase of their attack.

Later that year, in August 2019, security researchers found that the FIN6 group began another malicious campaign. The researchers believe the FIN6 threat actors were actively going after multinational organizations. Similar to the current incident, FIN6 spearphished specific employees with fake job offers. If the targets fell for the lure, they too were infected with the more_eggs backdoor trojan.

Evilnum – The Evilnum cybercrime group is best known for compromising financial technology companies, companies that provide stock trading platforms and tools. Their target is financial information about the targeted FINTECH companies and their customers. They target items such as spreadsheets and documents with customer lists, investments, trading operations, and credentials for trading software/platforms and software.

The Evilnum group is also known to spearphish employees of the companies they are targeting and enclose malicious zip files. If executed, the employees get hit with the more_eggs backdoor trojan, along with other malware.

Cobalt Group – The Cobalt Group is also known to go after financial companies, and it has repeatedly used the more_eggs backdoor trojan in their attacks.

More_Eggs Trojan Analysis

The More_Eggs trojan are been analysed in depth by the IBM X-Force Incident Response and Intelligence Services (IRIS).

As mentioned, to gain access to victim environments, the threat actor began by targeting handpicked employees using LinkedIn messaging and email, advertising fake jobs to lure recipients into checking into the supposed offers. 

Once the attacker has established communication with a victim via email, they convince them to click on a Google Drive URL purporting to contain an attractive job advert. Once clicked, the URL displays the message, “Online preview is not available,” then presents a second URL leading to a compromised or rogue domain, where the victim can download the payload under the guise of a job description.

Link provided in spear phishing email to an employee

That URL, in turn, downloads a ZIP file containing a malicious Windows Script File (WSF) that initiates the infection routine of the More_Eggs backdoor trojan.

Final landing page that downloads a malicious file

The ZIP file and WSF files are deleted upon a successful malware infection, likely in an attempt to prevent researchers from recovering the original files from the filesystem. The filesystem, however, contains evidence of a non-malicious decoy document dropped to the disk drive during the spear phishing attacks.

The spear phishing attacks led to initial compromise and the installation of the More_eggs JScript backdoor, which established a reverse shell connection to the attacker’s command-and-control (C&C) infrastructure. Additional capabilities of the More_eggs malware include the download and execution of files and scripts and running commands using cmd[.][exe].

X-Force IRIS determined that the More_eggs backdoor later downloaded additional files, including a signed binary shellcode loader and a signed Dynamic Link Library (DLL), as described below, to create a reverse shell and connect to a remote host. The shellcode loader was observed on one infected device as updater.exe with the Metasploit-style service name APTYnDS1ABEuUHEA, indicating that it was installed as a service.

Once the attackers established a foothold on the network, they employed WMI and PowerShell techniques to perform network reconnaissance and move laterally within the environment. This type of method, called ‘living off the land’, can often blend with legitimate system administration activities, which can make it challenging for security controls to detect.

To cement their foothold and add persistence throughout the compromised environment, X-Force IRIS uncovered evidence that the attacker had selected several additional devices on which to install the More_eggs backdoor, creating redundancy in ways to get back into the network. Hackers remotely connected to these devices using PowerShell and WMI and downloaded and executed a DLL file, subsequently installing More_eggs on the device without dropping the nonmalicious decoy document.

After a successful phishing attack in which users have opened emails and browsed to malicious links, hackers install the More_eggs JScript backdoor on user devices alongside several other malware components.

The process begins with the consistent execution of a malicious DLL using the legitimate regsvr32[.][exe] Windows Utility. Once executed, the DLL is deleted from the system and its components are dropped to the system.

Protection

The more_eggs trojan is yet another attack vector being used by hackers to exploit people in need. As hackers step up their game, individuals and business owners need the right tools to defend themselves against ever-advancing threats. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

What Is A VPN?

Virtual Private Networks, or VPNs, are an essential tool to online life, and they don’t need to be a mystery. At SaferNet we specialize in making the complex simple; learn more at www.safernet.com

Why VPN is necessary?

