6 ms·
Ars Technica used in malware campaign with never-before-seen obfuscation
- krackers 3y ago>Devices that were infected by the first stage automatically accessed the malicious string at the end of the URL. From there, they were infected with a second stage. I'm guessing the only reason it is done this way is to make network activity less suspicious than if the device were to connect to some novel 3rd party domain?
- ploum 3y agoIt is simply a way for the first stage to keep an updated URL where to download instructions about what to do. Hardcoding URL won’t do it because your URL might be taken down quite quickly. In my days, this was done by connecting to an IRC room and listening for specific messages. I find this way of doing it way more complicated and prone to errors (an IRC client is quite easy to do and there’s no realistic way to prevent anybody to send a strange message in a given room)
- alamortsubite 3y agoMaybe I'm missing something, but whether the first stage points to Ars/Vimeo or directly to the bad-guys, the URL has to be hardcoded somewhere. I think the comment you replied to is probably on the right track; hiding behind a legit intermediary seems a lot less suspicious if someone inspects the payload on the drive.
- acdha 3y agoThe first stage points to arstechnica.com because that’s unlikely to be blocked or attract much attention (your IT guys would probably unblock it). The URL is set on that profile page but the person who controls it can change that any time they want without attracting attention so it’s not hardcoded in the way it would be if it was embedded in the malware executable.
- netsharc 3y agoYeah but a socket connection to an IRC server and port will probably trigger a network monitoring firewall that a computer in the network has been compromised... A connection to arstechnica.com, the IT admin might even think "Cool, I didn't know that Bob from accounting is into tech..."
- willcipriano 3y agoCorporate firewalls throw so many alerts that it's unlikely that a human even sees it let alone looks into it.
- jcrawfordor 3y agoMost corporate SOCs would probably investigate IRC connections at least briefly, they have a very high signal to noise ratio for compromised devices. Modern security devices do generate a tremendous amount of information, but the security operations industry as a whole and SIEMs in particular were developed to make it feasible to risk score and triage these findings.
- willcipriano 3y agoThis is quite the opposite of all my personal experience.
- jdietrich 3y agoA well-configured corporate firewall is going to block anything that looks like an IRC packet, because for the overwhelming majority of users, the probability of that packet being malicious is ~1.
- mintplant 3y agoThis led to many ISPs blocking IRC connections :(
- ploum 3y agoIndeed, that’s probably the reason I was looking for.
- scosman 3y agoGood to see them reporting on it. So many publications wouldn’t.
- creatonez 3y agoI found it funny how Ars Technica (owned by Condé Nast) had some of the best reporting offering scathing criticism of Reddit (also owned by Condé Nast) while Steve Huffman was destroying the website by killing off the API and leaving volunteer moderators without the tools they need to deal with spam. I'm not sure how common this is, but it was refreshing to see journalists doing their job properly despite being faced with a massive conflict of interest.
- jbm 3y ago> Steve Huffman was destroying the website by killing off the API and leaving volunteer moderators Did this really happen? The site seems to be as busy as normal and with the same opinions being expressed everywhere. Don't get me wrong, I think that was a huge loss and I don't use Reddit anymore as a result.
- lmm 3y agoReddit is noticeably less active and worse, at least the parts of it I'm in. Far short of "killing", but it did some damage.
- DANmode 3y agoTo the value for you. Is it making less money?/profit?, for Condé?
- lebean 3y ago[dead]
- creatonez 3y agoThere has been a dramatic rise in spam and hate speech, starting the day of the first moderator strikes. This hasn't gone unnoticed by the community, you see this observation being made by people all over the site.
- kurthr 3y agoBrowse news in a throwaway VM instance that doesn't directly have password management. GoogleNews has served me several trojans, because I'm inherently clicking on unknown links. This attack was interesting, because it didn't leave Ars, but I would fear those who target HN with outlinks. They can serve malware only to targeted domains so you may be the only one hit. Even more targeted and obscured is to include several keywords in an article of interest that lead to a single controlled page optimized for search engines, which again serves targeted malware.
- LeoPanthera 3y ago> GoogleNews has served me several trojans, because I'm inherently clicking on unknown links. [Citation Needed] Extraordinary claims require extraordinary evidence, and I find this extremely difficult to believe. No news outlet linked to from Google News is going to send you a "trojan", or any other kind of malware. You may have misunderstood how the malware described in the article works - simply visiting Ars would not infect you, or anyone.
- nequo 3y agoI would be curious to learn more about Google News abuses too. It doesn’t sound completely far fetched. Google search is known to have served up malicious websites masquerading as legitimate ones. For example, here’s one that was disguised as gimp.org: https://news.ycombinator.com/item?id=33384236 https://news.ycombinator.com/item?id=33384236 Unlikely that such an attack would make it far on HN though.
