Via Gal Badishi's Security Bits Blog -
While working on Poison Ivy’s communication, one of my students approached me and asked me if the fact that an infected computer can connect to the C&C server means that the compromised host can break into the server. Well folks, it appears that it’s possible. We will now present a fully working exploit for all Windows platforms (i.e., bypassing DEP and ASLR), allowing a computer infected by Poison Ivy (or any computer, for that matter) to assume control of PI’s C&C server.
[...]
It’s important to note that the exploit data following our header never gets decrypted, so we don’t have to worry about PI ruining our values if we don’t encrypt the data.
In light of this analysis, a Metasploit module without encryption is being prepared.
Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Showing posts with label APT. Show all posts
Showing posts with label APT. Show all posts
Tuesday, June 26, 2012
Wednesday, May 30, 2012
Taking a Bite Out of IXESHE
Via TrendMicro Malware Blog -
We released a new research paper describing the activities of another APT campaign, IXESHE (pronounced “i-sushi”).
One of the most notable characteristics of the IXESHE campaign is the attackers’ use of compromised servers in target organizations as command-and-control (C&C) servers. This tactic allowed them to hide their presence by confusing their activities with data belonging to legitimate individuals. In one particular case, we saw C&C servers hosted on the compromised machines of an East Asian country, making targeted attacks against that government easier. In another case, we received an error message from a C&C server, which indicated that the front-end servers were merely acting as proxies for the actual back-end servers.
Our research also showed that attackers utilized dynamic Domain Naming System (DNS) servers and broadly distributed external C&C servers around the world to make detection and takedowns more difficult to do.
The IXESHE campaign has been underway since at least July 2009 when we first saw samples of this particular malware family. Its primary method of entry into user systems is via malicious .PDF files that exploit Adobe Acrobat, Reader, or Flash Player vulnerabilities. These malicious files are sent as attachments to targeted emails sent to potential victims within target organizations.
In the process of our investigation, we were able to determine that its victims could be broadly classified into three categories:
•East Asian governments
•Electronics manufacturers
•A German telecommunications company
For further details, please consult the full paper...
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_ixeshe.pdf
We released a new research paper describing the activities of another APT campaign, IXESHE (pronounced “i-sushi”).
One of the most notable characteristics of the IXESHE campaign is the attackers’ use of compromised servers in target organizations as command-and-control (C&C) servers. This tactic allowed them to hide their presence by confusing their activities with data belonging to legitimate individuals. In one particular case, we saw C&C servers hosted on the compromised machines of an East Asian country, making targeted attacks against that government easier. In another case, we received an error message from a C&C server, which indicated that the front-end servers were merely acting as proxies for the actual back-end servers.
Our research also showed that attackers utilized dynamic Domain Naming System (DNS) servers and broadly distributed external C&C servers around the world to make detection and takedowns more difficult to do.
The IXESHE campaign has been underway since at least July 2009 when we first saw samples of this particular malware family. Its primary method of entry into user systems is via malicious .PDF files that exploit Adobe Acrobat, Reader, or Flash Player vulnerabilities. These malicious files are sent as attachments to targeted emails sent to potential victims within target organizations.
In the process of our investigation, we were able to determine that its victims could be broadly classified into three categories:
•East Asian governments
•Electronics manufacturers
•A German telecommunications company
For further details, please consult the full paper...
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_ixeshe.pdf
Monday, May 14, 2012
Fundamentals of Chinese Information Warfare
The Potomac Institute Cyber Center hosted a special program on Fundamentals of Chinese Information Warfare and Impacts on the Western World on Friday, May 11, 2012. The guest speakers included William T. Hagestad II, author of the new book 21st Century Chinese Cyberwarfare (IT Governance, 2012)
http://www.potomacinstitute.org/index.php?option=com_content&view=article&id=1193:new-date-may-11-fundamentals-of-chinese-information-warfare&catid=65:past-events&Itemid=94
The commentary is pretty insightful and near the end of touches on some possible geopolitical solutions that can be used to change China's behavior.
Hat-tip to Bill and his Red Dragon Rising blog.
-----------------------------------------------
Here is the Potomac Institute for Policy Studies lecture and panel discussion on "Russian Cyber Capabilities".
http://www.potomacinstitute.org/index.php?option=com_content&view=article&id=1193:new-date-may-11-fundamentals-of-chinese-information-warfare&catid=65:past-events&Itemid=94
The commentary is pretty insightful and near the end of touches on some possible geopolitical solutions that can be used to change China's behavior.
Hat-tip to Bill and his Red Dragon Rising blog.
-----------------------------------------------
Here is the Potomac Institute for Policy Studies lecture and panel discussion on "Russian Cyber Capabilities".
Uighur Leader Accuses China of ‘Systematic Assimilation’
Via VOA News -
Exiled representatives of the Uighur, an ethnic group that lives mainly in Western China’s province of Xinjiang, are meeting in Japan for their fourth annual conference. The World Uighur Congress, based in Germany, opposes what it calls the Chinese occupation of their land, and the group's gatherings routinely draw criticism from Beijing.
Rebiya Kadeer, leader of the World Uighur Congress, and also known as "the Mother of the Uighur Nation," has been living in exile in the United States since her release from a Chinese prison in 2005.
She joined more than 100 representatives of the ethnic group from more than 20 countries, including the United States, Germany and Australia, to elect new leadership and discuss strategies to engage China over the issue of self-determination.
Kadeer said the Uighurs are facing a threat to their existence because of the Chinese government’s policy of systematic assimilation. She also accuses Chinese authorities of committing extra-judicial killings, economic exploitation, and destroying Uighur values.
--------------------------------------
With that in mind, could you guess who might want to target companies or organization interested in the Uyghur Congress with targeted zero-day malware? I wonder. ;)
APT: A Geopolitical Problem
http://www.ericjhuber.com/2011/08/apt-geopolitical-problem.html
Exiled representatives of the Uighur, an ethnic group that lives mainly in Western China’s province of Xinjiang, are meeting in Japan for their fourth annual conference. The World Uighur Congress, based in Germany, opposes what it calls the Chinese occupation of their land, and the group's gatherings routinely draw criticism from Beijing.
Rebiya Kadeer, leader of the World Uighur Congress, and also known as "the Mother of the Uighur Nation," has been living in exile in the United States since her release from a Chinese prison in 2005.
She joined more than 100 representatives of the ethnic group from more than 20 countries, including the United States, Germany and Australia, to elect new leadership and discuss strategies to engage China over the issue of self-determination.
Kadeer said the Uighurs are facing a threat to their existence because of the Chinese government’s policy of systematic assimilation. She also accuses Chinese authorities of committing extra-judicial killings, economic exploitation, and destroying Uighur values.
--------------------------------------
With that in mind, could you guess who might want to target companies or organization interested in the Uyghur Congress with targeted zero-day malware? I wonder. ;)
APT: A Geopolitical Problem
http://www.ericjhuber.com/2011/08/apt-geopolitical-problem.html
Friday, May 11, 2012
TTPs: Lessons from Today's Amnesty Hack
Via Imperva -
Amnesty International UK's website was hacked courtesy a backdoor dropped on visitors systems. Most likely done by a foreign government, many speculate that it's the Chinese. Websense's blog gives a good technical overview of the attack.
But what does it mean for security teams?
In some cases, hackers don’t want to steal the data from the website but rather want to infect the users who are visiting. This can lead to more access to business critical data which, for example, is often stored as files on a fileserver. In the Amnesty case, the real prize isn't Amnesty's data per se, but the corporate and individual data and files of those who visit the site.
-------------------------------------------------
This exact technique has been used by advanced adversaries in previous targeted attacks. Intelligence sources have obvsered this technique being used in attacks against the US defense industry as well.
July 2011 - Attack On Pacific Northwest National Lab Started At Public Web Servers
Amnesty International UK's website was hacked courtesy a backdoor dropped on visitors systems. Most likely done by a foreign government, many speculate that it's the Chinese. Websense's blog gives a good technical overview of the attack.
But what does it mean for security teams?
In some cases, hackers don’t want to steal the data from the website but rather want to infect the users who are visiting. This can lead to more access to business critical data which, for example, is often stored as files on a fileserver. In the Amnesty case, the real prize isn't Amnesty's data per se, but the corporate and individual data and files of those who visit the site.
-------------------------------------------------
This exact technique has been used by advanced adversaries in previous targeted attacks. Intelligence sources have obvsered this technique being used in attacks against the US defense industry as well.
