DreamBus Botnet Exploiting RocketMQ Vulnerability to Delivery Cryptocurrency Miner
The DreamBus botnet has resurfaced after a two-year break and it has been seen exploiting a recently patched Apache RocketMQ vulnerability in attacks whose goal is the delivery of a cryptocurrency miner.
Apache RocketMQ is a widely used distributed messaging and streaming platform. The exploited vulnerability is tracked as CVE-2023-33246 and its existence came to light in late May, when RocketMQ version 5.1.1 was released to patch the issue.
CVE-2023-33246 has been classified as ‘critical’ and it can be exploited by an unauthenticated attacker for remote command execution.
Details and proof-of-concept (PoC) exploits emerged in June, and reports of exploitation in the wild emerged shortly after. The ZoomEye cyberspace mapping service had recorded more than 6,000 traces of intrusion at the time — mainly in China — and the number has now gone up to 11,000.
Juniper Networks reported this week that it started seeing attacks exploiting CVE-2023-33246 in early June, with a peak reached in mid-June, as part of activity associated with the DreamBus botnet.
The first exploitation attempts were designed to look for vulnerable RocketMQ servers, but threat actors later started delivering a malicious bash script designed to download the main module of the DreamBus malware.
This main module, which is an ELF Linux binary, has been packed with the UPX executable file compressor but in a way that makes the malware’s analysis more difficult.
Advertisement. Scroll to continue reading.
DreamBus is a Linux malware that emerged in early 2019, but Juniper said it had not been seen since 2021, until now.
The main goal in this case appears to be the distribution of a Monero cryptocurrency miner on infected systems. However, Juniper researchers said DreamBus can also attempt to spread to internal and external IP ranges. This worm-like behavior is not new for the malware.
“As DreamBus malicious threat actors resurface, their primary objective remains the installation of a Monero cryptocurrency miner. However, the presence of a modular bot like the DreamBus malware equipped with the ability to execute bash scripts provides these cybercriminals the potential to diversify their attack repertoire, including the installation of various other forms of malware,” Juniper said.
Mysterious Malware Uses Wi-Fi Scanning to Get Location of Infected Device
Researchers at Secureworks have come across a mysterious piece of malware that scans for nearby Wi-Fi access points in an effort to obtain the location of the infected device.
The malware, dubbed Whiffy Recon, targets Windows systems and is designed to conduct Wi-Fi scanning every 60 seconds. The collected data is fed to a geolocation API from Google, which returns geographic coordinates by triangulating the location based on Wi-Fi access point and mobile network data.
Whiffy Recon is delivered by the widely used Smoke Loader malware downloader, but it’s unclear what it’s used for. Secureworks noted that threat actors could use the data to track compromised systems, potentially using it to intimidate victims or pressure them into complying with their demands.
“What is concerning about our discovery of Whiffy Recon is the motivation for its operation is unclear. Who, or what, is interested in the actual location of an infected device? The regularity of the scan at every 60 seconds is unusual, why update every minute? With this type of data a threat actor could form a picture of the geolocation of a device, mapping the digital to the physical,” Don Smith, VP of threat intelligence at Secureworks’ Counter Threat Unit (CTU), told SecurityWeek.
“This kind of activity is very rarely used by criminal actors,” Smith added. “As a standalone capability it lacks the ability to quickly monetize. The unknowns here are worrying and the reality is that it could be used to support any number of nefarious motivations.”
Organizations or individuals concerned that their systems may have been infected with Whiffy Recon can check the Startup folder in Windows for a file named ‘wlan.lnk’, which is used for persistence, ensuring that the malware is launched whenever the device boots up.
Removing the file from the Startup folder ensures that the malware will no longer run on startup, but there is no way to know how much location data has already been collected, Smith added.
Advertisement. Scroll to continue reading.
Secureworks has published technical details on the malware, as well as additional indicators of compromise (IoCs).
Qbot continua a far tremare l’Italia: secondo il Global Threat Index di Check Point Research relativo al mese di luglio, il malware è stato la minaccia principale del mese con un impatto del 6% rispetto al 5,39% globale.