A Virtual Private Network is required in today’s connected society because tools and methods to intercept your data have grown more sophisticated. Hackers, governments, and even your own Internet Service Provider have complete access to all your online activity, including transmission of sensitive passwords and identify details. Having this type of data in the wrong hands can lead to breached social media accounts, your job’s corporate system becoming exposed, compromised online bank accounts, and even identity theft.

IRS Warns of Phishing Campaign Targeting Colleges and Universities

Anew Phishing campaign has appeared which targets colleges and universities. The IRS has warned of scammers impersonating their service, who are targeting traditional educational institutions. The phishing attacks are carried out via email and attempt to lure the victims in with several methods, mostly through a tax refund promise. The campaign focuses on staff and students who are using a .edu email address.”The phishing emails appear to target university and college students from both public and private, profit and non-profit institutions,” the revenue service said.

The attacks were first noted by Abnormal Security in late March. Researchers noted that the campaign was sent to as many as 50,000 email inboxes. The subject messages usually appears as “Tax Refund Payment” or “Recalculation of your tax refund payment” to attract the targets’ attention. The email will also state that the victim is due to receive $1400.

Phishing
The Phishing Email Being Sent By The Scammers

Within the email is a link embedded in the text that reads ‘Claim your refund now.’ Clicking on the link will send the victim to the fraudulent IRS page and is prompted to fill out their information. Though many phishing web pages look suspicious, the fake IRS page, in this case, is high-fidelity.

Some of the information the victims is asked for includes:

  • Social Security number
  • First Name
  • Last Name
  • Date of Birth
  • Prior Year Annual Gross Income (AGI)
  • Driver’s License Number
  • Current Address
  • City
  • State/U.S. Territory
  • ZIP Code/Postal Code
  • Electronic Filing PIN

This impersonation is especially convincing as the attacker’s landing page is identical to the IRS website, including the popup alert that states, “THIS U.S. GOVERNMENT SYSTEM IS FOR AUTHORIZED USE ONLY,” a statement that also appears on the legitimate IRS website.

Phishing
The Fraudulent Webpage

The attacker also attempts to conceal the URL as to not alert the recipient that the url leads to a form hosted on an amazon domain. This was to obscure the landing page in an attempt to forge legitimacy.

One of the reasons why the campaign is successful is because it has been able to bypass Outlooks’ security features. This attack likely bypassed email gateways because the existing gateways only take threat examples from ongoing and current attacks that are in high volume. Phishing attempts that utilize social engineering are much lower in volume, target specific persons, and are able to be hosted on domains that can be quickly taken down. Hackers often utilize this form of entry to bypass email security.

The IRS advises university staff and students who received one of these phishing emails not to click on any of the links embedded within and forward the emails (as file attachments) to [email protected]. They should also get an Identity Protection PIN ASAP to block identity thieves from filing fraudulent tax returns in their names using stolen personal information.

Phishing and Identity Theft

The IRS have long been impersonated by scammers and hackers in phishing campaigns. The goal of these campaigns is to sell victims data online, which will go on to be used in identity theft.

As recently as a November, there was another IRS phishing campaign. Hackers sent phishing emails to trick potential victims, stating that they had outstanding charges related to missed or late payments.

The attack targeted Outlook users, and was sent to over 70,000 inboxes.

To intimidate and send their victims into panic mode, the scammers resorted to legal threats and even add the possibility of an eventual arrest right from the start of the emails whose titles include a “warrant for your arrest” warning.

For added effect, the recipients were also told that the emails would also be forwarded to their employer so that their made-up outstanding amounts will be legally withheld out of their wages.

“We have sent you this warning notification about legal proceedings in May 2019. But you failed to respond on time,” the messages said. “This time, if you fail to respond then we will register this case in court. Consider this as a Final Warning.”

Protection Against Phishing Attacks

When Phishing attacks can bypass outlook security, it is important to have additional tools to combat fraudulent emails. One of these tools is SaferNet. Even if an email makes it through inbox security, SaferNet will kick in when a victim clicks a link, protecting the target from viewing and interacting with the page.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Supply Chain Attacks on The Rise As PHP Infiltrated With Backdoor Malware

Malware has plagued the supply chain during the pandemic, providing an easy route for hackers to infiltrate systems relying on third-party applications and services. A new attack has been reported this week – on Sunday last; the PHP project announced that hackers gained access to its primary Git server. They proceeded to upload two malicious commits, including a backdoor. Luckily, the commits were discovered before being sent to production.

