Categories: Microsoft

Microsoft Shares Detection, Mitigation Advice For Azure LoLBins

Microsoft Shares Detection, Mitigation Advice For Azure LoLBins

Azure LoLBins can be used by attackers to bypass network defenses, deploy cryptominers, elevate privileges, and disable real-time protection on a targeted device.

On Windows systems, LoLBins (short for living-off-the-land binaries) are Microsoft-signed executables (downloaded or pre-installed) that threat actors can abuse to evade detection while performing various malicious tasks such as downloading, installing, or executing malicious code.

Attackers can abuse a wide range of Window legitimate tools, including but not limited to Microsoft DefenderWindows Update, and even the Windows Finger command.

As Microsoft said earlier today, they can also use Azure LoLBins by abusing Azure Compute virtual machine extensions, small apps used by admins for automation and post-deployment tasks.

“The usage of LoLBins is frequently seen, mostly combined with fileless attacks, where attacker payloads surreptitiously persist within the memory of compromised processes and perform a wide range of malicious activities,” Microsoft Senior Security Research Manager Ram Pliskin explained.

“Together with the use of legitimate LoLBins, attackers’ activities are more likely to remain undetected.”

Among the VM extensions susceptible for abuse in attacks, Pliskin says that Microsoft has observed these used by threat actors as Azure LoLBins:

Also Read: 15 Best Tools For Your Windows 10 Privacy Settings Setup

While being legitimately used by thousands of admins each day for managing their organizations’ Azure fleets, their capabilities can also be used for malicious purposes, including circumventing network defense lines.

For instance, Custom Script Extensions were used by threat actors to deploy cryptominers on the networks of multiple Microsoft customers “from different countries within a noticeably short timeframe.”

Additionally, VMAccess and Antimalware extensions can be abused to tamper with service users and disable real-time protection capabilities.

To detect such malicious behavior in your organization, Microsoft recommends using Azure Defender for Resource Manager, which keeps track of Azure management operations and alerts you if it spots suspicious activity.

“Every request to the Azure Resource Manager Endpoint on management.azure.com is logged and analyzed to reveal malicious intentions and threats,” Pliskin said.

To mitigate Azure LoLBins usage, you should follow the least privilege principle to ensure that anyone who wants to perform a given task using VM extensions meets the minimum required access.

Also Read: How Formidable is Singapore Cybersecurity Masterplan 2020?

“A least privilege model for the cloud relies on the ability to continuously adjust access controls,” Pliskin added. “We recommend monitoring all access events and establish a decision-making framework that distinguishes between legitimate and excessive permissions.”

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

2 weeks ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago