Threat Actor OPSEC mistakes during a CI/CD container operation

No ratings

Presented at Texas Cyber Summit 2023 by

A deep dive into the freejacking operations of PurpleUrchin, a South African-based freejacking operation, revealed unique forensic findings as well as geo-location identifiers for the actors behind this operation. PurpleUrchin primarily targets cloud platforms offering limited-time trials of cloud resources and they perform their crypto mining operations using CI/CD techniques such as vast container deployments and cross-platform architectures. In this talk, we will perform a deep dive into the container forensic techniques we used to uncover the creation of more than 130,000 automated user accounts across multiple targets, as well as, how the actor's poor OPSEC allowed researchers to zero in on their physical locations, and the gathering key metadata IOCs used to pivot and provide mitigation strategies. The audience for this talk will come away with a deeper understanding of how threat actors leverage CI/CD techniques to massively scale their malicious operations as well as how OPSEC leakages can lead researchers to identify not only the administrative API keys of several cryptocurrency exchanges used in the operation but also the geo-location of the actors themselves.Long:Unit 42 researchers performed a deep dive into the freejacking operations of PurpleUrchin. This South African-based "œorganization" primarily targets cloud platforms offering limited-time trials of cloud resources to perform their crypto mining operations. The actors are known to heavily use automation techniques typically associated with Continuous Integration and Continuous Development (CI/CD) DevOps practices to build a highly modular and containerized freejacking architecture. During this talk, we will lead the audience through our discovery of how PurpleUrchin actors created on average between three to five GitHub accounts every minute during their freejacking operations and performed these account creations, in some cases, by bypassing captcha images using simple image analysis techniques, leading to the creation of more than 100,000 user accounts created on cloud platform services Heroku and 20,000 accounts on GitHub.Using operational security (OPSEC) missteps performed by the PurpleUrchin operators during the creation of their CI/CD container creation operations, we were able to glean geo-location information from the container architecture that allowed researchers to locate the physical location of the actors. In order to discuss how these missteps were determined, we need to first discuss how the architecture was built and operated. We will lead the audience through the hosting and cloud service providers that were used, targeted, or otherwise compromised and how these instances were used within the larger mining architecture.Following the description and walkthrough of the different types of platforms used to host the mining operations, we will perform a deep dive into the automation of the container operations themselves. Specifically focused o