July 2011 - Attack On Pacific Northwest National Lab Started At Public Web Servers
Thursday, May 3, 2012
Microsoft Fingers Chinese Firewall/IPS Vendor In Windows Exploit Leak
Via Dark Reading -
Microsoft today announced that it had rooted out the source of a leak from within its third-party security software firm partnership program that resulted in the weaponization of a bug in Windows -- raising questions about whether the Microsoft Active Protections Program (MAPP) could be vulnerable to other such breaches.
Chinese firewall and IPS vendor Hangzhou DPTech Technologies Co., Ltd., according to Microsoft, was the culprit behind a rapid-fire turnaround of a working exploit for the Windows Remote Desktop (RDP) flaw in mid-March, just after the bug was patched by Microsoft.
[...]
Microsoft today was mum on how it ultimately rooted out DPTech as the source of the leak, or on just what Hangzhou DPTech Technologies did. "During our investigation into the disclosure of confidential data shared with our Microsoft Active Protections Program (MAPP) partners, we determined that a member of the MAPP program, Hangzhou DPTech Technologies Co., Ltd., had breached our non-disclosure agreement (NDA). Microsoft takes breaches of our NDAs very seriously and has removed this partner from the MAPP Program," said Yunsun Wee, director or Microsoft Trustworthy Computing, in a statement.
HD Moore, chief security officer at Rapid7 and creator of Metasploit, says it couldn't have been simple to trace the leak to a specific company. "[It's] interesting and somewhat surprising that they found it at all," Moore says.
Meanwhile, the announcement by Microsoft appears to raise more questions than it answers. Concerns about a Chinese security vendor leaking Windows vulnerability details before the patch window had closed, and whether this was truly the first breach of the MAPP program, sent a chill through the industry.
"Yes, it is a little concerning that it was a Chinese firm that leaked the Microsoft information. That being said, what did Microsoft really expect was going to happen? The Chinese do not have a very good track record of adhering to NDA and other agreements," says Paul Henry, security and forensic analyst at Lumension. "It is important to recognize that the MAPP program is relatively new, so there will be bumps in the road as Microsoft works out the delicate balance between strategic sharing and safeguarding the distribution of sensitive information regarding its products."
-----------------------------------------
MAPP Update: Taking Action to Decrease Risk of Information Disclosure
http://blogs.technet.com/b/msrc/archive/2012/05/03/mapp-update-taking-action-to-decrease-risk-of-information-disclosure.aspx
-----------------------------------------
Shocker. Kudos to MS for tracking this down to the company. Impressive.
Microsoft today announced that it had rooted out the source of a leak from within its third-party security software firm partnership program that resulted in the weaponization of a bug in Windows -- raising questions about whether the Microsoft Active Protections Program (MAPP) could be vulnerable to other such breaches.
Chinese firewall and IPS vendor Hangzhou DPTech Technologies Co., Ltd., according to Microsoft, was the culprit behind a rapid-fire turnaround of a working exploit for the Windows Remote Desktop (RDP) flaw in mid-March, just after the bug was patched by Microsoft.
[...]
Microsoft today was mum on how it ultimately rooted out DPTech as the source of the leak, or on just what Hangzhou DPTech Technologies did. "During our investigation into the disclosure of confidential data shared with our Microsoft Active Protections Program (MAPP) partners, we determined that a member of the MAPP program, Hangzhou DPTech Technologies Co., Ltd., had breached our non-disclosure agreement (NDA). Microsoft takes breaches of our NDAs very seriously and has removed this partner from the MAPP Program," said Yunsun Wee, director or Microsoft Trustworthy Computing, in a statement.
HD Moore, chief security officer at Rapid7 and creator of Metasploit, says it couldn't have been simple to trace the leak to a specific company. "[It's] interesting and somewhat surprising that they found it at all," Moore says.
Meanwhile, the announcement by Microsoft appears to raise more questions than it answers. Concerns about a Chinese security vendor leaking Windows vulnerability details before the patch window had closed, and whether this was truly the first breach of the MAPP program, sent a chill through the industry.
"Yes, it is a little concerning that it was a Chinese firm that leaked the Microsoft information. That being said, what did Microsoft really expect was going to happen? The Chinese do not have a very good track record of adhering to NDA and other agreements," says Paul Henry, security and forensic analyst at Lumension. "It is important to recognize that the MAPP program is relatively new, so there will be bumps in the road as Microsoft works out the delicate balance between strategic sharing and safeguarding the distribution of sensitive information regarding its products."
-----------------------------------------
MAPP Update: Taking Action to Decrease Risk of Information Disclosure
http://blogs.technet.com/b/msrc/archive/2012/05/03/mapp-update-taking-action-to-decrease-risk-of-information-disclosure.aspx
-----------------------------------------
Shocker. Kudos to MS for tracking this down to the company. Impressive.
Monday, April 30, 2012
Determined Adversaries and Targeted Attacks
Via Microsoft Security Intelligence Report -
Over the past two decades the internet has become fundamental to the pursuit of day-to-day commercial, personal, and governmental business. However, the ubiquitous nature of the internet as a communications platform has also increased the risk to individuals and organizations from cyberthreats. These threats include website defacement, virus and worm (or malware) outbreaks, and network intrusion attempts. In addition, the global presence of the internet has allowed it to be used as a significant staging ground for espionage activity directed at industrial, political, military, and civil targets.
During the past 5 years, one specific category of threat has become much more widely discussed. Originally referred to as Advanced Persistent Threats (APT) by the U.S. military — referring to alleged nation-state sponsored attempts to infiltrate military networks and exfiltrate sensitive data — the term APT is today widely used in media and IT security circles to describe any attack that seems to specifically target individual organization, or is thought to be notably technical in nature, regardless of whether the attack was actually either advanced or persistent.
In fact, this type of attack typically involves two separate components — the action(s) and the actor(s) — that may be targeted against governments, military organizations or, increasingly, commercial entities and civil society.
The actions are the attacks themselves, which may be IT-related or not, and are referred to as Targeted Attacks in this paper. These attacks are initiated and conducted by human actors, who are collectively referred to in this paper as Determined Adversaries. These definitions are important because they emphasize the point that the attacks are carried out by human actors who may use any tools or techniques necessary to achieve their goals; these attacks are not merely malicious software or exploits. Using an encompassing term such as APT can mask this reality and create the impression that all such attacks are technically sophisticated and malware-driven, making it harder to plan an effective defensive posture.
For these reasons, this paper uses Targeted Attacks and Determined Adversaries as more specific and meaningful terms to describe this category of attack.
-------------------------------------------------------------
Be sure to check out Microsoft's Security Intelligence Report (SIR) Volume 12.
http://www.microsoft.com/security/sir/default.aspx
Over the past two decades the internet has become fundamental to the pursuit of day-to-day commercial, personal, and governmental business. However, the ubiquitous nature of the internet as a communications platform has also increased the risk to individuals and organizations from cyberthreats. These threats include website defacement, virus and worm (or malware) outbreaks, and network intrusion attempts. In addition, the global presence of the internet has allowed it to be used as a significant staging ground for espionage activity directed at industrial, political, military, and civil targets.
During the past 5 years, one specific category of threat has become much more widely discussed. Originally referred to as Advanced Persistent Threats (APT) by the U.S. military — referring to alleged nation-state sponsored attempts to infiltrate military networks and exfiltrate sensitive data — the term APT is today widely used in media and IT security circles to describe any attack that seems to specifically target individual organization, or is thought to be notably technical in nature, regardless of whether the attack was actually either advanced or persistent.
In fact, this type of attack typically involves two separate components — the action(s) and the actor(s) — that may be targeted against governments, military organizations or, increasingly, commercial entities and civil society.
The actions are the attacks themselves, which may be IT-related or not, and are referred to as Targeted Attacks in this paper. These attacks are initiated and conducted by human actors, who are collectively referred to in this paper as Determined Adversaries. These definitions are important because they emphasize the point that the attacks are carried out by human actors who may use any tools or techniques necessary to achieve their goals; these attacks are not merely malicious software or exploits. Using an encompassing term such as APT can mask this reality and create the impression that all such attacks are technically sophisticated and malware-driven, making it harder to plan an effective defensive posture.
For these reasons, this paper uses Targeted Attacks and Determined Adversaries as more specific and meaningful terms to describe this category of attack.
-------------------------------------------------------------
Be sure to check out Microsoft's Security Intelligence Report (SIR) Volume 12.
http://www.microsoft.com/security/sir/default.aspx
The Microsoft Security Intelligence Report (SIR) analyzes the threat landscape of exploits, vulnerabilities, and malware using data from Internet services and over 600 million computers worldwide. Threat awareness can help you protect your organization, software, and people.
