By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    Mobile beasts and where to find them — part one
    8 months ago
    What is Zero-Day Exploit?
    8 months ago
    How to Get Rid of a Virus on Phone? | Android and iPhone
    8 months ago
    Latest News
    Safeguards against firmware signed with stolen MSI keys
    1 day ago
    WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
    1 day ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
    6 days ago
    Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
    1 week ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    What’s included in the ‘Battle of Shadow and Light’ update for Halo 5: Guardians
    8 months ago
    How to fix printer spooler problems on Windows 10
    8 months ago
    How to fix error 0x80004005 starting VirtualBox VM on Windows 10
    8 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    4 months ago
    Now you can speed up any video in your browser
    4 months ago
    How to restore access to a file after EFS or view it on another computer?
    4 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    5 months ago
  • How To
    How ToShow More
    What is two-factor authentication | Kaspersky official blog
    2 days ago
    Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
    4 days ago
    NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
    4 days ago
    How Oxy uses hooks for maximum extensibility
    How Oxy uses hooks for maximum extensibility
    5 days ago
    The personal threat landscape: securing yourself smartly
    5 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    The dream of a designer and web developer
    8 months ago
    Google Drive Public File Search
    8 months ago
    Chrome Tab Preview
    8 months ago
    Latest News
    How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
    2 days ago
    How to enable Taskbar End Task option to close apps on Windows 11
    2 days ago
    How to check USB4 devices specs from Settings on Windows 11
    2 days ago
    How to enable new header UI for File Explorer on Windows 11
    1 week ago
  • Glossary
  • My Bookmarks
Reading: DarkVishnya attacks from inside
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Threats

DarkVishnya attacks from inside

Tom Grant
Last updated: 13 October
Tom Grant 8 months ago
Share
5 Min Read

Normally, we start investigating a cyberincident by looking for a source of infection. The source is not difficult to find — we look for an e-mail with a malware attachment or a malicious link, or for a hacked server. As a rule, security specialists have a list of equipment, so all you need to do is figure out which machine started the malicious activity. But what if all of your computers are clean — yet malicious activity is still occurring?

Contents
DevicesHow are they connected?What should you do?

Recently, our experts investigated precisely such a situation. What they found: the attackers physically connected their own equipment to the corporate network.

This style of attack, dubbed DarkVishnya, begins with a criminal bringing a device to a victim’s office and connecting it to the corporate network. Through that device, they can remotely explore company’s IT infrastructure, intercept passwords, read information from public folders, and much more.

The technical details of this attack can be found in this Securelist post. In this particular case, malefactors targeted several banks in Eastern Europe. However, the method has potential for use against any big company. The bigger the better; it is much simpler to hide a malicious device in a large office — and especially effective if a company has many offices around the world connected to one network.

Devices

Investigating this case, our experts encountered three types of devices. We do not yet know whether all of them were planted by one group, or if there were multiple actors, but all attacks used the same principle. The devices involved were:

  • A cheap laptop or netbook. Attackers do not need a flagship model; they can buy a used one, plug in a 3G modem and install a remote-control program. They then simply hide the device to evade notice and connect two cables — one to the network and another to a power supply.
  • A Raspberry Pi. A miniature computer that is powered over a USB connection, a Raspberry Pi is inexpensive and inconspicuous — easier to purchase and hide in an office than a laptop. It can be plugged into a computer, where it will be camouflaged between wires, or, for example, in a USB port on a TV in a lobby or waiting area.
  • A Bash Bunny. Intended for use as a tool for penetration testing, the Bash Bunny is freely sold on hacker forums. It does not need a dedicated network connection; it works through a computer’s USB port. On the one hand, that makes it easier to hide — it looks like a flash drive. On the other hand, device control technology can react to it immediately, making this option less likely to succeed.

How are they connected?

Even in companies where security issues are taken seriously, planting such a device is not impossible. Couriers, job seekers, and representatives of clients and partners are commonly allowed into offices, so malefactors can try to impersonate any of them.

An additional risk: Ethernet sockets are installed almost everywhere in offices — in corridors, meeting rooms, halls, and so forth. Look around the average business center and you’ll probably find somewhere to hide a small device connected to the network and to a power supply.

What should you do?

This attack has at least one weak spot — an attacker must come to the office and physically attach a device. Therefore, you should start by restricting access to the network from places accessible by outsiders.

  • Disconnect unused Ethernet outlets in public areas. If that is not possible, at least isolate them on a separate network segment.
  • Situate Ethernet sockets in view of security cameras (that could be a deterrent or will at least be helpful in case you need to investigate an incident).
  • Use a security solution with reliable device control technologies (for example, Kaspersky Endpoint Security for Business).
  • Consider using a specialized solution for monitoring anomalies and suspicious activity on the network (for example, Kaspersky Anti Targeted Attack Platform).

Source: kaspersky.com

Translate this article

TAGGED: Authentication, Malware, Port scanning, Security, Targeted Attack, Threats
Tom Grant October 13, 2022 October 7, 2022
Share this Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Safeguards against firmware signed with stolen MSI keys
Threats 1 day ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats 1 day ago
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
News 2 days ago
How to enable Taskbar End Task option to close apps on Windows 11
News 2 days ago
How to check USB4 devices specs from Settings on Windows 11
News 2 days ago

Recent Posts

  • Safeguards against firmware signed with stolen MSI keys
  • WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
  • How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
  • How to enable Taskbar End Task option to close apps on Windows 11
  • How to check USB4 devices specs from Settings on Windows 11

You Might Also Like

Threats

Safeguards against firmware signed with stolen MSI keys

1 day ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats

WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin

1 day ago
News

How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11

2 days ago
News

How to check USB4 devices specs from Settings on Windows 11

2 days ago
Show More

Related stories

How to Use Cloudflare to Secure Your WordPress Site
How To Starting Chrome from the command line
How to fix error 0x80070057 in Chrome?
Windows 10 How To Disable Slide to Shutdown
Windows search not working (FIX)
How to watch movies and TV series for free on Kinopoisk?
Previous Next

10 New Stories

What is two-factor authentication | Kaspersky official blog
Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
How Oxy uses hooks for maximum extensibility
The personal threat landscape: securing yourself smartly
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
Previous Next
Hot News
Safeguards against firmware signed with stolen MSI keys
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
How to enable Taskbar End Task option to close apps on Windows 11
How to check USB4 devices specs from Settings on Windows 11
10alert.com10alert.com
Follow US

© 10 Alert Network. All Rights Reserved.

  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?