Full Report
Navigate the SMB threat landscape with Huntress’ SMB Threat Report. Gain insights into evolving cyber threats targeting SMBs. Read on for key insights.
Analysis Summary
# Incident Report: Q3 2023 SMB Threat Landscape Analysis
## Executive Summary
This report summarizes systemic threat trends targeting Small and Medium-sized Businesses (SMBs) during Q3 2023. The findings reveal a significant shift toward "malware-free" attacks, the weaponization of legitimate RMM tools, and a high volume of Business Email Compromise (BEC) via Microsoft 365. The primary outcome is an environment where attackers "blend in" to evade traditional signature-based security.
## Incident Details
- **Discovery Date:** July – September 2023 (Q3 Analysis)
- **Incident Date:** Ongoing throughout Q3 2023
- **Affected Organization:** Multiple SMBs and MSPs
- **Sector:** Cross-sector SMBs
- **Geography:** Global (Based on 2.4M endpoints and 1M M365 entities)
## Timeline of Events
### Initial Access
- **Date/Time:** Q3 2023
- **Vector:** Credential theft (Identity-based attacks) and exploitation of legitimate remote tools.
- **Details:** 24% of Microsoft 365 incidents involved logins from unauthorized or suspicious geographic locations.
### Lateral Movement
- **Method:** Use of "Living-off-the-Land" (LotL) techniques to move across networks without triggering malware alerts.
- **Tools:** Abuse of scripting frameworks and Remote Monitoring and Management (RMM) software to navigate victim environments.
### Data Exfiltration/Impact
- **Details:** Primarily focused on Business Email Compromise (BEC) and unauthorized information access. In 64% of M365 incidents, attackers created malicious inbox rules or forwarding addresses to intercept communications.
### Detection & Response
- **Discovery:** Identified through behavioral analysis and anomaly detection by Huntress.
- **Response Actions:** Huntress assisted MSPs in identifying hijacked RMM sessions and unauthorized Microsoft 365 configurations (e.g., deleting malicious forwarding rules).
## Attack Methodology
- **Initial Access:** Hijacking RMM tools, credential stuffing, and phishing.
- **Persistence:** 65% of incidents involved hijacking RMM/remote control tools for long-term access.
- **Defense Evasion:** 56% of incidents were "malware-free," utilizing LOLBins (29%) and scripting framework abuse (27%) to avoid antivirus signatures.
- **Credential Access:** Targeting cloud identity (Microsoft 365).
- **Discovery:** Using legitimate administrative tools to map the network.
- **Lateral Movement:** Utilizing pre-installed RMM agents.
- **Impact:** Business Email Compromise (BEC), unauthorized email forwarding, and potential financial fraud.
## Impact Assessment
- **Financial:** High risk of wire fraud and invoice manipulation via BEC.
- **Data Breach:** High volume of sensitive corporate communications compromised via inbox rules.
- **Operational:** Involuntary pressure on IT admins to distinguish between legitimate and malicious use of their own management tools.
- **Reputational:** Risks associated with data leaks and unauthorized access to client information via MSP tools.
## Indicators of Compromise
- **Behavioral Indicators:**
- Logons from suspicious/unexpected geographic locations.
- Creation of new inbox forwarding rules (e.g., "Move to Archive" or external forwarding).
- Unusual scripting activity (PowerShell, CMD) not initiated by IT staff.
- RMM sessions initiated from non-standard administrative IP addresses.
## Response Actions
- **Containment:** Disabling compromised user accounts and terminating unauthorized RMM sessions.
- **Eradication:** Removing malicious inbox rules and unauthorized scripting persistence mechanisms.
- **Recovery:** Restoring legitimate communications and rotating all administrative credentials.
## Lessons Learned
- **Signature Deficiencies:** Traditional anti-malware and spam filters are increasingly ineffective against malware-free tactics.
- **RMM Risk:** Legitimate management tools are now primary targets; if an RMM is compromised, the entire client base is at risk.
- **Identity is the Perimeter:** The surge in BEC highlights that identity security is now more critical than endpoint security in cloud-heavy environments.
## Recommendations
- **Transition to Behavioral Monitoring:** Implement Endpoint Detection and Response (EDR) focused on behavioral analysis rather than file signatures.
- **Hardened Identity:** Enforce Multi-Factor Authentication (MFA) across all M365 accounts and review logs for suspicious geolocations.
- **RMM Security:** Audit RMM access logs, enforce MFA for all technician accounts, and restrict RMM access to known administrative IP ranges.
- **Email Auditing:** Regularly audit Microsoft 365 for unauthorized inbox rules or forwarding configurations.