Monday, April 16, 2012
Recent Purported CEIEC Document Dump Booby-Trapped
Via ShadowServer -
In recent weeks thousands documents have been released online by a hacktivist going by the online moniker of "Hardcore Charlie." These documents appear to have potentially been sourced and possibly stolen from various businesses and governments in different countries including the United States, the Philippines, Myanmar, Vietnam, and others. In particular Hardcore Charlie has been attempting to draw attention to some of the documents that apparently relate to U.S. military operations in Afghanistan. The twist in all of this is that the documents are purported to have been stolen by Hardcore Charlie from the Beijing based military contractor China National Import & Export Corp (CEIEC). If true, that would mean that the documents were stolen at least twice. These are allegations that CEIEC has strongly denied and condemned in a post on their website.
This entire turn of events has raised more questions than they have answered. Are the documents legitimate? Where were they original stolen from? If these were really stolen twice, who stole them first? We unfortunately do not have the answer to any of these questions. However, one thing we do have are words of caution and some interesting information about a handful of the documents found in this dump. Within the document dump in a folder related to Vietnam are 11 malicious documents (8 unique) that exploit vulnerabilities (CVE-2010-3333 and CVE-2009-3129) in Microsoft Office to install malware. These documents installed four different types of backdoors that reported back to six distinct command and control servers. Two of the backdoors were unfamiliar to us and the other two were the well known Poison Ivy RAT and the Enfal/Lurid. At least one hostname could be tied back to a known set of persistent actors engaged in cyber espionage.
[...]
Vietnamese Targeting and Timeline
These nine unique samples from the document dump from Hardcore Charlie appear to lead to multiple different attack campaigns targeting Vietnamese interests. The malicious documents have Vietnamese names and will open legitimate clean versions of the documents in Vietnamese upon successful exploitation. At least one of the trojan samples even saves itself as a file that might blend in on a Vietnamese computer. Another has strings related to the Vietnamese version of Google, while another uses a DNS name that is in Vietnamese as well. We would suspect this may just be the tip of the ice berg.
As for timing -- several indicators seem to point to these documents being approximately a year old. The most obvious and more tamper proof piece of evidence being a VirusTotal submission from April 2011. You may note the document from this submission was named BC cua chi binh voi BCS.doc. However, this file has the same MD5 hash of of32f5ad4f09135fcdde86ecd4c466a993, which matches the file was saw named Danh sach.doc. This indicates that his activity is not new and these files may have been unknowingly included in this document dump
Conclusion
These malicious documents within the data dump raise several questions and can lead to plenty of speculation. Were these malicious documents resident on victim systems from previous targeted APT campaigns and exfiltrated alongside the legitimate documents as part of another cyber espionage operation? Could it be that they were intentionally placed into this data dump? Anything is possible and we do not have all the answers. However, we can tell you that a few of the malware samples had previously been submitted to VirusTotal in early 2011. Additionally meta data of the clean documents dropped by a few of the malware payloads showed that the documents were also created in 2011, indicating that the malicious documents have likely been circulating in the wild for more than year.
Although many questions remain, the following facts are clear:
These documents just go to show that malicious files can end up pretty much anywhere. We are stating the obvious but remember to exercise caution when viewing files you downloaded from the Internet. Microsoft patched the two vulnerabilities used in these attacks quite some time ago. They patched CVE-2009-3129 with MS09-067 and CVE-2010-3333 with MS10-087. Malicious documents that exploit vulnerabilities in Microsoft Office, Adobe Acrobat [Reader], or components loaded by these pieces of software are still some of the most common ways in which cyber espionage attacks are conducted. Staying current with the latest versions and security patches for any software you run is highly recommended.
In recent weeks thousands documents have been released online by a hacktivist going by the online moniker of "Hardcore Charlie." These documents appear to have potentially been sourced and possibly stolen from various businesses and governments in different countries including the United States, the Philippines, Myanmar, Vietnam, and others. In particular Hardcore Charlie has been attempting to draw attention to some of the documents that apparently relate to U.S. military operations in Afghanistan. The twist in all of this is that the documents are purported to have been stolen by Hardcore Charlie from the Beijing based military contractor China National Import & Export Corp (CEIEC). If true, that would mean that the documents were stolen at least twice. These are allegations that CEIEC has strongly denied and condemned in a post on their website.
This entire turn of events has raised more questions than they have answered. Are the documents legitimate? Where were they original stolen from? If these were really stolen twice, who stole them first? We unfortunately do not have the answer to any of these questions. However, one thing we do have are words of caution and some interesting information about a handful of the documents found in this dump. Within the document dump in a folder related to Vietnam are 11 malicious documents (8 unique) that exploit vulnerabilities (CVE-2010-3333 and CVE-2009-3129) in Microsoft Office to install malware. These documents installed four different types of backdoors that reported back to six distinct command and control servers. Two of the backdoors were unfamiliar to us and the other two were the well known Poison Ivy RAT and the Enfal/Lurid. At least one hostname could be tied back to a known set of persistent actors engaged in cyber espionage.
[...]
Vietnamese Targeting and Timeline
These nine unique samples from the document dump from Hardcore Charlie appear to lead to multiple different attack campaigns targeting Vietnamese interests. The malicious documents have Vietnamese names and will open legitimate clean versions of the documents in Vietnamese upon successful exploitation. At least one of the trojan samples even saves itself as a file that might blend in on a Vietnamese computer. Another has strings related to the Vietnamese version of Google, while another uses a DNS name that is in Vietnamese as well. We would suspect this may just be the tip of the ice berg.
As for timing -- several indicators seem to point to these documents being approximately a year old. The most obvious and more tamper proof piece of evidence being a VirusTotal submission from April 2011. You may note the document from this submission was named BC cua chi binh voi BCS.doc. However, this file has the same MD5 hash of of32f5ad4f09135fcdde86ecd4c466a993, which matches the file was saw named Danh sach.doc. This indicates that his activity is not new and these files may have been unknowingly included in this document dump
Conclusion
These malicious documents within the data dump raise several questions and can lead to plenty of speculation. Were these malicious documents resident on victim systems from previous targeted APT campaigns and exfiltrated alongside the legitimate documents as part of another cyber espionage operation? Could it be that they were intentionally placed into this data dump? Anything is possible and we do not have all the answers. However, we can tell you that a few of the malware samples had previously been submitted to VirusTotal in early 2011. Additionally meta data of the clean documents dropped by a few of the malware payloads showed that the documents were also created in 2011, indicating that the malicious documents have likely been circulating in the wild for more than year.
Although many questions remain, the following facts are clear:
- A small subset of the documents contained in the purported CEIEC dump are malicious.
- These malicious documents drop a mix of malware families including Poison Ivy, Enfal/Lurid and two unnamed families.
- Some of the malware samples extracted from the CEIEC dump connect to infrastructure used in previous APT campaigns.
These documents just go to show that malicious files can end up pretty much anywhere. We are stating the obvious but remember to exercise caution when viewing files you downloaded from the Internet. Microsoft patched the two vulnerabilities used in these attacks quite some time ago. They patched CVE-2009-3129 with MS09-067 and CVE-2010-3333 with MS10-087. Malicious documents that exploit vulnerabilities in Microsoft Office, Adobe Acrobat [Reader], or components loaded by these pieces of software are still some of the most common ways in which cyber espionage attacks are conducted. Staying current with the latest versions and security patches for any software you run is highly recommended.
Saturday, April 14, 2012
SabPub Mac OS X Backdoor: Java Exploits, Targeted Attacks and Possible APT link
Via Securelist.com (Kaspersky) -
We can confirm yet another Mac malware in the wild - Backdoor.OSX.SabPub.a being spread through Java exploits.
This new threat is a custom OS X backdoor, which appears to have been designed for use in targeted attacks. After it is activated on an infected system, it connects to a remote website in typical C&C fashion to fetch instructions. The backdoor contains functionality to make screenshots of the user’s current session and execute commands on the infected machine.
The remote C&C website - rt***.onedumb.com is hosted on a VPS located in the U.S, Fremont, CA.
“Onedumb.com” is a free dynamic DNS service. Interesting, the C&C at IP 199.192.152.* was used in other targeted attacks (known as “Luckycat”) in the past.
[...]
The Java exploits appear to be pretty standard, however, they have been obfuscated using ZelixKlassMaster, a flexible and quite powerful Java obfuscator. This was obviously done in order to avoid detection from anti-malware products.
