2022 Unit 42’s Brute Ratel C4 Research – Jen Miller-Osborn, Palo Alto Networks
Jen Miller-Osborn, Deputy Director of Threat Intelligence, Unit 42 at Palo Alto Networks joins Alan Shimmel to discuss a recent Unit 42 blog post from July about Brute Ratel C4, a penetration testing and adversary emulation framework. This tool is similar to Cobalt Strike, a common pentesting framework that is known to be leveraged by ransomware and APT actors (ex. Solarwinds). Brute Ratel C4 is specifically engineered to evade modern Endpoint Detection and Response (EDR) and AntiVirus (AV) capabilities. This Unit 42 research is significant in that it identifies a capability that is largely undetectable across most cybersecurity vendors with a growing user base that is now being adopted for malicious purposes by APTs. Unit 42 has shared its findings widely with government and industry partners around the globe, providing technical indicators that will help organizations identify activity from this tool. Unit 42 has also encouraged security vendors to create protections to detect related activity.
Transcript
This is texturing TV. Hey everyone, welcome to another tech strung TV segment here. I am really happy.
She hasn't been on in way too long. My friend Jen Miller Osborne from unit 42 over at Palo Alto. Hey Jen, how are you?
Hi, I'm doing well. How are you? It's good to see you again.
It's good to see you. I hope you've been doing well over the last couple months. It's been exciting kind of times I guess is you know, it's always exciting and security.
There's so much stuff flying around. But all good. Hey Jen for those who maybe are not I'm sure all of our audience knows Palo Alto networks, but they may not be familiar with unit 42 give them a quick little background and maybe a little bit of your background.
Sure, so unit 42 is both the threat intelligence and the security component part of Palo Alto networks previously before we had the Consulting arm. We were just right intelligence arm and the company realized we were bringing on an instant response firm that the most natural fit was within unit 42 because the what attackers were doing post compromise was really the only data point we were missing from a threat intelligence perspective previously. So this that filled that Gap so now we have the two components that run one.
That's the incident response side and then we have the threat intelligence side. Right and any kind of makes sense, right you get your thread Intel and and The Logical? Kind of next shoot a job is okay.
What happens here? When when it hits you? We're right and and so what's our incident response and those are both you know for someone like me who's been in security really long time where it was all about prevention.
Right the idea of thread in town and incident response. was when they first became kind of mainstream was like wow, there's different, but it's kind of you know standard operating procedure now, right if you're especially in Enterprise, but any organization out there you've got to be You know think about thread intelligence incident response. So it makes sense.
And of course, you know 42 and Palo Alto is one of the one of the Premier organizations in that industry, Jen. What about you? For people are not familiar with your background.
Uh, yeah, I am the deputy director of threat intelligence with unit 42 here before coming to unit 42. This is actually my first job in the private sector. I spent almost 10 years in the Air Force as a Chinese Mandarin translator, and then that's also where I was able to start getting into cyber security when it was a nascent field and they were looking for people that were kind of computer geeks.
Basically that had an interest in giving it a try from there. I did Contracting for a number of different three letter agencies also with the focus in cyber security and then I came here to unit 42 and I've been here ever since Very cool. Appreciate it.
So Jen, let's jump into what we want to talk about today, which is You know, all right. We were talking off camera that I've been traveling a bunch and one of the I took a little vacation in Greece and we were on this big. 120 foot boat, which was to me.
I mean it was crazy. But one of the things I learned that they say on both is there's always a bigger boat. And and it's the same thing with malware.
There's always a worse malware unfortunately, right. So it looks like we have a case of a worse malware coming out now that you guys have kind of led the charge on. Why don't you educate us?
Yeah. So what we've seen with cybersecurity over the years and I don't think this will be a surprise to any of the audiences we've seen attackers increasingly trying to figure out new ways to be successful, you know new adding on to their malware adding new capabilities and well we have here it's a tool called root retail C4 is actually a red teaming tool that's what it was designed for. It was red teaming in pen testing.
So it's meant to be legitimately used by organizations who are testing their own defenses what we've seen unfortunately and this is very similar to what we've seen with Cobalt strike as well where it was developed intending to for good. Was developed as a red team or a penny fantastic tool, but because you're developing something to test defenses and see if you can compromise something. It also makes that very attractive to malicious actors if they can actually get their hands on it because it's often very fully featured has a lot of functionality can be easy to use because it was designed to be sold.
To professional teams the new one that we're seeing now Cobalt strike in and of itself has been just a headache for everyone in the industry and continues to be so and this new one is unique in that the developer wrote it. With the goal of getting around and point detection Solutions and their protections. He had a background from both crowdstrike.
And so we had a lot of experience in this field before he moved into producing this tool and what we saw in our when we were reversing it and when we were running our tests very few vendors had out of the box protections for this and it was very very difficult to actually create protections for it's very challenging. It's going to be already is now the the next Cobalt strike. As it were you know, look this is not news.
You mentioned Cobalt strike. And I'm drawing a blank the open source pen testing tool HD Moore Medical. Terribly get all.
You know look people were using medusport for this years and years and years ago because that was an open source store. So every bad guy you wanted it got there hands on it. Now.
I'm not blaming HDM the meditate people. I'm not being blaming the people behind Cobalt strike. I'm not even gonna blame this person right tools.
We we need these tools have a legitimate purpose. It's when they're misused in the wrong hands. That we we have this and and I guess the real issue is how do you prevent?
