GitHub, migliaia di repository PoC sono falsi o malevoli


Un team di ricercatori del Leiden Institute of Advanced Computer Science ha individuato migliaia di repository GitHub di finte proof-of-concept (PoC) per diverse vulnerabilità conosciute.

Molti di questi repository, oltre a non essere in alcun modo una reale PoC di falle di sicurezza, contengono anche codice malevolo. Nel loro report i ricercatori hanno spiegato che alcuni progetti, se eseguiti, installano malware sul sistema o collezionano dati sensibili.

Le PoC false trovate dai ricercatori riguardavano vulnerabilità rese note tra il 2017 e il 2021. Gli indizi che hanno portato il team ad approfondire la natura dei repository sono stati diversi; in particolare i ricercatori hanno controllato la presenza di IP in blacklist nel codice, di file binari malevoli e di payload offuscati.

GitHub poc

Nel primo caso il team ha individuato tutti quei repository che nel codice avevano degli indirizzi IP presenti in blacklist pubbliche, catalogati come pericolosi e sospetti. Alcuni repository, poi, contenevano dei file eseguibili: i ricercatori hanno controllato l’hash di questi file per verificare se anch’esso fosse presente nelle blacklist. Infine il team ha controllato la presenza di payload offuscati e codificati in base64 o esadecimali, analizzandone poi la natura.

Su 47.313 repository GitHub analizzati, 4.893 sono stati classificati come PoC false o codice malevolo. Purtroppo la tecnica adottata non è in grado di individuarli tutti, ma è comunque un buon punto di partenza per sviluppi futuri.

“Questo approccio non è in grado di individuare ogni PoC falsa, in quanto esistono altri modi più ingegnosi per offuscare il codice malevolo” hanno specificato i ricercatori nel loro paper. “Abbiamo analizzato le similarità del codice come una feature per aiutare a identificare nuovi repository malevoli. I nostri risultati mostrano infatti che questi repository, in media, sono molto simili tra loro rispetto a quelli sicuri. Si tratta comunque di un primo step per sviluppare tecniche di analisi più precise”.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/10/24/github-poc-false-repository/?utm_source=rss&utm_medium=rss&utm_campaign=github-poc-false-repository




Never-before-seen malware has infected hundreds of Linux and Windows devices

A stylized skull and crossbones made out of ones and zeroes.

Researchers have revealed a never-before-seen piece of cross-platform malware that has infected a wide range of Linux and Windows devices, including small office routers, FreeBSD boxes, and large enterprise servers.

Black Lotus Labs, the research arm of security firm Lumen, is calling the malware Chaos, a word that repeatedly appears in function names, certificates, and file names it uses. Chaos emerged no later than April 16, when the first cluster of control servers went live in the wild. From June through mid-July, researchers found hundreds of unique IP addresses representing compromised Chaos devices. Staging servers used to infect new devices have mushroomed in recent months, growing from 39 in May to 93 in August. As of Tuesday, the number reached 111.

Black Lotus has observed interactions with these staging servers from both embedded Linux devices as well as enterprise servers, including one in Europe that was hosting an instance of GitLab. There are more than 100 unique samples in the wild.

“The potency of the Chaos malware stems from a few factors,” Black Lotus Labs researchers wrote in a Wednesday morning blog post. “First, it is designed to work across several architectures, including: ARM, Intel (i386), MIPS and PowerPC—in addition to both Windows and Linux operating systems. Second, unlike largescale ransomware distribution botnets like Emotet that leverage spam to spread and grow, Chaos propagates through known CVEs and brute forced as well as stolen SSH keys.”

CVEs refer to the mechanism used to track specific vulnerabilities. Wednesday’s report referred to only a few, including CVE-2017-17215 and CVE-2022-30525 affecting firewalls sold by Huawei, and CVE-2022-1388, an extremely severe vulnerability in load balancers, firewalls, and network inspection gear sold by F5. SSH infections using password brute-forcing and stolen keys also allow Chaos to spread from machine to machine inside an infected network.

Chaos also has various capabilities, including enumerating all devices connected to an infected network, running remote shells that allow attackers to execute commands, and loading additional modules. Combined with the ability to run on such a wide range of devices, these capabilities have lead Black Lotus Labs to suspect Chaos “is the work of a cybercriminal actor that is cultivating a network of infected devices to leverage for initial access, DDoS attacks and crypto mining,” company researchers said.