At the moment, it is not clear how users get infected with this, but the low number and it’s backdoor functionality indicates that it is most likely used in targeted attacks. Several reports exist which suggest the attack was launched through e-mails containing an URL pointing to two websites hosting the exploit, located in US and Germany.
The timing of the discovery of this backdoor is interesting because in March, several reports pointed to Pro-Tibetan targeted attacks against Mac OS X users. The malware does not appear to be similar to the one used in these attacks, though it is possible that it was part of the same or other similar campaigns.
One other important detail is that the backdoor has been compiled with debug information - which makes its analysis quite easy. This can be an indicator that it is still under development and it is not the final version.
--------------------------------------------------------------------------------------
Kaspersky redacted part of the C2 info, but Symantec did not...
Symantec - OSX.Sabpab
http://www.symantec.com/security_response/writeup.jsp?docid=2012-041310-1536-99&tabid=2
We can confirm yet another Mac malware in the wild - Backdoor.OSX.SabPub.a being spread through Java exploits.
This new threat is a custom OS X backdoor, which appears to have been designed for use in targeted attacks. After it is activated on an infected system, it connects to a remote website in typical C&C fashion to fetch instructions. The backdoor contains functionality to make screenshots of the user’s current session and execute commands on the infected machine.
The remote C&C website - rt***.onedumb.com is hosted on a VPS located in the U.S, Fremont, CA.
“Onedumb.com” is a free dynamic DNS service. Interesting, the C&C at IP 199.192.152.* was used in other targeted attacks (known as “Luckycat”) in the past.
[...]
The Java exploits appear to be pretty standard, however, they have been obfuscated using ZelixKlassMaster, a flexible and quite powerful Java obfuscator. This was obviously done in order to avoid detection from anti-malware products.
At the moment, it is not clear how users get infected with this, but the low number and it’s backdoor functionality indicates that it is most likely used in targeted attacks. Several reports exist which suggest the attack was launched through e-mails containing an URL pointing to two websites hosting the exploit, located in US and Germany.
The timing of the discovery of this backdoor is interesting because in March, several reports pointed to Pro-Tibetan targeted attacks against Mac OS X users. The malware does not appear to be similar to the one used in these attacks, though it is possible that it was part of the same or other similar campaigns.
One other important detail is that the backdoor has been compiled with debug information - which makes its analysis quite easy. This can be an indicator that it is still under development and it is not the final version.
--------------------------------------------------------------------------------------
Kaspersky redacted part of the C2 info, but Symantec did not...
Symantec - OSX.Sabpab
http://www.symantec.com/security_response/writeup.jsp?docid=2012-041310-1536-99&tabid=2
Next, the Trojan connects to the following location and opens a back door on the compromised computer: hxxp://rtx556.onedumb.com
Thursday, March 29, 2012
Case Based in China Puts a Face on Persistent Hacking
Via New York Times -
A breach of computers belonging to companies in Japan and India and to Tibetan activists has been linked to a former graduate student at a Chinese university — putting a face on the persistent espionage by Chinese hackers against foreign companies and groups.
The attacks were connected to an online alias, according to a report to be released on Friday by Trend Micro, a computer security firm with headquarters in Tokyo.
The owner of the alias, according to online records, is Gu Kaiyuan, a former graduate student at Sichuan University, in Chengdu, China, which receives government financing for its research in computer network defense.
Mr. Gu is now apparently an employee at Tencent, China’s leading Internet portal company, also according to online records. According to the report, he may have recruited students to work on the university’s research involving computer attacks and defense.
The researchers did not link the attacks directly to government-employed hackers. But security experts and other researchers say the techniques and the victims point to a state-sponsored campaign.
“The fact they targeted Tibetan activists is a strong indicator of official Chinese government involvement,” said James A. Lewis, a former diplomat and expert in computer security who is a director and senior fellow at the Center for Strategic and International Studies in Washington. “A private Chinese hacker may go after economic data but not a political organization.”
Neither the Chinese embassy in Washington nor the Chinese consulate in New York answered requests for comment.
The Trend Micro report describes systematic attacks on at least 233 personal computers. The victims include Indian military research organizations and shipping companies; aerospace, energy and engineering companies in Japan; and at least 30 computer systems of Tibetan advocacy groups, according to both the report and interviews with experts connected to the research. The espionage has been going on for at least 10 months and is continuing, the report says.
In the report, the researchers detailed how they had traced the attacks to an e-mail address used to register one of the command-and-control servers that directed the attacks. They mapped that address to a QQ number — China’s equivalent of an online instant messaging screen name — and from there to an online alias.
The person who used the alias, “scuhkr” — the researchers said in an interview that it could be shorthand for Sichuan University hacker — wrote articles about hacking, which were posted to online hacking forums and, in one case, recruited students to a computer network and defense research program at Sichuan University’s Institute of Information Security in 2005, the report said.
The New York Times traced that alias to Mr. Gu. According to online records, Mr. Gu studied at Sichuan University from 2003 to 2006, when he wrote numerous articles about hacking under the names of “scuhkr” and Gu Kaiyuan. Those included a master’s thesis about computer attacks and prevention strategies. The Times connected Mr. Gu to Tencent first through an online university forum, which listed where students found jobs, and then through a call to Tencent.
Reached at Tencent and asked about the attacks, Mr. Gu said, “I have nothing to say.”
----------------------------------------------
Lucky Cat might sound familiar? That is for good reason.
A breach of computers belonging to companies in Japan and India and to Tibetan activists has been linked to a former graduate student at a Chinese university — putting a face on the persistent espionage by Chinese hackers against foreign companies and groups.
The attacks were connected to an online alias, according to a report to be released on Friday by Trend Micro, a computer security firm with headquarters in Tokyo.
The owner of the alias, according to online records, is Gu Kaiyuan, a former graduate student at Sichuan University, in Chengdu, China, which receives government financing for its research in computer network defense.
Mr. Gu is now apparently an employee at Tencent, China’s leading Internet portal company, also according to online records. According to the report, he may have recruited students to work on the university’s research involving computer attacks and defense.
The researchers did not link the attacks directly to government-employed hackers. But security experts and other researchers say the techniques and the victims point to a state-sponsored campaign.
“The fact they targeted Tibetan activists is a strong indicator of official Chinese government involvement,” said James A. Lewis, a former diplomat and expert in computer security who is a director and senior fellow at the Center for Strategic and International Studies in Washington. “A private Chinese hacker may go after economic data but not a political organization.”
Neither the Chinese embassy in Washington nor the Chinese consulate in New York answered requests for comment.
The Trend Micro report describes systematic attacks on at least 233 personal computers. The victims include Indian military research organizations and shipping companies; aerospace, energy and engineering companies in Japan; and at least 30 computer systems of Tibetan advocacy groups, according to both the report and interviews with experts connected to the research. The espionage has been going on for at least 10 months and is continuing, the report says.
In the report, the researchers detailed how they had traced the attacks to an e-mail address used to register one of the command-and-control servers that directed the attacks. They mapped that address to a QQ number — China’s equivalent of an online instant messaging screen name — and from there to an online alias.
The person who used the alias, “scuhkr” — the researchers said in an interview that it could be shorthand for Sichuan University hacker — wrote articles about hacking, which were posted to online hacking forums and, in one case, recruited students to a computer network and defense research program at Sichuan University’s Institute of Information Security in 2005, the report said.
The New York Times traced that alias to Mr. Gu. According to online records, Mr. Gu studied at Sichuan University from 2003 to 2006, when he wrote numerous articles about hacking under the names of “scuhkr” and Gu Kaiyuan. Those included a master’s thesis about computer attacks and prevention strategies. The Times connected Mr. Gu to Tencent first through an online university forum, which listed where students found jobs, and then through a call to Tencent.
Reached at Tencent and asked about the attacks, Mr. Gu said, “I have nothing to say.”
----------------------------------------------
Lucky Cat might sound familiar? That is for good reason.
Wednesday, March 28, 2012
The Luckycat Hackers
http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the_luckycat_hackers.pdf
Overview
A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to successfully compromise a target and steal sensitive information. The attackers use very simple malware, which required little development time or skills, in conjunction with freely available Web hosting, to implement a highly effective attack. It is a case of the attackers obtaining a maximum return on their investment. The attack shows how an intelligent attacker does not need to be particularly technically skilled in order to steal the information they are after.
[...]
