When it comes to mission-critical systems, public safety agencies can’t afford any disruptions or downtime from cyber threats like malware. The faster you can find indicators of compromise (IOCs), the sooner you can take steps to prevent attacks from spreading and limit potential damage.
Read on to discover how Motorola Solutions’ Security Operations Center (SOC) team detected and shut down an early-stage SocGholish attack. It also illustrates the capabilities of our Managed Detection and Response services.
What is SocGholish?
In simple terms, SocGholish is a type of malware. It can also be described as a collection of JavaScript tools used to extract sensitive data — and some security researchers have posited that it could even potentially be a platform of scripts and servers managed by a criminal group. The “Soc” refers to social engineering techniques that SocGholish operators commonly use to prey on their victims by hosting malicious websites that claim to provide critical web browser or software updates.
When someone visits a compromised website, it redirects them to a page that looks like a legitimate website. It’s designed to trick them into downloading and installing a fake update. But it isn’t actually an update at all: it’s the first step in what can be a scary situation. Let’s take a deeper look now at how this attack happens.
Strengthen your cyber defenses
Our cost-effective managed security services protect endpoints, networks, cloud and systems from cyber threats.
-
Trusted 24/7 monitoring and response
-
Focused threat intelligence
-
Get visibility into relevant activity
How does a SocGholish attack work?
Once an unsuspecting victim downloads and opens the .zip file that allegedly has the update, it will execute malicious JavaScript code. The JavaScript then automatically reaches out to a command-and-control server — a computer that attackers use to send commands to systems compromised by malware — to trigger a download of its second-stage payload.
This enables the attackers to establish and maintain a foothold, also referred to as persistence, to carry out reconnaissance activities. The second-stage payload can include malware variants that give the threat actor or cybercriminals even more control over the victim’s device. Researchers have even seen SocGholish infections using Cobalt Strike to deliver ransomware.
How to protect against a SocGholish malware attack
To help protect you and your organization against a SocGholish malware attack, here are some best practices to follow:
- Awareness training: Educate users about SocGholish malware attacks, the social engineering tactics used by bad actors to look out for and how to maintain good cyber hygiene.
- Data security: Leveraging least privilege access control and data protection can help to secure defenses against a cyberattack.
- URL filtering: This helps to identify and block attempts by users to access URLs known to be associated with malware attacks.
- Endpoint security: Identify and block SocGholish malware from installing or causing harm to a system.
- Web security tools: Such tools can analyze web pages for malicious content and stop users from accessing these sites.
- Patch management: By keeping web browsers up to date with the latest security updates, organizations can protect against potential cyberattacks.
If a SocGholish malware attack occurs, it is important to:
- Initiate your cyber incident response and recovery plan.
- Isolate the infected device from the network.
- Apply measures to ensure the malware is fully contained.
- Establish 24/7 monitoring to detect malicious activity.
Case study: Detecting and preventing an early-stage SocGholish attack
Now let’s dive into a bit more technical detail of how Motorola Solutions detected this attack before it could do any damage.
The Advanced Threats and Research team in our SOC investigated SocGholish in a sandbox environment to fully understand how it behaves and how it infects victims. Armed with this information, the team then went threat hunting to look for indicators of it within customer networks.
To detect SocGholish activity, we looked for a Windows script host, loading a JavaScript code library, with a parent process of an archiving tool (Explorer, 7zip, Winrar), executing from the user’s “/temp” directory. Once we filtered out all the benign events, it was clear that the remaining results that were attempting to make network connections were extremely suspicious.
Fortunately, the SOC team spotted the attack before the network connection to the malicious domain could succeed. The infected device was immediately quarantined, and additional countermeasures were applied to ensure the threat was contained.
Combat cyber threats faster
Our ActiveEye platform powers rapid threat detection and response to help protect you from cybersecurity threats.
-
Support from a reliable team of analysts
-
Investigate alerts with a single click
-
Get full visibility into IT environments
Impact to public safety agencies
Although the ActiveEye SOC and other security researchers haven’t necessarily seen any indications that SocGholish is targeting specific industries or organizations, we encourage our customers to stay diligent about prevention and detection. Other threat actors are reportedly using SocGholish as an initial access broker (IAB) to get access to networks, even compromising an organization’s own website to infect employees with a drive-by download mechanism to install malware.
According to Motorola Solutions’ 2021 Cyber Threats to Public Safety: Criminal Operations report, IABs were prolific in 2021, and IABs selling either verified or likely legitimate access into emergency service environments represented 16 percent of all attacks.
In addition, IABs may be more inclined to target public safety agencies because of the higher costs they can charge for critical infrastructure access. Public Safety Answering Points (PSAPs) provide an enticing target for cybercriminals who wish to interfere with 9-1-1 call handling and dispatch. Land Mobile Radio (LMR) systems, used by the overwhelming majority of public safety agencies across the country, have become more susceptible to cyberattacks through increased integration with other systems, as the Cybersecurity and Infrastructure Security Agency (CISA) noted in a recently published guide for LMR security.
For both mission-critical networks, it is vitally important to detect and stop these increasingly sophisticated attacks. PSAPs and agencies should ensure they have 24/7 monitoring in place for both their mission-critical systems and IT networks to spot any abnormal activities. A comprehensive cyber incident response and disaster recovery plan that’s regularly tested is another must-have in today’s environment.
Summary
You don’t have to be a clairvoyant to understand that SocGholish is no treat for IT and security teams. The dangers it presents are very real, as malware infections can lead to disabled devices, data breaches, disruptions to communications and even downtime — all of which can cost precious minutes in the moments that matter.
For agencies and organizations without the staff to support 24/7 cybersecurity operations, or to research attacks in depth, a Managed Detection and Response (MDR) service provider like Motorola Solutions can help you better defend against SocGholish and similar threats. Every day, our Advanced Threats and Research team monitors dozens of threat intelligence sources, as well as millions of security alerts from a wide range of public safety and enterprise customers, to identify new attack techniques and emerging risks.
While there’s no magic spell to avoid cyber threats, engaging a 24/7 SOC with the experience and skillset to monitor and manage sophisticated Endpoint Detection and Response (EDR) tools and detect and shut them down on your behalf can make all the difference when it comes to fighting the evils that lurk when cyber criminals attack your organization.
Defend against cyber threats
Contact us today to find out how our ActiveEye security management platform and 24/7 SOC can help you combat threats.