Threat actors associated with the Vice Society ransomware gang have been observed using a bespoke PowerShell-based tool to fly under the radar and automate the process of exfiltrating data from compromised networks.
“Threat actors (TAs) using built-in data exfiltration methods like [living off the land binaries and scripts] negate the need to bring in external tools that might be flagged by security software and/or human-based security detection mechanisms,” Palo Alto Networks Unit 42 researcher Ryan Chapman said.
“These methods can also hide within the general operating environment, providing subversion to the threat actor.”