The most useful information about the attackers is in one of the log files retrieved from a C&C server. This log file appears to record connections to an FTP server running on the C&C server. The attackers probably use FTP to easily retrieve stolen data uploaded to the C&C server. 45 unique IP addresses were identified in the log. Of these, all but two are from the same ISP, based in Sichuan province in China. The remaining two are from South Korea.
Despite this, the IP address used for the new connection changes regularly. In figure 7, during a period of approximately an hour and 15 minutes, four different IP addresses were used for six distinct connections. This is unusual because if the attacker is using DHCP, generally an IP address will remain allocated to a particular computer for a longer period of time.
A possible explanation is that the IP addresses used are the point of egress of a VPN-like service. The attackers may be using a service through which they can route their connections. The service periodically rotates connections amongst a pool of IP addresses in order to render the attacker anonymous or implicate China as the source of the attack. There are two potential reasons for the South Korean IP addresses. The first is that the IP addresses are part of the VPN service and were assigned to the attacker as the service rotated through the range of IP addresses available. The second explanation is that the attacker may have forgotten to enable the VPN by mistake and connected directly to the C&C server.
Overview
A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to successfully compromise a target and steal sensitive information. The attackers use very simple malware, which required little development time or skills, in conjunction with freely available Web hosting, to implement a highly effective attack. It is a case of the attackers obtaining a maximum return on their investment. The attack shows how an intelligent attacker does not need to be particularly technically skilled in order to steal the information they are after.
[...]
The most useful information about the attackers is in one of the log files retrieved from a C&C server. This log file appears to record connections to an FTP server running on the C&C server. The attackers probably use FTP to easily retrieve stolen data uploaded to the C&C server. 45 unique IP addresses were identified in the log. Of these, all but two are from the same ISP, based in Sichuan province in China. The remaining two are from South Korea.
Despite this, the IP address used for the new connection changes regularly. In figure 7, during a period of approximately an hour and 15 minutes, four different IP addresses were used for six distinct connections. This is unusual because if the attacker is using DHCP, generally an IP address will remain allocated to a particular computer for a longer period of time.
A possible explanation is that the IP addresses used are the point of egress of a VPN-like service. The attackers may be using a service through which they can route their connections. The service periodically rotates connections amongst a pool of IP addresses in order to render the attacker anonymous or implicate China as the source of the attack. There are two potential reasons for the South Korean IP addresses. The first is that the IP addresses are part of the VPN service and were assigned to the attacker as the service rotated through the range of IP addresses available. The second explanation is that the attacker may have forgotten to enable the VPN by mistake and connected directly to the C&C server.
Adobe Flash Player w/ Automatic Updates!
Adobe has released Flash Player v11.2.202.228, which addresses critical vulnerabilities and introduces automatic updates.
Grab v11.2.202.228 here.
For more information, check out the Adobe Secure Software Engineering Team (ASSET) Blog, "An Update for the Flash Player Updater".
Adobe Reader and Adobe Flash Player has been heavily targeted by cyber criminals and APT actors in the past. It is good to see Adobe taking serious steps to make their product more resist to exploitation.
Oracle, are you listening? *cough* Java *cough*
Grab v11.2.202.228 here.
For more information, check out the Adobe Secure Software Engineering Team (ASSET) Blog, "An Update for the Flash Player Updater".
Adobe Reader and Adobe Flash Player has been heavily targeted by cyber criminals and APT actors in the past. It is good to see Adobe taking serious steps to make their product more resist to exploitation.
Oracle, are you listening? *cough* Java *cough*
Tuesday, March 27, 2012
Trojan.Taidoor Takes Aim at Policy Think Tanks
http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/trojan_taidoor-targeting_think_tanks.pdf
Executive Summary
Trojan.Taidoor has been consistently used in targeted attacks during the last three years. Since May 2011, there has been a substantial increase in its activity. Taidoor’s current targets are primarily private industry and influential international think tanks with a direct involvement in US and Taiwanese affairs. Facilities in the services sector that these organizations may use have also been targeted. There are a number of additional ancillary targets.
Trojan.Taidoor dates back to March 2008 and in-field telemetry has identified Taidoor being used in targeted attack emails since May 2009. Fourteen distinct versions and three separate families of the Trojan have been identified to date. The threat continues to evolve to suit the attackers’ requirements.
Executive Summary
Trojan.Taidoor has been consistently used in targeted attacks during the last three years. Since May 2011, there has been a substantial increase in its activity. Taidoor’s current targets are primarily private industry and influential international think tanks with a direct involvement in US and Taiwanese affairs. Facilities in the services sector that these organizations may use have also been targeted. There are a number of additional ancillary targets.
Trojan.Taidoor dates back to March 2008 and in-field telemetry has identified Taidoor being used in targeted attack emails since May 2009. Fourteen distinct versions and three separate families of the Trojan have been identified to date. The threat continues to evolve to suit the attackers’ requirements.
Wednesday, March 21, 2012
Targeted Attacks Against Tibet Organizations
Via Alien Vaults Labs (March 13, 2012) -
We recently detected several targeted attacks against Tibetan activist organizations including the Central Tibet Administration and International Campaign for Tibet, among others. We believe these attacks originate from the same group of Chinese hackers that launched the ‘Nitro’ attacks against chemical and defense companies late last year and are aimed at both spying on and stealing sensitive information about these organizations’ activities and supporters.
The attacks begin with a simple spear phishing campaign that uses a contaminated Office file to exploit a known vulnerability in Microsoft. The information in the spear phishing email is related to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. After further investigation, we discovered that the malware being used in this attack is a variant of Gh0st RAT (remote access Trojan), a type of software that enables anything from stealing documents to turning on a victim’s computer microphone. Gh0st RAT was a primary tool used in the Nitro attacks last year and the variant we uncovered in these attacks seem to come from the same actors. It’s likely that the same group is stealing from major industries as well as infiltrating organizations for political reasons.
It is no surprise that Tibetan organizations are being targeted – they have been for years – and we continue to see Chinese actors breaking into numerous organizations with impunity. Unfortunately, in this particular case, these attacks may have a direct impact on the abuse of human rights in these regions.
Below is a detailed analysis of one of the dozens of campaigns that we’ve been tracking, which illustrates the method used by the attackers and the possible connection to the Nitro attacks.
These latest attacks are linked to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. The spear phishing emails are not that sophisticated and feature a Microsoft attachment (Camp information at Bodhgaya.doc) that exploits a known Office stack overflow vulnerability (CVE-2010-3333).
[...]
Examining the resultant traffic confirms the code to be a variant of the Gh0st RAT (remote access trojan) using a data string of `ByShe’ in place of the more usual `Gh0st.’
[...]
We have found more samples using this modified header (“ByShe”):
http://www.threatexpert.com/report.aspx?md5=e4e64d365844dc7294e4a553fed7501f
http://www.threatexpert.com/report.aspx?md5=4A35488762F70170DC0D3F46F94A7BCB
It is worth noting that the sample – 4a35488762f70170dc0d3f46f94a7bcb – connects to jericho.3322.org using the `ByShe’ protocol, which was seen during the Nitro attacks we saw between April and November of last year.
This sample was used during the NitroAttacks last year, a targeted attack against chemical and defense companies that was traced to China.
We recently detected several targeted attacks against Tibetan activist organizations including the Central Tibet Administration and International Campaign for Tibet, among others. We believe these attacks originate from the same group of Chinese hackers that launched the ‘Nitro’ attacks against chemical and defense companies late last year and are aimed at both spying on and stealing sensitive information about these organizations’ activities and supporters.
The attacks begin with a simple spear phishing campaign that uses a contaminated Office file to exploit a known vulnerability in Microsoft. The information in the spear phishing email is related to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. After further investigation, we discovered that the malware being used in this attack is a variant of Gh0st RAT (remote access Trojan), a type of software that enables anything from stealing documents to turning on a victim’s computer microphone. Gh0st RAT was a primary tool used in the Nitro attacks last year and the variant we uncovered in these attacks seem to come from the same actors. It’s likely that the same group is stealing from major industries as well as infiltrating organizations for political reasons.
It is no surprise that Tibetan organizations are being targeted – they have been for years – and we continue to see Chinese actors breaking into numerous organizations with impunity. Unfortunately, in this particular case, these attacks may have a direct impact on the abuse of human rights in these regions.
Below is a detailed analysis of one of the dozens of campaigns that we’ve been tracking, which illustrates the method used by the attackers and the possible connection to the Nitro attacks.
These latest attacks are linked to the Kalachakra Initiation, a Tibetan religious festival that took place in early January. The spear phishing emails are not that sophisticated and feature a Microsoft attachment (Camp information at Bodhgaya.doc) that exploits a known Office stack overflow vulnerability (CVE-2010-3333).
