• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Subscribe
  • Project of the Week
  • About Us
    SEARCH
IT Infrastructure, Network Security, News

Why Active Directory Attack Paths are the Secret to Many Successful Ransomware Attacks

By gaining control of an organization’s AD, the adversary seizes the power to deploy ransomware to all systems through several mechanisms.

January 19, 2022 Andy Robbins Leave a Comment

Active Directory Misconfigurations
stock.adobe.com/monticellllo

It’s no secret that most major enterprises across the globe use Microsoft Active Directory (AD) for identity and access management. This ubiquity is also one of the predominant reasons AD is such a popular and attractive target for adversaries. What remains a mystery to many enterprises, however, is how adversaries – including the malicious actors behind the Conti, REvil, and DarkSide attacks use Attack Paths in AD to deploy ransomware. In fact, AD Attack Paths are the secret to many successful ransomware attacks. To demystify this regularly used – and often, extremely lucrative tactic, let’s take a closer look at how and more importantly, why these attacks work in the wild.

At its core, AD’s primary function is to enable administrators to manage permissions and control access to network resources. Therefore, control of an organization’s AD means control of all the users, processes, and systems within that organization. By gaining control of an organization’s AD, the adversary seizes the power to deploy ransomware to all systems through several mechanisms, including (but not limited to) Group Policy, System Center Configuration Manager (SCCM), and third-party software deployment products that typically run on domain-joined Windows systems. For adversaries, the common denominator in these scenarios, and the secret to their success, is the abuse of Attack Paths.

Related: Microsoft Warns Of New AD FS Compromise By Sunburst Hackers

Attack Paths allow adversaries to reliably take control of almost any enterprise’s AD environment because every AD environment in the world is vulnerable to identity Attack Paths, a type of attack that’s also commonly known as an identity snowball attack. To execute such an attack, the adversary compromises a user with access to a machine on a network – perhaps through a phishing attack to escalate privilege while avoiding detection.

Once the adversary has their malicious code up and running on a computer in the target network, they can use the privileges of the users logged into that host (as well as tools like Mimikatz and Responder) to compromise other systems and machines. These steps chart a “path” from the adversary’s initial point of access to their final objective. Attack Paths allow adversaries to deploy ransomware without abusing vulnerabilities or software exploits that could be noticed by defenders. Since AD Attack Paths largely use legitimate user credentials, they’re more difficult to prevent and more likely to slip past security controls.

Ransomware is only getting more dangerous over time, and ransomware operators continue to abuse the highly complex nature of AD to find and execute attack paths. Unsurprisingly, this past year several ransomware operators concentrated their focus on AD in order to take full control of their targets’ enterprises before deploying ransomware to most or all domain-joined systems. Take the Conti ransomware for example, which recently focused more on unpatched vulnerabilities to gain privileges in AD. As detailed in a joint alert issued by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) in September:

According to a recently leaked threat actor “playbook,” Conti actors also exploit vulnerabilities in unpatched assets, such as the following, to escalate privileges and move laterally across a victim’s network:

  • 2017 Microsoft Windows Server Message Block 1.0 server vulnerabilities;
  • “PrintNightmare” vulnerability (CVE-2021-34527) in Windows Print spooler service;
  • and “Zerologon” vulnerability (CVE-2020-1472) in Microsoft Active Directory Domain Controller systems.

Attack Paths can enable much more than ransomware. In AD, Attack Paths are the mechanism attackers use to gain privileged access to a network. Once they have that access, they can do more than deploy ransomware; they could steal sensitive data, launch other types of malware attacks, achieve persistence in the network or add backdoors that will allow them to instantly re-gain privileged access in the future, and more.

An adversary that is well versed in the dark art of attacking AD can gain privileges and move freely across Attack Paths leaving minimal risk of discovery from defenders, achieving persistence, and gaining the keys to the kingdom. To reduce their vulnerability to all these attacks and stop problems like ransomware at their source, organizations should work on eliminating the Attack Paths in their AD environment.

To combat such threats, it’s becoming more and more common for AD administrators to use the free and open-source software (FOSS) BloodHound to proactively remove or mitigate the most critical, or high-risk, attack paths before adversaries like ransomware groups can get to them–and use those Attack Paths to take full control of their target’s AD–first. Using tools like BloodHound FOSS (as well as resources like ADSecurity.org) defenders can better understand their exposure to attack paths, audit the most highly sensitive objects in AD, and execute targeted remediation to help eliminate the most dangerous Attack Paths before an attacker can find and exploit those same Attack Paths themselves.

Fortunately, this particular secret is out and gaining traction with both the United States Department of Homeland Security and professional services network PricewaterhouseCoopers recently recommending organizations do the very same in order to protect their enterprises.

Andy Robbins, technical architect at SpecterOps, is a co-creator of BloodHound, the free and open source Active Directory attack path mapping and analysis tool. Andy has spoken at several conferences including Black Hat USA, Black Hat Europe, and DEF CON, and has a background in professional red teaming and penetration testing.

 

Tagged With: Active Directory, Cybersecurity, ransomware

Related Content:

  • Security Awareness Training Security Awareness Training Needs to Change. Here’s Why.
  • Google Bard, OpenAI, ChatGPT, Generative AI Google Begins Making Its AI Chatbot Bard Available
  • Bing Image Creator Microsoft Begins Rolling Out DALL∙E-Based Image Creator in…
  • Businessman meeting and training character vector design, corporate LMS training The Big-Picture Benefits of A Corporate LMS Investment

Free downloadable guide you may like:

  • Four IT Trends That Will Define 2023Expert Series: Four IT Trends That Will Define 2023

    Learn about four key technologies we identified as critical to your IT organization’s success in 2023, as well as how to invest in new innovations emerging from each.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Four IT Trends That Will Define 2023
Expert Series: Four IT Trends That Will Define 2023

Learn about four key technologies we identified as critical to your IT organization’s success in 2023, as well as how to invest in new innovations ...

Harnessing the Power of Digital Signage
Harnessing the Power of Digital Signage

Choosing the best solutions for messaging, branding, and communicating in today’s content-everywhere landscape

Blueprint Series Cover: What works for hybrid work
Blueprint Series: What Works for Hybrid Work

Download this free resource to learn about how IT leaders can effectively manage and implement a hybrid work model.

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSTERMS OF USEPRIVACY POLICY

© 2023 Emerald X, LLC. All rights reserved.