3AM, la nuova famiglia ransomware usata come “ripiego” di LockBit


Il Threat Hunter Team di Symantec ha individuato una nuova famiglia di ransomware chiamata “3AM”. Il malware è stato visto in azione una sola volta: un gruppo di attaccanti ha cercato di diffondere LockBit nella rete target e, dopo essere stato bloccato, è ricorso a 3AM.

Il ransomware, scritto in Rust, tenta di arrestare i servizi in esecuzione sul dispositivo prima di cifrare i file; una volta cifrati, cerca di cancellare le copie Volume Shadow.

I ricercatori hanno analizzato il comportamento del malware dopo aver individuato alcune attività sospette in rete, prima fra tutte l’esecuzione del comando gpresult per visualizzare le policy di sicurezza di un utente del dispositivo. Il gruppo ha inoltre eseguito diverse componenti di Cobalt Strike e ha cercato di fare escalation di privilegi tramite PsExec.

In seguito, gli attaccanti hanno eseguito una serie di comandi per esplorare la rete e cercare di muoversi lateralmente, oltre a creare un nuovo utente per ottenere persistenza.

3am ransomware

Pixabay

All’inizio il gruppo ha usato LockBit per cifrare i file, ma è stato bloccato; subito dopo, è ricorso a 3AM. L’attacco è riuscito solo parzialmente: il ransomware è riuscito a infettare solo tre server della rete ed è stato bloccato su due di essi.

Il nome “3AM” fa riferimento all’estensione .threeamtime con cui vengono cifrati i file e viene specificato anche nella nota del riscatto: “3 am, il tempo del misticismo, non è così?” si legge. “Tutti i tentativi di recuperare i dati in autonomia li danneggeranno e sarà impossibile recuperarli” continua la nota.

Non si conosce ancora l’identità del gruppo dietro il ransomware 3AM e non è detto che sia legato a LockBit: come spiegano i ricercatori, non è la prima volta che gli attaccanti utilizzo due diversi tipi di ransomware in un singolo attacco quando il primo fallisce.

Se la percentuale di attacchi di successo dovesse cominciare ad aumentare, è molto probabile che 3AM continui a diffondersi nei prossimi mesi.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/09/14/3am-la-nuova-famiglia-ransomware-usata-come-ripiego-di-lockbit/?utm_source=rss&utm_medium=rss&utm_campaign=3am-la-nuova-famiglia-ransomware-usata-come-ripiego-di-lockbit




Le PMI italiane nel mirino dei ransomware


Il fenomeno dei ransomware non si arresta e, anzi, continua a crescere. Secondo l’ultimo report Threatland del Security Operation Center e del team di Cyber Threat Intelligence si Swascan, nel secondo trimestre del 2023 gli attacchi ransomware sono cresciuti del 34,6% in Italia e del 62% a livello globale. 

Il numero delle vittime è aumentato del 185% da inizio anno e del 105% se si confronta il dato con quello del secondo trimestre del 2022. Nel dettaglio, sono 1451 le aziende colpite e soggette a pubblicazione dei dati rubati a livello globale.

L’incremento generale dell’incidenza dei ransomware va di pare passo con l’aumento del numero di gruppi cybercriminali specializzati in questi attacchi (da 36 del trimestre precedente a 43). Il gruppo più attivo a livello mondiale è Lockbit, con 245 attacchi orchestrati nel corso del trimestre.

ransomware PMI - Credits: tonsnoei- Depositphotos

Credits: tonsnoei- Depositphotos

I gruppi criminali stanno espandendo il loro raggio d’azione: nel Q2 2023 i Paesi colpiti sono saliti a 89 rispetto ai 79 del trimestre precedenti. Maggio è stato in assoluto il mese con il maggior numero di attività con il 25% degli attacchi totali.

Le aziende di servizi sono state le più colpite (47% degli attacchi), seguite da quelle del settore manifatturiero (16%) e tecnologico (6%).

La situazione in Italia

In Italia la maggior parte delle vittime di ransomware è composta da PMI (80%) e il 91% da aziende con fatturato inferiore ai 250 milioni di euro. Le piccole e medie imprese si sono rivelate le più a rischio anche per via delle difese spesso inadeguate. 

