CheckMesh: Hidden Threats in Your FW

2024-07-09 • Hackers Eye •

https://hackerseye.net/all-blog-items/checkmesh/

Thumbnail for CheckMesh: Hidden Threats in Your FW

HackersEye describes an intrusion against an Israeli enterprise where an attacker used admin access to a Check Point firewall, moved from the GAIA web interface to SSH, and installed a malicious MeshAgent based ELF implant. The implant disguised itself as a legitimate process, gave the attacker encrypted C2 and persistence on the firewall Linux system, and let the actor operate as root. The attacker then used the firewall foothold for credential theft, password spraying or brute force activity, port forwarding, and RDP tunneling into internal systems. HackersEye says the TTPs resemble Cisco Talos reporting on LilacSquid, but the excerpt frames the attribution as similarity based rather than definitive.

Indicators of Compromise

Type Value First Seen Last Seen
YARA MeshAgent_Config 2024-07-09 2024-07-09
YARA MeshAgent_ELF 2024-07-09 2024-07-09
HASH 1134af27bea8518c62444a56f4bd4bc… 2024-07-09 2024-07-09
HASH 3840acb15880f6cb0a77347d4a3893c… 2024-07-09 2024-07-09
HASH 460acbb38b0bdb3d227de65010b1a32… 2024-07-09 2024-07-09
HASH c3f35c99bf40d43b4eaa759a92f9a1b… 2024-07-09 2024-07-09
DOMAIN gupdate.net 2024-07-09 2024-07-09
DOMAIN api.gupdate.net 2024-07-09 2024-07-09
IPv4 51.16.51.81 2024-07-09 2024-07-09
IPv4 78.141.238.182 2024-07-09 2024-07-09

Related Actors

Related Reports

« Back