Hackers Abuse MeshCentral for a RAT

Hackers Abuse MeshCentral for a RAT

Source: YouTube · John Hammond · published Oct 15, 2024 · 20:51

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

A malicious actor exploited CVE-2024-44711, a high-severity unauthenticated remote code execution vulnerability in VH Backup and Replication versions 12.1.1.56 and earlier, to execute a PowerShell-encoded command that downloaded a fake "VM agent.exe" 1:52.

Key Takeaways:
• CVE-2024-44711 enables unauthenticated RCE via deserialization of untrusted data, exploited through a PowerShell command that downloads a malicious "VM agent.exe" 1:52.
• The attacker used a legitimate meshCentral agent, disguised as genuine, to establish command-and-control via a self-signed certificate and websockets, connecting to 185.238.21.65 on port 443 3:33.
• The malicious PowerShell command invoked the fake agent, which then connected to the attacker’s meshCentral server using configuration data from an msh.txt file 2:01.
• The msh.txt file contains key-value pairs including server IP, mesh ID, and connection details, exposing the attacker’s C2 infrastructure 13:01.
• Sigma rules exist to detect mesh agent activity, enabling automated detection of such attacks in endpoint security systems 16:01.

This attack demonstrates how threat actors leverage known vulnerabilities in legitimate tools like meshCentral to establish persistent, stealthy command-and-control.

Sources:

  • 1:52 Discussion of CVE-2024-44711 and unauthenticated RCE in VH Backup and Replication
  • 2:01 Analysis of the PowerShell command and download to a malicious meshCentral endpoint
  • 3:33 Demonstration of C2 establis

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

our security operations center recently sent out this incident report for a malware investigation but it's a little bit interesting because this isn't malware as you would typically expect if we scroll down here we can see that they note evidence suggests that at a redacted date and time a user operating as the system level anti Authority system launched an encoded Powershell command from the executable C program files common files vhm backup and replication Mount service vhm backup mount service.exe this came from VH they continue on here the encoded command reached out to an external IP address that does not appear to be related to the Target and victim organization in order to download the executable C users public documents V agent.exe now I can tell you right off the bat and I'm sure …