Attacks/Breaches
5/14/2012
11:30 AM
Connect Directly
RSS
E-Mail
50%
50%

Amnesty International Hackers Learned From Flashback

Attackers used the same Java vulnerability employed by the Apple Flashback malware to try to infect site visitors with remote administration tools.

Hackers took aim last week at Amnesty International websites in Britain and Hong Kong with an exploit that targeted anyone visiting those websites.

According to technical details of the attack published by Websense, the attackers exploited the Hong Kong Amnesty site over the weekend, and the U.K. Amnesty site sometime between Tuesday and Wednesday of last week. In the case of the British Amnesty site, "the website was apparently injected with malicious code for these two days," according to the Websense analysis. "During that time, website users risked having sensitive data stolen and perhaps infecting other users in their network. However, the website owners rectified this issue after we advised them about the injection."

An Amnesty International official in Britain confirmed Monday that the group's website had been attacked, but offered a differing account of the exploit's duration. "Last Thursday, amnesty.org.uk was infected with a piece of malicious code. As soon as we became aware of the infection we worked with our hosting company Claranet to isolate it and remove it as a matter of urgency. Happily, the problem was resolved by Thursday lunchtime," said a spokeswoman for the group via email.

[ Stay safe while traveling. See 9 Tips To Block Hotel Wi-Fi Malware. ]

Amnesty gave credit for spotting the attack to its security monitoring tools. "Security is very important to us and as well as extensive security measures in place to prevent exploits such as this, we also have constant monitoring in place to alert us immediately when incidents like this occur," she said. "All our users' profiles are held on a completely separate website and server and were in no way compromised by this incident."

But attackers may have infected the website in part to gain access to the sequestered Amnesty files. "In some cases, hackers don't want to steal the data from the website but rather want to infect the users who are visiting. This can lead to more access to business-critical data which, for example, is often stored as files on a fileserver," said Rob Rachwald, director of security strategy at Imperva, in a blog post. "In the Amnesty case, the real prize isn't Amnesty's data per se, but the corporate and individual data and files of those who visit the site."

Interestingly, the Amnesty attackers attempted to infect website visitors by using the same Java exploit that was built into both Flashback and SabPub. While those malicious applications targeted Apple OS X users, the Amnesty attack was designed to push a binary file that runs on Windows operating systems, and which was signed using a VeriSign certificate that was issued to Tencent Technology (Shenzhen) Company Limited, and which remains valid until January 2013.

"Through further research we learn that this certificate has been in use for a while and does not appear to have been revoked at the time of this latest exploit activity," said Websense. But whoever built Flashback likely wasn't behind this attack, which Websense said appeared to have been built using the Metasploit penetration-testing framework.

Another interesting finding was that the binary file pushed by the exploited Amnesty sites "is a variant of the well-known remote administration tool Gh0st RAT, which is used mainly in targeted attacks to gain complete control of infected systems," said Websense. "With this control, the remote administrator has access to a user's files, email, passwords, and other sensitive personal information."

Also known as remote access tools, so-called RAT attacks gained notoriety last year after McAfee reported finding a command-and-control website tied to a tool it dubbed Shady RAT. The vendor said the gang behind that particular remote access tool had successfully compromised at least 72 organizations, including 22 governmental agencies and contractors, over a period of five years. While McAfee declined to nominate suspected perpetrators, many security experts suspected China to be behind the attacks.

Last week's attacks weren't the first attempts to hack an Amnesty International site to infect visitors with drive-by malware. Websense said the same Amnesty U.K. site had been compromised in 2009, as had the Hong Kong site, in 2010. In the case of that Hong Kong exploit, attackers inserted a malicious iFrame into the website that redirected all visitors to an external server controlled by the attackers. The site made use of various Adobe Flash, Shockwave, and Apple QuickTime bugs, as well as a zero-day Internet Explorer vulnerability, to attempt to install a Chinese-made remote access tool onto visitors' systems.

At a time when cybercrime has never been more prolific and sophisticated, budgets are being cut. In response, IT is taking a hard look using third-party services--outsourcing--to meet security challenges. Our Making The Security Outsourcing Decision report outlines the various security outsourcing options available. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0972
Published: 2014-08-01
The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent write access to IOMMU context registers, which allows local users to select a custom page table, and consequently write ...

CVE-2014-2627
Published: 2014-08-01
Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

CVE-2014-3009
Published: 2014-08-01
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct ph...

CVE-2014-3302
Published: 2014-08-01
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

CVE-2014-3534
Published: 2014-08-01
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a c...

Best of the Web
Dark Reading Radio