{"id":2018,"date":"2024-09-25T15:47:14","date_gmt":"2024-09-25T14:47:14","guid":{"rendered":"https:\/\/aegislens.com\/home\/?p=2018"},"modified":"2024-09-25T15:47:14","modified_gmt":"2024-09-25T14:47:14","slug":"cyberattacks-impacting-transportation-firms-with-lumma-stealer-netsupport-malware-a-comprehensive","status":"publish","type":"post","link":"https:\/\/aegislens.com\/home\/cyberattacks-impacting-transportation-firms-with-lumma-stealer-netsupport-malware-a-comprehensive\/","title":{"rendered":"Cyberattacks Impacting Transportation Firms with Lumma Stealer &#038; NetSupport Malware: A Comprehensive"},"content":{"rendered":"<p>as six malware families, including a novel info stealer, Lumma, and NetSupport RAT have been identified in relation to this cluster.<\/p>\n<h2>The Email Phishing Campaign<\/h2>\n<p>The criminals behind these attacks leverage multiple tools and methodologies, resulting in complex and sophisticated attack patterns.<\/p>\n<p>These attacks often start with a simple email.<\/p>\n<p>Attackers compromise legitimate email accounts within transportation companies and inject themselves into ongoing email conversations.<\/p>\n<p>The malicious actors attach a macro-laden document in the chain, which serves as the main infection vector in this campaign.<\/p>\n<p>Once the recipient opens the document and enables macros, the malware infection process begins (<a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/transportation-and-shipping-companies-hijacked-conversations\" rel=\"nofollow\">Proofpoint<\/a>).<\/p>\n<h2>Lumma Stealer and NetSupport Malware<\/h2>\n<p>Lumma, a novel info stealer first seen in relation to this activity cluster, harvests information from the victim\u2019s system, including system hardware, installed software, and running processes.<\/p>\n<p>This malware then proceeds to steal files from the system, often focusing on documents with certain extensions, like .doc, .docx, .pdf, and .xls.<\/p>\n<p>After stealing the required information, Lumma exfiltrates the data to a command and control server controlled by the attackers.<\/p>\n<p>Also in circulation in this campaign is the NetSupport Manager, a legitimate remote administration tool, repurposed as a remote access trojan (RAT).<\/p>\n<p>With extensive capabilities including screen capturing, file transferring, and remote desktop control, NetSupport provides cybercriminals with complete control over infected systems (<a href=\"https:\/\/www.netsupportsoftware.com\/netsupport-manager-remote-control\/\" rel=\"nofollow\">NetSupport<\/a>).<\/p>\n<h2>Impact and Previous Attacks<\/h2>\n<p>The impact of such cyberattacks on transportation companies is immense.<\/p>\n<p>Besides disruptions in operations, data theft exposes sensitive company information, leading to potentially unbudgeted recovery costs, and reputational damage.<\/p>\n<p>There have been notable similar attacks in the past, with Maersk suffering a $300 million loss to the notorious NotPetya incident in 2017 (<a href=\"https:\/\/www.bbc.com\/news\/technology-41095606\" rel=\"nofollow\">BBC News<\/a>).<\/p>\n<h2>Recommendations<\/h2>\n<p>Transportation companies must be proactive in their cybersecurity measures.<\/p>\n<p>Regular training should be done to ensure employees are aware of the threats posed by phishing emails and how to recognize them.<\/p>\n<p>Companies must keep all their software updated, regularly patch their systems, use strong, unique passwords, and employ multi-factor authentication.<\/p>\n<h2>Next Steps<\/h2>\n<p>To mitigate future threats, organizations should consider implementing advanced threat protection solutions that can ward off these kinds of blended attacks.<\/p>\n<p>Early detection is key in mitigating the risks posed by these malicious campaigns.<\/p>\n<p><strong>Follow-Up Reading:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/www.csoonline.com\/article\/3235947\/what-is-phishing-how-this-cyber-attack-works-and-how-to-prevent-it.html\">What is Phishing: A Comprehensive Guide to Phishing Attacks<\/a><\/li>\n<li><a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/6-ways-attackers-are-still-bypassing-sms-2-factor-authentication-\/a\/d-id\/1331683\">Six Ways Attackers Are Bypassing Two-Factor Authentication<\/a><\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/netsupport-manager-rat-abused-in-malware-attacks-disguised-as-covid-19\/\">NetSupport Manager RAT &#8211; Understand and Protect Against Its Abuse<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>as six malware families, including a novel info stealer, Lumma, and NetSupport RAT have been<\/p>\n","protected":false},"author":1,"featured_media":2019,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2,5],"tags":[],"class_list":["post-2018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-news","pmpro-has-access"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/comments?post=2018"}],"version-history":[{"count":1,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2018\/revisions"}],"predecessor-version":[{"id":2022,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2018\/revisions\/2022"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media\/2019"}],"wp:attachment":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media?parent=2018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/categories?post=2018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/tags?post=2018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}