APT36-Linked Campaign Uses KMS Auto in a Multi-Stage Intrusion
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A multi-stage intrusion was observed beginning with the abuse of KMS Auto to deliver a sequence of malicious payloads. The attack chain progressed from cryptocurrency mining via XMRig to remote access deployment using ScreenConnect and MeshAgent, culminating in a scareware payload masquerading as ransomware. The final stage utilized psychological tactics by changing wallpapers and displaying fake ransom prompts without actual file encryption.
Investigation
K7Labs analyzed a sequence of events where an initial KMS Auto execution led to a series of post-compromise activities with a consistent 12-24 hour interval between stages. Telemetry tracked the deployment of XMRig, followed by legitimate remote management tools used maliciously, and finally a payload named SecurityHealthServices.exe. Analysis confirmed the final payload was scareware designed to mimic ransomware behavior through visual defacement and file extension manipulation.
Mitigation
Organizations should restrict the use of unauthorized software activation utilities and monitor for the execution of known dual-use tools like XMRig or unauthorized RMM software. Implementing strict application whitelisting and monitoring for unusual file extensions or mass file renaming can help mitigate impact. Users should be educated to avoid unofficial software repositories and torrent sites for utility downloads.
Response
Upon detection, isolate the affected endpoint to prevent further stages of the multi-stage infection. Perform a full forensic sweep for hidden files in AppData and multiple persistence mechanisms in startup folders and registry run keys. Investigate the presence of unauthorized remote management tools like ScreenConnect or MeshAgent to identify the extent of attacker access.
Attack Flow
We are still updating this part.
Detections
Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)
Alternative Remote Access / Management Software (via process_creation)
Suspicious Binary / Scripts in Autostart Location (via file_event)
IOCs (HashMd5) to detect: From KMS Auto to Scareware: Tracking a Multi-Stage Intrusion Linked to APT36?
Multi-Stage Intrusion Involving KMS Auto and APT36 Scareware Tactics [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: An adversary has gained initial access and intends to deploy a cryptocurrency miner and remote access tools to maintain long-term presence and monetize the breach. The attacker first executes a tool named
kmsauto_setup.exefrom a temp directory. They then attempt to launchxmrig.exeto begin resource hijacking. To facilitate remote control, they drop and executemeshagent.exe. This sequence creates the specific string patterns the detection rule is designed to catch. -
Regression Test Script:
# Simulation of APT36-style multi-stage execution for rule validation $tempDir = "$env:TEMPSimulatedAttack" New-Item -ItemType Directory -Path $tempDir -Force | Out-Null # 1. Simulate KMS Auto execution (Triggering 'kmsauto' in Image path) $kmsPath = Join-Path $tempDir "kmsauto_installer.exe" New-Item -Path $kmsPath -ItemType File -Force | Out-Null Write-Host "[+] Simulating KMS Auto execution..." Start-Process $kmsPath -ArgumentList "/silent" -ErrorAction SilentlyContinue # 2. Simulate XMRig execution (Triggering 'xmrig' in CommandLine) $xmrigPath = Join-Path $tempDir "xmrig.exe" New-Item -Path $xmrigPath -ItemType File -Force | Out-Null Write-Host "[+] Simulating XMRig execution..." Start-Process $xmrigPath -ArgumentList "--donate-level=1 --cpu-max-threads-pct=50" -ErrorAction SilentlyContinue # 3. Simulate MeshAgent execution (Triggering 'meshagent' in CommandLine) $meshPath = Join-Path $tempDir "meshagent.exe" New-Item -Path $meshPath -ItemType File -Force | Out-Null Write-Host "[+] Simulating MeshAgent execution..." Start-Process $meshPath -ArgumentList "--install" -ErrorAction SilentlyContinue Write-Host "[!] Simulation complete. Check SIEM for alerts." -
Cleanup Commands:
# Cleanup simulation artifacts $tempDir = "$env:TEMPSimulatedAttack" if (Test-Path $tempDir) { Remove-Item -Path $tempDir -Recurse -Force Write-Host "[+] Cleanup successful: $tempDir removed." } else { Write-Host "[!] Cleanup failed: Directory not found." }