[...]
Examining the resultant traffic confirms the code to be a variant of the Gh0st RAT (remote access trojan) using a data string of `ByShe’ in place of the more usual `Gh0st.’
[...]
We have found more samples using this modified header (“ByShe”):
http://www.threatexpert.com/report.aspx?md5=e4e64d365844dc7294e4a553fed7501f
http://www.threatexpert.com/report.aspx?md5=4A35488762F70170DC0D3F46F94A7BCB
It is worth noting that the sample – 4a35488762f70170dc0d3f46f94a7bcb – connects to jericho.3322.org using the `ByShe’ protocol, which was seen during the Nitro attacks we saw between April and November of last year.
This sample was used during the NitroAttacks last year, a targeted attack against chemical and defense companies that was traced to China.
Sunday, March 18, 2012
Inside the Chinese Boom in Corporate Espionage
Via Business Week -
Last June, three men squeezed inside a wind turbine in China’s Gobi Desert. They were employees of American Superconductor Corp. (AMSC), a Devens (Mass.)-based maker of computer systems that serve as the electronic brains of wind turbines. From time to time, AMSC workers are required to head out to a wind farm in some desolate location—that’s where the wind usually is—to check on the equipment, do maintenance, make repairs, and keep the customers happy.
On this occasion, the AMSC technicians were investigating a malfunction. They entered the cylindrical main shaft of the turbine, harnessed themselves to a ladder, and climbed 230 feet in darkness up to the nacelle, an overpacked compartment that holds the machinery used to convert the rotation of the blades into electricity. AMSC had been using the turbine, manufactured by the company’s largest customer, China’s Sinovel Wind Group, to test a new version of its control system software. The software was designed to disable the turbine several weeks earlier, at the end of the testing period. But for some reason, this turbine ignored the system’s shutdown command and the blades kept right on spinning.
The AMSC technicians tapped into the turbine’s computer to get to the bottom of the glitch. The problem wasn’t immediately clear, so the technicians made a copy of the control system’s software and sent it to the company’s research center in Klagenfurt, Austria, which produced some startling findings. The Sinovel turbine appeared to be running a stolen version of AMSC’s software. Worse, the software revealed that Sinovel had complete access to AMSC’s proprietary source code. In short, Sinovel didn’t really need AMSC anymore.
Three days after that expedition in the Gobi, Daniel McGahn, AMSC’s chief executive officer, got the news on his cell phone while he was traveling in Russia. Hired in 2006, McGahn helped revamp the then-floundering company by focusing it on two things: China and wind power. Those bets paid off for a while, as Sinovel bought more and more turbine controllers from AMSC. Then in March 2011, Sinovel abruptly and inexplicably began turning away AMSC’s shipments at its enormous turbine assembly factory in Liaoning province.
[...]
On June 15, standing in a St. Petersburg office tower, McGahn listened to the report from the Austrian team for 30 minutes and felt the blood drain from his face. He had been trying for months to save the relationship with Sinovel and was making almost no progress. By the time he ended the call from his Austrian team, he knew why.
[...]
In other espionage cases, such as those involving Google (GOOG), Lockheed Martin (LMT), and DuPont (DD), thieves did a far better job of covering their digital tracks. Sinovel, however, was caught red-handed. AMSC has presented to law enforcement officials in Austria and China computer logs and messages that show Sinovel courting one of the U.S. company’s employees and paying him to aid in the code heist. “It’s a red-hot smoking gun example,” says John Kerry, chairman of the Senate Foreign Relations Committee and the Democratic senator from AMSC’s home state of Massachusetts. “If this is the way the Chinese choose to do business, it’s going to be very contentious and tough sledding ahead for this relationship.”
[...]
AMSC has filed four civil complaints against Sinovel in Chinese courts—where Sinovel has a steep home-field advantage—seeking $1.2 billion in damages. Sinovel has filed its own countersuits claiming that AMSC owes it $207 million for problems including defective equipment. Sinovel declined to make its chairman available for interview or to comment for this story. And because Chinese courts do not make legal documents available to the public, it was not possible to read Sinovel’s counterclaims. “How China responds to this is going to be central to how they respond to other issues of concern between us,” Kerry says.
[...]
According to court documents, in 2010, Sinovel began recruiting Dejan Karabasevic, a Serbian software engineer who worked at AMSC’s research facility in Klagenfurt. In December, Karabasevic sent his existing contract with AMSC to Sinovel employees for review; by January 2011, Sinovel was hunting for an apartment for him in Beijing. Once in China, the engineer was pressed to create software that could go on existing turbines as quickly as possible, using source code taken from AMSC’s server in Austria. For five days beginning on May 10, Karabasevic said in a confession to Austrian police, he worked steadily in his Beijing apartment and then traveled to a wind farm with three Sinovel employees to test the code in working turbines. By June it was done.
Karabasevic, who pleaded guilty, was sentenced in September to 12 months in jail and two years probation for distribution of trade secrets. His attorney, Gunter Huainigg, declined further comment.
Last June, three men squeezed inside a wind turbine in China’s Gobi Desert. They were employees of American Superconductor Corp. (AMSC), a Devens (Mass.)-based maker of computer systems that serve as the electronic brains of wind turbines. From time to time, AMSC workers are required to head out to a wind farm in some desolate location—that’s where the wind usually is—to check on the equipment, do maintenance, make repairs, and keep the customers happy.
On this occasion, the AMSC technicians were investigating a malfunction. They entered the cylindrical main shaft of the turbine, harnessed themselves to a ladder, and climbed 230 feet in darkness up to the nacelle, an overpacked compartment that holds the machinery used to convert the rotation of the blades into electricity. AMSC had been using the turbine, manufactured by the company’s largest customer, China’s Sinovel Wind Group, to test a new version of its control system software. The software was designed to disable the turbine several weeks earlier, at the end of the testing period. But for some reason, this turbine ignored the system’s shutdown command and the blades kept right on spinning.
The AMSC technicians tapped into the turbine’s computer to get to the bottom of the glitch. The problem wasn’t immediately clear, so the technicians made a copy of the control system’s software and sent it to the company’s research center in Klagenfurt, Austria, which produced some startling findings. The Sinovel turbine appeared to be running a stolen version of AMSC’s software. Worse, the software revealed that Sinovel had complete access to AMSC’s proprietary source code. In short, Sinovel didn’t really need AMSC anymore.
Three days after that expedition in the Gobi, Daniel McGahn, AMSC’s chief executive officer, got the news on his cell phone while he was traveling in Russia. Hired in 2006, McGahn helped revamp the then-floundering company by focusing it on two things: China and wind power. Those bets paid off for a while, as Sinovel bought more and more turbine controllers from AMSC. Then in March 2011, Sinovel abruptly and inexplicably began turning away AMSC’s shipments at its enormous turbine assembly factory in Liaoning province.
[...]
On June 15, standing in a St. Petersburg office tower, McGahn listened to the report from the Austrian team for 30 minutes and felt the blood drain from his face. He had been trying for months to save the relationship with Sinovel and was making almost no progress. By the time he ended the call from his Austrian team, he knew why.
[...]
In other espionage cases, such as those involving Google (GOOG), Lockheed Martin (LMT), and DuPont (DD), thieves did a far better job of covering their digital tracks. Sinovel, however, was caught red-handed. AMSC has presented to law enforcement officials in Austria and China computer logs and messages that show Sinovel courting one of the U.S. company’s employees and paying him to aid in the code heist. “It’s a red-hot smoking gun example,” says John Kerry, chairman of the Senate Foreign Relations Committee and the Democratic senator from AMSC’s home state of Massachusetts. “If this is the way the Chinese choose to do business, it’s going to be very contentious and tough sledding ahead for this relationship.”
[...]
AMSC has filed four civil complaints against Sinovel in Chinese courts—where Sinovel has a steep home-field advantage—seeking $1.2 billion in damages. Sinovel has filed its own countersuits claiming that AMSC owes it $207 million for problems including defective equipment. Sinovel declined to make its chairman available for interview or to comment for this story. And because Chinese courts do not make legal documents available to the public, it was not possible to read Sinovel’s counterclaims. “How China responds to this is going to be central to how they respond to other issues of concern between us,” Kerry says.
[...]
