Via Threatpost.com
One of the attackers who has been targeting Syrian anti-government activists with malware and surveillance tools has returned and upped the ante with the use of the BlackShades RAT, a remote-access tool that gives him the ability to spy on victims machines through keylogging and screenshots.
The original attacks against Syrian activists, who are working against the government's months-long violent crackdown, were using another RAT known as Xtreme RAT, with similar capabilities. That malware was being spread through a couple of different targeted attacks, including one in which activists were directed to YouTube videos and their account credentials were then stolen when they logged in to leave comments.
That attack continued with the installation of the RAT, giving the attacker surreptitious access to the victims' machines, enabling him to monitor their activities online. Now, researchers say that at least one attacker who is known to be involved in these targeted attacks also is using the BlackShades RAT in a new set of attacks.
The new attack is being run by spreading a malicious link to dissidents. When a victim clicks on the link, it takes him to a site that downloads a file called "new_new .pif." That file then goes through a long infection routine that includes the installation of several files. One of the files that's installed is a keylogger and the malware also creates a number of registry keys that ensure persistence on the machine, according to an analysis of the attack by researchers at the EFF and Citizen Lab.
---------------------------------------------
For those interested in samples, Mila posted copies of all three RATs used to target Syrian anti-government activists.
http://contagiodump.blogspot.com/2012/06/rat-samples-from-syrian-targeted.html
Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Showing posts with label Targeted Attack. Show all posts
Showing posts with label Targeted Attack. Show all posts
Wednesday, June 20, 2012
Friday, May 4, 2012
Xtreme RAT Used in Targeted Attack Against Syria Activist
Via F-Secure Labs -
Syria has been the center of much international attention lately. There's unrest in the country and the authoritarian government is using brutal tactics against dissidents. These tactics include using technology surveillance, trojans and backdoors.
Some time ago we received a hard drive via a contact. The drive had an image of the system of a Syrian activist who had been targeted by the local authorities.
The activist's system had become infected as a result of a Skype chat. The chat request came from a fellow activist. The problem was that the fellow activist had already been arrested and could not have started the chat.
Initial infection occurred when the activist accepted a file called MACAddressChanger.exe over the chat. This utility was supposed to change the hardware MAC address of the system in order to bypass some monitoring tools. Instead, it dropped a file called silvia.exe which was a backdoor — a backdoor called "Xtreme RAT".
Xtreme Rat is a full-blown malicious Remote Access Tool.
Sold for 100 euro (Paypal) via a page hosted at Google Sites: hxxps://sites.google.com/site/nxtremerat
We have reasons to believe this infection wasn't just bad luck. We believe the activist's computer was specifically targeted. In any case, the backdoor calls home to the IP address 216.6.0.28. This IP block belongs to Syrian Arab Republic — STE (Syrian Telecommunications Establishment).
This would not have been the first case of using trojans for such purposes in Syria, either.
Syria has been the center of much international attention lately. There's unrest in the country and the authoritarian government is using brutal tactics against dissidents. These tactics include using technology surveillance, trojans and backdoors.
Some time ago we received a hard drive via a contact. The drive had an image of the system of a Syrian activist who had been targeted by the local authorities.
The activist's system had become infected as a result of a Skype chat. The chat request came from a fellow activist. The problem was that the fellow activist had already been arrested and could not have started the chat.
Initial infection occurred when the activist accepted a file called MACAddressChanger.exe over the chat. This utility was supposed to change the hardware MAC address of the system in order to bypass some monitoring tools. Instead, it dropped a file called silvia.exe which was a backdoor — a backdoor called "Xtreme RAT".
Xtreme Rat is a full-blown malicious Remote Access Tool.
Sold for 100 euro (Paypal) via a page hosted at Google Sites: hxxps://sites.google.com/site/nxtremerat
We have reasons to believe this infection wasn't just bad luck. We believe the activist's computer was specifically targeted. In any case, the backdoor calls home to the IP address 216.6.0.28. This IP block belongs to Syrian Arab Republic — STE (Syrian Telecommunications Establishment).
This would not have been the first case of using trojans for such purposes in Syria, either.
Monday, April 30, 2012
Determined Adversaries and Targeted Attacks
Via Microsoft Security Intelligence Report -
Over the past two decades the internet has become fundamental to the pursuit of day-to-day commercial, personal, and governmental business. However, the ubiquitous nature of the internet as a communications platform has also increased the risk to individuals and organizations from cyberthreats. These threats include website defacement, virus and worm (or malware) outbreaks, and network intrusion attempts. In addition, the global presence of the internet has allowed it to be used as a significant staging ground for espionage activity directed at industrial, political, military, and civil targets.
During the past 5 years, one specific category of threat has become much more widely discussed. Originally referred to as Advanced Persistent Threats (APT) by the U.S. military — referring to alleged nation-state sponsored attempts to infiltrate military networks and exfiltrate sensitive data — the term APT is today widely used in media and IT security circles to describe any attack that seems to specifically target individual organization, or is thought to be notably technical in nature, regardless of whether the attack was actually either advanced or persistent.
In fact, this type of attack typically involves two separate components — the action(s) and the actor(s) — that may be targeted against governments, military organizations or, increasingly, commercial entities and civil society.
The actions are the attacks themselves, which may be IT-related or not, and are referred to as Targeted Attacks in this paper. These attacks are initiated and conducted by human actors, who are collectively referred to in this paper as Determined Adversaries. These definitions are important because they emphasize the point that the attacks are carried out by human actors who may use any tools or techniques necessary to achieve their goals; these attacks are not merely malicious software or exploits. Using an encompassing term such as APT can mask this reality and create the impression that all such attacks are technically sophisticated and malware-driven, making it harder to plan an effective defensive posture.
For these reasons, this paper uses Targeted Attacks and Determined Adversaries as more specific and meaningful terms to describe this category of attack.
-------------------------------------------------------------
Be sure to check out Microsoft's Security Intelligence Report (SIR) Volume 12.
http://www.microsoft.com/security/sir/default.aspx
Over the past two decades the internet has become fundamental to the pursuit of day-to-day commercial, personal, and governmental business. However, the ubiquitous nature of the internet as a communications platform has also increased the risk to individuals and organizations from cyberthreats. These threats include website defacement, virus and worm (or malware) outbreaks, and network intrusion attempts. In addition, the global presence of the internet has allowed it to be used as a significant staging ground for espionage activity directed at industrial, political, military, and civil targets.
During the past 5 years, one specific category of threat has become much more widely discussed. Originally referred to as Advanced Persistent Threats (APT) by the U.S. military — referring to alleged nation-state sponsored attempts to infiltrate military networks and exfiltrate sensitive data — the term APT is today widely used in media and IT security circles to describe any attack that seems to specifically target individual organization, or is thought to be notably technical in nature, regardless of whether the attack was actually either advanced or persistent.
In fact, this type of attack typically involves two separate components — the action(s) and the actor(s) — that may be targeted against governments, military organizations or, increasingly, commercial entities and civil society.
The actions are the attacks themselves, which may be IT-related or not, and are referred to as Targeted Attacks in this paper. These attacks are initiated and conducted by human actors, who are collectively referred to in this paper as Determined Adversaries. These definitions are important because they emphasize the point that the attacks are carried out by human actors who may use any tools or techniques necessary to achieve their goals; these attacks are not merely malicious software or exploits. Using an encompassing term such as APT can mask this reality and create the impression that all such attacks are technically sophisticated and malware-driven, making it harder to plan an effective defensive posture.
For these reasons, this paper uses Targeted Attacks and Determined Adversaries as more specific and meaningful terms to describe this category of attack.
-------------------------------------------------------------
Be sure to check out Microsoft's Security Intelligence Report (SIR) Volume 12.
http://www.microsoft.com/security/sir/default.aspx
The Microsoft Security Intelligence Report (SIR) analyzes the threat landscape of exploits, vulnerabilities, and malware using data from Internet services and over 600 million computers worldwide. Threat awareness can help you protect your organization, software, and people.
Tuesday, April 24, 2012
Nissan Gets Hacked, Intellectual Property Possible Target
Via DailyTech.com (April 24, 2012) -
Nissan Motor Company has announced that its information systems have been hacked. So far, the company doesn't know who the hackers were, or where they struck from and it's unclear what data may have been compromised. Nissan believes that the hackers were looking for intellectual property related to its EV drivetrains.
Nissan maintains that it quickly secured its system and issued a statement alerting customers and employees that its data systems were breached. Nissan says that the infiltration was noticed on April 13 so it has been roughly 10 days since the database was compromised.
The statement read:
------------------------------------------------------------------------------------------
Looks like Active Directory might have got popped.
Primary Sources....
