Showing posts with label Espionage Malware. Show all posts
Showing posts with label Espionage Malware. Show all posts

Tuesday, 16 June 2015

Attackers used Kaspersky certificate Foxconn


The attackers internal network anti-virus firm Kaspersky Lab infiltrated using a valid digital certificate from the Chinese company Foxconn to sign their malware. Foxconn is the largest electronics manufacturer in the world and produces, among other products for Apple, Dell and Cisco.

Last week Kaspersky Lab announced that attackers had managed to get malware on the internal network. It was a new variant of the highly advanced Duqu malware called Duqu 2.0. Duqu 2.0 hides the memory of infected computers. If the machine is restarted and malware consequently disappears, the computer via a compromised server again infected. For this, the attackers use special drivers.

During the operations, the attackers installed these drivers on firewalls, gateways and other servers with direct access to the Internet on one side and access to the company on the other side. In this way, the attackers managed to achieve various goals, such as accessing the internal infrastructure from the Internet, ensure that they appeared in the logs of the proxy servers and computers could contaminate permanently.

Certifications


For 64-bit Windows versions is mandatory that drivers digitally signed are. Researchers from Kaspersky Lab also looked surprised when she saw that one of the drivers discovered had been signed by a valid certificate of Foxconn. The same certificate in February 2013 was still used by the manufacturer for the signings of several drivers for Dell laptops. Using valid digital certificates is not new. Previously this was discovered Stuxnet and the first version of Duqu.

"The steal of digital certificates and signing of malware in the name of legitimate businesses is a proven method of Duqu attackers," said researchers at Kaspersky Lab. How the attackers managed to get the Foxconn certificate is unknown.However, the researchers attackers seem to have a preference for hardware manufacturers, as were used in Stuxnet and Duqu 1.0 certificates from Realtek and Jmicron.

Confidence

What is also striking is that the attackers did not use the same certificate twice. Something that at first Duqu version was the case. "If this is the case, this means that the attackers may have sufficient alternative digital certificates stolen from other manufacturers that are ready to be used in the next targeted attack," said the researchers. Which warn that it would be very worrying, as it undermines confidence in digital certificates. Meanwhile, would both certificate issuer Verisign Foxconn been notified of the certificate in question.

Thursday, 11 June 2015

Anti-virus Firm Kaspersky Victim Of Cyber Espionage


The Russian anti-virus firm Kaspersky Lab earlier this year become victims of cyber espionage in which various internal systems with advanced malware became infected. For spreading the malware, which was discovered during an internal security check with a new product, the attackers used an unknown vulnerability in the Windows kernel, which Microsoft patched yesterday. In addition, the virus-fighter does not exclude that there are two different zero-day vulnerabilities used have been patched at this time.

The original attack vector is as yet unknown, although the attackers probably used a spear phishing email. In one of the first casualties which showed that his mailbox and browsing history was erased to hide traces of the attack. Since the infected machines were fully patched Kaspersky believes that an unknown vulnerability is attacked. The attack on the corporate network would have no impact on the anti-virus software or the company's customers.

According to Kaspersky the attackers were interested in the intellectual property of the virus fighter, as well as the company's technology to the espionage attacks detects and analyzes. Kaspersky said in a statement that the decision of the attackers to carry out the attack was probably very difficult, as it would certainly be discovered. "Attacking security companies indicate that they have a lot of confidence that they will not get caught, or maybe they do not care if they are discovered."

To be discovered malware mainly hid in the memory of infected computers. Restarting the computer would mean in this case is that the infection disappeared. In order to infect computers still infected permanently attackers servers in the network with a high up-time, which then infected computers in the domain. This approach has the disadvantage that all computers and servers would be disinfected by a power failure. Therefore, drivers installed on a small number of computers. These drivers can traffic from outside the network tunneling toward the inside. The attackers were so connect via remote desktop sessions or from previously stolen credentials to login servers.

United States

The attack is according to Kaspersky Lab performed by the group that previously made ​​it very sophisticated Duqu virus. The Duqu virus was linked to the organization that developed Stuxnet. According to several experts, Stuxnet made ​​by the US government to disrupt Iran's nuclear program. Several sophisticated espionage operations that have been attributed to the US government in recent years were published by Kaspersky Lab.

Also in the case of Duqu 2.0, such as used malware is mentioned, there is according to the Russian anti-virus company existence of an attack performed by a state. This type of campaign could be only a costly and require a lot of resources. The framework in which Duqu 2.0 is built is estimated to cost $ 50 million. In addition, the dependence of the platform of zero-day vulnerabilities remarkable. Duqu 2.0 is also not designed for financial motives, as with much malware cybercriminals is the case.

In addition to Kaspersky Lab, the malware was also used against other targets. Worldwide, would have been observed less than one hundred infections. The Duqu first version it was less than fifty goals. Victims of version 2.0 are located in Western countries, the Middle East and Asia. As in 2011, would Duqu 2.0 and aim to spy on Iran's nuclear program. Symantec reports that include European and North African telecom provider via the malware attacked, as well as a manufacturer of electronic equipment in South East Asia.

DUQU 2.0 Indicators:

Action loaders:


C&C IPs:

Thursday, 19 February 2015

Victim Fanny-Espionage Worm Early In 2010 Already To Help


A victim of this week unveiled Fanny spy worm, which through two zero-day vulnerabilities in Windows spread that later were used by Stuxnet, early in 2010, all Internet users for help. However, they received no answer. That discovered Maarten van Dantzig Fox-IT.

A Malaysian forum posted a user with the alias "dkk" a call on July 13, 2010 how he could prevent his computer became infected with this virus. The user notes that he is infected via its USB stick, even though they are Autorun and Autoplay disabled. Much to the surprise of the user, different files found on the USB stick and the names also mentioned this, including Fanny.bmp. He also added a copy of the virus. However, there was no response.

Fanny.bmp is the same file that the report ( pdf ) from anti-virus firm Kaspersky Lab is known about the malware. The report also stated that Malaysia is among the countries where the worm is still active. Opposite Ars Technica confirms Kaspersky Lab that files who names the forum user match those of the Fanny worm. The worm was developed by a highly sophisticated espionage group and would have been deployed since 2008.