Inside the Hacker’s Arsenal: A Comprehensive Guide to Tools for Everything from Entry to Total Dominance

Cybersecurity experts have unearthed an extensive collection of hacker tools, revealing a detailed array of instruments designed to execute various stages of cyberattacks.

The toolkit, discovered in an unprotected directory, highlights the advanced techniques used by cybercriminals to infiltrate and control compromised systems. The discovery, made in early December 2023, exposed an assortment of batch scripts and malware targeting both Windows and Linux environments. These tools illustrate the hackers’ capacity to conduct a range of malicious activities, from breaching systems to maintaining control and extracting data.

Prominent among the findings were PoshC2 and Sliver, two prominent command and control (C2) frameworks. Although these open-source tools are commonly used by ethical hackers and security teams, they have been co-opted by malicious actors to facilitate their operations, signaling the attackers’ aim to establish enduring access to compromised networks.

The toolkit also featured a range of custom batch scripts intended for evading detection and manipulating systems. Scripts like atera_del.bat and atera_del2.bat were designed to eliminate Atera remote management agents, potentially erasing traces of legitimate administrative tools.

Additional scripts such as backup.bat and delbackup.bat were geared towards deleting system backups and shadow copies, a typical strategy to obstruct data recovery in ransomware scenarios.

The DFIR Report highlighted the inclusion of clearlog.bat, a script capable of wiping Windows event logs and removing traces of Remote Desktop Protocol (RDP) usage, underscoring the attackers’ focus on obscuring their activities and avoiding detection.

The toolkit also comprised several specialized utilities:

  • cmd.cmd: Disables User Account Control and adjusts registry settings
  • def1.bat and defendermalwar.bat: Deactivate Windows Defender and uninstall Malwarebytes
  • disable.bat and hyp.bat: Stop and disable various essential services
  • LOGOFALL.bat and LOGOFALL1.bat: Log off user sessions
  • NG1.bat and NG2.bat: Contain Ngrok authentication tokens for proxy functions
  • Ngrok.exe: A legitimate utility repurposed for proxy services
  • Posh_v2_dropper_x64.exe: PoshC2 dropper for Windows
  • native_dropper: Linux variant of the PoshC2 dropper
  • py_dropper.sh: Bash script to run a Python dropper for PoshC2
  • VmManagedSetup.exe: SystemBC malware executable
  • WILD_PRIDE.exe: Executable for the Sliver C2 framework

This discovery offers crucial insights into the tools and techniques utilized by contemporary cybercriminals. It emphasizes the necessity for strong cybersecurity practices and the need for organizations to stay alert against evolving threats.

Experts recommend that organizations adopt comprehensive security measures, including regular system updates, employee training, and advanced threat detection solutions to guard against such sophisticated attack toolkits.

Researchers speculate that these tools were likely employed in ransomware attacks, given their focus on disrupting services, deleting backups and shadow copies, and disabling or removing antivirus software. For a detailed list of Indicators of Compromise (IoCs), visit https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/.

More Articles & Posts