Le più colpite sono state le aziende del settore dei servizi, in cima alla lista con il 54% degli attacchi, seguite da quelle del manifatturiero (11%) e del sanitario (9%); gli attacchi contro queste ultime sono più che raddoppiati rispetto al trimestre precedente. Anche i settori finanziario e immobiliare non sono stati risparmiati dai ransomware.

Cresce il phishing e il furto di credenziali

Il phishing continua a confermarsi come una delle minacce più diffuse in qualsiasi Paese. In Italia sono state individuate 160.000 campagne di phishing, per lo più contro il settore bancario per ottenere le informazioni di pagamento delle vittime.

Nel dark web si moltiplicano i forum per la compravendita di credenziali in seguito alla compromissione di account e dispositivi, rendendo accessibili dati sensibili e informazioni personali. Globalmente, sono quasi 8 milioni i dispositivi compromessi; in Italia parliamo di 189.042 dispositivi, ovvero il 2,4% del totale globale.

ransomware PMI

Pixabay

Il furto di dati sensibili avviene anche tramite infostealer: da aprile a giugno 2023 questi malware sono stati la famiglia più diffusa nel mondo del cybercrimine.

“Attacchi come phishing, ransomware e malware stanno seguendo una curva di crescita che supera le spiegazioni legate a fenomeni casuali. Questa tendenza sottolinea l’urgenza di adottare strategie di difesa avanzate nell’era digitale per proteggere il patrimonio, l’economia e i cittadini” ha affermato Pierguido Iezzi, Cyber Security Director e CEO di Swascan. 

“Ora più che mai – ha concluso Iezzi – è imperativo garantire la sicurezza della rete per salvaguardare aspetti che ci riguardano da vicino, come il prestigio del “Made in Italy”, oltre che proteggere le persone da minacce dirette e indirette”.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/09/13/le-pmi-italiane-nel-mirino-dei-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=le-pmi-italiane-nel-mirino-dei-ransomware




Password-stealing Linux malware served for 3 years and no one noticed

Illustration of a Trojan horse in an electronic environment.
Enlarge / A digital Trojan horse.
Getty Images | posteriori

A download site surreptitiously served Linux users malware that stole passwords and other sensitive information for more than three years until it finally went quiet, researchers said on Tuesday.

The site, freedownloadmanager[.]org, offered a benign version of a Linux offering known as the Free Download Manager. Starting in 2020, the same domain at times redirected users to the domain deb.fdmpkg[.]org, which served a malicious version of the app. The version available on the malicious domain contained a script that downloaded two executable files to the /var/tmp/crond and /var/tmp/bs file paths. The script then used the cron job scheduler to cause the file at /var/tmp/crond to launch every 10 minutes. With that, devices that had installed the booby-trapped version of Free Download Manager were permanently backdoored.

After accessing an IP address for the malicious domain, the backdoor launched a reverse shell that allowed the attackers to remotely control the infected device. Researchers from Kaspersky, the security firm that discovered the malware, then ran the backdoor on a lab device to observe how it behaved.

“This stealer collects data such as system information, browsing history, saved passwords, cryptocurrency wallet files, as well as credentials for cloud services (AWS, Google Cloud, Oracle Cloud Infrastructure, Azure),” the researchers wrote in a report on Tuesday. “After collecting information from the infected machine, the stealer downloads an uploader binary from the C2 server, saving it to /var/tmp/atd. It then uses this binary to upload stealer execution results to the attackers’ infrastructure.”

The image below illustrates the infection chain.

The infection chain of Trojanized versions of Free Download Manager.
Enlarge / The infection chain of Trojanized versions of Free Download Manager.

After searching social media posts that discussed Free Download Manager, the researchers found that some people who visited freedownloadmanager[.]org received a benign version of the app, while others were redirected to one of the following malicious domains that served the booby-trapped version.

  • 2c9bf1811ff428ef9ec999cc7544b43950947b0f.u.fdmpkg[.]org
  • c6d76b1748b67fbc21ab493281dd1c7a558e3047.u.fdmpkg[.]org
  • 0727bedf5c1f85f58337798a63812aa986448473.u.fdmpkg[.]org
  • c3a05f0dac05669765800471abc1fdaba15e3360.u.fdmpkg[.]org

It’s unclear why some visitors received the non-malicious version of the software and others were redirected to a malicious domain. The malicious redirects ended in 2022 for unknown reasons.