Nissan Statement: Nissan is Taking Actions to Protect and Inform Employees and Customers Following an Intrusion into the Company's Global Network Systems
The Detroit Bureau: Nissan Scrambles After Major Cyber-Attack
Nissan Motor Company has announced that its information systems have been hacked. So far, the company doesn't know who the hackers were, or where they struck from and it's unclear what data may have been compromised. Nissan believes that the hackers were looking for intellectual property related to its EV drivetrains.
Nissan maintains that it quickly secured its system and issued a statement alerting customers and employees that its data systems were breached. Nissan says that the infiltration was noticed on April 13 so it has been roughly 10 days since the database was compromised.
The statement read:
We have detected an intrusion into our company's global information systems network.Nissan says that it opted to keep the hack secret for the last 10 days until it had a better idea what was going on according to a spokesman cited by The Detroit Bureau.
On April 13, 2012, our information security team confirmed the presence of a computer virus on our network and immediately took aggressive actions to protect the company's systems and data. This included actions to protect information related to customers, employees and other partners worldwide. This incident initially involved the malicious placement of malware within our IS network, which then allowed transfer from a data store, housing employee user account credentials.
As a result of our swift and deliberate actions we believe that our systems are secure and that no customer, employee or program data has been compromised. However, we believe that user IDs and hashed passwords were transmitted. We have no indication that any personal information and emails have been compromised. Regardless, we are continuing to take appropriate precautionary measures.
Due to the ever-evolving sophistication and tenacity of hackers targeting corporations and governments on a daily basis, we continue to vigilantly maintain our protection and detection systems and related countermeasures to keep ahead of emerging threats. Our focus remains on safeguarding the integrity of employee, consumer and corporate information.
------------------------------------------------------------------------------------------
Looks like Active Directory might have got popped.
Primary Sources....
Nissan Statement: Nissan is Taking Actions to Protect and Inform Employees and Customers Following an Intrusion into the Company's Global Network Systems
The Detroit Bureau: Nissan Scrambles After Major Cyber-Attack
Thursday, March 29, 2012
Case Based in China Puts a Face on Persistent Hacking
Via New York Times -
A breach of computers belonging to companies in Japan and India and to Tibetan activists has been linked to a former graduate student at a Chinese university — putting a face on the persistent espionage by Chinese hackers against foreign companies and groups.
The attacks were connected to an online alias, according to a report to be released on Friday by Trend Micro, a computer security firm with headquarters in Tokyo.
The owner of the alias, according to online records, is Gu Kaiyuan, a former graduate student at Sichuan University, in Chengdu, China, which receives government financing for its research in computer network defense.
Mr. Gu is now apparently an employee at Tencent, China’s leading Internet portal company, also according to online records. According to the report, he may have recruited students to work on the university’s research involving computer attacks and defense.
The researchers did not link the attacks directly to government-employed hackers. But security experts and other researchers say the techniques and the victims point to a state-sponsored campaign.
“The fact they targeted Tibetan activists is a strong indicator of official Chinese government involvement,” said James A. Lewis, a former diplomat and expert in computer security who is a director and senior fellow at the Center for Strategic and International Studies in Washington. “A private Chinese hacker may go after economic data but not a political organization.”
Neither the Chinese embassy in Washington nor the Chinese consulate in New York answered requests for comment.
The Trend Micro report describes systematic attacks on at least 233 personal computers. The victims include Indian military research organizations and shipping companies; aerospace, energy and engineering companies in Japan; and at least 30 computer systems of Tibetan advocacy groups, according to both the report and interviews with experts connected to the research. The espionage has been going on for at least 10 months and is continuing, the report says.
In the report, the researchers detailed how they had traced the attacks to an e-mail address used to register one of the command-and-control servers that directed the attacks. They mapped that address to a QQ number — China’s equivalent of an online instant messaging screen name — and from there to an online alias.
The person who used the alias, “scuhkr” — the researchers said in an interview that it could be shorthand for Sichuan University hacker — wrote articles about hacking, which were posted to online hacking forums and, in one case, recruited students to a computer network and defense research program at Sichuan University’s Institute of Information Security in 2005, the report said.
The New York Times traced that alias to Mr. Gu. According to online records, Mr. Gu studied at Sichuan University from 2003 to 2006, when he wrote numerous articles about hacking under the names of “scuhkr” and Gu Kaiyuan. Those included a master’s thesis about computer attacks and prevention strategies. The Times connected Mr. Gu to Tencent first through an online university forum, which listed where students found jobs, and then through a call to Tencent.
Reached at Tencent and asked about the attacks, Mr. Gu said, “I have nothing to say.”
----------------------------------------------
Lucky Cat might sound familiar? That is for good reason.
A breach of computers belonging to companies in Japan and India and to Tibetan activists has been linked to a former graduate student at a Chinese university — putting a face on the persistent espionage by Chinese hackers against foreign companies and groups.
The attacks were connected to an online alias, according to a report to be released on Friday by Trend Micro, a computer security firm with headquarters in Tokyo.
The owner of the alias, according to online records, is Gu Kaiyuan, a former graduate student at Sichuan University, in Chengdu, China, which receives government financing for its research in computer network defense.
Mr. Gu is now apparently an employee at Tencent, China’s leading Internet portal company, also according to online records. According to the report, he may have recruited students to work on the university’s research involving computer attacks and defense.
The researchers did not link the attacks directly to government-employed hackers. But security experts and other researchers say the techniques and the victims point to a state-sponsored campaign.
“The fact they targeted Tibetan activists is a strong indicator of official Chinese government involvement,” said James A. Lewis, a former diplomat and expert in computer security who is a director and senior fellow at the Center for Strategic and International Studies in Washington. “A private Chinese hacker may go after economic data but not a political organization.”
Neither the Chinese embassy in Washington nor the Chinese consulate in New York answered requests for comment.
The Trend Micro report describes systematic attacks on at least 233 personal computers. The victims include Indian military research organizations and shipping companies; aerospace, energy and engineering companies in Japan; and at least 30 computer systems of Tibetan advocacy groups, according to both the report and interviews with experts connected to the research. The espionage has been going on for at least 10 months and is continuing, the report says.
In the report, the researchers detailed how they had traced the attacks to an e-mail address used to register one of the command-and-control servers that directed the attacks. They mapped that address to a QQ number — China’s equivalent of an online instant messaging screen name — and from there to an online alias.
The person who used the alias, “scuhkr” — the researchers said in an interview that it could be shorthand for Sichuan University hacker — wrote articles about hacking, which were posted to online hacking forums and, in one case, recruited students to a computer network and defense research program at Sichuan University’s Institute of Information Security in 2005, the report said.
The New York Times traced that alias to Mr. Gu. According to online records, Mr. Gu studied at Sichuan University from 2003 to 2006, when he wrote numerous articles about hacking under the names of “scuhkr” and Gu Kaiyuan. Those included a master’s thesis about computer attacks and prevention strategies. The Times connected Mr. Gu to Tencent first through an online university forum, which listed where students found jobs, and then through a call to Tencent.
Reached at Tencent and asked about the attacks, Mr. Gu said, “I have nothing to say.”
----------------------------------------------
Lucky Cat might sound familiar? That is for good reason.
Wednesday, March 28, 2012
The Luckycat Hackers
http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the_luckycat_hackers.pdf
Overview
A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to successfully compromise a target and steal sensitive information. The attackers use very simple malware, which required little development time or skills, in conjunction with freely available Web hosting, to implement a highly effective attack. It is a case of the attackers obtaining a maximum return on their investment. The attack shows how an intelligent attacker does not need to be particularly technically skilled in order to steal the information they are after.
[...]
The most useful information about the attackers is in one of the log files retrieved from a C&C server. This log file appears to record connections to an FTP server running on the C&C server. The attackers probably use FTP to easily retrieve stolen data uploaded to the C&C server. 45 unique IP addresses were identified in the log. Of these, all but two are from the same ISP, based in Sichuan province in China. The remaining two are from South Korea.
Despite this, the IP address used for the new connection changes regularly. In figure 7, during a period of approximately an hour and 15 minutes, four different IP addresses were used for six distinct connections. This is unusual because if the attacker is using DHCP, generally an IP address will remain allocated to a particular computer for a longer period of time.
A possible explanation is that the IP addresses used are the point of egress of a VPN-like service. The attackers may be using a service through which they can route their connections. The service periodically rotates connections amongst a pool of IP addresses in order to render the attacker anonymous or implicate China as the source of the attack. There are two potential reasons for the South Korean IP addresses. The first is that the IP addresses are part of the VPN service and were assigned to the attacker as the service rotated through the range of IP addresses available. The second explanation is that the attacker may have forgotten to enable the VPN by mistake and connected directly to the C&C server.