- kurthr 3y agoI think the concern on HN would be targeting to particular IPs or domains, more like spear phishing. Agree it wouldn't last long, but it only takes once.
- kurthr 3y agoThanks for your question. It should be fairly clear that I'm not talking directly about the Ars issue. That isn't about an outlinked article (Ars doesn't aggregate quite that way) the way Google and HN do. However, using a VM separate from the browser sandbox is a nice way to anonymize and prevent any leaks/damage that can occur. I'm interested to know why you think this hasn't happened since most serous compromises are an untrusted link click away (esp in windows). The first time was in about 2012. There was a news link off of GoogNews (not the site itself obviously, and an outlink as described). The "News" trojan link page seemed to be up for only a short while and then blocked, since later searches for the title were completely missing. I'm guessing Google probably caught it on their end since it was probably infecting everyone who clicked. I only noticed it reasonably quickly due to a rapid change in network activity, but it had already escaped the browser sandbox and was downloading more. Drive forensics that day didn't show anything obvious on Friday, but the next Monday a trojan was found that had been using a zero-day. Since then I've used a VM for random browsing (it's not a panacea, but it's easy enough to do). If you believe that's ineffective, I'd like to understand more. A couple of times in the 13 years since, the AV in the VM has caught viruses and I don't really browse much except news from Google, Yahoo, HN, Ars, etc in that VM.
- rising-sky 3y agoSo in other words, this is harmless unless the target was previously infected with the malware `explore.ps1`. This URL just acts as a trigger to activate the malware? Do I have that somewhat right?
- alamortsubite 3y agoYes. Though that pizza looks pretty gross.
- scosman 3y agoNot a trigger. Just a payload. On a domain the government can’t seize/shutdown. Kinda interesting, but I imagine they can just extract all the target urls from the malware and get hosts to block?
- AtlasBarfed 3y agoBase64 is never-before seen? This isn't even very advanced stenography, am I right? Heck, something like the network buffer datastore seems a lot more advanced.
- foobiekr 3y agosmuggling things past firewalls is trivial. base48 or some other nonsandard scheme or encrypt a zip file and use a bananaphone scheme to make the content look low entropy. No firewall will flag that.
- bonton89 3y agoWhat is bananaphone? Based solely on the video I'm assuming you repeat data over and over again wasting space to obscure the actual type of content.
- foobiekr 3y agoA lot of inspecting transparent TLS firewalls look for high entropy blocks, the idea being to sniff out encrypted exfiltration. Making them low entropy is straightforward, as you say.
- dabber 3y ago> Base64 is never-before seen? Maybe they're referring to using a prominent website as a C&C server? Wait... no, they've seen that before when they reported, in 2017, on a: > "backdoor Trojan used comments posted to Britney Spears's official Instagram account to locate the control server that sends instructions and offloads stolen data to and from infected computers." [0] So they must be talking about the novel use of an image in the staged delivery? Oh... nevermind, that can't be it either because their reporting on VPNFilter in 2018 mentioned: > "stage 1 relies on a sophisticated mechanism to locate servers where stage 2 and stage 3 payloads were available. The primary method involved downloading images stored on Photobucket.com and extracting an IP address from six integer values used for GPS latitude and longitude stored in the EXIF field of the image." [1] So yeah, I guess Ars hasn't seen Base64 before it was embedded on their site. [0] https://arstechnica.com/information-technology/2017/06/russian-hackers-turn-to-britney-spears-for-help-concealing-espionage-malware/ https://arstechnica.com/information-technology/2017/06/russi... [1] https://arstechnica.com/information-technology/2018/06/vpnfilter-malware-infecting-50000-devices-is-worse-than-we-thought/ https://arstechnica.com/information-technology/2018/06/vpnfi...
- technion 3y agoEvery time I read about a massive company ransomware event: excel macros, mimimatz, phishing Any time something is actually described as a novel technique: cryptominer. Ugh.
- hamandcheese 3y agoThis seems novel in the same way that "<thing>... but on the internet" is a patentable idea. It seems no different in concept than a spy signaling another spy by leaving something in a public space.
- peddling-brink 3y agoThe “but on the Internet” part is not novel either. Any site that allows text entry and public viewing may deal with this. https://bitofhex.com/2020/05/31/youtube-is-my-c2/ https://bitofhex.com/2020/05/31/youtube-is-my-c2/ Perhaps using the picture of a pizza is novel?
- aaron695 3y ago[dead]