New APT group dubbed as 'Praying Mantis' targeted Microsoft IIS servers with ASP.NET exploits to load custom DLLs on the server...

Continue reading
A recently developed, highly persistent threat actor dubbed as Praying Mantis is targeting several high-profile public and private organizations in the U.S under a campaign of multiple cyber intrusion attacks by utilizing Microsoft Internet Information Services (IIS) servers to penetrate their networks.
Sygnia, an Israeli cybersecurity firm, first identified the series of attacks and tracked the ever-evolving adversary under the moniker "TG2021."
Researchers from Sygnia stated that "TG1021 uses a custom-made malware framework, built around a common core, tailor-made for IIS servers. The toolset is completely volatile, reflectively loaded into an affected machine's memory, and leaves a little-to-no trace on infected targets." They also added that "The threat actor also uses an additional stealthy backdoor and several post-exploitation modules to perform network reconnaissance, elevate privileges, and move laterally within networks."

The threat actor is highly capable of avoiding detection by actively intervening with logging mechanisms and successfully dodging commercial endpoint detection and response (EDR) systems, and leveraging an armory of ASP.NET web app exploits to obtain footholds and backdoor the servers by implanting a node called of ASP.NET web application exploits to load custom DLLs and handle HTTP requests made by the server.

The vulnerabilities misused by the threat actors are:
Sygnia's investigation into TG1021's TTPs revealed significant overlays to a nation-affiliated actor called Copy-Paste Compromises.
The researchers from Sygnia exclaimed that "Praying Mantis, which has been observed targeting high-profile public and private organizations in two major Western markets, represents a growing trend of cybercriminals using sophisticated, nation-state attack methods to target commercial organizations. Besides, Perpetual forensics ventures and appropriate incident response are crucial to identifying and adequately guarding networks against attacks by similar threat actors."

Backdoor.Daxin, the kernel-mode rootkit Symantec once called the most advanced tool ever tied to a China-linked espionage actor, has been found running again