The backdoor is an updated version of malware tracked as Bew, which was published in 2014. Bew was one of the components used in an attack in 2017. The stealer called by the backdoor was installed in a 2019 campaign after first exploiting a vulnerability in the Exim Mail Server.

“While the campaign is currently inactive,” the researchers wrote, referring to the recent incident, “this case of Free Download Manager demonstrates that it can be quite difficult to detect ongoing cyber attacks on Linux machines to the naked eye.” They added:

The malware observed in this campaign has been known since 2013. In addition, the implants turned out to be quite noisy, as demonstrated by multiple posts on social networks. According to our telemetry, victims of this campaign are located all over the world, including Brazil, China, Saudi Arabia and Russia. Given these facts, it may seem paradoxical that the malicious Free Download Manager package remained undetected for more than three years.

  • As opposed to Windows, Linux malware is much more rarely observed;
  • Infections with the malicious Debian package occurred with a degree of probability: some users received the infected package, while others ended up downloading the benign one;
  • Social network users discussing Free Download Manager issues did not suspect that they were caused by malware.

The post offers a variety of file hashes and domain and IP addresses that people can use to indicate if they’ve been targeted or infected in the campaign, which the researchers suspect was a supply chain attack involving the benign version of Free Download Manager. The researchers said people running the freedownloadmanager[.]org site didn’t respond to messages notifying them of the campaign. They also didn’t respond to an inquiry for this post.

https://arstechnica.com/?p=1967881




Il malware Chaes sfrutta DevTools di Chrome per sottrarre dati sensibili


I ricercatori di Morphisec hanno individuato una nuova, pericolosa variante di Chaes, un malware attivo dal 2020 che aveva come obiettivi principali i clienti di siti di e-commerce dell’America Latina.

Caratterizzato da un processo di infezione a più stage, il malware ora è in grado di sottrarre dati personali e finanziari non più solo degli utenti degli e-commerce, ma anche dei clienti del settore finanziario e logistico.

Chaes - Credits: maxkabakov- Depositphotos

Credits: maxkabakov- Depositphotos

La nuova variante del malware, identificata come la quarta versione, presenta numerosi miglioramenti: gli attaccanti dietro Chaes hanno ridefinito l’intera architettura migliorando la modularità del programma e riscrivendolo per lo più in Python per l’esecuzione dinamica in-memory.

I ricercatori hanno identificato sette diversi moduli che compongono il malware: oltre ai moduli per l’inizializzazione delle attività e la comunicazione con gli attaccanti, Chaes utilizza il modulo Chronod, incaricato di sottrarre le informazioni inviate dall’utente, siano esse di login o bancarie, e un modulo per l’upload dei file, in grado di cercare file sul dispositivo della vittima, raccoglierli e inviarli agli attaccanti.

La nuova versione di Chaes vanta inoltre numerosi tool e servizi per il furto di credenziali e l’uso di Websocket per la comunicazione tra i singoli moduli e il server C2 degli attaccanti.

Chaes

Pexels

Una delle novità più importanti della nuova varianti di Chaes è la capacità di accedere alle funzioni del browser e ai servizi target senza l’interazione utente. Ciò, spiegano i ricercatori, è possibile grazie a un’implementazione custom del protocollo DevTools di Chrome, in grado di analizzare e interagire con i contenuti delle pagine web.

“Invece di aspettare che sia l’utente ad aprire il servizio target, il modulo lo apre in autonomia e sottrae i dati sensibili” si legge nel report. Sfruttando il protocollo gli attaccanti sono in grado, tra le altre cose, di eseguire script, intercettare richieste di rete e leggere il contenuto delle richieste POST prima che vengano cifrati. Finora non era stato individuato alcun malware in grado di re-implementare il protocollo DevTools.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/09/08/il-malware-chaes-sfrutta-devtools-di-chrome-per-sottrarre-dati-sensibili/?utm_source=rss&utm_medium=rss&utm_campaign=il-malware-chaes-sfrutta-devtools-di-chrome-per-sottrarre-dati-sensibili




Le vecchie vulnerabilità Microsoft attirano ancora i cybercriminali


I prodotti Microsoft sono i preferiti di utenti e cybercriminali: decine di vulnerabilità, anche vecchie di anni, sono ancora sfruttate attivamente dagli attaccanti nonostante le patch rilasciate dalla compagnia.