Black Lotus Labs believes Chaos is an offshoot of Kaiji, a piece of botnet software for Linux-based AMD and i386 servers for performing DDoS attacks. Since coming into its own, Chaos has gained a host of new features, including modules for new architectures, the ability to run on Windows, and the ability to spread through vulnerability exploitation and SSH key harvesting.

Infected IP addresses indicate that Chaos infections are most heavily concentrated in Europe, with smaller hotspots in North and South America, and Asia Pacific.

Black Lotus Labs

Black Lotus Labs researchers wrote:

Over the first few weeks of September, our Chaos host emulator received multiple DDoS commands targeting roughly two dozen organizations’ domains or IPs. Using our global telemetry, we identified multiple DDoS attacks that coincide with the timeframe, IP and port from the attack commands we received. Attack types were generally multi-vector leveraging UDP and TCP/SYN across multiple ports, often increasing in volume over the course of multiple days. Targeted entities included gaming, financial services and technology, media and entertainment, and hosting. We even observed attacks targeting DDoS-as-a-service providers and a crypto mining exchange. Collectively, the targets spanned EMEA, APAC and North America.

One gaming company was targeted for a mixed UDP, TCP and SYN attack over port 30120. Beginning September 1 – September 5, the organization received a flood of traffic over and above its typical volume. A breakdown of traffic for the timeframe before and through the attack period shows a flood of traffic sent to port 30120 by approximately 12K distinct IPs – though some of that traffic may be indicative of IP spoofing.

Black Lotus Labs

A few of the targets included DDoS-as-a-service providers. One markets itself as a premier IP stressor and booter that offers CAPTCHA bypass and “unique” transport layer DDoS capabilities. In mid-August, our visibility revealed a massive uptick in traffic roughly four times higher than the highest volume registered over the prior 30 days. This was followed on September 1 by an even larger spike of more than six times the normal traffic volume.

DDoS-as-a-service organization incoming attack volume
Enlarge / DDoS-as-a-service organization incoming attack volume
Black Lotus Labs

The two most important things people can do to prevent Chaos infections are to keep all routers, servers, and other devices fully updated and to use strong passwords and FIDO2-based multifactor authentication whenever possible. A reminder to small office router owners everywhere: Most router malware can’t survive a reboot. Consider restarting your device every week or so. Those who use SSH should always use a cryptographic key for authentication.

https://arstechnica.com/?p=1885478




Trojanized versions of PuTTY utility being used to spread backdoor

Trojanized versions of PuTTY utility being used to spread backdoor

Researchers believe hackers with connections to the North Korean government have been pushing a Trojanized version of the PuTTY networking utility in an attempt to backdoor the network of organizations they want to spy on.

Researchers from security firm Mandiant said on Thursday that at least one customer it serves had an employee who installed the fake network utility by accident. The incident caused the employer to become infected with a backdoor tracked by researchers as Airdry.v2. The file was transmitted by a group Mandiant tracks as UNC4034.

“Mandiant identified several overlaps between UNC4034 and threat clusters we suspect have a North Korean nexus,” company researchers wrote. “The AIRDRY.V2 C2 URLs belong to compromised website infrastructure previously leveraged by these groups and reported in several OSINT sources.”

The threat actors posed as people recruiting the employee for a job at Amazon. They sent the target a message over WhatsApp that transmitted a file named amazon_assessment.iso. ISO files have been increasingly used in recent months to infect Windows machines because, by default, double-clicking on them causes them to mount as a virtual machine. Among other things, the image had an executable file titled PuTTY.exe.

PuTTY is an open source secure shell and telnet application. Secure versions of it are signed by the official developer. The version sent in the WhatsApp message was not signed.

The executable file installed the latest version of Airdry, a backdoor the US government has attributed to the North Korean government. The US Cybersecurity and Infrastructure Security Agency has a description here. Japan’s community emergency response team has this description of the backdoor, which is also tracked as BLINDINGCAN.

https://arstechnica.com/?p=1882005




New Linux malware combines unusual stealth with a full suite of capabilities

Skull and crossbones in binary code

Researchers this week unveiled a new strain of Linux malware that’s notable for its stealth and sophistication in infecting both traditional servers and smaller Internet-of-things devices.