Overview
A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to successfully compromise a target and steal sensitive information. The attackers use very simple malware, which required little development time or skills, in conjunction with freely available Web hosting, to implement a highly effective attack. It is a case of the attackers obtaining a maximum return on their investment. The attack shows how an intelligent attacker does not need to be particularly technically skilled in order to steal the information they are after.
[...]
The most useful information about the attackers is in one of the log files retrieved from a C&C server. This log file appears to record connections to an FTP server running on the C&C server. The attackers probably use FTP to easily retrieve stolen data uploaded to the C&C server. 45 unique IP addresses were identified in the log. Of these, all but two are from the same ISP, based in Sichuan province in China. The remaining two are from South Korea.
Despite this, the IP address used for the new connection changes regularly. In figure 7, during a period of approximately an hour and 15 minutes, four different IP addresses were used for six distinct connections. This is unusual because if the attacker is using DHCP, generally an IP address will remain allocated to a particular computer for a longer period of time.
A possible explanation is that the IP addresses used are the point of egress of a VPN-like service. The attackers may be using a service through which they can route their connections. The service periodically rotates connections amongst a pool of IP addresses in order to render the attacker anonymous or implicate China as the source of the attack. There are two potential reasons for the South Korean IP addresses. The first is that the IP addresses are part of the VPN service and were assigned to the attacker as the service rotated through the range of IP addresses available. The second explanation is that the attacker may have forgotten to enable the VPN by mistake and connected directly to the C&C server.
Wednesday, March 21, 2012
Targeted Attacks Against Tibet Organizations
Via Alien Vaults Labs (March 13, 2012) -
We recently detected several targeted attacks against Tibetan activist organizations including the Central Tibet Administration and International Campaign for Tibet, among others. We believe these attacks originate from the same group of Chinese hackers that launched the ‘Nitro’ attacks against chemical and defense companies late last year and are aimed at both spying on and stealing sensitive information about these organizations’ activities and supporters.
The attacks begin with a simple spear phishing campaign that uses a contaminated Office file to exploit a known vulnerability in Microsoft. The information in the spear phishing email is related to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. After further investigation, we discovered that the malware being used in this attack is a variant of Gh0st RAT (remote access Trojan), a type of software that enables anything from stealing documents to turning on a victim’s computer microphone. Gh0st RAT was a primary tool used in the Nitro attacks last year and the variant we uncovered in these attacks seem to come from the same actors. It’s likely that the same group is stealing from major industries as well as infiltrating organizations for political reasons.
It is no surprise that Tibetan organizations are being targeted – they have been for years – and we continue to see Chinese actors breaking into numerous organizations with impunity. Unfortunately, in this particular case, these attacks may have a direct impact on the abuse of human rights in these regions.
Below is a detailed analysis of one of the dozens of campaigns that we’ve been tracking, which illustrates the method used by the attackers and the possible connection to the Nitro attacks.
These latest attacks are linked to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. The spear phishing emails are not that sophisticated and feature a Microsoft attachment (Camp information at Bodhgaya.doc) that exploits a known Office stack overflow vulnerability (CVE-2010-3333).
[...]
Examining the resultant traffic confirms the code to be a variant of the Gh0st RAT (remote access trojan) using a data string of `ByShe’ in place of the more usual `Gh0st.’
[...]
We have found more samples using this modified header (“ByShe”):
http://www.threatexpert.com/report.aspx?md5=e4e64d365844dc7294e4a553fed7501f
http://www.threatexpert.com/report.aspx?md5=4A35488762F70170DC0D3F46F94A7BCB
It is worth noting that the sample – 4a35488762f70170dc0d3f46f94a7bcb – connects to jericho.3322.org using the `ByShe’ protocol, which was seen during the Nitro attacks we saw between April and November of last year.
This sample was used during the NitroAttacks last year, a targeted attack against chemical and defense companies that was traced to China.
We recently detected several targeted attacks against Tibetan activist organizations including the Central Tibet Administration and International Campaign for Tibet, among others. We believe these attacks originate from the same group of Chinese hackers that launched the ‘Nitro’ attacks against chemical and defense companies late last year and are aimed at both spying on and stealing sensitive information about these organizations’ activities and supporters.
The attacks begin with a simple spear phishing campaign that uses a contaminated Office file to exploit a known vulnerability in Microsoft. The information in the spear phishing email is related to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. After further investigation, we discovered that the malware being used in this attack is a variant of Gh0st RAT (remote access Trojan), a type of software that enables anything from stealing documents to turning on a victim’s computer microphone. Gh0st RAT was a primary tool used in the Nitro attacks last year and the variant we uncovered in these attacks seem to come from the same actors. It’s likely that the same group is stealing from major industries as well as infiltrating organizations for political reasons.
It is no surprise that Tibetan organizations are being targeted – they have been for years – and we continue to see Chinese actors breaking into numerous organizations with impunity. Unfortunately, in this particular case, these attacks may have a direct impact on the abuse of human rights in these regions.
Below is a detailed analysis of one of the dozens of campaigns that we’ve been tracking, which illustrates the method used by the attackers and the possible connection to the Nitro attacks.
These latest attacks are linked to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. The spear phishing emails are not that sophisticated and feature a Microsoft attachment (Camp information at Bodhgaya.doc) that exploits a known Office stack overflow vulnerability (CVE-2010-3333).
[...]
Examining the resultant traffic confirms the code to be a variant of the Gh0st RAT (remote access trojan) using a data string of `ByShe’ in place of the more usual `Gh0st.’
[...]
We have found more samples using this modified header (“ByShe”):
http://www.threatexpert.com/report.aspx?md5=e4e64d365844dc7294e4a553fed7501f
http://www.threatexpert.com/report.aspx?md5=4A35488762F70170DC0D3F46F94A7BCB
It is worth noting that the sample – 4a35488762f70170dc0d3f46f94a7bcb – connects to jericho.3322.org using the `ByShe’ protocol, which was seen during the Nitro attacks we saw between April and November of last year.
This sample was used during the NitroAttacks last year, a targeted attack against chemical and defense companies that was traced to China.
Friday, February 24, 2012
DarkComet RAT Surfaced in the Targeted Attacks in Syrian Conflict
Via TrendMicro Malware Blog -
The Internet has played a significant role in the current conflict in Syria. The opposition has made increasing use of platforms such as Facebook to organize and spread their message. In response, supporters of the regime like the “Syrian Electronic Army” have sought to disrupt these activities by defacing websites and spamming Facebook pages. Recently, this conflict took on a new dimension with reports that suggested targeted malware attacks were being used against supporters of the Syrian opposition movement.
Dark Comet RAT Used as “Syrian Spyware”
The malware used in the attacks reportedly spreads through Skype chats. Once users execute the malware, it connects to a C&C (command and control) server in Syria at {BLOCKED}.{BLOCKED}.0.28, which belongs to an IP range assigned to the Syrian Telecommunications Establishment. While the malware has been described as “complex” and “invisible”, it turns out that it is the widely available Remote Access Trojan (RAT) known as Dark Comet.
In our analysis, which confirms an earlier investigation by Telecomix, we found that the samples connecting to {BLOCKED}.{BLOCKED}.0.28 are instances of the DarkComet RAT versions 3.3 and 5. However, some samples are “downloaders” that connect to this same IP address via HTTP and download a encrypted “Update.bin” file, which is then decrypted and executed. The payload is the actual DarkComet RAT.
DarkComet is a full featured RAT that has the ability to take pictures via webcam, listen in on conversations via a microphone attached to a PC, and gain full control of the infected machine. But the features attracting most people using this RAT are the keylogging and file transfer functionality. This way, an attacker can load any files onto the infected machine or even steal documents.
DarkComet is still being developed and version 5 was released last January 15. It is created by a coder using the handle DarkCoderSc and was first coded in 2008. Since the reports of its use in connection with events in Syria, the author of DarkComet has expressed regret and while he will continue developing the RAT, he plans to make a DarkComet detector/remover available to the Syrian people.
[...]
These developments illustrate that targeted attacks can be conducted with widely available DIY malware tools. These tools possess all the “complex” functionality attackers need to compromise their targets.
The Internet has played a significant role in the current conflict in Syria. The opposition has made increasing use of platforms such as Facebook to organize and spread their message. In response, supporters of the regime like the “Syrian Electronic Army” have sought to disrupt these activities by defacing websites and spamming Facebook pages. Recently, this conflict took on a new dimension with reports that suggested targeted malware attacks were being used against supporters of the Syrian opposition movement.
