5 ms·
This has a good breakdown of how it works https://redcanary.com/blog/clipping-silver-sparrows-wings/ https://redcanary.com/blog/clipping-silver-sparrows-wings/
by marcod 6y ago
This has a good breakdown of how it works https://redcanary.com/blog/clipping-silver-sparrows-wings/ https://redcanary.com/blog/clipping-silver-sparrows-wings/
- skybrian 6y agoUnless I missed something, it doesn’t explain how they entice people into installing the malware?
- sudhirj 6y agoWhy would the malware use S3? Won't AWS just boot them off if they recognize malware? And report their payment details to the authorities?
- deleted 6y ago[deleted]
- whoopdedo 6y agoStolen buckets maybe.
- Jtsummers 6y ago1. It may not be their bucket. Getting someone's credentials and uploading to S3 means the wrong party would be assigned blame/responsibility. 2. It may be their bucket, but with false credentials. Stolen CC and faked contact information.
- smogcutter 6y agoRight, but if amazon disables the bucket then don’t they lose contact with all the infected hosts? And anyway, I can’t imagine expecting a recurring charge like an AWS account to last too long on a stolen CC. Along with the apparent lack of any actual payload, it seems to point to this being some kind of proof of concept.
- mike_d 6y agoBad guys have figured out there are tons of 1-year promo offers for AWS and hosting a single file stays well within the free tier. They toss a stolen card on the account to verify it, which honestly most people won't question a $1 charge then refund from Amazon. They also had a backup hosted on Akamai.
- yarcob 6y agoThe article mentions that using S3 makes it harder to block. You can't block Amazon S3 without breaking very many things. Presumably the malware author would open an AWS account with a stolen or prepaid credit card. They could probably even get away with using AWS's free tier. Or they could even abuse a random web service that uploads data to predictable locations on S3.
- helsinkiandrew 6y agoIt appears Amazon or the bucket owners have blocked the URLs the malware uses (at least those listed on the article). I’m not sure if this means that the malware is no longer a thread
- jandrese 6y agoUsually botnet control systems like this will generate a new domain every day using some difficult-to-predict algorithm. Maybe seed it off of the previous day Dow Jones Index closing figure or something. This makes it a race to try to register the domain before the bad guys do. I find it weird how all of the stories about this thing have the tone of "oh no, what could it be for, there is no payload!?!", when it phones home to a control server regularly waiting for payload. Guys, it's a botnet. They're just waiting for it to get big enough to be worth selling. This isn't some huge mystery. It could be used for hundreds of uses from DDOSing, to spamming, to being a covert VPN network, to Warez distribution, porn, etc... Plus it will probably eventually install a keylogger on the system to harvest CC numbers and passwords from the infected users, maybe run some crypto-locking ransomware if the devs need some bitcoin. All of the typical stuff you can expect after a box is rooted by one of these botnet operators.
- mike_d 6y agoStuxnet for example, didn't really seem to do anything useful. Unless you happened to have a very specific version of industrial control software installed. No obvious payload is actually the worst kind of malware to deal with, because you have no idea if Matthew in accounting had the specific key on his machine that installed a second stage that you know nothing about and can't detect.
- adrr 6y agoYou need to host it somewhere. S3 won't set off any IDS/Firewall alert. IDS would pick up calls to China or Russia. Payment details are probably stolen credit cards or credit cards setup with fake/stolen identities. They'll be a dead end.
- Beached 6y agomost malware infra uses AWS these days. amazon is terrible at preventing it, and in my experience make it nearly impossible to report.