Full Report
Take a look back at some of the biggest threats we observed and analyzed in 2024.
Analysis Summary
# Incident Report: 2024 Global Threat Landscape Review
## Executive Summary
In 2024, the threat landscape was characterized by the exploitation of critical vulnerabilities in remote management tools, advanced phishing techniques, and the targeting of specific social groups by APTs. Notable incidents included the "SlashAndGrab" exploitation of ScreenConnect and the use of legitimate software (BOINC) for malicious Command and Control (C2) operations. These events highlight a shift toward abusing trusted software and bypassing multi-factor authentication (MFA) via sophisticated "Adversary-in-the-Middle" (AiTM) attacks.
## Incident Details
- **Discovery Date:** Multiple (February through December 2024)
- **Incident Date:** Various dates across 2024
- **Affected Organization:** Global organizations using ConnectWise ScreenConnect, Cleo software, and macOS devices.
- **Sector:** Healthcare, Technology, Human Rights, and Small-to-Medium Businesses (SMBs).
- **Geography:** Global (specific focus noted in Vietnam and North America).
## Timeline of Events
### Initial Access
- **Date/Time:** February 2024 (ScreenConnect); May 2024 (HTML Smuggling); July 2024 (SocGholish).
- **Vector:** Vulnerability exploitation (CVE-2024-1709), HTML Smuggling, and Fake Browser Updates.
- **Details:** Attackers exploited an authentication bypass in ScreenConnect to gain administrative access and used HTML smuggling to deliver AitM phishing pages to bypass MFA.
### Lateral Movement
- **Techniques:** Post-exploitation tradecraft following ScreenConnect compromise; use of BOINC software to facilitate file transfers and remote task execution across networks.
### Data Exfiltration/Impact
- **Details:** Ransomware deployment (BlackCat/ALPHV), unauthorized access to sensitive healthcare data, and long-term surveillance of human rights activists by APT OceanLotus.
### Detection & Response
- **Discovery:** Huntress analysts identified anomalous authentication bypasses and suspicious use of legitimate volunteer computing software.
- **Response Actions:** Release of community hotfixes for ScreenConnect, publication of macOS LightSpy detection rules on GitHub, and mass notification of "Oh No Cleo!" vulnerability (CVE-2024-55956).
## Attack Methodology
- **Initial Access:** Exploit Public-Facing Application (CVE-2024-1709, CVE-2024-55956), Phishing (HTML Smuggling).
- **Persistence:** Sophisticated persistence methods used by OceanLotus; malicious autoruns in ScreenConnect.
- **Defense Evasion:** Use of legitimate software (BOINC) to mask C2 traffic; HTML smuggling to hide malicious payloads from email gateways.
- **Credential Access:** Adversary-in-the-Middle (AiTM) techniques to bypass MFA.
- **Lateral Movement:** Remote access tools (ScreenConnect) and volunteer computing software.
- **Impact:** Ransomware (BlackCat), data theft, and political surveillance.
## Impact Assessment
- **Financial:** High potential costs related to BlackCat ransomware demands and recovery.
- **Data Breach:** Compromise of healthcare endpoints and sensitive data belonging to human rights defenders.
- **Operational:** Widespread patching requirements for ConnectWise and Cleo LexiCom users; potential service disruptions during remediation.
- **Reputational:** Significant impact on software vendors whose tools were leveraged for mass exploitation.
## Indicators of Compromise
- **Network Indicators:** Connections to look-a-like servers configured via BOINC; known C2 infrastructure for OceanLotus (defanged: hxxp[://]bad-actor-domain[.]com).
- **File Indicators:** Malicious LightSpy macOS binaries; modified BOINC configuration files.
- **Behavioral Indicators:** Unexpected administrative account creation via ScreenConnect; browser updates initiated from non-standard domains.
## Response Actions
- **Containment:** Community-wide alerts to patch ScreenConnect to version 23.9.8 immediately.
- **Eradication:** Identification and removal of unauthorized autoruns on ScreenConnect servers.
- **Recovery:** Deployment of hotfixes and updated detection logic for EDR/MDR platforms.
## Lessons Learned
- **Key Takeaways:** Attackers are increasingly targeting "foundational" software (RMM tools, file transfer services) to gain high-privilege access to multiple downstream victims.
- **Process Gaps:** The delay between vulnerability disclosure and patching remains the primary window of opportunity for "SlashAndGrab" style attacks.
## Recommendations
- **Prevention:**
- Implement aggressive patching cycles for internet-facing management tools.
- Utilize FIDO2-compliant security keys to defend against AiTM phishing/HTML smuggling.
- Monitor for the installation of unauthorized "legitimate" software like BOINC or other peer-to-peer applications.
- Regularly audit administrative account creation within Remote Monitoring and Management (RMM) tools.