{"id":12725,"date":"2024-12-20T06:00:50","date_gmt":"2024-12-20T14:00:50","guid":{"rendered":"https:\/\/legacy.gosecure.ai\/?p=12725"},"modified":"2024-12-20T06:00:56","modified_gmt":"2024-12-20T14:00:56","slug":"threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration","status":"publish","type":"post","link":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/","title":{"rendered":"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration"},"content":{"rendered":"<p><span data-contrast=\"auto\"><img class=\"alignright wp-image-12722 size-medium\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/December-2024-THOTM-300x157.jpg\" alt=\"\" width=\"300\" height=\"157\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-300x157.jpg 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-1024x535.jpg 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-768x401.jpg 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-1080x564.jpg 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-980x512.jpg 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-480x251.jpg 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM.jpg 1200w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>In December 2024, GoSecure Threat Hunters have identified a concerning use of remote access software by cybercriminals to gain initial access within corporate environments. The attackers start by flooding a victim\u2019s email with spam and then pose as IT support via Microsoft Teams. This social engineering tactic lures victims into installing remote access software, which is then exploited to deploy a custom implant that exfiltrates sensitive information and sets the stage for ransomware attacks.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Why This Matters<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The use of remote access software as an attack vector is particularly alarming because it exploits the human element: employees&rsquo; trust in their IT departments. This method bypasses typical security measures and allows attackers to gain deep access without immediate detection. The threat actors&rsquo; ability to remain undetected on the network long enough to deploy ransomware poses a significant risk to organizational security.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Detection and Monitoring<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Our Threat Hunters hypothesized that cybercriminals are leveraging social engineering to exploit remote access software for network infiltration. Through diligent validation and threat hunting, our team confirmed no adversaries were present within our managed clients&rsquo; environments. However, we have established robust detection rules to continuously monitor for suspicious activities related to remote access tools:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Detection Rule:<\/span><\/b><span data-contrast=\"auto\"> Execution of Discovery Techniques followed by RMM Tool Usage<\/span><br \/>\n<b><span data-contrast=\"auto\">Description:<\/span><\/b><span data-contrast=\"auto\"> Detects when system information and network configuration commands are followed by the execution of a remote access tool, indicating potential unauthorized activity.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Recommendations<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Organizations are advised to standardize the use of remote access software within their environments and block unapproved tools at the network level. We also recommend enhancing endpoint detection capabilities and educating users about the risks associated with unsolicited IT support communications.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Conclusion<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The December Threat Hunt highlights the evolving nature of cyber threats and emphasizes the importance of vigilance and advanced detection strategies. GoSecure\u2019s MXDR service is specifically designed to provide comprehensive surveillance and proactive threat mitigation to protect against sophisticated cyber threats, including those utilizing remote access software. For further details on bolstering your defenses, or to discuss our findings and recommendations, please contact us directly at (888)-287-5858 or <a href=\"mailto:info@gosecure.ai\">info@gosecure.ai<\/a>.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Stay secure!<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Your GoSecure Threat Hunting Team<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p><span data-contrast=\"auto\"><img class=\"alignright wp-image-12722 size-medium\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-300x157.jpg\" alt=\"\" width=\"300\" height=\"157\" \/>In December 2024, GoSecure Threat Hunters have identified a concerning use of remote access software by cybercriminals to gain initial access within corporate environments. The attackers start by flooding a victim\u2019s email with spam and then pose as IT support via Microsoft Teams. This social engineering tactic lures victims into installing remote access software, which is then exploited to deploy a custom implant that exfiltrates sensitive information and sets the stage for ransomware attacks.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[437,563,632],"tags":[664,665,666,667,668,669,670,567],"class_list":["post-12725","post","type-post","status-publish","format-standard","hentry","category-avis-de-securite","category-ransomware-fr","category-threat-intelligence-fr","tag-corporate-network-security-fr","tag-cybercrime-fr","tag-network-infiltration-fr","tag-ransomware-attacks-fr","tag-remote-access-software-fr","tag-security-detection-fr","tag-social-engineering-fr","tag-threat-hunting-fr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.0 (Yoast SEO v23.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration - GoSecure<\/title>\n<meta name=\"description\" content=\"Discover how cybercriminals exploit remote access software to infiltrate corporate networks. Learn from GoSecure Threat Hunters about the dangers of unsolicited IT support and the advanced detection strategies needed to protect sensitive corporate environments. Stay informed and secure with GoSecure&#039;s MXDR service.