PHP is a general-purpose scripting language especially suited to web development. It is extremely popular and a powerful tool for making dynamic and interactive Web pages. PHP can be embedded into HTML, which can make a PHP-driven attack particularly dangerous.

The attacks were pushed to the php-src (source) repository, meaning the hackers could pull off a supply chain attack if developers picked up the code, believing it to be legitimate.

Both pushes, which be viewed here, claimed to be ‘fixing a typo’ within the code. The pushes were made using the accounts of PHPs founders, Rasmus Lerdorf and Nikita Popov. This gave the push an air of credibility, as it appeared to come from trusted sources.

In a statement, Popov explained, “We don’t yet know how exactly this happened, but everything points towards a compromise of the

git.php.net server (rather than a compromise of an individual git account).”

Popov went on to explain that PHP would be moving its servers to GitHub, hoping for added security.

“While investigation is still underway, we have decided that maintaining our own git infrastructure is an unnecessary security risk, and that we will discontinue the git.php.net server. Instead, the repositories on GitHub, which were previously only mirrors, will become canonical. This means that changes should be pushed directly to GitHub rather than to git.php.net.”

Popov also explained they would review their entire repository, searching for any corruption or traces of Malware.

Craig Young principal security researcher at Tripwire said regarding the attack, “Had it not been detected, the code could have ultimately poisoned the binary package repositories which countless organizations rely upon and trust. Open-source projects which are self-hosting their code repositories may be at increased risk of this type of supply chain attack and must have robust processes in place to detect and reject suspicious commits”

Malware Attacks On The Supply Chain

Malware

As business relies more on third-services, the digital supply chain has placed a target on its back for hackers with malware. While a business or industry may employ tight cybersecurity practices, a supply chain malware attack can mean targeting the weakest link and finding a foothold into a secured business. These sorts of attacks have been rife in the last 12 months, most notably the SolarWinds attack, which SaferNet covered previously.

Weaponizing code dependencies, like with PHP, is a relatively new attack vector. Last year, researchers spotted malicious packages targeting internal applications for Amazon, Lyft, Slack and Zillow (among others) inside the npm public code repository — all of which exfiltrated sensitive information. The packages weaponized a proof-of-concept (PoC) code dependency-confusion exploit that was recently devised by security researcher Alex Birsan to inject rogue code into developer projects.

In December, RubyGems, an open-source package repository and manager for the Ruby web programming language, took two of its software packages offline after they were found to be laced with malware.

And in January, three malicious software packages were published to npm, masquerading as legitimate by using brandjacking. Any applications corrupted by the code could steal tokens and other information from Discord users, researchers said.

Previous to the pandemic, one of the most infamous malware supply chain attacks occurred in 2017, which was attributed to Russia. The NotPetya malware compromised Ukrainian accounting software as part of an attack designed to target the country’s infrastructure, but the malware spread quickly to other countries. NotPetya wound up doing more than $10 billion in damage and disrupted operations for multinational corporations such as Maersk, FedEx, and Merck.

Supply chain attacks are attractive to hackers because when commonly used software is compromised, the attackers could potentially gain access to all the enterprises that use that software.

Protection

safernet

As cyberattacks evolve and become more frequent, it’s important that homes and businesses have the right tools to combat the threats they’re facing. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Latest Mirai Botnet Update Targets Routers and New IoT Devices

The Mirai Botnet has found itself back in the headlines after a barrage of new attacks using updated modules against D-Link, Netgear, and Sonic Wall devices and routers. The new updates bring with its abilities to target flaws never seen before in Internet-of-Things (IoT) devices. Since late February, groups using Mirai have been targeting six known vulnerabilities and three previously unknown ones. These exploits include:

