UMBRELLA STAND and SHOE RACK are two advanced malware strains targeting FortiGate 100D series firewalls. UMBRELLA STAND is a multi-component malware enabling remote shell access, file manipulation, and network exfiltration, while SHOE RACK serves as a post-exploitation tool, using reverse SSH tunneling and DNS-over-HTTPS for secure communication and remote access.
1. Initial Compromise:UMBRELLA STAND exploits vulnerabilities in FortiGate 100D series firewalls, gaining access and deploying various tools for persistence and control.SHOE RACK, once deployed after the initial compromise, establishes a reverse SSH connection using a non-standard version of SSH, allowing attackers to bypass traditional network security measures.
2. Persistence Mechanism:UMBRELLA STAND uses a combination of reboot hooks, ldpreload techniques, and file manipulation to ensure the malware survives reboots and remains undetected.SHOE RACK ensures persistence by modifying SSH configurations and creating reverse SSH tunnels, allowing attackers to maintain remote access to the compromised device without detection.
3. C2 Communication:UMBRELLA STAND communicates with its C2 server over fake TLS traffic on port 443, masking its true intent by mimicking legitimate encrypted communications.SHOE RACK uses DNS-over-HTTPS (DOH) to resolve the C2 server’s IP, then establishes a TCP/TLS connection for SSH communication. It uses non-standard SSH channels, making detection difficult.
4. Data Exfiltration and Command Execution:UMBRELLA STAND facilitates file exfiltration, remote shell commands, and manipulation of system settings.SHOE RACK, via reverse SSH tunnels, allows the attacker to interact with the compromised device and tunnel traffic from other networked systems, enabling deep network pivoting
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.
Keeping this cookie enabled helps us to improve our website.
Please enable Strictly Necessary Cookies first so that we can save your preferences!
This website uses the following additional cookies:
(List the cookies that you are using on the website here.)
More information about our Cookie Policy