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration\" \/>\n<meta property=\"og:description\" content=\"Discover how cybercriminals exploit remote access software to infiltrate corporate networks. Learn from GoSecure Threat Hunters about the dangers of unsolicited IT support and the advanced detection strategies needed to protect sensitive corporate environments. Stay informed and secure with GoSecure&#039;s MXDR service.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/\" \/>\n<meta property=\"og:site_name\" content=\"GoSecure\" \/>\n<meta property=\"article:published_time\" content=\"2024-12-20T14:00:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-12-20T14:00:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-300x157.jpg\" \/>\n<meta name=\"author\" content=\"GoSecure\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:site\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"GoSecure\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/\",\"name\":\"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration - GoSecure\",\"isPartOf\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/December-2024-THOTM-300x157.jpg\",\"datePublished\":\"2024-12-20T14:00:50+00:00\",\"dateModified\":\"2024-12-20T14:00:56+00:00\",\"author\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\"},\"description\":\"Discover how cybercriminals exploit remote access software to infiltrate corporate networks. Learn from GoSecure Threat Hunters about the dangers of unsolicited IT support and the advanced detection strategies needed to protect sensitive corporate environments. Stay informed and secure with GoSecure's MXDR service.\",\"breadcrumb\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#primaryimage\",\"url\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/December-2024-THOTM-300x157.jpg\",\"contentUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/December-2024-THOTM-300x157.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/legacy.gosecure.ai\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/\",\"name\":\"GoSecure\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\",\"name\":\"GoSecure\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration - GoSecure","description":"Discover how cybercriminals exploit remote access software to infiltrate corporate networks. Learn from GoSecure Threat Hunters about the dangers of unsolicited IT support and the advanced detection strategies needed to protect sensitive corporate environments. Stay informed and secure with GoSecure's MXDR service.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/","og_locale":"fr_FR","og_type":"article","og_title":"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration","og_description":"Discover how cybercriminals exploit remote access software to infiltrate corporate networks. Learn from GoSecure Threat Hunters about the dangers of unsolicited IT support and the advanced detection strategies needed to protect sensitive corporate environments. Stay informed and secure with GoSecure's MXDR service.","og_url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/","og_site_name":"GoSecure","article_published_time":"2024-12-20T14:00:50+00:00","article_modified_time":"2024-12-20T14:00:56+00:00","og_image":[{"url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/December-2024-THOTM-300x157.jpg"}],"author":"GoSecure","twitter_card":"summary_large_image","twitter_creator":"@GoSecure_Inc","twitter_site":"@GoSecure_Inc","twitter_misc":{"\u00c9crit par":"GoSecure","Dur\u00e9e de lecture estim\u00e9e":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/","url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/","name":"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration - GoSecure","isPartOf":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#primaryimage"},"image":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#primaryimage"},"thumbnailUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/December-2024-THOTM-300x157.jpg","datePublished":"2024-12-20T14:00:50+00:00","dateModified":"2024-12-20T14:00:56+00:00","author":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca"},"description":"Discover how cybercriminals exploit remote access software to infiltrate corporate networks. Learn from GoSecure Threat Hunters about the dangers of unsolicited IT support and the advanced detection strategies needed to protect sensitive corporate environments. Stay informed and secure with GoSecure's MXDR service.","breadcrumb":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#primaryimage","url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/December-2024-THOTM-300x157.jpg","contentUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/December-2024-THOTM-300x157.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/12\/20\/threat-hunt-of-the-month-remote-access-software-exploited-for-corporate-network-infiltration\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legacy.gosecure.ai\/fr\/"},{"@type":"ListItem","position":2,"name":"Threat Hunt of the Month: Remote Access Software Exploited for Corporate Network Infiltration"}]},{"@type":"WebSite","@id":"https:\/\/legacy.gosecure.ai\/fr\/#website","url":"https:\/\/legacy.gosecure.ai\/fr\/","name":"GoSecure","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca","name":"GoSecure"}]}},"_links":{"self":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/12725","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/comments?post=12725"}],"version-history":[{"count":0,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/12725\/revisions"}],"wp:attachment":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/media?parent=12725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/categories?post=12725"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/tags?post=12725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}