Dubbed Shikitega by the AT&T Alien Labs researchers who discovered it, the malware is delivered through a multistage infection chain using polymorphic encoding. It also abuses legitimate cloud services to host command-and-control servers. These things make detection extremely difficult.

“Threat actors continue to search for ways to deliver malware in new ways to stay under the radar and avoid detection,” AT&T Alien Labs researcher Ofer Caspi wrote. “Shikitega malware is delivered in a sophisticated way, it uses a polymorphic encoder, and it gradually delivers its payload where each step reveals only part of the total payload. In addition, the malware abuses known hosting services to host its command and control servers.”

AT&T Alien Labs

The ultimate objective of the malware isn’t clear. It drops the XMRig software for mining the Monero cryptocurrency, so stealthy cryptojacking is one possibility. But Shikitega also downloads and executes a powerful Metasploit package known as Mettle, which bundles capabilities including webcam control, credential stealing, and multiple reverse shells into a package that runs on everything from “the smallest embedded Linux targets to big iron.” Mettle’s inclusion leaves open the potential that surreptitious Monero mining isn’t the sole function.

The main dropper is tiny—an executable file of just 376 bytes.

AT&T Alien Labs

The polymorphic encoding happens courtesy of the Shikata Ga Nai encoder, a Metasploit module that makes it easy to encode the shellcode delivered in Shikitega payloads. The encoding is combined with a multistage infection chain, in which each link responds to a part of the previous one to download and execute the next one.

“Using the encoder, the malware runs through several decode loops, where one loop decodes the next layer, until the final shellcode payload is decoded and executed,” Caspi explained. “The encoder stud is generated based on dynamic instruction substitution and dynamic block ordering. In addition, registers are selected dynamically.”

AT&T Alien Labs
AT&T Alien Labs

A command server will respond with additional shell commands for the targeted machine to execute, as Caspi documented in the packet capture shown below. The bytes marked in blue are the shell commands that the Shikitega will execute.

AT&T Alien Labs

The commands and additional files, such as the Mettle package, are automatically executed in memory without being saved to disk. This adds further stealth by making detection through antivirus protection difficult.

To maximize its control over the compromised device, Shikitega exploits two critical escalation of privileges vulnerabilities that give full root access. One bug, tracked as CVE-2021-4034 and colloquially known as PwnKit, lurked in the Linux kernel for 12 years until it was discovered early this year. The other vulnerability is tracked as CVE-2021-3493 and came to light in April 2021. While both vulnerabilities have received patches, the fixes may not be widely installed, particularly on IoT devices.

The post provides file hashes and domains associated with Shikitega that interested parties can use as indicators of a compromise. Given the work the unknown threat actors responsible devoted to the malware’s stealth, it wouldn’t be surprising if the malware is lurking undetected on some systems.

https://arstechnica.com/?p=1880148




Organizations are spending billions on malware defense that’s easy to bypass

Organizations are spending billions on malware defense that’s easy to bypass
Getty Images / Aurich Lawson

Last year, organizations spent $2 billion on products that provide Endpoint Detection and Response, a relatively new type of security protection for detecting and blocking malware targeting network-connected devices. EDRs, as they’re commonly called, represent a newer approach to malware detection. Static analysis, one of two more traditional methods, searches for suspicious signs in the DNA of a file itself. Dynamic analysis, the other more established method, runs untrusted code inside a secured “sandbox” to analyze what it does to confirm it’s safe before allowing it to have full system access.

EDRs—which are forecasted to generate revenue of $18 billion by 2031 and are sold by dozens of security companies—take an entirely different approach. Rather than analyze the structure or execution of the code ahead of time, EDRs monitor the code’s behavior as it runs inside a machine or network. In theory, it can shut down a ransomware attack in progress by detecting that a process executed on hundreds of machines in the past 15 minutes is encrypting files en masse. Unlike static and dynamic analyses, EDR is akin to a security guard that uses machine learning to keep tabs in real time on the activities inside a machine or network.

Nohl and Gimenez

Streamlining EDR evasion

Despite the buzz surrounding EDRs, new research suggests that the protection they provide isn’t all that hard for skilled malware developers to circumvent. In fact, the researchers behind the study estimate EDR evasion adds only one additional week of development time to the typical infection of a large organizational network. That’s because two fairly basic bypass techniques, particularly when combined, appear to work on most EDRs available in the industry.