  • VisualDoor – a SonicWall SSL-VPN remote command injection vulnerability that came to light earlier this January
  • CVE-2020-25506 – a D-Link DNS-320 firewall remote code execution (RCE) vulnerability
  • CVE-2021-27561 and CVE-2021-27562 – Two vulnerabilities in Yealink Device Management that allow an unauthenticated attacker to run arbitrary commands on the server with root privileges
  • CVE-2021-22502 – an RCE flaw in Micro Focus Operation Bridge Reporter (OBR), affecting version 10.40
  • CVE-2019-19356 – a Netis WF2419 wireless router RCE exploit, and
  • CVE-2020-26919 – a Netgear ProSAFE Plus RCE vulnerability

The three previously undisclosed command injection vulnerabilities were deployed against unknown targets, one of which, according to the researchers, has been observed in conjunction with a separate botnet by the name of MooBot.

Mirais longevity in the cybercrime community owes to the fact that its source code was publicly released in 2016, leading to slew of variants and updates since then. Its’ shifting nature has made it difficult to keep tabs on.

For the known vulnerabilities Mirai targeted, all have been patched. The only devices it is known to be affecting at current are devices without the latest updates. The unknown vulnerabilities are believed to be tied to IoT devices, a target group that Mirai has always gone after in its lifetime.

“We cannot say with certainty what the targeted devices are for the unidentified exploits,” Zhibin Zhang, principal researcher for Unit 42 stated, “However, based off of the other known exploits in the samples, as well as the nature of exploits historically selected to be incorporated with Mirai, it is highly probable they target IoT devices.”

mirai
Mirai port scanning in February, observed by Unit 42

The exploits themselves include two RCE attacks — including an exploit targeting a command-injection vulnerability in certain components; an exploit targeting the Common Gateway Interface (CGI) login script (stemming from a key parameter not being properly sanitized). The third exploit targets the op_type parameter, which is not properly sanitized leading to a command injection, said researchers.

The latter has “been observed in the past being used by the Moobot botnet, however, the exact target is unknown,” researchers noted

Mirai: A Storied Botnet

mirai

The Mirai Botnet has been around for several years. While other malware may go into periods of slow activity, Mirai has remained at the forefront of botnet headlines since its inception.

Perhaps Mirai’s most infamous attack came on October 12, 2016. On that date, a massive denial of service (DDoS) attack left much of the internet inaccessible on the U.S. east coast. The attack, which authorities initially feared was the work of a hostile nation-state, was in fact the work of the Mirai botnet.

This attack, which initially had much less grand ambitions grew more powerful than its creators ever dreamed possible. The origins of the botnet were speculated for some time, many believing it to be the work of high-profile cybercriminals. Instead, Mirai was created by a group of three friends who were using the botnet to run an extortion ring on Minecraft servers, a video game they played together.

It encapsulated some clever techniques, including the list of hardcoded passwords. But, in the words of an FBI agent who investigated the attacks, “These kids are super smart, but they didn’t do anything high level—they just had a good idea.”

Much more damaging than simply developing the botnet, the creators released the source code publicly in 2016. This has lead to a wild fire of Mira-related attacks, and researchers estimate there are more than 60 variations of the botnet currently.

Mirai has a few key characteristics seen across all variations of it:

  • Mirai can launch both HTTP flood and network-level attacks
  • There are certain IP address ranges that Mirai is hard-wired to avoid, including those owned by GE, Hewlett-Packard, and the U.S. Department of Defense
  • Upon infecting a device, Mirai looks for other malware on that device and wipes it out, in order to claim the gadget as its own
  • Mirai’s code contains a few Russian-language strings. This was intended to be a red-herring on its origin, but still remains in variations

Protection

With evolving botnet tools like Mirai posing new threats every day, its important you use the tools required to protect your devices. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Opportunistic Hackers Swoop In On American Rescue Act To Deploy Banking Malware

Malware often makes its nest in crisis areas. Individuals looking for aid, financial or otherwise, are key targets for phishing lures put out by hackers. These crisis-focused campaigns can be lucrative but are often looked down upon even in the most radical black-hat hacking circles. Regardless of the ethics behind the behavior, the American Rescue Act has proved to be an opportunity too tempting to pass up for a group of hackers targeting individuals seeking financial aid via stimulus checks.