Dark Comet RAT Used as “Syrian Spyware”
The malware used in the attacks reportedly spreads through Skype chats. Once users execute the malware, it connects to a C&C (command and control) server in Syria at {BLOCKED}.{BLOCKED}.0.28, which belongs to an IP range assigned to the Syrian Telecommunications Establishment. While the malware has been described as “complex” and “invisible”, it turns out that it is the widely available Remote Access Trojan (RAT) known as Dark Comet.
In our analysis, which confirms an earlier investigation by Telecomix, we found that the samples connecting to {BLOCKED}.{BLOCKED}.0.28 are instances of the DarkComet RAT versions 3.3 and 5. However, some samples are “downloaders” that connect to this same IP address via HTTP and download a encrypted “Update.bin” file, which is then decrypted and executed. The payload is the actual DarkComet RAT.
DarkComet is a full featured RAT that has the ability to take pictures via webcam, listen in on conversations via a microphone attached to a PC, and gain full control of the infected machine. But the features attracting most people using this RAT are the keylogging and file transfer functionality. This way, an attacker can load any files onto the infected machine or even steal documents.
DarkComet is still being developed and version 5 was released last January 15. It is created by a coder using the handle DarkCoderSc and was first coded in 2008. Since the reports of its use in connection with events in Syria, the author of DarkComet has expressed regret and while he will continue developing the RAT, he plans to make a DarkComet detector/remover available to the Syrian people.
[...]
These developments illustrate that targeted attacks can be conducted with widely available DIY malware tools. These tools possess all the “complex” functionality attackers need to compromise their targets.
Wednesday, December 7, 2011
Analyzing CVE-2011-2462 - Part One
Via 9bplus.com (Brandon Dixon) -
Before I went to bed last night I took a look at uploaded files to PDF X-RAY in hopes that Christmas would come early (CVE-2011-2462 in my reports) and was surprised when I came across a file with /U3D references. I snatched the file off the server, opened up my snapshots to the latest 9.4 build of Adobe and ran the file. Reader crashed, and a new document was successfully opened. That was enough to stay up, so analysis started and can be found below.
Read the full analysis by Brandon @ 9bplus.com
--------------------------------------
Mila Parkour also links to Brandon's analysis and adds additional information over at Contagio.
Before I went to bed last night I took a look at uploaded files to PDF X-RAY in hopes that Christmas would come early (CVE-2011-2462 in my reports) and was surprised when I came across a file with /U3D references. I snatched the file off the server, opened up my snapshots to the latest 9.4 build of Adobe and ran the file. Reader crashed, and a new document was successfully opened. That was enough to stay up, so analysis started and can be found below.
Read the full analysis by Brandon @ 9bplus.com
--------------------------------------
Mila Parkour also links to Brandon's analysis and adds additional information over at Contagio.
Symantec: Four-Fold Increase in the Number of Daily Targeted Attacks Since January
Via Symantec Intelligence Blog -
With targeted attacks and advanced persistent threats being very much in the news this year, we thought it would be a good time as the end of the year draws closer to begin our review of targeted attacks and look more closely at what has been described as “advanced persistent threats” or APTs for short. Terms such as APT have been overused and sometimes misused by the media, but APTs are a real threat to some companies and industries.
In November, one in 255 emails was malicious, but approximately one in 8,300 of those were highly targeted. This means that highly targeted attacks, which may be the precursor to an APT, account for approximately one in every two million emails, still a rare incident rate. Targeted malware in general has grown in volume and complexity in recent years, but as it is designed to steal company secrets, it can be very difficult for recipients to recognize, especially when the attacker employs compelling social engineering techniques, as we highlight in this report.
A persistent threat residing inside your company’s network may be the by-product of a successful targeted attack, rather than the targeted email itself containing an APT, it is likely to contain a downloader component for the actual APT. Hence, targeted attacks of this nature can lead to an APT being deployed on your network if you don’t have the right defenses in place.
[...]
Targeted attacks have been around for a number of years now, and when they first surfaced back in 2005, Symantec.cloud would identify and block approximately one such attack in a week. Over the course of the following year, this number rose to one or two per day and over the following years it rose still further to approximately 60 per day in 2010 and 80 per day by the end of the first quarter of 2011. By November 2011, the number of attacks blocked rose to approximately 94 per day, almost four times the number in January.
[...]
The types of organizations being targeted tended to be large, well-known multi-national organizations, and were often within particular industries, including the public sector, defense, energy and pharmaceutical. In more recent years the scope has widened to include almost any organization, including smaller and medium-sized businesses.
[...]
To find out more, the full report can be downloaded here (PDF).
------------------------------------------------------------------------------------
The number of targeted attacks outlined by Symantec are only representative of Symantec E-mail service customers and Symatec.cloud customers, however two general points can be taken from the data. Targeted attacks are happening on a daily basis and the sectors which experience targeted attackers continue to increase and widen.
Whitepaper - Advanced Persistent Threats: A Symantec Perspective
http://www.symantec.com/content/en/us/enterprise/white_papers/b-advanced_persistent_threats_WP_21215957.en-us.pdf
With targeted attacks and advanced persistent threats being very much in the news this year, we thought it would be a good time as the end of the year draws closer to begin our review of targeted attacks and look more closely at what has been described as “advanced persistent threats” or APTs for short. Terms such as APT have been overused and sometimes misused by the media, but APTs are a real threat to some companies and industries.
In November, one in 255 emails was malicious, but approximately one in 8,300 of those were highly targeted. This means that highly targeted attacks, which may be the precursor to an APT, account for approximately one in every two million emails, still a rare incident rate. Targeted malware in general has grown in volume and complexity in recent years, but as it is designed to steal company secrets, it can be very difficult for recipients to recognize, especially when the attacker employs compelling social engineering techniques, as we highlight in this report.
A persistent threat residing inside your company’s network may be the by-product of a successful targeted attack, rather than the targeted email itself containing an APT, it is likely to contain a downloader component for the actual APT. Hence, targeted attacks of this nature can lead to an APT being deployed on your network if you don’t have the right defenses in place.
[...]
Targeted attacks have been around for a number of years now, and when they first surfaced back in 2005, Symantec.cloud would identify and block approximately one such attack in a week. Over the course of the following year, this number rose to one or two per day and over the following years it rose still further to approximately 60 per day in 2010 and 80 per day by the end of the first quarter of 2011. By November 2011, the number of attacks blocked rose to approximately 94 per day, almost four times the number in January.
[...]
The types of organizations being targeted tended to be large, well-known multi-national organizations, and were often within particular industries, including the public sector, defense, energy and pharmaceutical. In more recent years the scope has widened to include almost any organization, including smaller and medium-sized businesses.
[...]
To find out more, the full report can be downloaded here (PDF).
------------------------------------------------------------------------------------
The number of targeted attacks outlined by Symantec are only representative of Symantec E-mail service customers and Symatec.cloud customers, however two general points can be taken from the data. Targeted attacks are happening on a daily basis and the sectors which experience targeted attackers continue to increase and widen.
Whitepaper - Advanced Persistent Threats: A Symantec Perspective
http://www.symantec.com/content/en/us/enterprise/white_papers/b-advanced_persistent_threats_WP_21215957.en-us.pdf
"An APT is always a targeted attack, but a targeted attack is not necessarily an APT."
Tuesday, December 6, 2011
New Adobe Reader Zeroday Used in Targeted Attacks
Via Adobe Secure Software Engineering Team (ASSET) Blog -
We have just posted Security Advisory APSA11-04 regarding a new vulnerability (CVE-2011-2462) that is currently being exploited in the wild in limited, targeted attacks against Adobe Reader 9.4.6 on Windows. Here is a summary of our approach to address this issue:
[...]
I’d like to take this moment to encourage any remaining users still running Adobe Reader or Acrobat 9.x (or worse, older unsupported versions) to PLEASE upgrade to Adobe Reader or Acrobat X. We put a tremendous amount of work into securing Adobe Reader and Acrobat X, and, to date, there has not been a single piece of malware identified that is effective against a version X install. Help us help you by running the latest version of the software!
------------------------------------------------------
http://www.adobe.com/support/security/advisories/apsa11-04.html
Acknowledgments
Adobe would like to thank Lockheed Martin CIRT and members of the Defense Security Information Exchange for reporting this issue and for working with Adobe to help protect our customers.
We have just posted Security Advisory APSA11-04 regarding a new vulnerability (CVE-2011-2462) that is currently being exploited in the wild in limited, targeted attacks against Adobe Reader 9.4.6 on Windows. Here is a summary of our approach to address this issue:
- We are planning to release an out-of-cycle security update for Adobe Reader and Acrobat 9.x for Windows no later than the week of December 12, 2011.