“EDR evasion is well-documented, but more as a craft than a science,” Karsten Nohl, chief scientist at Berlin-based SRLabs, wrote in an email. “What’s new is the insight that combining several well-known techniques yields malware that evades all EDRs that we tested. This allows the hacker to streamline their EDR evasion efforts.”

Both malicious and benign apps use code libraries to interact with the OS kernel. To do this, the libraries make a call directly to the kernel. EDRs work by interrupting this normal execution flow. Instead of calling the kernel, the library first calls the EDR, which then collects information about the program and its behavior. To interrupt this execution flow, EDRs partly overwrite the libraries with additional code known as “hooks.”

Nohl and fellow SRLabs researcher Jorge Gimenez tested three widely used EDRs sold by Symantec, SentinelOne, and Microsoft, a sampling they believe fairly represents the offerings in the market as a whole. To the researchers’ surprise, they found that all three were bypassed by using one or both of two fairly simple evasion techniques.

The techniques take aim at the hooks the EDRs use. The first method goes around the hook function and instead makes direct kernel system calls. While successful against all three EDRs tested, this hook avoidance has the potential to arouse the suspicion of some EDRs, so it’s not foolproof.

Nohl and Gimenez

The second technique, when implemented in a dynamic link library file, also worked against all three EDRs. It involves using only fragments of the hooked functions to keep from triggering the hooks. To do this, the malware makes indirect system calls. (A third technique involving unhooking functions worked against one EDR but was too suspicious to fool the other two test subjects.)

Nohl and Gimenez

In a lab, the researchers packed two commonly used pieces of malware—one called Cobalt Strike and the other Silver—inside both an .exe and .dll file using each bypass technique. One of the EDRS—the researchers aren’t identifying which one—failed to detect any of the samples. The other two EDRs failed to detect samples that came from the .dll file when they used either technique. For good measure, the researchers also tested a common antivirus solution.

Nohl and Gimenez

The researchers estimated that the typical baseline time required for the malware compromise of a major corporate or organizational network is about eight weeks by a team of four experts. While EDR evasion is believed to slow the process, the revelation that two relatively simple techniques can reliably bypass this protection means that the malware developers may not require much additional work as some might believe.

“Overall, EDRs are adding about 12 percent or one week of hacking effort when compromising a large corporation—judged from the typical execution time of a red team exercise,” Nohl wrote.

The researchers presented their findings last week at the Hack in the Box security conference in Singapore. Nohl said EDR makers should focus on detecting malicious behavior more generically rather than triggering only on specific behavior of the most popular hacking tools, such as Cobalt Strike. This overfocus on specific behavior makes EDR evasion “too easy for hackers using more bespoke tooling,” Nohl wrote.

“Complementary to better EDRs on endpoints, we still see potential in dynamic analysis within sandboxes,” he added. “These can run in the cloud or attached to email gateways or web proxies and filter out malware before it even reaches the endpoint.”

https://arstechnica.com/?p=1876978




10 malicious Python packages exposed in latest repository attack

Supply-chain attacks, like the latest PyPi discovery, insert malicious code into seemingly functional software packages used by developers. They're becoming increasingly common.
Enlarge / Supply-chain attacks, like the latest PyPi discovery, insert malicious code into seemingly functional software packages used by developers. They’re becoming increasingly common.
Getty Images

Researchers have discovered yet another set of malicious packages in PyPi, the official and most popular repository for Python programs and code libraries. Those duped by the seemingly familiar packages could be subject to malware downloads or theft of user credentials and passwords.

Check Point Research, which reported its findings Monday, wrote that it didn’t know how many people had downloaded the 10 packages, but it noted that PyPi has 613,000 active users, and its code is used in more than 390,000 projects. Installing from PyPi through the pip command is a foundational step for starting or setting up many Python projects. PePy, a site that estimates Python project downloads, suggests most of the malicious packages saw hundreds of downloads.

Such supply-chain attacks are becoming increasingly common, especially among open source software repositories that support a wide swath of the world’s software. Python’s repository is a frequent target, with researchers finding malicious packages in September 2017; June, July, and November 2021; and June of this year. But trick packages have also been found in RubyGems in 2020, NPM in December 2021, and many more open source repositories.