Lo ha rivelato un recente report di Qualys, secondo il quale delle 20 vulnerabilità più colpite dagli attaccanti negli ultimi anni, 15 risiedono nei prodotti Microsoft. Un primato triste, considerando anche che alcune di esse risalgono a più di 5 anni fa.

vulnerabilità Microsoft

Pixabay

I prodotti più vulnerabili sono quelli del pacchetto Office, in molteplici versioni. Il primo bug della lista è una vecchia vulnerabilità di memory corruption (CVE-2017-11882) risalente al 2017, sfruttata da 53 gruppi criminali e cyberattaccanti in 467 diversi malware e 14 ransomware. L’uso più recente del bug risale allo scorso 31 agosto.

La vulnerabilità consente a un attaccante di eseguire codice arbitrario usando i permessi dell’utente autenticato; nel caso l’utente abbia i permessi di amministratore, l’attaccante può ottenere il controllo dell’intero sistema, installare programmi e creare altri account con permessi di admin.

Anche la seconda vulnerabilità della lista (CVE-2017-0199) risale al 2017 e colpisce alcune versioni di Office e WordPad. In questo caso si tratta di un bug nel processo di parsing dei file che consente a un attaccante di eseguire codice arbitrario nel contesto di sicurezza dell’utente e di ottenere il controllo dell’intero sistema.

Questa vulnerabilità è stata utilizzata da 53 gruppi criminali e singoli attaccanti in 93 malware e 5 ransomware, ed è stata utilizzata l’ultima volta il 4 settembre scorso.

vulnerabilità Microsoft - Credits: dedivan1923- Deposiphotos

Credits: dedivan1923- Deposiphotos

La vulnerabilità più vecchia che appare nella lista risale al 2012 (CVE-2012-0158) ed è stata sfruttata da 45 cybercriminali in 63 malware e 2 ransomware. Si tratta di un bug presente nei controlli Windows standard che consente a un attaccante di eseguire codice remoto e ottenere i privilegi dell’utente connesso.

Per sfruttarla è sufficiente che un utente visiti una pagina web ad hoc, senza effettuare alcuna interazione. In caso di successo, un attaccante può installare programmi, manipolare i file del sistema e creare nuovi account con privilegi di amministratore. L’ultimo caso di malware che ha sfruttato il bug risale al 31 agosto scorso.

Tutte le vulnerabilità della lista sono state già patchate da anni; nonostante ciò, molti sistemi non sono stati ancora aggiornati e rimangono quindi vulnerabili. Per colpa delle mancanze di aziende e privati, il cybercrimine continua ad avere una vita facile e prosperare su errori che potrebbero essere risolti (quasi) senza sforzo. È fondamentale che gli amministratori dei sistemi aggiornino quanto prima le versioni vulnerabili dei prodotti seguendo le procedure dei vendor e rimangano aggiornati sulle ultime indicazioni di sicurezza.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/09/07/le-vecchie-vulnerabilita-microsoft-attirano-ancora-i-cybercriminali/?utm_source=rss&utm_medium=rss&utm_campaign=le-vecchie-vulnerabilita-microsoft-attirano-ancora-i-cybercriminali




Nuova campagna malware colpisce solo gli utenti macOS


I ricercatori di Phylum hanno individuato una nuova campagna malware che prende di mira i dispositivi macOS. I ricercatori hanno scoperto alcuni pacchetti malevoli caricati negli ecosistemi di Python (PyPI), Javascript (NPM) e Ruby (RubyGems) pensati per colpire gli sviluppatori e sottrare informazioni sensibili.

Il primo indizio della campagna in corso è stato trovato lo scorso 3 settembre nel package kwxiaodian di Python. Il file di setup del pacchetto contiene istruzioni per raccogliere informazioni sul dispositivo della vittima (nome, id, password si sistema e IP) e inviarle poi a un server controllato dall’attaccante. I dati, spiegano i ricercatori, vengono collezionati solo se il dispositivo ha sistema operativo macOS.

malware macOS

Pixabay

Più o meno nello stesso momento, i ricercatori hanno ricevuto delle segnalazioni su alcuni package malevoli pubblicati su NMP. Dall’analisi del team di Phylum è emerso che i pacchetti raccolgono informazioni sulle interfacce di rete, sulla memoria del dispositivo e sul sistema operativo, interrompendo l’esecuzione se non era macOS. Come nel caso del package Python, le informazioni raccolte vengono inviate allo stesso server.

