Friday, February 3, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory
  • Login
  • Register
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
No Result
View All Result
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
No Result
View All Result
Cloud7 News
No Result
View All Result

Home > Cybersecurity > Details of Conti’s Costa Rica attack revealed

Details of Conti’s Costa Rica attack revealed

Cybersecurity researchers have published the details of the notorious Conti gang's attack targetting the Costa Rican government.


Erdem Yasar Erdem Yasar
July 22, 2022
3 min read
Details of Conti's Costa Rica attack revealed
  • Conti started its attack on the Costa Rican government on the 11th of April.
  • The initial attack vector was compromised credential access via VPN.
  • The president of Costa Rica declared a state of emergency and claimed that traitors helped hackers during the attacks.

The Conti ransomware group, emerged in 2020, gained significant notoriety with its successful attacks on Costa Rican government. It was also the group’s last attack before evolving into a new structure and starting working with other gangs. Before the Costa Rica attack, organizations from both the private and public sectors fell victim to its attacks.

5-day intrusion

Conti started its attack on the Costa Rica government on the 11th of April. The group used a system of Costa Rica’s Ministry of Finance as the entry point. A member, named MemberX, gained access by using a VPN connection and compromised credentials. According to the report published by AdvIntel, in the early stages of the attack, the group set up over 10 Cobalt Strike beacons. The initial attack vector for this operation was compromised credential access via VPN.

Name: Ministerio de Hacienda Costa Rica

Domain: hacienda.go.cr

Threat Actor Name: MemberX

Date(s): April 11, 2022

Timeline of Exploitation Operation: April 11, 2022 to April 15, 2022

According to the report, the group used the following methods:

  1. The infection followed a typical attack flow wherein the adversaries gained access from the compromised VPN log by installing a crypted form of Cobalt Strike inside the Costa Rica sub-network.
  2. The adversaries obtained local network domain administrator and enterprise administrator recon.
  3. The threat actors then performed network reconnaissance via Nltest domain trust enumeration, before scanning the network for file shares by leveraging the ShareFinder utility and AdFind from C:\ProgramData.
  4. The adversary (referenced by internal pseudonym “MemberX”) downloaded the fileshare output on their local machine via the Cobalt Strike channel.
  5. Then, the adversaries leveraged Cobalt Strike’s Mimikatz to dump logon passwords and NTDS hashes of the local machine users, obtaining plaintext and brute-forceable local admin, domain, and enterprise administrator hashes.
  6. The adversaries leveraged the enterprise user credentials to perform a DCSync and Zerologon attack. This effectively gained them access to every host on the Costa Rica interconnected networks.
  7. The adversaries then uploaded MSI scripts with Atera Remote Management Tool (RMM), the remote hosts selecting those with local admin access and less user activity. This established “anchoring” and safe return in case the threat actors’ beacons were burned or detected by the well-known EDR tool utilized by Costa Rica.
  8. The adversaries pinged the whole network and re-scanned the network domain trusts, leveraging enterprise administrator credentials with ShareFinder and compiling a list of all corporate assets and databases available under their new elevated privileges.
  9. On several network hosts, the adversaries also created a Rclone configuration file, which their data exfiltration tool leveraged as input with the MEGA Share uploader. They then began exfiltration from the network.
  10. The adversaries uploaded Process Hacker, Power Tools, and Do Not Sleep tools, and batch scripts filled in with the fileshare access locations.

The attacks caused Rodrigo Chaves Robles, the President of Costa Rica to declare a state of national emergency due to cyber attacks. He named them an act of terrorism and stated that the country was in a state of war, and that there was evidence that people were helping Conti from within Costa Rica. AdvIntel said,

« Given that the Costa Rican attacks were done partially as a form of symbolic closure for the Conti syndicate, this decision to stick with the toolkit that the group was renowned for feels intentional on the part of the threat actors, the anatomy of these hacks, as seen with the Ministry of Finance, was unmistakably in Conti’s signature attack style. 

The notability and recognizability in Conti’s attack style also ultimately contributed to the group’s downfall, however. As Conti honed their attack methodology to a high degree of proficiency, defense and security agencies began to catch on to distinctive Conti method of operations, and develop mitigations for them. This is a contributing factor to the rise of more adaptive and personalized tactics being utilized by Conti’s successors, such as social engineering and complex phishing schemes. »

See more Cybersecurity News


Tags: AdvIntel
Erdem Yasar

Erdem Yasar

Erdem Yasar is a news editor at Cloud7 News. Erdem started his career by writing video game reviews in 2007 for PC World magazine while he was studying computer engineering. In the following years, he focused on software development with various programming languages. After his graduation, he continued to work as an editor for several major tech-related websites and magazines. During the 2010s, Erdem Yasar shifted his focus to cloud computing, hosting, and data centers as they were becoming more popular topics in the tech industry. Erdem Yasar also worked with various industry-leading tech companies as a content creator by writing blog posts and other articles. Prior to his role at Cloud7 News, Erdem was the managing editor of T3 Magazine.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
[Event] Build a website in WordPress Hosting and WordPress set up

[Event] Build a website in WordPress: Hosting and WordPress set up

Related News

LockBit encryptor source code is updated

LockBit encryptor source code is updated

February 3, 2023 4:40 pm
Fortinet is expanding its SOC offerings portfolio

Fortinet is expanding its SOC offerings portfolio

February 3, 2023 2:00 pm
Radware announces a new partner program

Radware announces a new partner program

February 3, 2023 1:30 pm
APTs are looking for developers to hire with hefty paychecks

APTs are looking for developers to hire with hefty paychecks

February 1, 2023 2:30 pm
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Editor's Choice

What’s new in Linux kernel 6.2 rc6?

10 Best Web Hosting Services of 2023

Ubuntu 22.04 LTS is available for download. What is new?

CERN and Fermilab recommend AlmaLinux

7 best hosting control panels of 2023

How to update Linux Kernel without rebooting?

7 best Linux mail servers of 2023

7 best cPanel alternatives for 2023

7 best Linux web browsers for 2023

7 best CentOS alternatives

7 best Linux server distros of 2023

Interview with Igor Seletskiy on AlmaLinux

How to create a VM on VMware Workstation

Recent News

  • LockBit encryptor source code is updated
  • LibreOffice 7.5 Community is released. What’s new?
  • NTT to add Palo Alto Networks’ solution to its portfolio
  • Gcore announces partnership with Super Protocol
  • Fortinet is expanding its SOC offerings portfolio

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.