Most notably, a private-source supply-chain attack by Russian hackers through the SolarWinds business software wreaked notable havoc, resulting in the infection of more than 100 companies and at least nine US federal agencies, including the National Nuclear Security Administration, the Internal Revenue Service, the State Department, and the Department of Homeland Security.

The increasingly common discovery of fake, malicious packages is moving repositories to act. Just yesterday, GitHub, owner of the NPM repository for JavaScript packages, opened a request for comments on offering an opt-in system for package developers to sign and verify their packages. Using Sigstore, a collaboration among numerous open source and industry groups, NPM developers can sign off on packages, signaling that the code inside them matches their original repository.

Having a clear indication that the package you’re downloading is related to the code you need might have helped people avoid the most recently discovered PyPi bad actors, though perhaps not entirely. “Ascii2text” directly copied almost every aspect of the ASCII art library “art,” minus the release details. To perhaps nearly 1,000 downloaders, its descriptive name might have suggested a more defined purpose than “art.”

Installing ascii2text triggered the download of a malicious script, which then searched the local storage of Opera, Chrome, and other browsers for tokens, passwords, or cookies, along with certain crypto wallets, and sent them along to a Discord server.

The malicious script inside the misleading asciii2text Python package, as discovered by Check Point Software.
Enlarge / The malicious script inside the misleading asciii2text Python package, as discovered by Check Point Software.

Other packages discovered by Check Point targeted AWS and other credentials and environment variables. Here’s the list of reported and since removed PyPi packages:

  • ascii2text
  • pyg-utils
  • pymocks
  • PyProto2
  • test-async
  • free-net-vpn
  • free-net-vpn2
  • zlibsrc
  • browserdiv
  • WINRPCexploit

https://arstechnica.com/?p=1872326




Nuovo malware per Linux installa rootkit e backdoor


Lightning Framework è stato definito dai suoi scopritori come un “coltellino svizzero” del malware e ha plugin modulari e la capacità di installare rootkit

Intezer ha identificato una minaccia per Linux precedentemente non documentata né rilevata, chiamata Lightning Framework, traducibile in italiano come Framework Fulmine. Come sottolinea il report, è raro vedere un framework così complesso sviluppato per colpire i sistemi Linux.

Lightning è infatti un framework modulare dotato di una vasta gamma di funzioni e della capacità di installare diversi tipi di rootkit, nonché di eseguire plugin. Dispone di funzionalità passive e attive per la comunicazione con l’attore della minaccia, tra cui l’apertura di collegamenti SSH su una macchina infetta e la creazione di backdoor.

Fa un uso massiccio del typosquatting, ossia il mascherare un elemento malevolo con il nome di un programma legittimo scritto con un piccolo errore di battitura, per rimanere inosservato. Si fa passare per il gestore di password e chiavi di crittografia Seahorse per GNOME per eludere il rilevamento sui sistemi infetti.

Il malware è composto da un downloader e da un modulo centrale, con una serie di plugin che includono strumenti open source. Il modulo centrale è quello principale ed è in grado di ricevere comandi dal server di comando e controllo (C2) e di eseguire i moduli plugin. Ha molte funzionalità e utilizza una serie di tecniche per nascondere gli artefatti e rimanere inosservato.

Stabilisce anche la persistenza creando uno script che viene eseguito all’avvio del sistema. Per farlo crea un file in /etc/rc.d/init.d/elastisearch. Il nome sembra essere un typosquat del server di ricerca legittimo Elasticsearch. Non sono ancora stati individuati attacchi basati su Lightning Framework.

Come sottolinea Intezer, anno dopo anno gli ambienti Linux sono sempre più oggetto di attacchi a causa del crescente interesse dei pirati per questo sistema operativo, molto utilizzato sul cloud.

Il malware che prende di mira gli ambienti Linux ha registrato un’impennata nel 2021, con molta innovazione che ha portato alla creazione di nuovo codice malevolo, soprattutto per quanto riguarda ransomware, trojan e botnet.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/07/25/nuovo-malware-per-linux-installa-rootkit-e-backdoor/?utm_source=rss&utm_medium=rss&utm_campaign=nuovo-malware-per-linux-installa-rootkit-e-backdoor




Diminuiscono gli attacchi ransomware


Lo scioglimento del gruppo Conti e il passaggio di Lockbit a una nuova versione sono stati tra i principali motivi del calo del 34% degli attacchi ransomware nel secondo trimestre del 2022

Il secondo trimestre del 2022 ha visto un calo significativo degli attacchi ransomware, secondo il GRIT Ransomware Report pubblicato da Guidepoint Security. Da aprile a giugno ci sono state infatti 574 vittime dichiarate, rispetto alle 868 vittime del trimestre precedente, con una diminuzione del 34%.

