Showing posts with label Stuxnet Malware. Show all posts
Showing posts with label Stuxnet Malware. Show all posts

Tuesday, 16 June 2015

Attackers used Kaspersky certificate Foxconn


The attackers internal network anti-virus firm Kaspersky Lab infiltrated using a valid digital certificate from the Chinese company Foxconn to sign their malware. Foxconn is the largest electronics manufacturer in the world and produces, among other products for Apple, Dell and Cisco.

Last week Kaspersky Lab announced that attackers had managed to get malware on the internal network. It was a new variant of the highly advanced Duqu malware called Duqu 2.0. Duqu 2.0 hides the memory of infected computers. If the machine is restarted and malware consequently disappears, the computer via a compromised server again infected. For this, the attackers use special drivers.

During the operations, the attackers installed these drivers on firewalls, gateways and other servers with direct access to the Internet on one side and access to the company on the other side. In this way, the attackers managed to achieve various goals, such as accessing the internal infrastructure from the Internet, ensure that they appeared in the logs of the proxy servers and computers could contaminate permanently.

Certifications


For 64-bit Windows versions is mandatory that drivers digitally signed are. Researchers from Kaspersky Lab also looked surprised when she saw that one of the drivers discovered had been signed by a valid certificate of Foxconn. The same certificate in February 2013 was still used by the manufacturer for the signings of several drivers for Dell laptops. Using valid digital certificates is not new. Previously this was discovered Stuxnet and the first version of Duqu.

"The steal of digital certificates and signing of malware in the name of legitimate businesses is a proven method of Duqu attackers," said researchers at Kaspersky Lab. How the attackers managed to get the Foxconn certificate is unknown.However, the researchers attackers seem to have a preference for hardware manufacturers, as were used in Stuxnet and Duqu 1.0 certificates from Realtek and Jmicron.

Confidence

What is also striking is that the attackers did not use the same certificate twice. Something that at first Duqu version was the case. "If this is the case, this means that the attackers may have sufficient alternative digital certificates stolen from other manufacturers that are ready to be used in the next targeted attack," said the researchers. Which warn that it would be very worrying, as it undermines confidence in digital certificates. Meanwhile, would both certificate issuer Verisign Foxconn been notified of the certificate in question.

Thursday, 11 June 2015

Anti-virus Firm Kaspersky Victim Of Cyber Espionage


The Russian anti-virus firm Kaspersky Lab earlier this year become victims of cyber espionage in which various internal systems with advanced malware became infected. For spreading the malware, which was discovered during an internal security check with a new product, the attackers used an unknown vulnerability in the Windows kernel, which Microsoft patched yesterday. In addition, the virus-fighter does not exclude that there are two different zero-day vulnerabilities used have been patched at this time.

The original attack vector is as yet unknown, although the attackers probably used a spear phishing email. In one of the first casualties which showed that his mailbox and browsing history was erased to hide traces of the attack. Since the infected machines were fully patched Kaspersky believes that an unknown vulnerability is attacked. The attack on the corporate network would have no impact on the anti-virus software or the company's customers.

According to Kaspersky the attackers were interested in the intellectual property of the virus fighter, as well as the company's technology to the espionage attacks detects and analyzes. Kaspersky said in a statement that the decision of the attackers to carry out the attack was probably very difficult, as it would certainly be discovered. "Attacking security companies indicate that they have a lot of confidence that they will not get caught, or maybe they do not care if they are discovered."

To be discovered malware mainly hid in the memory of infected computers. Restarting the computer would mean in this case is that the infection disappeared. In order to infect computers still infected permanently attackers servers in the network with a high up-time, which then infected computers in the domain. This approach has the disadvantage that all computers and servers would be disinfected by a power failure. Therefore, drivers installed on a small number of computers. These drivers can traffic from outside the network tunneling toward the inside. The attackers were so connect via remote desktop sessions or from previously stolen credentials to login servers.

United States

The attack is according to Kaspersky Lab performed by the group that previously made ​​it very sophisticated Duqu virus. The Duqu virus was linked to the organization that developed Stuxnet. According to several experts, Stuxnet made ​​by the US government to disrupt Iran's nuclear program. Several sophisticated espionage operations that have been attributed to the US government in recent years were published by Kaspersky Lab.

Also in the case of Duqu 2.0, such as used malware is mentioned, there is according to the Russian anti-virus company existence of an attack performed by a state. This type of campaign could be only a costly and require a lot of resources. The framework in which Duqu 2.0 is built is estimated to cost $ 50 million. In addition, the dependence of the platform of zero-day vulnerabilities remarkable. Duqu 2.0 is also not designed for financial motives, as with much malware cybercriminals is the case.

In addition to Kaspersky Lab, the malware was also used against other targets. Worldwide, would have been observed less than one hundred infections. The Duqu first version it was less than fifty goals. Victims of version 2.0 are located in Western countries, the Middle East and Asia. As in 2011, would Duqu 2.0 and aim to spy on Iran's nuclear program. Symantec reports that include European and North African telecom provider via the malware attacked, as well as a manufacturer of electronic equipment in South East Asia.

DUQU 2.0 Indicators:

Action loaders:


C&C IPs:

Wednesday, 11 March 2015

Microsoft Patches 45 Vulnerabilities, Including Stuxnet And FREAK


Microsoft has during Patch Tuesday of March 14 released updates, which together 45 vulnerabilities in Windows, Office, Exchange and Internet Explorer fix, including the Stuxnet leak from 2010 and the recently discovered FREAK leak. Especially re-patching the Stuxnet leak creates experts in amazement.Through the vulnerability knew the Stuxnet worm and the Fanny-espionage worm to spread.

Only connect a USB stick that made ​​the leak abuse was sufficient to infect Windows, even stood Autorun and Autoplay disabled. It was in fact a whole new way to attack Windows computers. In 2010, Microsoft came up with an update for the leak, but this patch showed the vulnerable code is not corrected, allowing Windows computers all the time were vulnerable, so warn researchers from HP.

There is also an update to the " FREAK-leak "in SSL / TLS appeared. Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Other vulnerabilities

In addition to the update for the Stuxnet leak four other updates are labeled as critical. Through these updates fix vulnerabilities that an attacker in the worst case can take over the entire system. It comes to vulnerabilities in Internet Explorer, the VBScript Scripting Engine in Windows, Adobe Font Driver and Office. In the case of one of the IE-leakage was the vulnerability already publicly known before the patch appeared. Through other vulnerabilities that Microsoft patched attackers could increase their rights to systems retrieve information, cause a denial of service and bypass security measures.Can update via Windows Update .