In seguito sono stati individuati pacchetti Rubygem dal funzionamento analogo a quelli di NPM e PyPI.

L’autore o il gruppo dietro il malware ha come obiettivo solo gli utenti macOS, ma non si conoscono ancora le motivazioni precise di questa scelta e più in generale degli attacchi. La campagna potrebbe proseguire a breve con una seconda fase, oppure l’attaccante potrebbe aver semplicemente venduto le informazioni sul dark web.

Come proteggersi

Non è una novità che i malware vengano distribuiti anche tramite i registri di pacchetti. Come ricorda Phylum, rimane valida l’indicazione di non installare pacchetti provenienti da fonti sconosciute.

malware macOS

Pixabay

I ricercatori consigliano anche di utilizzare soluzioni automatizzate per il controllo dei pacchetti per determinare se violano le policy di sicurezza personali o aziendali.

PyPI ha confermato di aver eliminato i pacchetti malevoli dal registro, ma l’attenzione deve rimanere comunque alta: la campagna è attualmente in corso e gli attaccanti potrebbero pubblicare nuovi pacchetti.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/09/06/nuova-campagna-malware-colpisce-solo-gli-utenti-macos/?utm_source=rss&utm_medium=rss&utm_campaign=nuova-campagna-malware-colpisce-solo-gli-utenti-macos




Threat Actors Adopt, Modify Open Source ‘SapphireStealer’ Information Stealer

Multiple threat actors have adopted ‘SapphireStealer’ after the information stealer’s source code was published on GitHub, Cisco’s Talos security researchers report.

Written in .NET, the information stealer can harvest system data (such as IP address, hostname, screen resolution, OS version, and CPU and GPU information), screenshots, files with specific extensions, and cached browser credentials.

The threat was observed targeting Chrome, Yandex, Edge, and Opera to kill their processes. The malware also searches for credential databases associated with 16 browsers, including Chrome, Edge, Brave, Opera, Comodo, and Yandex.

SapphireStealer dumps the harvested data in a working directory to stage it for exfiltration, and creates a subdirectory to collect victim files that have the .txt, .pdf, .doc, .docx, .xml, .img, .jpg, and .png extensions. The harvested data is sent to the attackers over the Simple Mail Transfer Protocol (SMTP).

Shortly after the malware’s source code was released on December 25, threat actors started using it in attacks and modifying it to expand its capabilities and to make detection more difficult, with the newly compiled variants starting to emerge as soon as mid-January.

New samples continued to emerge through the first half of the year, and numerous threat actors started employing SapphireStealer variants in attacks, Cisco explains.

Most of the observed modifications focused on improving the malware’s data exfiltration capabilities and on receiving alerts on new infections.

Advertisement. Scroll to continue reading.

“As this malware is open-source and being used by multiple distinct threat actors, much of this development activity has occurred independently and new functionality is not present in sample clusters associated with other threat actors,” Cisco notes.

One of the observed samples performed data exfiltration using the Discord webhook API, while other samples notified the attackers of new infections by sending log data via the Telegram posting API. Other variants were modified to target different file extensions for exfiltration.

“During our analysis of other SapphireStealer samples over time, we observed repeated evidence that various threat actors had taken steps to streamline the malware’s operations, refactor the code significantly, and otherwise improve upon the core functionality of the stealer,” Cisco says.

Some of the observed samples attempted to use the FUD-Loader malware downloader, which was released on GitHub on January 2, roughly a week after SapphireStealer’s source code was published. The downloader was also used by DcRat, njRAT, DarkComet, AgentTesla, and other malware operators as well.

During their investigation into one of the samples, Cisco’s researchers discovered hardcoded credentials and personally identifiable SMTP account information that allowed them to identify personal accounts associated with the threat actor, including accounts on Steam and on a Russian language freelance forum.

“This account was being used to advertise freelance web development services. The user profile also lists the domain observed hosting SapphireStealer samples and various dependency components retrieved for parsing credential databases and exfiltrating the data,” Cisco notes.