Un fattore significativo in questo calo è stato lo scioglimento ufficiale del famigerato gruppo ransomware Conti, avvenuto a maggio.

Questo ha fatto sì che il gruppo abbia mietuto solo 41 vittime, rispetto alle 103 del primo trimestre del 2022, contribuendo alla diminuzione delle vittime totali del periodo. Secondo il report, i suoi principali sviluppatori e affiliati si sono probabilmente spostati verso altre operazioni RaaS, tra cui Blackbasta e AlphV.

L’analisi ha anche osservato una forte diminuzione delle vittime dichiarate dal gruppo di ransomware Clop, con solo 11 segnalazioni in questo trimestre, rispetto ai 173 del primo del 2022.

Il più prolifico Ransomware-as-a-Service (RaaS), Lockbit, ha inoltre visto un rinnovamento completo passando dalla versione 2.0 alla 3.0, o Lockbit Black. La transizione ha portato a un calo significativo degli attacchi nel mese di giugno, che equivale a circa 40 vittime in meno rispetto a quanto previsto in base al tasso medio di vittime dichiarate nel 2022.

Il settore manifatturiero e quello edile sono stati tra i settori più colpiti questo trimestre, con il 18,3% di tutte le vittime denunciate. Sono anche stati gli obiettivi principali del gruppo ransomware Blackbasta, che è il secondo per numero di vittime in questo ambito dopo Lockbit.

Secondo il rapporto, anche il settore tecnologico è stato pesantemente preso di mira, così come le agenzie governative. Gli Stati Uniti sono stati il Paese più attaccato, rappresentando quasi un quarto di tutte le vittime globali di ransomware.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/07/22/diminuiscono-gli-attacchi-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=diminuiscono-gli-attacchi-ransomware




Hackers are targeting industrial systems with malware

Hackers are targeting industrial systems with malware
Getty Images

From the what-could-possibly-go-wrong files comes this: An industrial control engineer recently made a workstation part of a botnet after inadvertently installing malware advertising itself as a means for recovering lost passwords.

Lost passwords happen in many organizations. A programmable logic controller—used to automate processes inside factories, electric plants, and other industrial settings—may be set up and largely forgotten over the following years. When a replacement engineer later identifies a problem affecting the PLC, they can discover the now long-gone original engineer never left the passcode behind before departing the company.

According to a blog post from security firm Dragos, an entire ecosystem of malware attempts to capitalize on scenarios like this one inside industrial facilities. Online advertisements like those below promote password crackers for PLCs and human-machine interfaces, which are the workhorses inside these environments.

When your industrial system is part of a botnet

Dragos—which helps firms secure industrial control systems against ransomware, state-sponsored hackers, and potential saboteurs—recently performed a routine vulnerability assessment and discovered a customer’s system had run software that was able to successfully recover the plaintext password for the DirectLogic 06, a PLC sold by Automation Direct. The software recovered the password, but not through the normal method of cracking the cryptographic hash. Instead, the software exploited a zero-day vulnerability in Automatic Direct PLCs that exposed the passcode.

“Previous research targeting DirectLogic PLCs has resulted in successful cracking techniques,” Dragos researcher Sam Hanson wrote. “However, Dragos found that this exploit does not crack a scrambled version of the password as historically seen in popular exploitation frameworks. Instead, a specific byte sequence is sent by the malware dropper to a COM port.”

The vulnerability, and a related one also found by Hanson, have now been patched and are tracked as CVE-2022-2033 and CVE-2022-2004. The latter vulnerability can recover passwords and send them to a remote hacker, bringing the severity rating to 7.5 out of a possible 10.

Besides recovering the password, the software installed on the Dragos customer’s network also installed malware known as Sality. It made the infected system part of a botnet and monitored the clipboard of the infected workstation every half second for any data related to cryptocurrency wallet addresses.

“If seen, the hijacker replaces the address with one owned by the threat actor,” Hanson said. “This in-real-time hijacking is an effective way to steal cryptocurrency from users wanting to transfer funds and increases our confidence that the adversary is financially motivated.”

