{"id":25782,"date":"2017-03-27T10:00:18","date_gmt":"2017-03-27T17:00:18","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=25782"},"modified":"2026-06-11T15:32:55","modified_gmt":"2026-06-11T22:32:55","slug":"unit42-threat-brief-credential-theft-keystone-shamoon-2-attacks","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2017\/03\/unit42-threat-brief-credential-theft-keystone-shamoon-2-attacks\/","title":{"rendered":"Threat Brief: Credential Theft - The Keystone of the Shamoon 2 Attacks"},"content":{"rendered":"<p>Unit 42 researchers have been following the <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/tag\/shamoon-2\/\">Shamoon 2<\/a> attacks closely since November 2016. To date, Shamoon 2 has unfolded in three separate attack waves on <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2016\/11\/unit42-shamoon-2-return-disttrack-wiper\/\">November 11, 2016<\/a>, <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2017\/01\/unit42-second-wave-shamoon-2-attacks-identified\/\">November 29, 2016<\/a>, and <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2017\/01\/unit42-threat-brief-shamoon-2-wave-3-attacks\/\">January 23, 2017<\/a>.<\/p>\n<p>Based on our newest <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2017\/03\/unit42-shamoon-2-delivering-disttrack\/\">research<\/a>, we can answer a question that many have had about these attacks: how is Shamoon 2 able to enter an organization\u2019s network and spread so widely? The answer is simple: credential theft.<\/p>\n<p>Credential theft has been known to be a key part of the Shamoon 2 attacks. What our research is showing that\u2019s new is how the attackers use the credentials once they\u2019ve breached the network.\u00a0 And from this we can see how credential theft is the keystone of Shamoon 2 attacks; if an organization can prevent credential theft, the Shamoon 2 attacks can\u2019t succeed.<\/p>\n<p>In our research, we\u2019re able to outline that Shamoon 2 enters and spreads through an organization in three stages:<\/p>\n<ol>\n<li>Shamoon 2 attackers access and compromise a single system in the network, using Remote Desktop Protocol (RDP) with stolen, legitimate credentials. This becomes their distribution server: they download their tools and malware to this system.<\/li>\n<li>Attackers execute commands on the distribution server to connect to specific, named systems on the network, using the stolen, legitimate credentials, and infect them with the Disttrack malware.<\/li>\n<li>The Disttrack malware will execute on those named systems the attacker has successfully infected. The Disttrack malware will attempt to connect to and spread itself to up to 256 IP addresses on its local network. Any systems successfully infected in this stage will also attempt to infect up to 256 IP addresses on their local networks.<\/li>\n<\/ol>\n<p>These stages are outlined in the image below.<\/p>\n<p><div style=\"max-width:100%\" data-width=\"2167\"><span class=\"ar-custom\" style=\"padding-bottom:61.56%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"alignnone size-full wp-image-25728 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2017\/03\/Shamoon-diagram-social-ads-final_unit-42-diagram-linkedin-520x320.png\" alt=\"shamoon-diagram-social-ads-final_unit-42-diagram-linkedin-520x320\" width=\"2167\" height=\"1334\" \/><\/span><\/div><\/p>\n<p>And that credential theft is a key element in each stage:<\/p>\n<ol>\n<li>Attackers must have valid credentials to gain access via RDP to the system they will use as their distribution server in Stage 1.<\/li>\n<li>Once on the distribution server, the attackers must be able to execute their tools and scripts in an account that has valid credentials for them to successfully connect to and control the named hosts in Stage 2.<\/li>\n<li>The Disttrack malware itself must have valid, stolen credentials embedded within it to spread itself in Stage 3.<\/li>\n<\/ol>\n<p>It\u2019s also worth noting that credentials are a keystone issue in <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2017\/01\/unit42-second-wave-shamoon-2-attacks-reveal-possible-new-tactic\/\">Shamoon 2 wave 2<\/a> too: we saw evidence of targeting an organization\u2019s virtual desktop infrastructure (VDI) solutions with default credentials. While not stolen credentials, the effect is the same: attackers can use those credentials to abuse otherwise legitimate access and privileges to carry out their attacks.<\/p>\n<p>At this time, we do not have research that explains definitively how the Shamoon 2 attackers have obtained these credentials. We do believe there is evidence suggestive of a connection between Shamoon 2 and the <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2017\/02\/unit42-magic-hound-campaign-attacks-saudi-targets\/\">Magic Hound campaign<\/a>, which could indicate these two attack campaigns could have worked in conjunction with each other to execute the Shamoon 2 attacks.