CryptMove: Moving Stealthily through Legitimate and Encrypted Communication Channels

Md Rabbi Alam, Jinpeng Wei, Qingyang Wang · 2024

To move laterally inside an enterprise environment, Advanced Persistent Threat (APT) attacks have used multiple techniques. Due to the arms race between the attacks and the defenses, such techniques have evolved over time, with the latest one capable of reusing existing network connections for stealthy lateral movement. However, this technique has limited impact because it cannot reuse encrypted connections that are becoming the norm. In this paper, we present CryptMove, a novel technique that can abuse existing and encrypted channels for lateral movement. CryptMove secretly accesses the memory of the target process to duplicate the security context that is used by the target process to perform encryption/decryption; it also secretly duplicates sockets owned by the target process and injects encrypted malicious commands through these sockets into the encrypted communication channels. Since the location of the security context is specific to the target application, CryptMove employs automated analysis of the target application's binary code, in order to learn a path to reach the security context via a sequence of memory accesses. To demonstrate the feasibility of CryptMove, we built PoC attack tools (on both Windows and Linux) that successfully attacked popular applications (e.g., OpenSSH, PuTTY, WinSCP and WinRM) under 63 different cipher-protocol combinations. We also confirmed that the CryptMove PoC is not detectable by several popular Antivirus and Endpoint Detection and Response systems.

Read the paper · More papers on PaperTik