Cado Security today released new research on the Legion hacking tool, which is used by threat adversaries to steal user credentials in the cloud and abuse carrier networks and SMS text messages from major carriers including AT&T, Sprint and Verizon. Legion is described by Cado Security as a Python-based credential harvester and hacktool.

The researchers suspect that Legion is related to AndroxGh0st malware family that first emerged in December 2022. Legion is a hacking tool that  can retrieve credentials for various web services, including email providers, cloud service providers, server management systems, databases, and payment platforms like Stripe and PayPal. Additionally, Legion can hijack SMS messages and compromise AWS credentials. According to Cado Security, Legion is being sold to would-be-hackers via the Telegram messaging service and there are even tutorial videos available.

"Legion is different to other credential harvesting tools as it focuses on compromising SMTP (email and SMS) services," Matt Muir, Threat Intelligence Researcher at Cado Security, told SDxCentral. "It is an SMTP abuse tool primarily but it relies on opportunistic exploitation of misconfigured web services to harvest credentials for said abuse." It also bundles additional functionality traditionally found in more common hacktools, such as the ability to execute web server specific exploit code and bruteforce account credentials.

The state of credential harvesting tools in 2023

The concept of credential harvesting is all about attackers using tools to collect or harvest credentials like usernames and passwords. With stolen or harvested credentials, attackers can then go on to execute other malicious operations including data theft and other forms of fraud.

Muir commented that from his perspective, Legion appears to be part of an emerging generation of cloud-focused credential harvester utilities. He noted that developers of these tools often steal each other's code, making attribution to a particular group difficult.

Cado Security's research has shown that Legion bears some similarities to tools such as Andr0xGhost, discovered by Lacework, and AlienFox, discovered by SentinelOne. These tools are often distributed via Telegram and their features make them attractive to those wishing to conduct mass spam or phishing operations.

"Based on the sample we analyzed, it appears that Legion is sold as a tool under a perpetual license model," Muir said. "Generally a one-off fee is paid to the administrator of the Telegram group where the tool is advertised."

Legion is not exploiting new vulnerabilities

It's important to note that Legion is not some kind of zero-day attacker tool.

Rather it is taking advantage of previously disclosed vulnerabilities and misconfigurations. Legion makes use of the Shodan search engine, which is a service that can help users to identify services and websites that might be running particular versions of code.

"Much of the exploit code shipped with the tool is derived from public Proof of Concepts or based on code from other offensive security tools," Muir said. "Shodan is most likely used to gather targets and the vulnerability exploitation features are then leveraged against the targets in an opportunistic manner."

Looking at how Legion abuses telecom carrier networks, the tool is also opportunistic. Muir explained that Legion builds up lists of telco or area specific numbers to target using Python web scraping. It then uses SMTP credentials retrieved during the credential harvesting phase to send messages to the numbers.

"Phishing would be an obvious use for this functionality but it can also be useful for general spamming operations," Muir commented. "If you have a requirement to send SMS  messages en masse to random phone numbers then Legion can help with this."

It's unclear exactly how many attackers are currently making use of Legion or what the financial impact of Legion attacks might be on organizations. Muir said that there isn’t a dollar impact or number of victims to report, due to the malware being analyzed in isolation rather than as part of an ongoing incident. That said, Muir noted that the Telegram groups used to distribute Legion have a combined membership of 5000.

"Although we can assume not everybody in these groups will purchase a license for the software, it shows that there is considerable demand for such a tool," Muir said. "If even half of the members purchased a license and used the SMTP abuse capabilities for spam or phishing purposes, I don’t think it’s unreasonable to assume that tens of thousands of users would be affected."