The act itself was recently signed into law and aims to give financial aid to Americans, especially those hit particularly hard by the economic downturn caused by the pandemic. The act sends Americans who earn under a certain threshold a stimulus amount of $1,400 each.

Hackers see a payday for themselves here, and since early March, one group has been involved in an email phishing campaign, purporting to be the IRS. The group uses the IRS logo and even spoofs the sender domain in a reasonably convincing manner. The email says, “It is possible to get aid from the federal government of your choice” and then offers “quotes” for too-good-to-be-true things – such as a $4,000 check, the ability to “skip the queue for vaccination” and free food.

Malware
Phishing Email Used In The Campaign

If the target clicks “Get apply form,” they’ll be taken to an Excel sheet which states, “Fill this form below to accept Federal State Aid.”. The catch here is that the user is told that they must enable content macros if they wish to see the document in its entirety. Doing this will enable macros that set off a chain that will deploy the Dridex banking trojan on their machine. Dridex is a veteran in the banking malware scene and will siphon any and all banking credentials off an infected machine without a user’s knowledge.

Phishing attack prevention researchers Confense have been investigating the campaign. “While static analysis easily identifies the URLs used to download malware in this case, automated behavioral analysis may have trouble recognizing the activity as malicious because it does not use macros to directly download malware or run a PowerShell script,” researchers explained, in a posting on Tuesday. “The macros used by the .XLSM files drop an .XSL file to disk, and then use a Windows Management Instrumentation (WMI) query to gather system information.”

WMI is a subsystem of PowerShell that gives admins access to system monitoring tools, including the ability to ask for information about anything that exists on a given computer – such as which files and applications are present. It can also request responses to these queries to be given in a certain format.

“The WMI query employed in this case…demands that the dropped .XSL file be used to format the response to the query,” researchers wrote. “This formatting directive allows JavaScript contained in the .XSL file to be executed via WMI and download malware, avoiding the more commonly seen methods via PowerShell.”

Dridex Malware Origins

Malware

Dridex is an older strain of malware, first being reported a decade ago in 2011. It also goes by the names Bugat and Cridex. Dridex is mostly commonly deployed via phishing emails, and it generally targets banking credentials.

Dridex’ gain in popularity was comparatively slow, but by 2015 it had become the worlds foremost financial trojan. Most often, Dridex campaign targeted corporate emails. This lead to later versions of the Malware being updated to include ransomware deploying capabilities. Furthermore, Dridex developed increased obfuscation techniques as corporate anti-virus grew more sophisticated.

The original developers of Dridex are believed to be a Russian cybercrime group named ‘Evil Corp.’ (No points for originality!). In December 2019, authorities cracked down on the group with sanctions and charges against its leader, Maksim Yakubets, known for his lavish lifestyle. U.S. authorities are still offering up to $5 million for information leading to his arrest; they allege that Yakubets and Evil Corp. have stolen millions of dollars from victims using the Dridex banking trojan and Zeus malware.

Prevention

As with all phishing campaigns, they key to prevention is education. When reading emails, look for errors and keep a suspicious eye. Be wary of “too good to be true” claims, and keep up to date on government plans on distributing aid like seen with the American Rescue Act.

Beyond education, there are tools that can protect your home and business against Malware attacks like Dridex. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Hacking On A Budget: WSH RAT Leads Way For Malware-As-A-Service

Malware has always been a threat in computing for nearly as long as computers have existed. Typically, the developers and spreaders of Malware would be skilled programmers and intellectuals who decided to use their talent for nefarious purposes. This high-entry threshold made it easier for cybersecurity companies. Talented hackers were fairly rare to come by, and so the number of major threats was once upon a time much lower than it is today.

The late ’90s and ’00s saw the genesis of Malware-as-a-Service (MaaS) with the appearance of Script Kiddies. A script kiddie was an individual, usually a juvenile; we would download hacking or malware scripts from websites and run them to carry out several attacks. These attacks were usually on the lower end of what malware is capable of.

The term is considered derogatory; Script kiddies usually only acted to impress others; they themselves were devoid of any meaningful skill with a computer.