Conosciuto anche come Qakbot, Qbot è un trojan multiuso in circolazione dal 2008 diffuso generalmente tramite e-mail di spam. Il malware è in grado di sottrarre le credenziali dell’utente e i cookie del browser, spiare le attività di online banking e distribuire altri malware. Qakbot presenta inoltre funzionalità di keylogging e dispone di tecniche anti-VM, anti-debug e anti-sandbox che lo rendono piuttosto difficile da individuare.
Credits: welcomia – Depositphotos
A seguire, la seconda minaccia più grande in Italia è stata Blindingcan, trojan ad accesso remoto di origine nord coreana, con un impatto del 4,89%, percentuale molto elevata se comparata allo 0,21% globale. In terza posizione troviamoRemcos, un altro trojan ad accesso remoto che nel nostro Paese ha avuto un impatto del 4,33%, quasi il doppio dell’impatto globale del 2,21%.
Le minacce a livello globale
Se si guarda al quadro globale, Qbot è rimasto la minaccia principale con un impatto del 5% sulle organizzazioni di tutto il mondo, seguito da Formbook, un infostealer che colpisce i sistemi Windows. Formbook viene venduto come malware-as-a-service a un prezzo contenuto ed è in grado di ottenere le credenziali dai browser, fare screenshot ed effettuare keylogging, oltre a scaricare ed eseguire file.
Al terzo posto troviamo il già citato Remcos, il trojan in grado di eseguire malware con privilegi elevati aggirando la protezione UAC di Windows.
Secondo il report, i settori più colpiti sono stati quello dell’istruzione e della ricerca, seguito dal governativo e militare e infine dalla sanità.
La vulnerabilità più sfruttata di luglio è stata la Web Servers Malicious URL Directory Traversal, legata a un errore di convalida dell’input di un server Web. La seconda vulnerabilità più sfruttata è stata la Log4j Remote Code Execution, mentre al terzo posto ci sono diverse vulnerabilità legate all’esecuzione di codice remota tramite header HTTP.
Pixabay
Tra le minacce contro dispositivi mobili si segnalano Anubis, SpinOk e AhMith: la prima è un trojan bancario per smartphone Android che nel tempo ha acquisito funzionalità aggiuntive, come il keylogging e feature di ransomware; la seconda è un modulo software per Android che opera come spyware; infine, il terzo è un trojan ad accesso remoto per Android in grado di raccogliere informazioni sensibili, inviare sms, effettuare screenshot e attivare la fotocamera.
I mesi estivi risultano particolarmente redditizi per i criminali informatici: il personale aziendale è ridotto a causa delle ferie, di conseguenza la capacità di monitorare i sistemi è alterata. “L’introduzione di processi di sicurezza consolidati e automatizzati può aiutare le aziende a mantenere alte le difese durante i periodi di vacanza più impegnativi” ha spiegato Maya Horowitz, VP Research di Check Point, riconoscendo la criticità del periodo.
È molto probabile quindi che il report di agosto confermi l’andamento di quello di luglio, potenzialmente registrando impatti anche più gravi vista la carenza di personale durante il mese di vacanza.
Researchers Uncover Real Identity of CypherRAT and CraxsRAT Malware Developer
Cybersecurity company Cyfirma claims to have uncovered the real identity of the developer behind the CypherRAT and CraxsRAT remote access trojans (RATs).
Using the online handle of ‘EVLF DEV’ and operating out of Syria for the past eight years, the individual is believed to have made over $75,000 from selling the two RATs to various threat actors. The same person is also a malware-as-a-service (MaaS) operator, according to Cyfirma.
For the past three years, EVLF has been offering CraxsRAT, one of the most dangerous Android RATs available now, on a surface web store, with at least 100 lifetime licenses sold to date.
The CraxsRAT builder, Cyfirma says, generates highly obfuscated packages, allowing threat actors to customize the contents based on the type of attack they are preparing, including with WebView page injections.
The builder also includes a quick install feature that generates applications with few install permissions to help bypass detections. After installation, however, the threat actor can send requests to turn on additional permissions.
“In order to gain access to the device’s screen and keystrokes, the app needs to enable its accessibility in settings. So, the builder allows the threat actor to edit the page which pops up right after the app’s installation is completed,” Cyfirma notes.