Hanson went on to say that he has found password crackers advertised online for a wide range of industrial software sold by other companies. They include:

Vendor and Asset System Type
Automation Direct DirectLogic 06 PLC
Omron CP1H PLC
Omron C200HX PLC
Omron C200H PLC
Omron CPM2* PLC
Omron CPM1A PLC
Omron CQM1H PLC
Siemens S7-200 PLC
Siemens S7-200 Project File (*.mwp)
Siemens LOGO! 0AB6 PLC
ABB Codesys Project File (*.pro)
Delta Automation DVP, ES, EX, SS2, EC Series PLC
Fuji Electric POD UG HMI
Fuji Electric Hakko HMI
Mitsubishi Electric FX Series (3U and 3G) PLC
Mitsubishi Electric Q02 Series PLC
Mitsubishi Electric GT 1020 Series HMI
Mitsubishi Electric GOT F930 HMI
Mitsubishi Electric GOT F940 HMI
Mitsubishi Electric GOT 1055 HMI
Pro-Face GP Pro-Face HMI
Pro-Face GP Project File (*.prw)
Vigor VB PLC
Vigor VH PLC
Weintek HMI
Allen Bradley MicroLogix 1000 PLC
Panasonic NAIS F P0 PLC
Fatek FBe and FBs Series PLC
IDEC Corporation HG2S-FF HMI
LG K80S PLC
LG K120S PLC

Dragos tested only the malware targeting the DirectLogic devices, but a rudimentary analysis of a few samples indicated they also contained malware.

“In general, it appears there is an ecosystem for this type of software,” Hanson said. “Several websites and multiple social media accounts exist all touting their password ‘crackers.’”

The account is concerning because it illustrates the laxness that continues to operate in many industrial control settings. The criminals behind the malware infecting the Dragos customer were after money, but there’s no reason more malicious hackers out to sabotage a dam, power plant, or similar facility couldn’t perform a similar intrusion with much more severe consequences.

https://arstechnica.com/?p=1867297




Vulnerabilities allowing permanent infections affect 70 Lenovo laptop models

Vulnerabilities allowing permanent infections affect 70 Lenovo laptop models

For owners of more than 70 Lenovo laptop models, it’s time once again to patch the UEFI firmware against critical vulnerabilities that attackers can exploit to install malware that’s nearly impossible to detect or remove.

The laptop maker on Tuesday released updates for three vulnerabilities that researchers found in the UEFI firmware used to boot up a host of its laptop models, including the Yoga, ThinkBook, and IdeaPad lines. The company assigned a medium severity rating to the vulnerabilities, which are tracked CVE-2022-1890, CVE-2022-1891, and CVE-2022-1892 and affect the ReadyBootDxe, SystemLoadDefaultDxe, and SystemBootManagerDxe drivers, respectively.

“The vulnerabilities can be exploited to achieve arbitrary code execution in the early phases of the platform boot, possibly allowing the attackers to hijack the OS execution flow and disable some important security features,” security firm ESET said. “These vulnerabilities were caused by insufficient validation of DataSize parameter passed to the UEFI Runtime Services function GetVariable. An attacker could create a specially crafted NVRAM variable, causing buffer overflow of the Data buffer in the second GetVariable call.”

Short for Unified Extensible Firmware Interface, UEFI is the software that bridges a computer’s device firmware with its operating system. As the first piece of software to run when virtually any modern machine is turned on, it’s the first link in the security chain. Because the UEFI resides in a flash chip on the motherboard, infections are difficult to detect and remove. Typical measures such as wiping the hard drive and reinstalling the OS have no meaningful impact because the UEFI infection will simply reinfect the computer afterward.

Many motherboard-resident flash chips that store the UEFI have access control mechanisms that can be locked during the boot process to prevent unauthorized firmware changes. It’s not clear if the affected Lenovo models have that capability. Even if they do, these protections are often turned off, misconfigured, or hampered by vulnerabilities. ESET researchers weren’t immediately available to comment on the requirements for exploits of these particular vulnerabilities.

In any event, owners of Lenovo laptops should take a minute to check Wednesday’s advisory to see if their model is vulnerable since firmware updates often require manual installation.

https://arstechnica.com/?p=1866641