Attacks/Breaches
4/22/2013
01:23 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Chinese Hackers Seek Drone Secrets

"Comment Crew" gang that fanned fears of Chinese hacking launches malware that combs for drone technology information.

A notorious cyber-espionage gang is being blamed for a set of recently discovered spear-phishing attacks that aim to steal information relating to unmanned aerial vehicles (UAVs), better known as drones.

"The set of targets cover all aspects of unmanned vehicles, land, air, and sea, from research to design to manufacturing of the vehicles and their various subsystems," said James T. Bennett, a senior threat research engineer at FireEye, in a blog post.

Furthermore, the advanced persistent threat (APT) group behind both attacks, according to FireEye, is the gang known as the "Comment Crew," which was singled out in a recent report from Mandiant. The security firm accused the group, dubbed APT1, of being an elite Chinese military hacking unit based in Shanghai, known as the People's Liberation Army (PLA) Unit 61398, which is suspected of having attacked at least 141 organizations across numerous industries. Chinese government officials have denied those accusations.

[ U.S. intelligence agencies are using analysis software to identify security threats. Read more at Military Uses Big Data As Spy Tech. ]

Regardless of the group's sponsor, one recent set of attacks it launched targeted about a dozen organizations -- across the aerospace, defense, telecommunications and government sectors -- in both the United States and India, beginning in December 2011, if not earlier. But FireEye also found that the malicious infrastructure and command-and-control (C&C) servers used in the attacks are the same as those employed in a campaign known as Operation Beebus, so named for the related malware used by attackers, which was first submitted for testing to VirusTotal in April 2011. Including those spear-phishing attacks, which were discovered in February, FireEye now has a running total of 20 targets, including government-funded drone researchers in academia.

The earlier Beebus attacks involved malicious PDF and Word files -- with names such as "sensor environments.doc" and "RHT_SalaryGuide_2012.pdf" -- emailed to targets. The documents attempted to exploit a well-known DLL search order hijacking vulnerability in Windows and drop a malicious DLL file in the Windows directory.

In the latest series of attacks, the tactics have remained largely the same, although this time one of the decoy documents includes a reference to Pakistan's UAV program, while another appears to have been sent from a military email address at Joint Base Andrews in Maryland, titled "Family Planning Association of Base (FPAB)."

If a target opens the malicious document, it will attempt to exploit the Windows DLL vulnerability. If successful, the attack results in the installation of backdoor software known as Mutter, which uses what Bennett has dubbed a "hide-in-plain-sight" tactic in that the malicious file is 41 MB in size. "With rare exceptions, malware typically have a small size, usually no larger than a few hundred kilobytes," he said. "When an investigator comes across a file [that's] megabytes in size, he may be discouraged from taking a closer look."

To build the 41-MB file, the malware dropper first decodes a malicious DLL file -- only 140 KB in size -- that's included in the dropper's resource file, then places the DLL file onto the compromised system, proceeding to fill its resource section with randomly generated data, Bennett explained. "This has another useful side effect of giving each DLL a unique hash, making it more difficult to identify."

After infection, the malware will stay dormant for some period of time before attempting to exfiltrate data from the infected PC. That behavior mirrors that of the "wiper" malware that successfully exploited 48,000 systems at South Korean banks and broadcasters last month, although the malware isn't related.

Attend Interop Las Vegas May 6-10 and learn the emerging trends in information risk management and security. Use Priority Code MPIWK by March 22 to save an additional $200 off the early bird discount on All Access and Conference Passes. Join us in Las Vegas for access to 125+ workshops and conference classes, 300+ exhibiting companies, and the latest technology. Register today!

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-5704
Published: 2014-04-15
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."

CVE-2013-5705
Published: 2014-04-15
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

CVE-2014-0341
Published: 2014-04-15
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_internal/entries.tpl; (4) an event field to ob...

CVE-2014-0342
Published: 2014-04-15
Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .php or (2) .php# extension, and then accessing it via unspecified vectors.

CVE-2014-0348
Published: 2014-04-15
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to login to arbitrary domain accounts by using the corresponding...

Best of the Web