CheckMesh: Hidden Threats in Your FW

2024-07-09 Hackers Eye

https://hackerseye.net/all-blog-items/checkmesh/

Thumbnail for CheckMesh: Hidden Threats in Your FW

HackersEye describes an intrusion against an Israeli enterprise where an attacker used admin access to a Check Point firewall, moved from the GAIA web interface to SSH, and installed a malicious MeshAgent based ELF implant. The implant disguised itself as a legitimate process, gave the attacker encrypted C2 and persistence on the firewall Linux system, and let the actor operate as root. The attacker then used the firewall foothold for credential theft, password spraying or brute force activity, port forwarding, and RDP tunneling into internal systems. HackersEye says the TTPs resemble Cisco Talos reporting on LilacSquid, but the excerpt frames the attribution as similarity based rather than definitive.

Indicators of Compromise

Type Value First Seen Last Seen
YARA MeshAgent_Config 2024-07-09 2024-07-09
YARA MeshAgent_ELF 2024-07-09 2024-07-09
HASH 1134af27bea8518c62444a56f4bd4bc… 2024-07-09 2024-07-09
HASH 3840acb15880f6cb0a77347d4a3893c… 2024-07-09 2024-07-09
HASH 277e376f8e521b5127d45da965a5a43d 2024-07-09 2024-07-09
HASH b1b15e09ea98228203e110456d51432… 2024-07-09 2024-07-09
DOMAIN gupdate.net 2024-07-09 2024-07-09
DOMAIN api.gupdate.net 2024-07-09 2024-07-09
IPv4 51.16.51.81 2024-07-09 2024-07-09
IPv4 78.141.238.182 2024-07-09 2024-07-09

Related Actors

Related Reports

« Back