<\/p>\n<p>We also believe the presence of specific, valid named hosts from the network used in Stage 2 shows they were obtained directly from Active Directory on a domain controller. This is also suggestive of access to the network through legitimate, stolen credentials. In one sample we examined, we found a total of 844 hostnames.<\/p>\n<p>This also helps to set context for how widely Disttrack can attempt to spread: 844 systems, each attempting to spread to 256, means that from one distribution server, Shamoon 2 attackers could potentially try to spread Disttrack to 216,064 systems; and that\u2019s not counting if any of those infected systems, in turn, attempts to spread to an additional 256 systems.<\/p>\n<p>Shamoon 2 attacks are very targeted to a specific region. But it would be a mistake to write-off the threat that Shamoon 2 demonstrates. Shamoon 2 attackers are using a rudimentary, but effective, distribution system of their own making. The power of their attack doesn\u2019t lie in the tools they use but in their ability to obtain and abuse legitimate credentials.<\/p>\n<p>This underscores why credential theft is something that organizations should prioritize as a top threat and take steps to understand it and prevent it. We\u2019ve recently published a new Unit 42 <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2017\/03\/unit42-new-white-paper-preventing-credential-phishing-theft-abuse\/\">white paper on credential theft<\/a> that we encourage you to read.<\/p>\n<p>To help customers take steps to better understand and protect against this threat, we\u2019ve posted information in our article <a href=\"https:\/\/live.paloaltonetworks.com\/t5\/Threat-and-Vulnerability\/PAN-OS-Configuration-Recommendations-to-Protect-Against-Shamoon\/ta-p\/149451\">PAN-OS Configuration Recommendations to Protect Against Shamoon 2<\/a> located in our <a href=\"https:\/\/live.paloaltonetworks.com\/t5\/Threat-and-Vulnerability\/tkb-p\/ThreatArticles\">Threat and Vulnerability Articles<\/a> section on our Live Community. You can also join in the discussion in our \u201c<a href=\"https:\/\/live.paloaltonetworks.com\/t5\/Threat-and-Vulnerability\/bd-p\/Threat_Discussions\">About Threat and Vulnerability Discussions<\/a>\u201d on the Live Community.<\/p>\n<p><a href=\"http:\/\/go.paloaltonetworks.com\/ignite2017\"><div style=\"max-width:100%\" data-width=\"820\"><span class=\"ar-custom\" style=\"padding-bottom:41.46%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"alignnone wp-image-25356 size-full lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2017\/03\/ignite17-social-cover-img-facebook-820x340.png\" alt=\"ignite17-social-cover-img-facebook-820x340\" width=\"820\" height=\"340\" \/><\/span><\/div><\/a><\/p>\n<p><strong>Ignite \u201917 Security Conference: Vancouver, BC June 12\u201315, 2017<\/strong><\/p>\n<p>Ignite \u201917 Security Conference is a live, four-day conference designed for today\u2019s security professionals. Hear from innovators and experts, gain real-world skills through hands-on sessions and interactive workshops, and find out how breach prevention is changing the security industry. Visit the <a href=\"http:\/\/www.paloaltonetworksignite.com\" rel=\"nofollow,noopener\" >Ignite website<\/a> for more information on tracks, workshops and marquee sessions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Unit 42 Threat Brief: Credential Theft - The Keystone of the Shamoon 2 Attacks.<\/p>\n","protected":false},"author":287,"featured_media":25785,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[10737],"tags":[3191,3039,3116,3125],"coauthors":[3069],"class_list":["post-25782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-intelligence","tag-credential-theft","tag-disttrack-wiper","tag-shamoon-2","tag-threat-brief"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2017\/03\/Linkedin.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/25782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/287"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=25782"}],"version-history":[{"count":9,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/25782\/revisions"}],"predecessor-version":[{"id":25809,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/25782\/revisions\/25809"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/25785"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=25782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=25782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=25782"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=25782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}