However, this idea of being able to carry out a cyberattack without any skill took root in the community, and some business-savvy hackers saw an opportunity. In 2010, Chinese hackers released the IMDDOS service. At the time, IMDDOS was one of the largest botnets in the world. The hackers would charge customers a monthly service fee. After paying, a customer could sign in and choose to use parts of the botnet to carry out a DDOS attack on any target they wanted.

IMDDOS was extremely popular in the hacking community, and the service opened the floodgates. What Netflix did for streaming, IMDDOS did for MaaS. Like any other industries, different groups vied for control – Price wars occurred, monopolies were gained, disruptive new players entered the scene – Everything you’d expect from any new, popular industry.

One of the biggest to hold a monopoly was the H-Worm, also known as Houdini. Houdini appeared in 2013 as a Remote-Access-Trojan (RAT). A RAT allows the hacker to control nearly every aspect of a target machine using shell command execution, keyloggers, and spyware. The author of the Malware, also named Houdini, is based in Algeria. He is believed to be connected to another hacker, njq8, who developed njw0rm and njRAT/LV. The two share a common codebase – Sharing notes effectively.

The Houdini RAT was a popular Malware in the MaaS scene for many years, with many customers using it to carry out attacks globally. 2019 saw its successor, WSH RAT. WSH RAT uses mostly the same codebase as Houdini, though it executes via Javascript. This change makes its proliferation much more common.

MaaS is usually distributed on the Dark Web. Getting to distribution sites is one hurdle potential customers have to overcome, but it is not a particularly large one. This is another area WSH RAT does better than its competitors – It’s available on the front page of Google. This makes WSH RAT the most easily accessible piece of Malware available on the internet.

hsbc
Phishing Email Holding WSH RAT

WSH RATs’ first appearance in 2019 was a series of attack campaigns on banking customers. Victims would receive an email purporting to be a bank, with a zip attached. The zip would contain an .EXE, which, when run, would let WSH RAT take hold of the system. The banking campaign in 2019 stole thousands of credentials from victims, which were sold on the Dark Web by various groups who had bought WSH RAT.

WSH-RAT features many out-of-the-box features attractive to cybercriminals, including:

  • Password siphoning from the major browsers and email applications
  • Full Remote Control
  • File Download and Execution
  • Script Execution
  • CMD Execution
  • Keylogging

The service is helpful for criminals on a budget, starting at $25 a month.

packages
Feature and Price List From the WSH RAT website

WSH RAT has remained the go-to choice for hackers interested in Remote-Access attacks since 2019. Intrusion kits like WSH-RAT are continuously customized and wrapped by additional layers of multi-language code, most of the time unknown to the community. This can create issues for detection.

MaaS is the part of the underground cyber criminal that enables a wide range of attackers to leverage advanced capabilities to conduct intrusion operations and frauds, lowering the entry bar of cyber-crime and hacking. Though only being around a little longer than a decade, MaaS may well be the future of cyberthreats.

WSH RAT – Malware Analysis

malware

Researchers at cybersecurity company Yoroi have carried out extensive research on WSH RAT.

The initial infection chain is a RTF malicious document, which uses the MS-17-11882 exploit.

malware
Exploit MS17-11882

The equation editor’s shellcode downloads the second component of the infection chain from a previously compromised WordPress website. The file is a wrapper opportunely packed and with the only purpose to deploy the next stage, the entire Visual Basic Script of WSH-Rat. The contained packer is highly obfuscated to try to escape reverse engineering.

The core of WSH-RAT begins its head with the configuration. This is to allow threat actors re-code parts of WSH-RAT for their purpose.

malware
Config Settings

Deeper into the core is the Command and Control (C&C) mechanism – Allowing WSH RAT to communicate with the hacker and listen for commands.

malware
Retrieving the C&C info

After that, the bot retrieves the commands to execute from the C&C and it saves the inside the variable “cmd”. The command list is where WHS RAT can do most of its work.

Within the core of WSH RAT is also a payload launcher; allowing it to function as a carrier for other Malware.