Additionally, a ‘super mod’ feature is available, to make the application difficult to remove from the infected devices, by crashing the page whenever an uninstall attempt is detected.
Advertisement. Scroll to continue reading.
On the infected devices, the RAT can fetch precise device location, read and steal contacts, access the device’s storage, and read messages and call logs.
Cyfirma’s investigation into EVLF’s whereabouts led to the discovery of a Telegram channel with over 10,000 subscribers, and of a crypto wallet that revealed the malware developer’s earnings from selling the RATs over at least three years.
Cyfirma reached out to the cryptocurrency wallet company to request a freeze of the threat actor’s assets until an identity verification was performed.
With the funds remaining frozen after verification, EVLF started a thread on a crypto discussion forum, which helped Cyfirma to discover additional information on the adversary, such as the real name, various usernames, IP address, and email address.
“Based on our investigation, it can be ascertained with high confidence that EVLF is being operated by a man from Syria,” Cyfirma notes.
Thousands of Systems Turned Into Proxy Exit Nodes via Malware
Threat actors are leveraging access to malware-infected Windows and macOS systems to deploy a proxy application, AT&T’s Alien Labs reports.
To date, AT&T Alien Labs researchers have identified over 400,000 systems that act as proxy exit nodes in this network. However, it is unclear how many of these were infected, and the company that offers the proxy service claims that all devices pertain to users who are aware of the proxy application’s functionality.
Last week, the company said it identified roughly 10,000 macOS systems behaving as proxy exit nodes, with some of them potentially repurposed after being infected with the AdLoad adware.
The researchers believe that AdLoad might be running a pay-per-install campaign, monetizing access to the infected macOS systems by deploying the legitimate proxy application on them.
“Alien Labs has identified over 10,000 IPs reaching out to the proxy servers each week that have the potential to be proxy exit nodes. It is unclear if all these systems have been infected or are voluntarily offering their systems as proxies, but it could be indicative of a bigger infection globally,” AT&T Alien Labs noted last week.
In a new report on Wednesday, the researchers provide details on a 400,000-strong proxy botnet that appears to have been created as the result of a similar infection campaign, but focused on Windows machines.
“Alien Labs has evidence that malware writers are installing the proxy silently in infected systems. In addition, as the proxy application is signed, it has no anti-virus detection, going under the radar of security companies,” the researchers note.
Advertisement. Scroll to continue reading.
Over the course of one week, the researchers observed more than 1,000 new malware samples that were delivering the same proxy application to the infected systems.
The proxy is written in the Go programming language and shares similar source code between macOS and Windows. Unlike the Windows application, however, the macOS variant is detected as malicious by numerous antivirus engines.
After infecting a system, the malware quietly downloads and installs the proxy application, without requiring user interaction. Additional malware is often deployed alongside the signed application.
The proxy was seen collecting large amounts of information from the systems it is running on, to adapt to the system’s operations, and communicating with its command-and-control (C&C) server over port 7001, to receive instructions.
“The rise of malware delivering proxy applications as a lucrative investment, facilitated by affiliate programs, highlights the cunning nature of adversaries’ tactics. These proxies, covertly installed via alluring offers or compromised software, serve as channels for unauthorized financial gains,” AT&T Alien Labs notes.
Il gruppo iraniano APT34 ha colpito di nuovo: conosciuti largamente anche come OilRig e Twisted Kitten, i cybercriminali hanno preso di mira diversi obiettivi legati alle istituzioni governative degli Emirati Arabi Uniti.
Come si legge su DarkReading, ricercatori di Kaspersky hanno individuato un attacco supply chain che aveva come obiettivo ultimo quello di ottenere accesso persistente ai dispositivi di vittime legate al governo.
Gli attaccanti hanno creato un sito web per fingersi una compagnia IT del Paese e inviare offerte di lavoro. Gli annunci sono stati condivisi con vari dipendenti di una compagnia IT che tra i suoi clienti ha anche firme e persone legate al governo; quando le vittime hanno aperto il documento per candidarsi all’offerta di lavoro, un malware ha infettato i dispositivi e ha collezionato informazioni sensibili e credenziali per accedere ai sistemi dei clienti.