According to court documents, in 2010, Sinovel began recruiting Dejan Karabasevic, a Serbian software engineer who worked at AMSC’s research facility in Klagenfurt. In December, Karabasevic sent his existing contract with AMSC to Sinovel employees for review; by January 2011, Sinovel was hunting for an apartment for him in Beijing. Once in China, the engineer was pressed to create software that could go on existing turbines as quickly as possible, using source code taken from AMSC’s server in Austria. For five days beginning on May 10, Karabasevic said in a confession to Austrian police, he worked steadily in his Beijing apartment and then traveled to a wind farm with three Sinovel employees to test the code in working turbines. By June it was done.
Karabasevic, who pleaded guilty, was sentenced in September to 12 months in jail and two years probation for distribution of trade secrets. His attorney, Gunter Huainigg, declined further comment.
Friday, March 16, 2012
Russia Ups the APT Bar
Via HBGary Blog -
Depending on who you ask, Russia and China are considered the top two espionage threats by the United States. China gets more media attention as an 'APT' threat, but this is only because China keeps getting caught with their hand in the cookie jar. In our own investigations, we still catch China more than any other country. Part of this might be the relative ease in which Chinese APT can be detected. As we have stated in numerous forums, detecting lateral movement is game-set-match for detecting Chinese APT. But China is not the only player.
We are investigating an increasing amount of economic espionage. In this, we are uncovering attackers from several countries other than China. Of particular note, Russia seems to be the next in line for APT-like economic espionage. And, Russian APT attacks seem much more technically advanced. Whether this is influenced by a long history and culture of malware development is unclear.
Russian APT contrasts sharply with Chinese attacks. As we have pointed out before, Chinese APT hides in plain sight. Their backdoors are simple in nature, doing only the minimum of command and control required to maintain remote persistent access. Once access is gained to the network, the Chinese APT is largely about lateral movement, use of command-line tools, and passing of credentials. Russian APT, on the other hand, clearly involves skilled malware development. Russian remote access tools have all of their capabilities hard-coded internally. There are no external, third-party tools. For example, password hash-dumping is performed by an internal function. Thus, a pass-the-hash toolkit is not required. Also, the command-and-control is more complex and richly featured. The malware is a one-stop shop of capability in the network. This shows a significantly different style between Chinese and Russian groups.
Of course, this cannot be a hard-and-fast rule for attribution. But, this is something we are witnessing and it's prudent to raise the alarm regarding advanced malware tactics. The threat may be evolving because simple APT tactics are easy to detect. Large corporations are certainly taking notice of the APT problem now, and just taking the time to look will likely uncover an attack. Some of the most advanced malware stealth techniques have emerged from the Russian underground. It is likely that these techniques will continue to be disseminated to the international malware development community, including those who participate in APT attacks.
It seems the cat is out of the bag with respect to APT. Cyberattacks are just too easy, and a state-level capability can be put together on a modest budget. We expect an increasing number of attacks of a more sophisticated nature over the next few years.
--Rich Cummings
-------------------------------------------------
Nov 2011 - NCIX: Foreign Spies Stealing US Economic Secrets in Cyberspace
Depending on who you ask, Russia and China are considered the top two espionage threats by the United States. China gets more media attention as an 'APT' threat, but this is only because China keeps getting caught with their hand in the cookie jar. In our own investigations, we still catch China more than any other country. Part of this might be the relative ease in which Chinese APT can be detected. As we have stated in numerous forums, detecting lateral movement is game-set-match for detecting Chinese APT. But China is not the only player.
We are investigating an increasing amount of economic espionage. In this, we are uncovering attackers from several countries other than China. Of particular note, Russia seems to be the next in line for APT-like economic espionage. And, Russian APT attacks seem much more technically advanced. Whether this is influenced by a long history and culture of malware development is unclear.
Russian APT contrasts sharply with Chinese attacks. As we have pointed out before, Chinese APT hides in plain sight. Their backdoors are simple in nature, doing only the minimum of command and control required to maintain remote persistent access. Once access is gained to the network, the Chinese APT is largely about lateral movement, use of command-line tools, and passing of credentials. Russian APT, on the other hand, clearly involves skilled malware development. Russian remote access tools have all of their capabilities hard-coded internally. There are no external, third-party tools. For example, password hash-dumping is performed by an internal function. Thus, a pass-the-hash toolkit is not required. Also, the command-and-control is more complex and richly featured. The malware is a one-stop shop of capability in the network. This shows a significantly different style between Chinese and Russian groups.
Of course, this cannot be a hard-and-fast rule for attribution. But, this is something we are witnessing and it's prudent to raise the alarm regarding advanced malware tactics. The threat may be evolving because simple APT tactics are easy to detect. Large corporations are certainly taking notice of the APT problem now, and just taking the time to look will likely uncover an attack. Some of the most advanced malware stealth techniques have emerged from the Russian underground. It is likely that these techniques will continue to be disseminated to the international malware development community, including those who participate in APT attacks.
It seems the cat is out of the bag with respect to APT. Cyberattacks are just too easy, and a state-level capability can be put together on a modest budget. We expect an increasing number of attacks of a more sophisticated nature over the next few years.
--Rich Cummings
-------------------------------------------------
Nov 2011 - NCIX: Foreign Spies Stealing US Economic Secrets in Cyberspace
"Chinese actors are the world’s most active and persistent perpetrators of economic espionage....Russia’s intelligence services are conducting a range of activities to collect economic information and technology from US targets....We judge that the governments of China and Russia will remain aggressive and capable collectors of sensitive US economic information and technologies, particularly in cyberspace."
Thursday, February 9, 2012
United States Ranks 4th Globally in Cyber Defense
Via Defense News (Jan 31, 2012) -
The U.S. ranked behind Finland, Israel and Sweden in a new report analyzing the ability of countries to defend themselves against cyber attacks. The report pointed to information-sharing limitations as one of the key stumbling blocks for U.S. security, giving the country four out of a possible five stars.
“Government only inhales, it never exhales,” said Jason Healey, director of the Cyber Statecraft Initiative at the Atlantic Council. He was part of a panel assembled for the release of the report Jan. 30. “It will take all the information, but it will find any excuse to not share.”
The reputational rankings appeared in “Cyber-security: The vexed question of global rules,” a report based on surveys with 250 leaders in 35 countries that rated 23 countries. Produced by the Security & Defense Agenda, a Brussels-based think tank, and the cybersecurity company McAfee, the report used a methodology developed by Robert Lentz, former deputy assistant secretary of defense for cyber, that measures preparedness based upon a country’s technology and available pool of expertise.
While ranked as even with Germany, France and the United Kingdom, among others, the United States was ahead of China and Russia, which only received three stars. The two countries are often cited as the source of the vast majority of cyber attacks, with those emanating from China appearing to be state-sponsored espionage and those from Russia likely financial crime related.
Although information-sharing was cited as the best technique for combating cyber attacks, the details can be difficult to figure out, experts said.
[...]
Attribution remains a tricky problem, experts said, but that doesn’t mean that companies aren’t getting better. Tim McKnight, a chief information security officer at Northrop Grumman, indicated that the company had been able to pinpoint a collection of groups that have been waging attacks.
“We track about 26 different gangs that have been attacking our company for the last seven years,” he said.
The U.S. ranked behind Finland, Israel and Sweden in a new report analyzing the ability of countries to defend themselves against cyber attacks. The report pointed to information-sharing limitations as one of the key stumbling blocks for U.S. security, giving the country four out of a possible five stars.
“Government only inhales, it never exhales,” said Jason Healey, director of the Cyber Statecraft Initiative at the Atlantic Council. He was part of a panel assembled for the release of the report Jan. 30. “It will take all the information, but it will find any excuse to not share.”
The reputational rankings appeared in “Cyber-security: The vexed question of global rules,” a report based on surveys with 250 leaders in 35 countries that rated 23 countries. Produced by the Security & Defense Agenda, a Brussels-based think tank, and the cybersecurity company McAfee, the report used a methodology developed by Robert Lentz, former deputy assistant secretary of defense for cyber, that measures preparedness based upon a country’s technology and available pool of expertise.
While ranked as even with Germany, France and the United Kingdom, among others, the United States was ahead of China and Russia, which only received three stars. The two countries are often cited as the source of the vast majority of cyber attacks, with those emanating from China appearing to be state-sponsored espionage and those from Russia likely financial crime related.
Although information-sharing was cited as the best technique for combating cyber attacks, the details can be difficult to figure out, experts said.
[...]
Attribution remains a tricky problem, experts said, but that doesn’t mean that companies aren’t getting better. Tim McKnight, a chief information security officer at Northrop Grumman, indicated that the company had been able to pinpoint a collection of groups that have been waging attacks.
“We track about 26 different gangs that have been attacking our company for the last seven years,” he said.