The bad guys from getting their hands on this stuff. Right in the case of Open Source. It's impossible.
But in the case of these tools that are not necessarily open source. What what do we you know, how what do you do? What we've seen with some of the other companies is they'll have contract language when they're selling the licenses that it can only be used for legitimate purposes or pen testing red seeming whether or not the person who's buying it intends to hold to that can be a different story.
And then the more these tools are used in different legitimate attempted red teaming and Pen testing exercises. The more chance there is for one of the samples to end up somewhere public like on virus total that's actually where we found the first sample of this was there and then it's it's outside of the developer's hands at that point. That's you know, how we got a hold of it to reverse it.
That's how attackers are getting a hold of it to use it. We've seen some rantelware families definitely starting to adopt this tool and use it in place of cobalt strike because they've also recognized how Functional it is and how useful it can be for them. And it's just it's that constant.
You know you write these tools. They're meant to be for the Defenders to be able to help you or for your administrators to be able to more easily take care of the networks. And then the problem is that those exact same tools that are meant for that can then also be used by attackers because they're trying to carry out the same sorts of activities within your network or against your network.
They're just trying to do them for malicious purposes. So, I mean we all do respect. Putting a contract clause in there that says there should only be used for lawful purposes.
It sounds like the if you outlaw guns only Outlaws have guns the bad guys. Don't give a crap. They don't know what I mean.
They don't care what it says in the contract because what they're doing is illegal anyway, right and and so I'm wondering if there is it. Some other kind of is there a biometric or two factor or something that you've got this software. But before you can function you've got to get a one-time use code or you've got to You know, you got to do something that validates you are who you say you are and you're using it for the purpose.
You say you're using it so that we can rapidly Trace back right with a verification of identity and stuff like that of whose hands attend and and maybe that'll be too much of a you know, a Pia. for the legitimate users and and impede the use of the tool but when you weigh You know balancing the the good and the bad here. Maybe it's worth it.
Yeah, it could be I think one of the things is once these are going to get out. It's you're just kind of stock for root retail. There are specific keys at least so the author says there are specific keys by customer by contract and he noted that if you would send him those then he'll disable the accounts doing malicious activity because once it's sold they don't necessarily know how it's going to be used either if they're selling it thinking this is someone who's using it for legitimate purposes, unless someone that actually gets hacked with it.
Contacts them to be like, hey, this was your tool that that happened. There's no way for the developers to even really know. That it's being used that way.
Absolutely. And again, I'm not blaming the developers. I'm not saying we don't need these tools, you know, there's a legitimate need for these kinds of tools, right?
I just you know, there's got to be a better way I think to because I mean a tool like right so this one is A generation ahead of cobalt strike. It evades endpoint. detector it's the next one going to be right and the one after that and You know if we can't.
We've got to put some common sense not to sound like a politician, but we got to put some common sense. Restrictions here because otherwise, I mean what what do we supposed to do? What's unit?
42 Gonna Do Right? We've got some thread into I guess it's good business for the incident response piece of it. Huh?
But I mean, how how do you stop this? That's why we wrote up the blog and made sure it was technical enough that. Other organizations could figure out how to put Protections in place because we recognized not only did we need to do research and up our protections, but that it was likely a lot of other people in the industry were going to be in the same space.
So we chose to publish it. We pre-briefed a number of governments about it in advance to make them aware that this was a new threat that they should be looking for. We really just tried to drive the level of Community awareness that this was a tool being used for malicious activity now and here at least when we published that was the current version.
So here's you know information that you can use to get a leg up and actually be able to detect this and defend against it. Because yeah to your point. That's the only real way people know is if there's if There's word out there.
That is happening. Yeah. Well look.
You know putting shining a light on these. Dark underbellies of the net with you know, this kind of bad. Crap happens is is always a good thing to do.
You know what for people want to get more information around this. Where could you mention the blog posts? Where can when they get that?
It is a very long URL. It is unit 42 dot Palo Alto Networks. calm And you'll get to our blog site and this researchers.
Yep, all of our research is there and we also recently published our first incident response paper. So there's links to that and the highlights of the what we found there as well if people haven't seen that yet. Very cool.
It's not that hard to remember guys. It's unit 42. com.
Excellent. So Jen we're we're filming this black hat DEF CON week. Your home I'm home.
We didn't go. any any big news though coming out of black cat from the unit 42 team that you are you free to talk about one of our members Michael Sikorski will actually be giving a talk on Cobalt strike and brute retell and what that means for the community that tools like this are being Abused and weaponize and how we what we need to look out for and how we can potentially get ahead of that kind of problem. All right.
So for our friends watching this, so the time you see it blackheads probably over because this probably won't play till at least later this week early next week, but definitely check that out if you're there Jen anything else exciting? You want to share with the audience? So just you know, same old same old, it's always interesting interview.
Well, I'm sure we'll talk again the next time that this tool gets an update and we need to share more about possibility for abuses if we don't see a Jen that means things are generally. Simmering not boiling over that's true. That's what I wanted to be quiet for what?
That would be nice. Hey stay cool out there. Thanks for coming on.
It's a pleasure to see you as always and keep up the great work to you and the whole uniform 42 team Jen. Thank you. Good to see you.
All right, Jen Miller Osborne from unit 42 Palo Alto networks here on techstrong TV. We'll take a break and we're going to be back in a moment with another guest.