BSI explains first attack vector on Berlin authorities

BSI explains first attack vector on Berlin authorities
View on original source
Category: Politics
Share
Archive
Like
The Federal Office for Information Security (BSI) warns of a new attack campaign called 'TerminalFix'. The authority refers to an analysis by Microsoft. Explosive: TerminalFix was apparently the entry ticket for cybercriminals into the networks of the Berlin Senate. The attack, which became known in mid-August, led to massive data exfiltration with partially critical information. Continue after ad The BSI confirmed in a post on Mastodon that the TerminalFix method is the attack vector used by the cyber gang Rhysida. This information is not found in the authority's BSI security notice (BITS) ( PDF). However, on Mastodon, the BSI directly refers to this notice. Thus, it is certain: The Senate administrations for Building and Transport were attacked via TerminalFix. This is a variant of the malware campaign 'ClickFix', which Microsoft warned about back in February 2026. As already described in detail, users are tricked by ClickFix into executing the Windows Terminal. PowerShell is available there, through which commands can be given to the operating system, for example, to copy files or execute programs. TerminalFix differs from ClickFix primarily in that it uses Windows + X to access the Windows Terminal directly, rather than executing commands directly via Windows + R (as in 'run'), followed by pressing the 'I' key for direct access to PowerShell. A fake captcha leads to shell commands Via PowerShell, a malicious command is then executed, which the user must paste from the clipboard. It is there because it was copied there by a manipulated website before these actions via JavaScript. These websites, according to Microsoft, display a fake Cloudflare captcha. There is also a bit of social engineering involved here, because: The real Cloudflare captchas, to be effective, always have to look a little different and demand various things from the user. The fact that one sometimes has to press a few keys and not just click something might not be immediately apparent to unsuspecting users. The command that lands in PowerShell downloads the attackers' first malware from their systems in the background via a script. In the foreground, the manipulated website with the fake captcha prompts the user for further actions. The user is thus distracted while their PC is being infected. Among other things, the script calls the signed and benign Windows file 'LockScreenContentServer.exe', through which part of the malware is installed as 'dui70.dll' via sideloading. The code within downloads PNG image files from the attackers, in which further programs and DLLs are hidden using steganography. Continue after ad Persistent malware and proxy Subsequently, the package of malicious software installs itself persistently, i.e., permanently, via registry keys on the attacked system. Every 60 minutes, the malware checks if it is still running and listens for new commands from the attackers. They also set up a SOCKS proxy, thus having access to the attacked organization's network through a tunnel. What the user does there can therefore be monitored and intercepted, provided not everything is properly encrypted. As is common with professional attacks, all these actions are concealed, for example, by hiding files and directories from plain view in Windows Explorer. As a result, the attackers listen in and have at least access to the user's local files and the directories they can access. From there, they can work their way further. Since the Berlin authorities – as has already been confirmed – also maintained plaintext password lists, Rhysida likely had a relatively easy game. How the criminals gained access to apparently all the data of the two Senate administrations is still unclear. Public administrations are an easy target For all this to work, the first target person only needs to be lured into visiting a correspondingly manipulated website and then operating it as described. This can be done, for example, via a phishing email or a link via social media, in forums, or on websites. Such attacks are also called 'Water-Holing', as they are placed on websites where victims regularly gather -- similar to a watering hole that attracts herds of animals in the savanna. Since the names and email addresses, as well as personnel structures of authorities, are usually at least partially public, social engineering is easy to accomplish. And even if it only succeeds on perhaps the twentieth attempt: The demanded around 2 million Euros in Bitcoin make the effort worthwhile. Threats from gangs like Rhysida should be taken very seriously. As the BSI reports, citing an unnamed external service provider, in 92 percent of cases where criminals threaten publication, it actually occurs. Rhysida therefore primarily focuses on the healthcare and education sectors – government agencies are still among the five most frequently mentioned target types. (nie)

(0)Comments

 

A note on cookies

Newshunt uses essential cookies to keep you signed in and to remember your language and country, so the site works the way you expect. With your permission, we'd also like to use analytics cookies to understand how people use Newshunt and improve it over time.

Accepting only affects analytics. To learn more, view our Privacy Policy or Terms & Conditions.