Protection

Malware-as-a-Service is here to stay, and the future of cybersecurity means being able to protect against new threats on the horizon. Protecting your home or business means having the right tools for the job. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

REvil Ransomware Group Makes Moves Globally in 2021

Ransomware struck industries hard in 2020, and 2021 is shaping up to be no different. The REvil Ransomware group, which targeted several hospitals last year, has made a series of attacks last month. In the last two weeks alone, the group has hit 9 large organizations across Africa, Europe, Mexico, and the United States. Within the US, companies hit include law firms, an insurance firm, an architectural company, and an agricultural co-op. The Ransomware group is being tracked by cybersecurity researchers at eSentire.

REvil, also known as Sodinokibi or Sodin, was quiet for some years before resurfacing in 2019. The group behind the malware have hit several high-profile targets like Grubman Shire Meiselas & Sacks, Travelex and Brown-Forman Corp. REvil has also being reported on many hospital systems. Due to it being sold as Ransomware-as-a-Service (RaaS), it is frequently witnessed in infections.

The cybercriminals have posted much of the stolen data to Dark Web already. These include company computer file directories, partial customer lists, customer quotes, and copies of contracts. Researchers said they also posted what appears to be several official IDs, either belonging to an employee or a customer of the victim companies.

It is speculated a part of the gangs’ success has been in part due to their use of the Gootloader malware loader, which is designed to seed the virus. The loader has previously been seen to deploy REvil as well as the Gootkit Malware family. Beyond REvil, Gootloader has been reported as launching the Kronos Trojan and Cobalt Strike Malware. SaferNet reported on Gootloader and Gootkit in an article last week.

Researchers said they have seen REvil expanding its extortion tricks tactics and procedures (TTPs) to now contact victims’ business associates and the media, in order to put on the maximum amount of pressure on the victim to pay. They noted that in the last couple of days, the threat group also appears to be updating its website to make it easier to browse its victim list.

REvil SSN And Personal Records Breach

Ransomware

One of the larger attacks the REvil hackers took part in last month was a devastating attack on IT infrastructure and managed services firm Standley Systems. During the attack, the group managed to steal troves of personal information, including SSNs, service contracts, medical documents, personal data from Standley’s clients, and passports and licenses of Standley’s employees.

“Your customers have entrusted you with the most valuable thing – their backups and data for storage, but you have not coped with your task,” REvil wrote on its leak site. “Even after we provided you with the lost data, we did not hear a single word in response. Accordingly, you don’t give a damn about your customers … You are disrupting both your reputation and the reputation of people who have trusted you with their safety.”

The Standley Systems data was first posted to the REvil site on Feb. 15 and was then taken down from the site for some time before reappearing more recently. The information might have been taken down due to the start of negotiations between REvil and Standley and then reposted once talks between the two sides fell through.

The six Standley customers mentioned on REvils’ dark web site are natural gas producer Chaparral Energy, oil company Crawley Petroleum, injury evaluator Ellis Clinic, gas exploration company Everquest Energy Corporation, the Oklahoma Medical Board; and structural steel fabricator W&W Steel.

Generally, the Ransomware gang will first post a snippet of stolen data to a website; this is a tactic to ensure the company are frightened and become compliant. If the company is unmoved, the gang will auction the data.

REvil likes to go after data that can be used for identity theft or data that creates liability issues for clients of the victim organization. More than 1,300 companies lost intellectual property and other sensitive information last year after ransomware operators published their data to a leak site.

REvil Ransomware Analysis

Ransomware

Deployments of REvil first were observed a few years ago, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725. It is highly configurable, and it can be customized to behave differently depending on the host. This makes it a highly attractive RaaS client. Some of its features include:

  • Exploits a kernel privilege escalation vulnerability to gain SYSTEM privileges using CVE-2018-8453.
  • Whitelists files, folders and extensions from encryption.
  • Kills specific processes and services prior to encryption.
  • Encrypts files on local and network storage.
  • Customizes the name and body of the ransom note, and the contents of the background image.
  • Exfiltrates encrypted information on the infected host to remote controllers.
  • REvil uses Hypertext Transfer Protocol Secure (HTTPS) for communication with its controllers.