Related: Hacker Forum Credentials Found on 120,000 PCs Infected With Info-Stealer Malware

Related: Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware

Related: New Information Stealer ‘Mystic Stealer’ Rising to Fame

https://www.securityweek.com/threat-actors-adopt-modify-open-source-sapphirestealer-information-stealer/




Russia targets Ukraine with new Android backdoor, intel agencies say

Ukrainian soldiers.
Enlarge / Ukrainian soldiers.
Getty Images

Russia’s military intelligence unit has been targeting Ukrainian Android devices with “Infamous Chisel,” the tracking name for new malware that’s designed to backdoor devices and steal critical information, Western intelligence agencies said on Thursday.

“Infamous Chisel is a collection of components which enable persistent access to an infected Android device over the Tor network, and which periodically collates and exfiltrates victim information from compromised devices,” intelligence officials from the UK, US, Canada, Australia, and New Zealand wrote. “The information exfiltrated is a combination of system device information, commercial application information and applications specific to the Ukrainian military.”

A “serious threat”

Ukraine’s security service first called out the malware earlier this month. Ukrainian officials said then that Ukrainian personnel had “prevented Russia’s intelligence services from gaining access to sensitive information, including the activity of the Armed Forces, deployment of the Defense Forces, their technical provision, etc.”

Infamous Chisel gains persistence by replacing the legitimate system component known as netd with a malicious version. Besides allowing Infamous Chisel to run each time a device is restarted, the malicious netd is also the main engine for the malware. It uses shell scripts and commands to collate and collect device information and also searches directories for files that have a predefined set of extensions. Depending on where on the infected device a collected file is located, netd sends it to Russian servers either immediately or once a day.

When exfiltrating files of interest, Infamous Chisel uses the TLS protocol and a hard-coded IP and port. Use of the local IP address is likely a mechanism to relay the network traffic over a VPN or other secure channel configured on the infected device. This would allow the exfiltration traffic to blend in with expected encrypted network traffic. In the event a connection to the local IP and port fails, the malware falls back to a hard-coded domain that’s resolved using a request to dns.google.

Infamous Chisel also installs a version of the Dropbear SSH client that can be used to remotely access a device. The version installed has authentication mechanisms that have been modified from the original version to change the way users log in to an SSH session.

In Thursday’s write-up, officials wrote:

The Infamous Chisel components are low to medium sophistication and appear to have been developed with little regard to defence evasion or concealment of malicious activity.

The searching of specific files and directory paths that relate to military applications and exfiltration of this data reinforces the intention to gain access to these networks. Although the components lack basic obfuscation or stealth techniques to disguise activity, the actor may have deemed this not necessary, since many Android devices do not have a host-based detection system. Two interesting techniques are present in Infamous Chisel:

  • the replacement of the legitimate <code>netd</code> executable to maintain persistence
  • the modification of the authentication function in the components that include dropbear

These techniques require a good level of C++ knowledge to make the alterations and an awareness of Linux authentication and boot mechanisms.

Even with the lack of concealment functions, these components present a serious threat because of the impact of the information they can collect.

The report didn’t say how the malware gets installed. In the advisory Ukraine’s security service issued earlier this month, officials said that Russian personnel had “captured Ukrainian tablets on the battlefield, pursuing the aim to spread malware and abuse available access to penetrate the system.” It’s unclear if this was the vector.

Infamous Chisel, the report said, was created by a threat actor tracked as Sandworm. Sandworm is among the most skilled and cutthroat hacking groups in the world, and it has been behind some of the most destructive attacks in history. The group has been definitively linked to the NotPetya wiper attacks of 2017, a global outbreak that a White House assessment said caused $10 billion in damages, making it the most costly hack in history. Sandworm has also been definitively tied to hacks on Ukraine’s power grid that caused widespread outages during the coldest months of 2016 and again in 2017.

https://arstechnica.com/?p=1964854




Scoperta una tecnica che sfrutta l’isolamento dei container Windows per eludere la sicurezza


Daniel Avinoam, ricercatore di sicurezza presso Deep Instinct, ha scoperto la possibilità di manipolare il framework Windows per l’isolamento dei container per eludere i controlli di sicurezza e modificare file nei container.

Avinoam ha illustrato questa nuova tecnica durante la conferenza di sicurezza DEF CON, spiegando che un attaccante può facilmente diffondere un malware nei sistemi sfruttando alcune funzionalità del framework.

La tecnica sfrutta la funzionalità delle immagini dei container generate dinamicamente che servono a separare i file system di ogni container dall’host ed evitarne la duplicazione.