- Because Adobe Reader X Protected Mode and Adobe Acrobat X Protected View would prevent an exploit targeting this vulnerability from executing, we are planning to address this issue in Adobe Reader and Acrobat X for Windows with the next quarterly security update on January 10, 2012.
- The risk to Macintosh and UNIX users is significantly lower. We are therefore planning to address this issue in Adobe Reader and Acrobat X and earlier versions for Macintosh as part of the next quarterly update on January 10, 2012. An update to address this issue in Adobe Reader 9.x for UNIX is planned for January 10, 2012.
[...]
I’d like to take this moment to encourage any remaining users still running Adobe Reader or Acrobat 9.x (or worse, older unsupported versions) to PLEASE upgrade to Adobe Reader or Acrobat X. We put a tremendous amount of work into securing Adobe Reader and Acrobat X, and, to date, there has not been a single piece of malware identified that is effective against a version X install. Help us help you by running the latest version of the software!
------------------------------------------------------
http://www.adobe.com/support/security/advisories/apsa11-04.html
Acknowledgments
Adobe would like to thank Lockheed Martin CIRT and members of the Defense Security Information Exchange for reporting this issue and for working with Adobe to help protect our customers.
Tuesday, November 15, 2011
APT: Anatomy of a Zero Day Attack
http://www.informationweek.com/video/security/1194518768001
Pacific Northwest National Laboratory (PNNL) CIO, Jerry Johnson, provides some lessons learned from the attacks on his organization in July -- a highly publicized attack on an organization that provides cyber security services for the Dept. of Energy.
-------------------------------------------
It is a long interview, but it is very insightful into these types of ongoing APT attacks.
Pacific Northwest National Laboratory (PNNL) CIO, Jerry Johnson, provides some lessons learned from the attacks on his organization in July -- a highly publicized attack on an organization that provides cyber security services for the Dept. of Energy.
-------------------------------------------
It is a long interview, but it is very insightful into these types of ongoing APT attacks.
Sunday, October 2, 2011
Targeted Attacks and the Need to Keep Document Parsers Updated
Via Microsoft Security Blog -
Over the past few years there has been a lot of concern about “advanced persistent threat” and targeted attacks such as “spear-phishing” and “whaling”. In my discussions with security professionals in different parts of the world I have encountered many different views on the risks associated with these attacks, ranging from disbelief that they actually happen to the belief that every email with an attachment contains an exploit.
The Microsoft Security Engineering Center (MSEC) studies such attacks looking for ways to mitigate the threats to current products, such as Microsoft Office, and help engineer mitigations into future products currently under development. We have published data and insights on some of the methods attackers use to perform targeted attacks, in past volumes of the Microsoft Security Intelligence Report (SIR).
For example, in SIR volume 8 we published a study the MSEC did on document file format exploits. I want to highlight this study here because I think it helps add a little context to the topic of targeted attacks and provides actionable guidance to help manage some of the associated risks.
Document File Format Exploits
Increasingly, attackers are using common file formats as transmission vectors for exploits. Most modern e-mail and instant messaging programs are configured to block the transmission of potentially dangerous files by extension, such as .exe, .com, and .scr, which have historically been misused to transmit malware. However, these same programs typically permit the transmission of many popular file formats, like .doc, .pdf, .ppt, and .xls. These formats are used legitimately by many people every day to share information and get work done, so blocking them is often not practical. This has made them an attractive target for exploitation.
[...]
To assess the use of Microsoft Office system file formats as an attack vector, Microsoft analyzed a sample of several hundred files that were used for successful attacks in 2H09 (the second half of 2009). The data set was taken from submissions of malicious code sent to Microsoft from customers worldwide.
[...]
All nine of these vulnerabilities had security updates available at the time of attack. The affected users were exposed because they had not applied the updates. Office 2000, Office XP, Office 2003, and the 2007 Microsoft Office system were each affected by at least one of the nine vulnerabilities.
Most of the vulnerabilities exploited in the data sample were several years old, with a third of them first identified in 2006.
[...]
Users who do not keep their Office program installations up to date with service packs and security updates are at increased risk of attack.
[...]
The key things to take away from this study are:
-------------------------------------------------------------------------------------------
As a former Microsoft Systems Management Server (SMS) admin, I can tell you that patching isn't easy as it sounds and it isn't as flashy as some other threat mitigation processes....but it is critically important for organizations to have a patch process in place - it is truly the last line of defense.
In today's threat landscape, patching just IE isn't enough anymore. You have to patch OS, browser, browser plug-ins and other programs that are being used in targeted attacks (like Office) against employee endpoints.
In large enterprises, the 'patchable' software surface can be daunting to patch management administrators. Combine that feeling with the reality that many employees have the ability to install whatever they want on my corporate endpoints (due to admin rights and/or a less managed endpoint posture) and you have a patch management nightmare that seems impossible.
So what can you do?
Use threat and exploit intelligence to focus your efforts on the vulnerabilities that you know are being exploited. Patch those now...and use that protection space generated by those efforts to evaluate your specific environment and identify the next subset of programs which should be patched - using a risk-based approach.
Over the past few years there has been a lot of concern about “advanced persistent threat” and targeted attacks such as “spear-phishing” and “whaling”. In my discussions with security professionals in different parts of the world I have encountered many different views on the risks associated with these attacks, ranging from disbelief that they actually happen to the belief that every email with an attachment contains an exploit.
The Microsoft Security Engineering Center (MSEC) studies such attacks looking for ways to mitigate the threats to current products, such as Microsoft Office, and help engineer mitigations into future products currently under development. We have published data and insights on some of the methods attackers use to perform targeted attacks, in past volumes of the Microsoft Security Intelligence Report (SIR).
For example, in SIR volume 8 we published a study the MSEC did on document file format exploits. I want to highlight this study here because I think it helps add a little context to the topic of targeted attacks and provides actionable guidance to help manage some of the associated risks.
Document File Format Exploits
Increasingly, attackers are using common file formats as transmission vectors for exploits. Most modern e-mail and instant messaging programs are configured to block the transmission of potentially dangerous files by extension, such as .exe, .com, and .scr, which have historically been misused to transmit malware. However, these same programs typically permit the transmission of many popular file formats, like .doc, .pdf, .ppt, and .xls. These formats are used legitimately by many people every day to share information and get work done, so blocking them is often not practical. This has made them an attractive target for exploitation.
[...]
To assess the use of Microsoft Office system file formats as an attack vector, Microsoft analyzed a sample of several hundred files that were used for successful attacks in 2H09 (the second half of 2009). The data set was taken from submissions of malicious code sent to Microsoft from customers worldwide.
[...]
All nine of these vulnerabilities had security updates available at the time of attack. The affected users were exposed because they had not applied the updates. Office 2000, Office XP, Office 2003, and the 2007 Microsoft Office system were each affected by at least one of the nine vulnerabilities.
Most of the vulnerabilities exploited in the data sample were several years old, with a third of them first identified in 2006.
[...]
Users who do not keep their Office program installations up to date with service packs and security updates are at increased risk of attack.
[...]
The key things to take away from this study are:
- Once attackers figure out how to exploit a document parser vulnerability, they will try to use that exploit for years to come.
- Newer is better: running the latest version of document parsers and the latest service pack is a very effective mitigation against these types of attacks.
- Keep all of your software up to date including document parsers such as Microsoft Office, Adobe Acrobat, Adobe Reader, and others.
- Use Microsoft Update to keep your Windows based systems up to date, instead of Windows Update. Microsoft Update will help keep all of your Microsoft software updated including Windows operating systems and Microsoft Office, where Windows Update only keeps Windows operating systems up to date.
- If you haven’t updated the document parsers you have installed on your systems, you should give serious consideration to doing so.
- Don’t open email attachments or documents hosted on the Internet if you don’t know and trust their source.
-------------------------------------------------------------------------------------------
As a former Microsoft Systems Management Server (SMS) admin, I can tell you that patching isn't easy as it sounds and it isn't as flashy as some other threat mitigation processes....but it is critically important for organizations to have a patch process in place - it is truly the last line of defense.
In today's threat landscape, patching just IE isn't enough anymore. You have to patch OS, browser, browser plug-ins and other programs that are being used in targeted attacks (like Office) against employee endpoints.
In large enterprises, the 'patchable' software surface can be daunting to patch management administrators. Combine that feeling with the reality that many employees have the ability to install whatever they want on my corporate endpoints (due to admin rights and/or a less managed endpoint posture) and you have a patch management nightmare that seems impossible.
So what can you do?
Use threat and exploit intelligence to focus your efforts on the vulnerabilities that you know are being exploited. Patch those now...and use that protection space generated by those efforts to evaluate your specific environment and identify the next subset of programs which should be patched - using a risk-based approach.