REvil was first advertised on Russian-language cybercrime forums. The main actor associated with advertising and promoting REvil ransomware is called Unknown aka UNKN. The RaaS is operated as an affiliate service, where affiliates spread the malware by acquiring victims and the REvil operators maintain the malware and payment infrastructure. Affiliates receive 60% to 70% of the ransom payment.

Unkown has acknowledged that his Ransomware is based on the now-retired GrandCrab Ransomware, saying, “We used to be affiliates of the GandCrab affiliate program. We bought the source code and started our own business. We developed custom features for our purposes”

Ransomware

REvil ransomware exploits a kernel privilege escalation vulnerability in win32k.sys tracked as CVE-2018-8453 to gain SYSTEM privileges on the infected host. If the configuration instructs a sample to execute this exploit, it will allocate executable memory, decrypt the exploit code in the newly allocated region and invoke it.

Protection Against Ransomware

REvil and other Ransomware clients are some of the most common and deadly cybersecurity threats out there today. Families and businesses should be aware of these threats, and equip the right tools to tackle them. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Obscure Programming Language Used to Deliver New Malware Loader Through Spear-Phishing Campaign

Malware developers use a variety of methods to avoid detection. An on-going campaign highlights one of these methods – Coding in an obscure programming language to bypass security defenses. Since February 3rd, threat actor TA800 has carried out a spear-phishing campaign to deliver their new Malware loader, NimzaLoader. NimzaLoader is programmed in Nim, an imperative, general-purpose language with syntax similar to Python. Nim is an uncommon language, meaning reverse-engineering NimzaLoader can be tricky, and security tools may be unable to analyze it.

TA800 has a long cybercrime history, and NimzaLoader seems to be a less-detectable version of a previous loader of theirs, BazaLoader. The campaign thus far has used highly-targeted spear-phishing and has claim 100 victim organizations across 40 industries.

The full extent of NimzaLoaders’ capabilities is not yet fully clear, but it has been reported as distributing Cobalt Strike. Cobalt Strike is a sophisticated Malware that has a host of tools at its hands, including keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement. It is sold as Malware-as-a-Service (MaaS).

Consistent with previous campaigns, TA800 uses personalized details in the email lure, including the recipients’ name and company name.

phishing

The message contains a link, often shortened or obscured, purporting to be a link to important business PDF documents. Following the link, the target will be brought to a landing page with a link to the PDF. The link is disguised with Adobe logos and is hosted on Slack.

Downloading the file will immediately deploy NimzaLoader to the users’ machine, though it is unlikely they will experience any immediate changes. Use of the Nim programming language means the Malware can slide past file-scanning programs effortlessly. Once on the machine, NimzaLoader will drop Cobalt Strike, and the damage will begin.

NimzaLoader Malware Analysis

phishing

Much of this analysis has been carried out by cybersecurity researchers at Proofpoint.

NimzaLoader was developed using the Nim programming language, which can be seen various ‘Nim’ related strings in the executable:

phishing

TA800 has been active in the cybercrime scene for a few years and is mostly known as affiliate distributors. Affiliate distributors rarely write their own Malware and use MaaS in their attacks.

TA800 has mostly been active in North America and has targeted a wide range of industries. Usually, they are known for distributing banking trojans and malware loaders. The group is also known for carrying out several spear-phishing attacks. The attacks always include some sense of urgency for the users to carry out instructions. Some of these lures have included hard-to-resist subjects such as payment, meetings, termination, bonuses, and complaints in the email’s subject line or body.

The hackers made headlines in late 2020 when they carried out a series of attacks on the healthcare sector using a malware loader named BazaLoader. When hospital systems became infected with Bazaloader, it dropped Ryuk as a payload. Ryuk is a notorious Ransomware we have covered in previous articles.

Protection

In many forms of cyberattacks, but especially those of a phishing nature, education and intuition are key to protection. Being able to discern a legitimate email and a phishing email is a skill that is the first line of defense. In small businesses, employees should receive regular cybersecurity training to learn the signs.

Beyond training, there are tools out there that can prevent attacks like phishing. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.