Credits: lollok- Depositphotos
Il gruppo, ha spiegato Kaspersky, ha utilizzato l’infrastruttura email del gruppo IT per creare un canale di comunicazione C2 e ottenere i dati sensibili. Pur non riuscendo a verificare l’effettivo impatto dell’attacco, i ricercatori sostengono con una certa sicurezza che sia andato a buon fine.
APT34 è attivo ormai dal 2014 e ha sempre condotto attacchi supply chain, sfruttando la rete di comunicazione e fiducia tra le compagnie del paese per raggiungere gli obiettivi governativi e ottenere persistenza sui sistemi. Per sferrare i propri attacchi il gruppo utilizza tool pubblici e non, e spesso sfrutta gli account compromessi per condurre campagne di spear-phishing contro altri obiettivi.
Sebbene il gruppo usi principalmente tecniche di social engineering, in alcuni casi ha dimostrato di saper sfruttare anche diverse vulnerabilità dei sistemi per ottenere accesso persistente. Nel corso degli anni APT34 ha colpito non solo obiettivi governativi, ma anche industrie finanziarie, dell’energia e delle telecomunicazioni.
Secondo il governo degli Stati Uniti, il gruppo sarebbe finanziato dal governo iraniano: l’uso dell’infrastruttura del paese per sferrare gli attacchi e la presenza di motivazioni in linea con quelle governative confermerebbero l’ipotesi.
Emergono nuovi dettagli su AVRecon, un trojan per l’accesso remoto basato su Linux attivo ormai da due anni, e non sono rassicuranti: il malware è molto più diffuso di ciò che si pensava inizialmente.
A metà luglio i ricercatori di Lumen avevano individuato un’intera botnet creata grazie al malware e usata per nascondere varie attività criminali. Secondo i ricercatori, da maggio 2021 a oggi il malware ha colpito più di 70.000 dispositivi, ottenendo accesso persistente su più di 40.000 IP in tutto il mondo.
Una successiva indagine di KrebsonSecurity e Spur.us ha dimostrato anche che AVrecon è anche il malware dietro il servizio SocksEscort, una rete di dispositivi residenziali e di piccoli business affittati ai cybercriminali per evadere la localizzazione online.
Credits: whatawin- Depositphotos
Il servizio, attivo da ben 14 anni, è stato definito dai ricercatori di Lumen come “Una delle botnet recenti più estese che colpiscono i router home-office e small-office”. SocksEscort è passata inosservata per quasi 12 anni, finché non è stata identificata a metà del 2021.
Il servizio di proxy sfrutta i dispositivi compromessi per instradare il traffico contro nuove vittime. Spesso, spiegano i ricercatori, gli utenti non sanno che i loro dispositivi fanno parte della botnet; il motivo è che AVrecon non sottrae una larghezza di banda eccessiva, quindi la sua attività raramente impatta quella dell’utente.
Il malware sembra diffondersi tramite un’applicazione malevola per Windows che gli utenti devono installare sulla propria macchina. I ricercatori di Lumen non sono riusciti a capire come i dispositivi venissero infettati con AVrecon; è probabile che gli attaccanti abbiano sfruttato la debolezza delle credenziali di amministratore e vulnerabilità conosciute dei firmware.
Pixabay
Sembra che dietro SocksEscort ci sia una compagnia moldava, la Server Management LLC, che vende anche una VPN mobile gratuita per Apple chiamata HideIPVPN. I ricercatori di KrebsonSecurity hanno cercato di approfondire l’apparente legame tra la compagnia e SocksEscort, ma non ha ottenuto una risposta soddisfacente.
È molto probabile che l’applicazione, ancora disponibile sull’Apple Store, sia un altro modo per espandere la botnet. Vista la difficoltà nell’individuare l’eventuale compromissione dei router, i ricercatori invitano i consumatori a resettare i dispositivi, mantenerli aggiornati con le patch di sicurezza ufficiali e aggiornare le credenziali.