Wednesday, September 21, 2011
Security Update Available for Adobe Flash Player (APSB11-26)
Critical vulnerabilities have been identified in Adobe Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.186.6 and earlier versions for Android. These vulnerabilities could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that one of these vulnerabilities (CVE-2011-2444) is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message. This universal cross-site scripting issue could be used to take actions on a user's behalf on any website or webmail provider if the user visits a malicious website.
http://www.adobe.com/support/security/bulletins/apsb11-26.html
----------------------------------------------------------------------------
Based on the limited information provided by Adobe above, I suspect this new vulnerability (CVE-2011-244) was used in a new series of targeted web e-mail (Gmail) attacks – just as was the case with the last Flash Universal XSS detected and patched out-of-band by Adobe in June 2011. Note in the Adobe advisory that CVE-2011-2444 is credited to Google. Coincidence?
According to Google, that June 2011 campaign against Gmail, appeared to originate from Jinan, China and affected what seem to be the personal Gmail accounts of hundreds of users including, among others, senior U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists.
In the same June timeframe, TrendMicro noted that in addition to Gmail, Hotmail and Yahoo! Mail were also been targeted. While the attacks appear to have been separately conducted, these have some significant similarities.
http://www.adobe.com/support/security/bulletins/apsb11-26.html
----------------------------------------------------------------------------
Based on the limited information provided by Adobe above, I suspect this new vulnerability (CVE-2011-244) was used in a new series of targeted web e-mail (Gmail) attacks – just as was the case with the last Flash Universal XSS detected and patched out-of-band by Adobe in June 2011. Note in the Adobe advisory that CVE-2011-2444 is credited to Google. Coincidence?
According to Google, that June 2011 campaign against Gmail, appeared to originate from Jinan, China and affected what seem to be the personal Gmail accounts of hundreds of users including, among others, senior U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists.
In the same June timeframe, TrendMicro noted that in addition to Gmail, Hotmail and Yahoo! Mail were also been targeted. While the attacks appear to have been separately conducted, these have some significant similarities.
Friday, August 19, 2011
Inside an APT Covert Communications Channel
http://www.hbgary.com/hbgary-blog
For many years, hackers operating out of China have been attacking a myriad of commercial and government systems here in the US and abroad. The term “APT” or Advanced Persistent Threat has often been used to describe these attackers. While HBGary is primarily a product company selling an enterprise incident response product, the team has been deep into APT analysis for over five years. Most of the analysis work is in direct support of Digital DNA – an automated system for detection of unknown malware and APT intrusions. I presented a technical description of how this attribution works, what is solves and what it doesn’t, at the BlackHat Conference last year. The work is about tracking threat groups – that is, tracking the humans and the human factors behind the digital artifacts we see. There are many hacking groups involved in these intrusions. One such group has often been called “Comment Crew” for their use of HTML comments as a means of command and control. This group has been associated with the recent “Shady RAT” intrusion revealed by McAfee. For this article I am going to give you a technical in-depth tour of how such a group operates.
---------------------------------------------------------------
CyberESI - Trojan.Letsgo Analysis
http://www.cyberesi.com/2011/06/15/trojan-letsgo-analysis/
This is malware captured during an ongoing APT attack which utilized various techniques (i.e. Targeted Spear-phishing, HTML Comment Base64 C2, Encoded Binaries in GIFs, etc.) to bypass standard enterprise perimeter-based security measures (e.g. Proxy/Network Reputation Checking, Proxy AV, Proxy File Type Blocking, Firewalls). This attack also included "interaction with the host" by the attacker.
The CyberESI's blog is full of these types of analysis...another example:
Cyber ESI - The PNG Trojan AcroRD32.exe
http://www.cyberesi.com/2011/05/16/the-png-trojan-%E2%80%93-acrord32-exe/
Again, this is malware using the techniques outlined above (i.e. HTML Comment Based64 C2, Encoded Binaries in PNGs, etc.). Again, the attacker interactions with the host using basic commandline 'administration' command.
For many years, hackers operating out of China have been attacking a myriad of commercial and government systems here in the US and abroad. The term “APT” or Advanced Persistent Threat has often been used to describe these attackers. While HBGary is primarily a product company selling an enterprise incident response product, the team has been deep into APT analysis for over five years. Most of the analysis work is in direct support of Digital DNA – an automated system for detection of unknown malware and APT intrusions. I presented a technical description of how this attribution works, what is solves and what it doesn’t, at the BlackHat Conference last year. The work is about tracking threat groups – that is, tracking the humans and the human factors behind the digital artifacts we see. There are many hacking groups involved in these intrusions. One such group has often been called “Comment Crew” for their use of HTML comments as a means of command and control. This group has been associated with the recent “Shady RAT” intrusion revealed by McAfee. For this article I am going to give you a technical in-depth tour of how such a group operates.
---------------------------------------------------------------
CyberESI - Trojan.Letsgo Analysis
http://www.cyberesi.com/2011/06/15/trojan-letsgo-analysis/
This is malware captured during an ongoing APT attack which utilized various techniques (i.e. Targeted Spear-phishing, HTML Comment Base64 C2, Encoded Binaries in GIFs, etc.) to bypass standard enterprise perimeter-based security measures (e.g. Proxy/Network Reputation Checking, Proxy AV, Proxy File Type Blocking, Firewalls). This attack also included "interaction with the host" by the attacker.
The CyberESI's blog is full of these types of analysis...another example:
Cyber ESI - The PNG Trojan AcroRD32.exe
http://www.cyberesi.com/2011/05/16/the-png-trojan-%E2%80%93-acrord32-exe/
Again, this is malware using the techniques outlined above (i.e. HTML Comment Based64 C2, Encoded Binaries in PNGs, etc.). Again, the attacker interactions with the host using basic commandline 'administration' command.
Friday, August 12, 2011
DDoS Attack Forces Hong Kong Exchange Site Offline for Second Day
Via Threatpost.com -
Trading on Hong Kong’s stock market, Hong Kong Exchanges & Clearing, remains suspended today following a "coordinated and sustained" distributed denial of service attack on one of the exchange’s websites Wednesday. Several companies, including HSBC, China Power International and Cathay Pacific found their shares unavailable late Wednesday following the attack according to a report from BBC.
A Web site usually used for company announcements was forced offline in the attack on Wednesday. The attacks continued on Thursday, despite efforts to filter malicious traffic. A subsequent investigation by the Exchange's Information Technology team and outside security experts identified an attack stemming from a botnet located outside Hong Kong and intended to "intentionally interrupt the operation of the HKExnews website."
The Exchange did not give any indication of who the hackers are or what their motive is.
[...]
Security experts have warned that the financial services sector and, in particular, stock exchanges are vulnerable to hacking and are of interest to both criminal groups and state based actors who wish to use access for illicit profit, promote local firms or sow chaos - possibly as a prelude to a larger kinetic or cyber attack.
-----------------------------------------------------------------------------
HKEx News Release: Further Information about the Organised Attack on the HKExnews Website and Mitigation Measures
-----------------------------------------------------------------------------
This is freaking awesome....but freaking awesome in a scary bad way.
The DDoS isn't actually affecting the trading platform, it is hitting an Internet-facing website used to release (i.e make public) announcements from corporations. I believe, these announcements have to be public for the stock to trade per legal requirements - meaning nothing can trade until public has access.
Therefore, the HKEx is looking to expand their publication of these announcements via newspapers, e-mail and even other on-line portals.
At its core, this is a DDoS aimed at the business logic of the HKEx platform.
Weather the attackers knew that killing the publication website would stop trading is unknown. But I think we have to assume they did.
Trading on Hong Kong’s stock market, Hong Kong Exchanges & Clearing, remains suspended today following a "coordinated and sustained" distributed denial of service attack on one of the exchange’s websites Wednesday. Several companies, including HSBC, China Power International and Cathay Pacific found their shares unavailable late Wednesday following the attack according to a report from BBC.
A Web site usually used for company announcements was forced offline in the attack on Wednesday. The attacks continued on Thursday, despite efforts to filter malicious traffic. A subsequent investigation by the Exchange's Information Technology team and outside security experts identified an attack stemming from a botnet located outside Hong Kong and intended to "intentionally interrupt the operation of the HKExnews website."
The Exchange did not give any indication of who the hackers are or what their motive is.
[...]
Security experts have warned that the financial services sector and, in particular, stock exchanges are vulnerable to hacking and are of interest to both criminal groups and state based actors who wish to use access for illicit profit, promote local firms or sow chaos - possibly as a prelude to a larger kinetic or cyber attack.
