Savvy Seahorse Leverages DNS Canonical Names In Financial Scam Campaigns

Related Vulnerabilities: CVE-2024-1708   CVE-2024-1709  

Properties
Threat Severity

Medium

Description

In February 2024, ConnectWise disclosed serious vulnerabilities (CVE-2024-1708 and CVE-2024-1709) in its ScreenConnect software versions 23.9.7 and earlier, allowing unauthorized access and control. Exploitation of these flaws has led to ransomware attacks, causing significant disruptions. ConnectWise has released critical security patches and urges customers to update to the latest version to mitigate risks. Black Basta, among other groups, exploited these vulnerabilities, deploying Cobalt Strike beacons for reconnaissance and privilege escalation. Another group, utilizing Cobalt Strike payloads, attempted to disable Windows Defender to evade detection. Additionally, the Bl00dy Ransomware group, using leaked builders from Conti and LockBit Black, capitalized on these vulnerabilities, identifying themselves through ransom notes. The Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Trend Micro and shared publicly https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html

Knowledge Base
  • Available Soon
Global Prevalence
Low
High
Observed Countries6
  • United States3.14 devices found impacted per 1M devices
  • Germany1.7 devices found impacted per 1M devices
  • Belgium11.61 devices found impacted per 1M devices
  • Brazil1.61 devices found impacted per 1M devices
  • Colombia3.56 devices found impacted per 1M devices
  • France1.32 devices found impacted per 1M devices
Observed Sectors1
  • Various Sectors
    2.74 devices found impacted per 1M devices
Compare Detections

Detection rate is the number of artifact detections reported by McAfee global sensors for this threat over 8 days.

Threat Prevalence - Past 8 days

The detection rate bubbles are sized based on the values below:

1-20 20-50 50-100 100+
Mar 4, 2024
Mar 5, 2024
Mar 6, 2024
Mar 7, 2024
Mar 8, 2024
Mar 9, 2024
Mar 10, 2024
Mar 11, 2024
Sector
Country
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0
Detection Rate: 0