Conti Move To Remote System

Using the Jambi agent from the previous chain, discover targets on the Active Directory and then perform targeted lateral movement of the Jambi agent by first moving the agent to the desired target and then starting the agent.

TTP Tuesday: Conti (Release 4)

Move to remote systems

Theme Overview

We're releasing the fourth installment of our Conti ransomware theme with new TTPs focused on Windows lateral-movement using live off the land techniques. To date, our Conti theme now contains the following kill-chains:

1. Recon and Initial Access
2. Local and Remote Discovery
3. Gain privileges and persist
4. Move to remote systems (Current Release)
5. Data collection and exfiltration
6. Deploy ransomware

Move To Remote Systems

This chain performs lateral movement within the domain. First, we check for all hosts on the domain. After selecting a target, we then enable access to the target's storage resources. We then move the agent executable from our current host to the target host. Finally, we execute the agent on the target host performing lateral movement within the domain. This chain does have a user custom fact for the target host information which you can provide in the facts section, or you can modify the TTP itself removing #{target.host} and providing the information manually.

Watch a demonstration: Conti Move to Remote Systems

Staying up to date

Thanks for reading our latest TTP Tuesday release! Please subscribe and reach out with any feedback. We love to hear from our community!

There are several ways to follow us and learn more about Prelude and our team members:

Get our products

Download Prelude Operator: https://www.prelude.org/download/current
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg

Join our community

Discord: https://discord.gg/gzUv4XNquu
Reddit: https://www.reddit.com/r/preludeorg/
Twitter: https://twitter.com/preludeorg

Read, watch, and listen

Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org
Watch our live streams: https://www.twitch.tv/preludeorg
Watch our pre-recorded content: https://www.youtube.com/c/preludeorg

Follow our team

David: privateducky
Alex: khyberspache
Kris: Xanthonus
Octavia: VVX7
Sam: wasupwithuman

Source: https://feed.prelude.org
Read more

Execute this chain

Download Operator (1.7.1)
Learn about Operator

TTPs

Conti list all computers in domain
Provides access to target shared resources
Conti agent lateral movement
Conti start agent remotely

User-Set Custom Variables

  • target.host: TARGET.domain.tld