-----------------------------------------------------------------------------
HKEx News Release: Further Information about the Organised Attack on the HKExnews Website and Mitigation Measures
-----------------------------------------------------------------------------
This is freaking awesome....but freaking awesome in a scary bad way.
The DDoS isn't actually affecting the trading platform, it is hitting an Internet-facing website used to release (i.e make public) announcements from corporations. I believe, these announcements have to be public for the stock to trade per legal requirements - meaning nothing can trade until public has access.
Therefore, the HKEx is looking to expand their publication of these announcements via newspapers, e-mail and even other on-line portals.
At its core, this is a DDoS aimed at the business logic of the HKEx platform.
Weather the attackers knew that killing the publication website would stop trading is unknown. But I think we have to assume they did.
Thursday, August 11, 2011
Continued Targeted Attacks Against Personal Gmail Accounts
Via Contagio Dump Blog (Mila Parkour) -
I am posting this only to highlight the fact that once compromises happen and are covered in the news, they do not disappear and attackers don't give up or stop. They continue their business as usual. Here is a small update to the post dated Feb 17, 2011 Targeted attacks against personal accounts of military, government employees and associates. This post was mentioned a few times in the news thanks to Google mention in their blogpost in June 2011.
I received a phishing email sample indicating that the attackers described in the above post continue their efforts with a very slight modifications to the original themes and I must note that this incident is even more simple than the previous one. I don't know if any accounts were compromised this time, I hope the public disclosure of the previous attacks along with the notifications on Forward rules and two-factor authentication in Gmail helped prevent most if not all compromises.
P.S. Google are aware of this, there is not much they can do to prevent these from coming in but I am sure they are trying. If you are concerned about your account safety, please use two-factor authentication and change your passwords often.
-----------------------------------------------------------------------
Excellent detailed update by Mila on the ongoing personal web-based e-mail attacks.
As Mila outlines, these attackers have purpose. While the media has moved on the the next "big story", these [persistent] attackers continue their targeted hacking campaign...grinding away to fulfill their objectives.
I am posting this only to highlight the fact that once compromises happen and are covered in the news, they do not disappear and attackers don't give up or stop. They continue their business as usual. Here is a small update to the post dated Feb 17, 2011 Targeted attacks against personal accounts of military, government employees and associates. This post was mentioned a few times in the news thanks to Google mention in their blogpost in June 2011.
I received a phishing email sample indicating that the attackers described in the above post continue their efforts with a very slight modifications to the original themes and I must note that this incident is even more simple than the previous one. I don't know if any accounts were compromised this time, I hope the public disclosure of the previous attacks along with the notifications on Forward rules and two-factor authentication in Gmail helped prevent most if not all compromises.
P.S. Google are aware of this, there is not much they can do to prevent these from coming in but I am sure they are trying. If you are concerned about your account safety, please use two-factor authentication and change your passwords often.
-----------------------------------------------------------------------
Excellent detailed update by Mila on the ongoing personal web-based e-mail attacks.
As Mila outlines, these attackers have purpose. While the media has moved on the the next "big story", these [persistent] attackers continue their targeted hacking campaign...grinding away to fulfill their objectives.
Friday, July 15, 2011
Symantec: A Look Inside Targeted Email Attacks
Via Symantec Über Security Response Blog -
The number of targeted attacks has increased dramatically in recent years. Major companies, government agencies, and political organizations alike have reported being the target of attacks. The rule of the thumb is, the more sensitive the information that an organization handles, the higher the possibility of becoming a victim of such an attack.
Here, we’ll attempt to provide insight on a number of key questions related to targeted attacks, such as where did the malicious email come from, which particular organizations are being targeted, which domains (spoofed or not) sent the email, what kinds of malicious attachments did the emails contain, etc. Our analysis of the data showed that, on average, targeted email attacks are on the rise:
[...]
Three out of the top 10 are governmental agencies. Among the remaining seven organizations, four have strong ties to either local or international governmental bodies. Two organizations (in sixth and tenth position) are not under governmental control; however, their business operations are heavily regulated and may be influenced by governmental organizations.
Governmental organizations are obviously targeted for their politically sensitive information. But why target NPOs and private companies? It’s a foot-in-the-door technique. By compromising those companies with strong ties to government agencies, attackers may acquire contact information for government personnel and craft their next attack around that stolen information.
In one particular organization, ranked 7th on our most targeted list, we observed the following:
Having said that, targeting the top-ranking personnel in an organization is not a “must” for attackers; often, targets are likely to include P.A.s as well as I.T. staff (who often have administrative rights on the target infrastructure). Once the attacker successfully infects or compromises one machine in the organization, they then have the potential to compromise other machines or devices on the same network. This may enable the attackers to harvest further contact information (belonging to other organizations) along the way, which leads to future attacks against different entities—the attackers just need that initial foot in the door.
[...]
In summary:
The number of targeted attacks has increased dramatically in recent years. Major companies, government agencies, and political organizations alike have reported being the target of attacks. The rule of the thumb is, the more sensitive the information that an organization handles, the higher the possibility of becoming a victim of such an attack.
Here, we’ll attempt to provide insight on a number of key questions related to targeted attacks, such as where did the malicious email come from, which particular organizations are being targeted, which domains (spoofed or not) sent the email, what kinds of malicious attachments did the emails contain, etc. Our analysis of the data showed that, on average, targeted email attacks are on the rise:
[...]
Three out of the top 10 are governmental agencies. Among the remaining seven organizations, four have strong ties to either local or international governmental bodies. Two organizations (in sixth and tenth position) are not under governmental control; however, their business operations are heavily regulated and may be influenced by governmental organizations.
Governmental organizations are obviously targeted for their politically sensitive information. But why target NPOs and private companies? It’s a foot-in-the-door technique. By compromising those companies with strong ties to government agencies, attackers may acquire contact information for government personnel and craft their next attack around that stolen information.
In one particular organization, ranked 7th on our most targeted list, we observed the following:
- Forty-one people received 10 or more emails, making up 98% of the total attack emails sent to that organization.
- The remaining 2% of emails were targeted at 13 others, resulting in an average of less than two emails per person.
Having said that, targeting the top-ranking personnel in an organization is not a “must” for attackers; often, targets are likely to include P.A.s as well as I.T. staff (who often have administrative rights on the target infrastructure). Once the attacker successfully infects or compromises one machine in the organization, they then have the potential to compromise other machines or devices on the same network. This may enable the attackers to harvest further contact information (belonging to other organizations) along the way, which leads to future attacks against different entities—the attackers just need that initial foot in the door.
[...]
In summary:
- On average, targeted email attacks increased during the two-year period we looked at.
- The more sensitive the information that an organization handles, the higher the probability of becoming a victim of such an attack.
- The government/public sector is the most targeted industry.
- A small percentage of people receive the bulk of the emails.
- The attachments of choice are .pdf and .doc, making up a combined 67% of all targeted email attachments.
- Some targeted attacks can be extremely well crafted and quite convincing.
- Certain organizations and companies make for more attractive targets than others.
- The people who work for these “higher value targets” need to take extra special care when dealing with emails that contain attachments or links.
Friday, July 1, 2011
Spam Profits Down, Cybercrooks Flock to Targeted Attacks
Via Threatpost.com -
A new report from Cisco Systems Inc. analyzing illegal activities from spammers and other online scams suggests that cyber criminals are abandoning large spam runs and indiscriminate attacks in search of higher profits doing targeted hacks.
The findings of the report, released at a press and analyst event on Thursday, suggest a precipitous drop in revenue generated by mass spam- and phishing attacks of the last five years, and a shift to lower volume, but more profitable targeted attacks, according to the report.
Cisco estimated that worldwide revenue from high volume spamming has decreased by more than two thirds since last year, from $1 billion a year ago to just $300 million today. During the same period, revenue from scams and other malicious attacks has quadrupled from $50 million to around $200 million, the company reported.
[...]
Targeted attacks are a subset of spam and share many characteristics with mass spam runs, including the use of e-mail messages containing malicious file attachments or Web links. However, targeted attacks rely on extensive planning and research on the likely recipients of the e-mail. Time is taken to craft e-mail messages that seem to be from legitimate sources and directed to the recipient.
Targeted spam runs are far smaller than mass spam runs, but have similar block rates. The key difference is a far higher conversion rate among the few users who end up seeing the targeted e-mails. Fully 70% of those who see a targeted e-mail message opened it, Cisco data suggests, and 50% of those clicked through to the malicious Web page or attachment and were "converted."
The average value per victim, for attackers, can be 40 times that of a mass attack and the profit from a spearphishing campaign can be 10 times that of a high volume spam run, Cisco said.