Queste immagini, spiega Avinoam, non sono altro che “copie” del sistema operativo contenenti link che collegano i file del container (chiamati “file fantasma”) a file esistenti e non modificabili sul file system dell’host. Il ricercatore si è chiesto quindi se fosse possibile utilizzare questo meccanismo per offuscare le operazioni sul file system ed eludere i controlli delle soluzioni di sicurezza.

Container Windows

Credits: Microsoft

In breve, la risposta è: sì. La funzionalità di isolamento dei container si occupa della separazione tra i container Windows e l’host, gestendo il reindirizzamento dei file fantasma con quelli dell’host tramite il parsing dei “reparse point”, ovvero punti di ripristino usati per archiviare i dati ed elaborare i file in apertura.

Il framework di isolamento opera in uno specifico range di altitudine, cioè una stringa di precisione infinita interpretata come numero decimale, che va da 180000 a 189999, mentre le operazioni degli antivirus avvengono ad altre altitudini, nel range compreso tra 320000 e 329999; ciò significa che un attaccante può eseguire operazioni sui file senza che si attivino i controlli delle soluzioni di sicurezza.

Avinoam ha condiviso con Microsoft i dettagli della tecnica; la compagnia ha riconosciuto la possibilità che si verifichi un attacco del genere, ma ha spiegato di non voler rilasciare patch: “La tecnica è stata identificata come un metodo per eludere l’individuazione dei malware e non una vulnerabilità di sicurezza da risolvere con un aggiornamento”.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/08/31/scoperta-una-tecnica-che-sfrutta-lisolamento-dei-container-windows-per-eludere-la-sicurezza/?utm_source=rss&utm_medium=rss&utm_campaign=scoperta-una-tecnica-che-sfrutta-lisolamento-dei-container-windows-per-eludere-la-sicurezza




Five Eyes Report: New Russian Malware Targeting Ukrainian Military Android Devices

Five Eyes agencies have issued a joint report on the malware used recently by Russian state-sponsored hackers to target Android devices belonging to the Ukrainian military. 

The new malware, named Infamous Chisel, is actually a collection of components designed to provide persistent backdoor access to compromised Android devices over the Tor network, and enable the attackers to collect and exfiltrate data.

The campaign has been linked to the threat actor known as Sandstorm, which was previously connected to Russia’s GRU foreign military intelligence agency.

According to the agencies, the Infamous Chisel malware is designed to periodically scan infected Android devices for information and files that could be of interest to the attackers. 

Targeted information includes device details, as well as data associated with commercial apps and applications used by the Ukrainian military. 

“The searching of specific files and directory paths that relate to military applications and exfiltration of this data reinforces the intention to gain access to these networks,” the report reads.

In addition, the malware scans the local network for information on active hosts, banners and open ports. Capabilities provided by Infamous Chisel also include SSH access to the device, SCP file transfer, and network monitoring and traffic collection. 

Advertisement. Scroll to continue reading.

“The Infamous Chisel components are low to medium sophistication and appear to have been

developed with little regard to defense evasion or concealment of malicious activity,” the report explains. “Although the components lack basic obfuscation or stealth techniques to disguise activity, the actor may have deemed this not necessary, since many Android devices do not have a host-based detection system.”

The joint report was written by the UK’s National Cyber Security Centre (NCSC); the US’s National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and  Federal Bureau of Investigation (FBI); New Zealand’s National Cyber Security Centre (NCSC-NZ); Canada’s Centre for Cyber Security; and the Australian Signals Directorate (ASD).

The report includes technical details on each Infamous Chisel component, MITRE ATT&CK information, and indicators of compromise (IoCs).

The report does not mention how the malware has been distributed. However, earlier this month, the Security Service of Ukraine (SBU) reported that Russian forces had captured Ukrainian tablets on the battlefield and attempted to use them to spread malware. They also tried to leverage the access provided by the tablets to breach military networks. 

The SBU said the attacks, which involved nearly 10 malware samples designed for stealing information, were linked to the Sandworm group. The agency said the attack attempts were blocked. 

Related: North Korean Hackers Targeted Russian Missile Developer

Related: A Year of Conflict: Cybersecurity Industry Assesses Impact of Russia-Ukraine War

Related: Deadly Secret: Electronic Warfare Shapes Russia-Ukraine War

https://www.securityweek.com/five-eyes-report-new-russian-malware-targeting-ukrainian-military-android-devices/