Attacks/Breaches
5/14/2012
11:30 AM
50%
50%

Amnesty International Hackers Learned From Flashback

Attackers used the same Java vulnerability employed by the Apple Flashback malware to try to infect site visitors with remote administration tools.

Hackers took aim last week at Amnesty International websites in Britain and Hong Kong with an exploit that targeted anyone visiting those websites.

According to technical details of the attack published by Websense, the attackers exploited the Hong Kong Amnesty site over the weekend, and the U.K. Amnesty site sometime between Tuesday and Wednesday of last week. In the case of the British Amnesty site, "the website was apparently injected with malicious code for these two days," according to the Websense analysis. "During that time, website users risked having sensitive data stolen and perhaps infecting other users in their network. However, the website owners rectified this issue after we advised them about the injection."

An Amnesty International official in Britain confirmed Monday that the group's website had been attacked, but offered a differing account of the exploit's duration. "Last Thursday, amnesty.org.uk was infected with a piece of malicious code. As soon as we became aware of the infection we worked with our hosting company Claranet to isolate it and remove it as a matter of urgency. Happily, the problem was resolved by Thursday lunchtime," said a spokeswoman for the group via email.

[ Stay safe while traveling. See 9 Tips To Block Hotel Wi-Fi Malware. ]

Amnesty gave credit for spotting the attack to its security monitoring tools. "Security is very important to us and as well as extensive security measures in place to prevent exploits such as this, we also have constant monitoring in place to alert us immediately when incidents like this occur," she said. "All our users' profiles are held on a completely separate website and server and were in no way compromised by this incident."

But attackers may have infected the website in part to gain access to the sequestered Amnesty files. "In some cases, hackers don't want to steal the data from the website but rather want to infect the users who are visiting. This can lead to more access to business-critical data which, for example, is often stored as files on a fileserver," said Rob Rachwald, director of security strategy at Imperva, in a blog post. "In the Amnesty case, the real prize isn't Amnesty's data per se, but the corporate and individual data and files of those who visit the site."

Interestingly, the Amnesty attackers attempted to infect website visitors by using the same Java exploit that was built into both Flashback and SabPub. While those malicious applications targeted Apple OS X users, the Amnesty attack was designed to push a binary file that runs on Windows operating systems, and which was signed using a VeriSign certificate that was issued to Tencent Technology (Shenzhen) Company Limited, and which remains valid until January 2013.

"Through further research we learn that this certificate has been in use for a while and does not appear to have been revoked at the time of this latest exploit activity," said Websense. But whoever built Flashback likely wasn't behind this attack, which Websense said appeared to have been built using the Metasploit penetration-testing framework.

Another interesting finding was that the binary file pushed by the exploited Amnesty sites "is a variant of the well-known remote administration tool Gh0st RAT, which is used mainly in targeted attacks to gain complete control of infected systems," said Websense. "With this control, the remote administrator has access to a user's files, email, passwords, and other sensitive personal information."

Also known as remote access tools, so-called RAT attacks gained notoriety last year after McAfee reported finding a command-and-control website tied to a tool it dubbed Shady RAT. The vendor said the gang behind that particular remote access tool had successfully compromised at least 72 organizations, including 22 governmental agencies and contractors, over a period of five years. While McAfee declined to nominate suspected perpetrators, many security experts suspected China to be behind the attacks.

Last week's attacks weren't the first attempts to hack an Amnesty International site to infect visitors with drive-by malware. Websense said the same Amnesty U.K. site had been compromised in 2009, as had the Hong Kong site, in 2010. In the case of that Hong Kong exploit, attackers inserted a malicious iFrame into the website that redirected all visitors to an external server controlled by the attackers. The site made use of various Adobe Flash, Shockwave, and Apple QuickTime bugs, as well as a zero-day Internet Explorer vulnerability, to attempt to install a Chinese-made remote access tool onto visitors' systems.

At a time when cybercrime has never been more prolific and sophisticated, budgets are being cut. In response, IT is taking a hard look using third-party services--outsourcing--to meet security challenges. Our Making The Security Outsourcing Decision report outlines the various security outsourcing options available. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Game Change: Meet the Mach37 Fall Startups
Ericka Chickowski, Contributing Writer, Dark Reading,  10/18/2017
Why Security Leaders Can't Afford to Be Just 'Left-Brained'
Bill Bradley, SVP, Cyber Engineering and Technical Services, CenturyLink,  10/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.