FlawedGrace

Malware updated 23 days ago (2024-11-29T14:17:24.013Z)
Download STIX
Preview STIX
FlawedGrace is a notorious malware, a remote access trojan (RAT), that has been used extensively in cyberattacks. It was first brought to light in June 2023 when The DFIR Report revealed its use in Truebot operations. In these operations, following the successful download of a malicious file, Truebot would rename itself and then load FlawedGrace onto the host system. This malware was also delivered via email as a compressed attachment and exploited vulnerabilities to issue commands via the SysAid software. A significant feature of FlawedGrace is its ability to modify registry and print spooler programs that control the order that documents are loaded to a print queue. The Lace Tempest operators and a Russian-speaking gang have been identified as users of FlawedGrace, utilizing it to escalate privileges, establish persistence on compromised systems, and conduct additional operations. The malware has been associated with ransomware such as Cl0p and LockBit, and the TrueBot botnet. Microsoft confirmed this in a tweet, stating that the Russian-speaking gang loads GraceWire, another name for FlawedGrace, onto compromised systems. Once deployed, FlawedGrace creates scheduled tasks and injects payloads into msiexec, enabling it to establish a command and control (C2) connection and load dynamic link libraries (DLLs) for privilege escalation. The US Cybersecurity & Infrastructure Security Agency (CISA) highlighted that during FlawedGrace's execution phase, the RAT stores encrypted payloads within the registry. After breaching networks, the cybercriminals install FlawedGrace to escalate their privileges and establish persistence on the compromised systems. By leveraging Truebot to download FlawedGrace or Cobalt Strike beacons, they gain further network access once they infiltrate the Active Directory server. Hence, the FlawedGrace malware poses a significant threat to cybersecurity, and organizations need to take adequate measures to safeguard their systems.
Description last updated: 2024-05-04T16:28:00.752Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Truebot is a possible alias for FlawedGrace. Truebot is a malicious software (malware) utilized by the CL0P actors, designed to exploit and damage computer systems. This malware can infiltrate systems through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside, Truebot serves multiple purposes: it can dow
5
Gracewire is a possible alias for FlawedGrace. Gracewire is a potent malware that has been deployed by threat actors to exploit and damage computer systems. It is typically delivered through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside a system, it can steal personal information, disrupt operations,
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Rat
Payload
Cobalt Strike
Phishing
Ransomware
Trojan
Loader
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Get2 Malware is associated with FlawedGrace. Get2 is a type of malware, harmful software designed to infiltrate and damage computer systems or devices. It can be unknowingly downloaded through suspicious emails, downloads, or websites, enabling it to steal personal information, disrupt operations, or hold data hostage for ransom. Among the mosUnspecified
4
The Clop Malware is associated with FlawedGrace. Clop, a malicious software (malware), is linked to a Russian-speaking cybercriminal group also known as Cl0p. It is designed to exploit and damage computer systems by stealing personal information, disrupting operations, or holding data hostage for ransom. In May 2023, the Clop group began exploitinUnspecified
3
The truebot malware Malware is associated with FlawedGrace. Truebot malware is a malicious software that infiltrates computer systems, often without the user's knowledge, to exploit and damage the device. It was primarily delivered by cyber threat actors via malicious phishing email attachments, but newer versions observed in 2023 also gained initial access Unspecified
2
The Sdbot Malware is associated with FlawedGrace. SDBot is a malicious software, or malware, that has been leveraged by threat actors known as TA505 and CL0P to exploit vulnerabilities in computer systems. It is used as a backdoor to enable the execution of commands and functions in the compromised computer, often without the user's knowledge. The Unspecified
2
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The TA505 Threat Actor is associated with FlawedGrace. TA505, also known as Cl0p Ransomware Gang and Lace Tempest, is a highly active and sophisticated cybercriminal group. The group has been associated with various high-profile cyber-attacks, demonstrating adaptability through a multi-vector approach to their operations. In June 2023, the U.S. CybersecUnspecified
4
The cl0p Threat Actor is associated with FlawedGrace. Cl0p is a threat actor group that has emerged as the most used ransomware in March 2023, dethroning LockBit. The group has successfully exploited zero-day vulnerabilities in the past, but such attacks are relatively rare. Recent research by Malwarebytes highlights the bias of ransomware gangs for atUnspecified
2
Source Document References
Information about the FlawedGrace Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
BankInfoSecurity
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago
CISA
a year ago
Flashpoint
2 years ago
CISA
2 years ago
CERT-EU
2 years ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago