APT36-Linked Multi-Stage Intrusion Explained | #ransomware | #cybercrime


Summary

A multi-stage intrusion was observed beginning with the abuse of KMS Auto to deliver a sequence of malicious payloads. The attack chain progressed from cryptocurrency mining via XMRig to remote access deployment using ScreenConnect and MeshAgent, culminating in a scareware payload masquerading as ransomware. The final stage utilized psychological tactics by changing wallpapers and displaying fake ransom prompts without actual file encryption.

Investigation

K7Labs analyzed a sequence of events where an initial KMS Auto execution led to a series of post-compromise activities with a consistent 12-24 hour interval between stages. Telemetry tracked the deployment of XMRig, followed by legitimate remote management tools used maliciously, and finally a payload named SecurityHealthServices.exe. Analysis confirmed the final payload was scareware designed to mimic ransomware behavior through visual defacement and file extension manipulation.

Mitigation

Organizations should restrict the use of unauthorized software activation utilities and monitor for the execution of known dual-use tools like XMRig or unauthorized RMM software. Implementing strict application whitelisting and monitoring for unusual file extensions or mass file renaming can help mitigate impact. Users should be educated to avoid unofficial software repositories and torrent sites for utility downloads.

Response

Upon detection, isolate the affected endpoint to prevent further stages of the multi-stage infection. Perform a full forensic sweep for hidden files in AppData and multiple persistence mechanisms in startup folders and registry run keys. Investigate the presence of unauthorized remote management tools like ScreenConnect or MeshAgent to identify the extent of attacker access.

Attack Flow

We are still updating this part.

Detections

Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)

SOC Prime Team

Alternative Remote Access / Management Software (via process_creation)

SOC Prime Team

Suspicious Binary / Scripts in Autostart Location (via file_event)

SOC Prime Team

IOCs (HashMd5) to detect: From KMS Auto to Scareware: Tracking a Multi-Stage Intrusion Linked to APT36?

SOC Prime AI Rules

Multi-Stage Intrusion Involving KMS Auto and APT36 Scareware Tactics [Windows Process Creation]

SOC Prime AI Rules

Simulation Execution

  • Attack Narrative & Commands: An adversary has gained initial access and intends to deploy a cryptocurrency miner and remote access tools to maintain long-term presence and monetize the breach. The attacker first executes a tool named kmsauto_setup.exe from a temp directory. They then attempt to launch xmrig.exe to begin resource hijacking. To facilitate remote control, they drop and execute meshagent.exe. This sequence creates the specific string patterns the detection rule is designed to catch.

  • Regression Test Script:

    # Simulation of APT36-style multi-stage execution for rule validation
    $tempDir = "$env:TEMPSimulatedAttack"
    New-Item -ItemType Directory -Path $tempDir -Force | Out-Null
    
    # 1. Simulate KMS Auto execution (Triggering 'kmsauto' in Image path)
    $kmsPath = Join-Path $tempDir "kmsauto_installer.exe"
    New-Item -Path $kmsPath -ItemType File -Force | Out-Null
    Write-Host "[+] Simulating KMS Auto execution..."
    Start-Process $kmsPath -ArgumentList "/silent" -ErrorAction SilentlyContinue
    
    # 2. Simulate XMRig execution (Triggering 'xmrig' in CommandLine)
    $xmrigPath = Join-Path $tempDir "xmrig.exe"
    New-Item -Path $xmrigPath -ItemType File -Force | Out-Null
    Write-Host "[+] Simulating XMRig execution..."
    Start-Process $xmrigPath -ArgumentList "--donate-level=1 --cpu-max-threads-pct=50" -ErrorAction SilentlyContinue
    
    # 3. Simulate MeshAgent execution (Triggering 'meshagent' in CommandLine)
    $meshPath = Join-Path $tempDir "meshagent.exe"
    New-Item -Path $meshPath -ItemType File -Force | Out-Null
    Write-Host "[+] Simulating MeshAgent execution..."
    Start-Process $meshPath -ArgumentList "--install" -ErrorAction SilentlyContinue
    
    Write-Host "[!] Simulation complete. Check SIEM for alerts."
  • Cleanup Commands:

    # Cleanup simulation artifacts
    $tempDir = "$env:TEMPSimulatedAttack"
    if (Test-Path $tempDir) {
        Remove-Item -Path $tempDir -Recurse -Force
        Write-Host "[+] Cleanup successful: $tempDir removed."
    } else {
        Write-Host "[!] Cleanup failed: Directory not found."
    }



Click Here For The Original Source.

——————————————————–

..........

.

.