CISA Analyzes Malware Used in Barracuda ESG Attacks
The US Cybersecurity and Infrastructure Security Agency (CISA) has published analysis reports on three malware families deployed in an attack exploiting a recent remote command injection vulnerability in Barracuda Email Security Gateway (ESG).
Tracked as CVE-2023-2868 and affecting versions 5.1.3.001 to 9.2.0.006 of the appliance, the flaw was exploited as a zero-day starting at least October 2022. Barracuda released patches for the bug in late May 2023.
A Chinese state-sponsored cyberespionage group tracked as UNC4841 was seen exploiting the vulnerability to gain access to victim networks, execute a reverse shell, and then download custom backdoors for persistence.
Identified malware families include the SeaSpy, SaltWater, and SeaSide custom backdoors, the SandBar rootkit, and SeaSpray and SkipJack, which are trojanized versions of legitimate Barracuda Lua modules.
The observed attacks targeted victims in at least 16 different countries, including government officials and high-profile academics. More than half of the impacted organizations are in the Americas.
On Friday, CISA published malware analysis reports detailing an exploit payload and backdoor, the SeaSpy backdoor, and Submarine, a persistent backdoor executed with root privileges, which have been used in at least one attack that exploited the Barracuda appliance.
The agency says it has obtained 14 malware samples representing “Barracuda exploit payloads and reverse shell backdoors”.
Advertisement. Scroll to continue reading.
Delivered via a phishing email containing a malicious attachment, the payload triggers the command injection (CVE-2023-2868) to deploy and execute a reverse shell that establishes command-and-control (C&C) communication via OpenSSL and fetches the SeaSpy backdoor, CISA explains.
The SeaSpy backdoor, which masquerades as a legitimate Barracuda service, monitors traffic from the C&C for a command to establish a TCP reverse shell that provides the attackers with command execution capabilities.
Submarine, CISA says, is a novel persistent backdoor “that lives in a Structured Query Language (SQL) database on the ESG appliance”, providing attackers with lateral movement capabilities.
“Submarine comprises multiple artifacts—including a SQL trigger, shell scripts, and a loaded library for a Linux daemon—that together enable execution with root privileges, persistence, command-and-control, and cleanup,” the agency notes.
In addition to technical information on the identified samples, CISA’s malware analysis reports include indicators of compromise (IoCs) and YARA rules for detection.
Android malware steals user credentials using optical character recognition
Getty Images
Security researchers have unearthed a rare malware find: malicious Android apps that use optical character recognition to steal credentials displayed on phone screens.
The malware, dubbed CherryBlos by researchers from security firm Trend Micro, has been embedded into at least four Android apps available outside of Google Play, specifically on sites promoting money-making scams. One of the apps was available for close to a month on Google Play but didn’t contain the malicious CherryBlos payload. The researchers also discovered suspicious apps on Google Play that were created by the same developers, but they also didn’t contain the payload.
Advanced techniques
The apps took great care to conceal their malicious functionality. They used a paid version of commercial software known as Jiagubao to encrypt code and code strings to prevent analysis that can detect such functionality. They also featured techniques to ensure the app remained active on phones that had installed it. When users opened legitimate apps for Binance and other cryptocurrency services, CherryBlos overlaid windows that mimicked those of the legitimate apps. During withdrawals, CherryBlos replaced the wallet address the victim selected to receive the funds with an address controlled by the attacker.
The most interesting aspect of the malware is its rare, if not novel, feature that allows it to capture mnemonic passphrases used to gain access to an account. When the legitimate apps display passphrases on phone screens, the malware first takes an image of the screen and then uses OCR to translate the image into a text format that can be used to raid the account.
“Once granted, CherryBlos will perform the following two tasks: 1. Read pictures from the external storage and use OCR to extract text from these pictures [and] 2. Upload the OCR results to the C&C server at regular intervals,” the researchers wrote.
Most apps related to banking and finance use a setting that prevents the taking of screenshots during sensitive transactions. CherryBlos appears to bypass such restrictions by obtaining accessibility permissions used by people with vision impairments or other types of disabilities.
Searches for previous instances of malware that uses OCR came up empty, suggesting the practice isn’t common. Trend Micro representatives didn’t respond to an email asking if there are other examples.