Monday, February 6, 2012
Adobe Flash Player Sandboxing is Coming to Firefox
Via Adobe Secure Software Engineering Team (ASSET) Blog -
In December of 2010, I wrote a blog post describing the first steps towards sandboxing Flash Player within Google Chrome. In the blog, I stated that the Flash Player team would explore bringing sandboxing technology to other browsers.
[...]
Today, Adobe has launched a public beta of our new Flash Player sandbox (aka “Protected Mode”) for the Firefox browser. The design of this sandbox is similar to what Adobe delivered with Adobe Reader X Protected Mode and follows the same Practical Windows Sandboxing approach. Like the Adobe Reader X sandbox, Flash Player will establish a low integrity, highly restricted process that must communicate through a broker to limit its privileged activities. The sandboxed process is restricted with the same job limits and privilege restrictions as the Adobe Reader Protected Mode implementation. Adobe Flash Player Protected Mode for Firefox 4.0 or later will be supported on both Windows Vista and Windows 7. We would like to thank the Mozilla team for assisting us with some of the more challenging browser integration bugs. For Flash Player, this is the next evolutionary step in protecting our customers.
Sandboxing technology has proven very effective in protecting users by increasing the cost and complexity of authoring effective exploits. For example, since its launch in November 2010, we have not seen a single successful exploit in the wild against Adobe Reader X. We hope to see similar results with the Flash Player sandbox for Firefox once the final version is released later this year.
-----------------------------------------------
Kudos to Adobe for embracing sandboxing technique as a way to minimize exploit impact in Adobe Reader X and now Adobe Flash Player. Now if they will do it for IE on Windows 7, then we will be getting somewhere.
Unfortunately, the bad guys (both criminal and nation-state) are taking advantage of Oracle's inability to do anything to secure Java JRE usage. So it might be too little too late to really help enterprises counter advanced threats.
In December of 2010, I wrote a blog post describing the first steps towards sandboxing Flash Player within Google Chrome. In the blog, I stated that the Flash Player team would explore bringing sandboxing technology to other browsers.
[...]
Today, Adobe has launched a public beta of our new Flash Player sandbox (aka “Protected Mode”) for the Firefox browser. The design of this sandbox is similar to what Adobe delivered with Adobe Reader X Protected Mode and follows the same Practical Windows Sandboxing approach. Like the Adobe Reader X sandbox, Flash Player will establish a low integrity, highly restricted process that must communicate through a broker to limit its privileged activities. The sandboxed process is restricted with the same job limits and privilege restrictions as the Adobe Reader Protected Mode implementation. Adobe Flash Player Protected Mode for Firefox 4.0 or later will be supported on both Windows Vista and Windows 7. We would like to thank the Mozilla team for assisting us with some of the more challenging browser integration bugs. For Flash Player, this is the next evolutionary step in protecting our customers.
Sandboxing technology has proven very effective in protecting users by increasing the cost and complexity of authoring effective exploits. For example, since its launch in November 2010, we have not seen a single successful exploit in the wild against Adobe Reader X. We hope to see similar results with the Flash Player sandbox for Firefox once the final version is released later this year.
-----------------------------------------------
Kudos to Adobe for embracing sandboxing technique as a way to minimize exploit impact in Adobe Reader X and now Adobe Flash Player. Now if they will do it for IE on Windows 7, then we will be getting somewhere.
Unfortunately, the bad guys (both criminal and nation-state) are taking advantage of Oracle's inability to do anything to secure Java JRE usage. So it might be too little too late to really help enterprises counter advanced threats.
Saturday, February 4, 2012
Operation Starlight: The Chinese PLA Assault on RSA and the Undermining of the Authentication Control Supply Chain
Via Diocyde's Veiled Shadows Blog -
This post will be one of several that will reveal the origins of the investigation, research, and analysis group effort behind what has been revealed as Operation Starlight.
BACKGROUND
The formation, vision, and strategy behind Starlight was a direct result of the compromise and Intellectual Property data theft of vital technical information from RSA that forms the underpinnings of Authentication Frameworks used in thousands of companies and Government organizations worldwide.
[...]
Over the past year, Government officials active and retired, congressmen, and security researchers have come out explicitly linking and declaring this to be the case. They should know. There is YEARS of evidentiary data linking this activity to exact groups and individuals behind these activities. The old tired adages of how ATTRIBUTION is too hard of a problem, and how its impossible to track the source of an attack are a RED HERRING in this industry. Do not believe it for a second. If your told that you are being lied to. The abilities of Nation States to conduct Multi-INT intelligence analysis on threats is unparalleled. This intelligence supports the missions of Counter-Intelligence, Law Enforcement, and provides data for Strategy and National Leadership Decision Making.
Future postings here will reveal many of the lessons learned through this experience.
It is my hope that it inspires the community of security experts, investigators, forensic professionals, incident responders, and malware analysts to recognize clearly that there is a dire need to come together as one to share their threat data, become educated on the specific technical threats and the groups behind them, and operate as a single unified entity in confronting the single most damaging threat to our future, described as “the greatest transfer of wealth through theft and piracy in the history of the world and we are on the losing end of it.”
----------------------------
Big shout out to @diocyde. Keep up the good work.
This post will be one of several that will reveal the origins of the investigation, research, and analysis group effort behind what has been revealed as Operation Starlight.
BACKGROUND
The formation, vision, and strategy behind Starlight was a direct result of the compromise and Intellectual Property data theft of vital technical information from RSA that forms the underpinnings of Authentication Frameworks used in thousands of companies and Government organizations worldwide.
[...]
Over the past year, Government officials active and retired, congressmen, and security researchers have come out explicitly linking and declaring this to be the case. They should know. There is YEARS of evidentiary data linking this activity to exact groups and individuals behind these activities. The old tired adages of how ATTRIBUTION is too hard of a problem, and how its impossible to track the source of an attack are a RED HERRING in this industry. Do not believe it for a second. If your told that you are being lied to. The abilities of Nation States to conduct Multi-INT intelligence analysis on threats is unparalleled. This intelligence supports the missions of Counter-Intelligence, Law Enforcement, and provides data for Strategy and National Leadership Decision Making.
Future postings here will reveal many of the lessons learned through this experience.
It is my hope that it inspires the community of security experts, investigators, forensic professionals, incident responders, and malware analysts to recognize clearly that there is a dire need to come together as one to share their threat data, become educated on the specific technical threats and the groups behind them, and operate as a single unified entity in confronting the single most damaging threat to our future, described as “the greatest transfer of wealth through theft and piracy in the history of the world and we are on the losing end of it.”
----------------------------
Big shout out to @diocyde. Keep up the good work.
Analysis Of Sykipot Smartcard Proxy Variant
Via EipLoader Blog -
Executive Summary
In this analysis report, it attests Alientvault’s claim that users who are using ActivIdentity ActivClient software are affected. See link: http://labs.alienvault.com/labs/index.php/2012/when-the-apt-owns-your-smart-cards-and-certs
This malware does not only attempts to capture keystrokes and clipboard data, it also serves as a backdoor to remote control the victim’s system fully, and access protected resources that require authentication using smartcard.
Having said that, it is also important to note that the malware requires the smartcard to be in the reader when access is required. In another word, this victim is used as a smartcard proxy, where the stolen login pin is used to access the smartcard.
By analyzing this malware’s behavior, it is highly likely an espionage malware, which is particularly keen in email messages and reports craft while Outlook, Firefox and/or Internet Explorer is running through key logging. Additionally, this malware takes extra precautionary measures to maintain stealth in the victim’s system, and it hopes to remain undetected for a long period.
Executive Summary
In this analysis report, it attests Alientvault’s claim that users who are using ActivIdentity ActivClient software are affected. See link: http://labs.alienvault.com/labs/index.php/2012/when-the-apt-owns-your-smart-cards-and-certs
This malware does not only attempts to capture keystrokes and clipboard data, it also serves as a backdoor to remote control the victim’s system fully, and access protected resources that require authentication using smartcard.
Having said that, it is also important to note that the malware requires the smartcard to be in the reader when access is required. In another word, this victim is used as a smartcard proxy, where the stolen login pin is used to access the smartcard.
By analyzing this malware’s behavior, it is highly likely an espionage malware, which is particularly keen in email messages and reports craft while Outlook, Firefox and/or Internet Explorer is running through key logging. Additionally, this malware takes extra precautionary measures to maintain stealth in the victim’s system, and it hopes to remain undetected for a long period.
Subscribe to:
Posts (Atom)