------------------------------------------------------------------------------------------------------
In the current security landscape and marketing hype, it can be difficult to remember not every attack is an APT, even if that attack is very well planned, executed and has the objective of obtaining data to facilitate or improve future cybercrime / fraud.
A quote on targeted attacks from McAfee's 2011 Threat Predictions whitepaper (PDF)..
So how are they improving? By going for quality over quantity and improving the social engineering aspects of their attacks with better aim - increasing the likelihood that the victim will bite the bait.
In Nov 2010, Return Path Inc. issued a warning to their ESP (Email Service Provider) partners...
http://www.returnpath.net/blog/received/2010/11/security-alert-phishing-attack-aimed-at-esps/
What better to improve than stealing the customer mailing list for Company X, spending a small amount of time crafting a fake e-mail from Company X and then sending it specifically to their customers, which are already expecting an e-mail from Company X? Brilliant!
It's spear-phishing (or spear-spamming) by group, as opposed to by individual. The attacker could use take it one step further, depending on the stolen o loytaly btained...and include each person's first and last name....perhaps part of their loyalty number.
The better the information obtained before the attack (e.g. intelligence), the more targeted the attack can be...and thus more effective (and profitable). It's simple economics.
A new report from Cisco Systems Inc. analyzing illegal activities from spammers and other online scams suggests that cyber criminals are abandoning large spam runs and indiscriminate attacks in search of higher profits doing targeted hacks.
The findings of the report, released at a press and analyst event on Thursday, suggest a precipitous drop in revenue generated by mass spam- and phishing attacks of the last five years, and a shift to lower volume, but more profitable targeted attacks, according to the report.
Cisco estimated that worldwide revenue from high volume spamming has decreased by more than two thirds since last year, from $1 billion a year ago to just $300 million today. During the same period, revenue from scams and other malicious attacks has quadrupled from $50 million to around $200 million, the company reported.
[...]
Targeted attacks are a subset of spam and share many characteristics with mass spam runs, including the use of e-mail messages containing malicious file attachments or Web links. However, targeted attacks rely on extensive planning and research on the likely recipients of the e-mail. Time is taken to craft e-mail messages that seem to be from legitimate sources and directed to the recipient.
Targeted spam runs are far smaller than mass spam runs, but have similar block rates. The key difference is a far higher conversion rate among the few users who end up seeing the targeted e-mails. Fully 70% of those who see a targeted e-mail message opened it, Cisco data suggests, and 50% of those clicked through to the malicious Web page or attachment and were "converted."
The average value per victim, for attackers, can be 40 times that of a mass attack and the profit from a spearphishing campaign can be 10 times that of a high volume spam run, Cisco said.
------------------------------------------------------------------------------------------------------
In the current security landscape and marketing hype, it can be difficult to remember not every attack is an APT, even if that attack is very well planned, executed and has the objective of obtaining data to facilitate or improve future cybercrime / fraud.
A quote on targeted attacks from McAfee's 2011 Threat Predictions whitepaper (PDF)..
"Not all APT attacks are highly advanced and sophisticated, just as not every highly complex and well-executed targeted attack is an APT."So why would standard cybercriminals want to improve their attacks? The same reason anyone wants to improve a process - to do it cheap and to make it more profitable. The new Cisco report above shows just how profitable a little improvement can be for the bad guys.
So how are they improving? By going for quality over quantity and improving the social engineering aspects of their attacks with better aim - increasing the likelihood that the victim will bite the bait.
In Nov 2010, Return Path Inc. issued a warning to their ESP (Email Service Provider) partners...
http://www.returnpath.net/blog/received/2010/11/security-alert-phishing-attack-aimed-at-esps/
Over the course of the past five weeks, spam campaigns have been aimed at the staff members of over 100 ESPs and gambling sites. These targets have received emails typically with content that mentions the staffer by name, and purports to be from a couple, presumably friends or co-workers.
The phish message has been sent numerous times, over several different systems, including using the facility of some ESPs, using online greeting card sites, and by way of a botnet. Sources confirm the list of addresses is very small (less than 3,000 addresses) and aimed 100% at staff responsible for email operations.
[...]
This is an organized, deliberate, and destructive attack clearly intent on gaining access to industry-grade email deployment systems. Further, the potential consequences should ESP client mailing lists be compromised at this time of the year is unimaginable.
What better to improve than stealing the customer mailing list for Company X, spending a small amount of time crafting a fake e-mail from Company X and then sending it specifically to their customers, which are already expecting an e-mail from Company X? Brilliant!
It's spear-phishing (or spear-spamming) by group, as opposed to by individual. The attacker could use take it one step further, depending on the stolen o loytaly btained...and include each person's first and last name....perhaps part of their loyalty number.
The better the information obtained before the attack (e.g. intelligence), the more targeted the attack can be...and thus more effective (and profitable). It's simple economics.
Friday, June 17, 2011
Exploit for MS11-50 Vulnerability in the Wild
Via Symantec Über Security Response Blog -
Symantec Security Response has confirmed that the Microsoft Internet Explorer Time Element Uninitialized Memory Remote Code Execution Vulnerability (CVE-2011-1255) is being exploited in the wild. The vulnerability affects Internet Explorer versions 6, 7, and 8; however, the exploit we have acquired seems to only affect version 8. Microsoft has already released patches as part of the MS Tuesday release on June 14, so Symantec advises all users to install the patch. So far, we have only seen limited attacks taking advantage of this vulnerability and believe that the exploit is only being carried out in targeted attacks at present.
We have been able to confirm the existence of one such attack that involves a compromised website hosting content for a neighborhood restaurant. It appears that a duplicate of the top page of the website was either hacked to include a hidden iframe tag linking to an exploit page or was prepared from scratch, which, if run successfully, the included shell code downloads an encrypted malicious file from the same site. Interestingly, a link to cnzz.com, which is a site that offers statistical analysis, is included in the page to perhaps to provide the attackers with an idea of how the attack is progressing. The downloaded malware then contacts 323332.3322.org using the HTTP protocol and awaits further commands. 3322.org provides a type of dynamic DNS service and is known to be used for various malicious purposes, so it may not be a bad idea to block access to this domain and, if needed, whitelist the subdomains that you may need access to. It's likely that the attacker sends emails to targets with a link to the website with the intent to steal confidential information, which is a common method used in targeted attacks.
To protect themselves from attack, users should apply the latest patch for this vulnerability. They should also keep all other software on their computer up to date as well, including security software. Users should also be cautious when receiving emails with attachments and links they receive from both known and unknown sources.
------------------------------------------------------------------------
Threat Mitigation - Apply MS11-050
The vulnerability outlined above was patched in Microsoft's Security Bulletin MS11-050 - Cumulative Security Update for Internet Explorer (2530548)
http://www.microsoft.com/technet/security/Bulletin/MS11-050.mspx
Symantec Security Response has confirmed that the Microsoft Internet Explorer Time Element Uninitialized Memory Remote Code Execution Vulnerability (CVE-2011-1255) is being exploited in the wild. The vulnerability affects Internet Explorer versions 6, 7, and 8; however, the exploit we have acquired seems to only affect version 8. Microsoft has already released patches as part of the MS Tuesday release on June 14, so Symantec advises all users to install the patch. So far, we have only seen limited attacks taking advantage of this vulnerability and believe that the exploit is only being carried out in targeted attacks at present.
We have been able to confirm the existence of one such attack that involves a compromised website hosting content for a neighborhood restaurant. It appears that a duplicate of the top page of the website was either hacked to include a hidden iframe tag linking to an exploit page or was prepared from scratch, which, if run successfully, the included shell code downloads an encrypted malicious file from the same site. Interestingly, a link to cnzz.com, which is a site that offers statistical analysis, is included in the page to perhaps to provide the attackers with an idea of how the attack is progressing. The downloaded malware then contacts 323332.3322.org using the HTTP protocol and awaits further commands. 3322.org provides a type of dynamic DNS service and is known to be used for various malicious purposes, so it may not be a bad idea to block access to this domain and, if needed, whitelist the subdomains that you may need access to. It's likely that the attacker sends emails to targets with a link to the website with the intent to steal confidential information, which is a common method used in targeted attacks.
To protect themselves from attack, users should apply the latest patch for this vulnerability. They should also keep all other software on their computer up to date as well, including security software. Users should also be cautious when receiving emails with attachments and links they receive from both known and unknown sources.
------------------------------------------------------------------------
Threat Mitigation - Apply MS11-050
The vulnerability outlined above was patched in Microsoft's Security Bulletin MS11-050 - Cumulative Security Update for Internet Explorer (2530548)
http://www.microsoft.com/technet/security/Bulletin/MS11-050.mspx
Subscribe to:
Posts (Atom)