CherryBlos was embedded into the following apps available from these websites:
Label
Package name
Phishing domain
GPTalk
com.gptalk.wallet
chatgptc[.]io
Happy Miner
com.app.happyminer
happyminer[.]com
Robot 999
com.example.walljsdemo
robot999[.]net
SynthNet
com.miner.synthnet
synthnet[.]ai
“Like most modern banking trojans, CherryBlos requires accessibility permissions to work,” the researchers wrote. “When the user opens the app, it will display a popup dialogue window prompting users to enable accessibility permissions. An official website will also be displayed via WebView to avoid suspicion from the victim.”
Once the malicious app obtains the permissions, it uses them not only to capture images of sensitive information displayed on screens, but also to perform other nefarious activities. They include defense evasion techniques such as (1) automatically approving permission requests by auto-clicking the “allow” button when a system dialogue appears and (2) returning users to the home screen when they enter the app settings, possibly as an anti-uninstall or anti-kill contingency.
The malicious apps also use accessibility permissions to monitor when a legitimate wallet app launches. When detected, it then uses them to launch predefined fake activities. The goal is to induce victims to fill in their credentials.
The researchers found dozens of additional apps, most of which were hosted on Google Play, that used the same digital certificate or attacker infrastructure as the four CherryBlos apps. While the 31 apps didn’t contain the malicious payload, the researchers flagged them nonetheless.
“Although these apps appear to have complete functionality on the surface, we still found them exhibiting some abnormal behavior,” they wrote. “Specifically, all the apps are highly similar, with the only difference being the language applied to the user interface since they are derived from the same app template. We also found that the description of the apps on Google Play are also the same.”
The researchers said that Google has removed all such apps that were available on Play. A list of those apps is available here.
The research is only the latest to illustrate the threat of malicious apps. There’s no silver bullet for avoiding these threats, but a few smart practices can go a long way toward that goal. Among them:
Don’t download apps from third-party sites and sideload them unless you know what you’re doing and trust the party controlling the site.
Read reviews of apps before installing them. Be especially careful to look for reviews that claim the apps are malicious.
Carefully review permissions required by the app, with a particular eye for apps that seek accessibility permissions.
“The threat actor behind these campaigns employed advanced techniques to evade detection, such as software packing, obfuscation, and abusing Android’s Accessibility Service,” the researchers wrote. “These campaigns have targeted a global audience and continue to pose a significant risk to users, as evidenced by the ongoing presence of malicious apps on Google Play.”
https://arstechnica.com/?p=1957518
Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware
A threat actor infected their own computer with an information stealer, which has allowed Israeli threat intelligence company Hudson Rock to uncover their real identity.
Using the online moniker ‘La_Citrix’, the threat actor has been active on Russian speaking cybercrime forums since 2020, offering access to hacked companies and info-stealer logs from active infections.
La_Citrix, Hudson Rock says, has been observed hacking into organizations and compromising Citrix, VPN, and RDP servers to sell illicit access to them.
The hacker, the cybersecurity firm says, was careless enough to infect their own computer with an information stealer and to sell access to the machine without noticing.
This allowed Hudson Rock to explore the cybercriminal’s computer, which had been used to perpetrate intrusions at hundreds of companies. The computer contained employee credentials at almost 300 organizations, and the browser stored corporate credentials used to perform hacks.
According to Hudson Rock, La_Citrix was employing information stealers to exfiltrate corporate credentials that were then used to access organizations’ networks without authorization.
Further analysis of the threat actor’s computer also helped the cybersecurity firm discover their real identity and their location.
Advertisement. Scroll to continue reading.
“Data from La_Citrix’s computer such as ‘Installed Software’ reveals the real identity of the hacker, his address, phone, and other incriminating evidence such as ‘qTox’, prominent messenger used by ransomware groups, being installed on the computer,” Hudson Rock notes.
The threat intelligence company, which notes that it has knowledge of thousands of hackers who accidentally infected their own computers with malware, says it will forward the uncovered evidence to the relevant law enforcement authorities.
“This is not the first time we’ve identified hackers who accidentally got compromised by info-stealers, and we expect to see more as info-stealer infections grow exponentially,” the company notes.