Attacks/Breaches
5/14/2012
11:30 AM
Connect Directly
RSS
E-Mail
50%
50%

Amnesty International Hackers Learned From Flashback

Attackers used the same Java vulnerability employed by the Apple Flashback malware to try to infect site visitors with remote administration tools.

Hackers took aim last week at Amnesty International websites in Britain and Hong Kong with an exploit that targeted anyone visiting those websites.

According to technical details of the attack published by Websense, the attackers exploited the Hong Kong Amnesty site over the weekend, and the U.K. Amnesty site sometime between Tuesday and Wednesday of last week. In the case of the British Amnesty site, "the website was apparently injected with malicious code for these two days," according to the Websense analysis. "During that time, website users risked having sensitive data stolen and perhaps infecting other users in their network. However, the website owners rectified this issue after we advised them about the injection."

An Amnesty International official in Britain confirmed Monday that the group's website had been attacked, but offered a differing account of the exploit's duration. "Last Thursday, amnesty.org.uk was infected with a piece of malicious code. As soon as we became aware of the infection we worked with our hosting company Claranet to isolate it and remove it as a matter of urgency. Happily, the problem was resolved by Thursday lunchtime," said a spokeswoman for the group via email.

[ Stay safe while traveling. See 9 Tips To Block Hotel Wi-Fi Malware. ]

Amnesty gave credit for spotting the attack to its security monitoring tools. "Security is very important to us and as well as extensive security measures in place to prevent exploits such as this, we also have constant monitoring in place to alert us immediately when incidents like this occur," she said. "All our users' profiles are held on a completely separate website and server and were in no way compromised by this incident."

But attackers may have infected the website in part to gain access to the sequestered Amnesty files. "In some cases, hackers don't want to steal the data from the website but rather want to infect the users who are visiting. This can lead to more access to business-critical data which, for example, is often stored as files on a fileserver," said Rob Rachwald, director of security strategy at Imperva, in a blog post. "In the Amnesty case, the real prize isn't Amnesty's data per se, but the corporate and individual data and files of those who visit the site."

Interestingly, the Amnesty attackers attempted to infect website visitors by using the same Java exploit that was built into both Flashback and SabPub. While those malicious applications targeted Apple OS X users, the Amnesty attack was designed to push a binary file that runs on Windows operating systems, and which was signed using a VeriSign certificate that was issued to Tencent Technology (Shenzhen) Company Limited, and which remains valid until January 2013.

"Through further research we learn that this certificate has been in use for a while and does not appear to have been revoked at the time of this latest exploit activity," said Websense. But whoever built Flashback likely wasn't behind this attack, which Websense said appeared to have been built using the Metasploit penetration-testing framework.

Another interesting finding was that the binary file pushed by the exploited Amnesty sites "is a variant of the well-known remote administration tool Gh0st RAT, which is used mainly in targeted attacks to gain complete control of infected systems," said Websense. "With this control, the remote administrator has access to a user's files, email, passwords, and other sensitive personal information."

Also known as remote access tools, so-called RAT attacks gained notoriety last year after McAfee reported finding a command-and-control website tied to a tool it dubbed Shady RAT. The vendor said the gang behind that particular remote access tool had successfully compromised at least 72 organizations, including 22 governmental agencies and contractors, over a period of five years. While McAfee declined to nominate suspected perpetrators, many security experts suspected China to be behind the attacks.

Last week's attacks weren't the first attempts to hack an Amnesty International site to infect visitors with drive-by malware. Websense said the same Amnesty U.K. site had been compromised in 2009, as had the Hong Kong site, in 2010. In the case of that Hong Kong exploit, attackers inserted a malicious iFrame into the website that redirected all visitors to an external server controlled by the attackers. The site made use of various Adobe Flash, Shockwave, and Apple QuickTime bugs, as well as a zero-day Internet Explorer vulnerability, to attempt to install a Chinese-made remote access tool onto visitors' systems.

At a time when cybercrime has never been more prolific and sophisticated, budgets are being cut. In response, IT is taking a hard look using third-party services--outsourcing--to meet security challenges. Our Making The Security Outsourcing Decision report outlines the various security outsourcing options available. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3409
Published: 2014-10-25
The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (device reload) via malformed CFM packets, aka Bug ID CSCuq93406.

CVE-2014-4620
Published: 2014-10-25
The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.

CVE-2014-4623
Published: 2014-10-25
EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force a...

CVE-2014-4624
Published: 2014-10-25
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call.

CVE-2014-6151
Published: 2014-10-25
CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.