Attacks/Breaches
4/22/2013
01:23 PM
50%
50%

Chinese Hackers Seek Drone Secrets

"Comment Crew" gang that fanned fears of Chinese hacking launches malware that combs for drone technology information.

A notorious cyber-espionage gang is being blamed for a set of recently discovered spear-phishing attacks that aim to steal information relating to unmanned aerial vehicles (UAVs), better known as drones.

"The set of targets cover all aspects of unmanned vehicles, land, air, and sea, from research to design to manufacturing of the vehicles and their various subsystems," said James T. Bennett, a senior threat research engineer at FireEye, in a blog post.

Furthermore, the advanced persistent threat (APT) group behind both attacks, according to FireEye, is the gang known as the "Comment Crew," which was singled out in a recent report from Mandiant. The security firm accused the group, dubbed APT1, of being an elite Chinese military hacking unit based in Shanghai, known as the People's Liberation Army (PLA) Unit 61398, which is suspected of having attacked at least 141 organizations across numerous industries. Chinese government officials have denied those accusations.

[ U.S. intelligence agencies are using analysis software to identify security threats. Read more at Military Uses Big Data As Spy Tech. ]

Regardless of the group's sponsor, one recent set of attacks it launched targeted about a dozen organizations -- across the aerospace, defense, telecommunications and government sectors -- in both the United States and India, beginning in December 2011, if not earlier. But FireEye also found that the malicious infrastructure and command-and-control (C&C) servers used in the attacks are the same as those employed in a campaign known as Operation Beebus, so named for the related malware used by attackers, which was first submitted for testing to VirusTotal in April 2011. Including those spear-phishing attacks, which were discovered in February, FireEye now has a running total of 20 targets, including government-funded drone researchers in academia.

The earlier Beebus attacks involved malicious PDF and Word files -- with names such as "sensor environments.doc" and "RHT_SalaryGuide_2012.pdf" -- emailed to targets. The documents attempted to exploit a well-known DLL search order hijacking vulnerability in Windows and drop a malicious DLL file in the Windows directory.

In the latest series of attacks, the tactics have remained largely the same, although this time one of the decoy documents includes a reference to Pakistan's UAV program, while another appears to have been sent from a military email address at Joint Base Andrews in Maryland, titled "Family Planning Association of Base (FPAB)."

If a target opens the malicious document, it will attempt to exploit the Windows DLL vulnerability. If successful, the attack results in the installation of backdoor software known as Mutter, which uses what Bennett has dubbed a "hide-in-plain-sight" tactic in that the malicious file is 41 MB in size. "With rare exceptions, malware typically have a small size, usually no larger than a few hundred kilobytes," he said. "When an investigator comes across a file [that's] megabytes in size, he may be discouraged from taking a closer look."

To build the 41-MB file, the malware dropper first decodes a malicious DLL file -- only 140 KB in size -- that's included in the dropper's resource file, then places the DLL file onto the compromised system, proceeding to fill its resource section with randomly generated data, Bennett explained. "This has another useful side effect of giving each DLL a unique hash, making it more difficult to identify."

After infection, the malware will stay dormant for some period of time before attempting to exfiltrate data from the infected PC. That behavior mirrors that of the "wiper" malware that successfully exploited 48,000 systems at South Korean banks and broadcasters last month, although the malware isn't related.

Attend Interop Las Vegas May 6-10 and learn the emerging trends in information risk management and security. Use Priority Code MPIWK by March 22 to save an additional $200 off the early bird discount on All Access and Conference Passes. Join us in Las Vegas for access to 125+ workshops and conference classes, 300+ exhibiting companies, and the latest technology. Register today!

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8551
Published: 2014-11-26
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.

CVE-2014-8552
Published: 2014-11-26
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.

CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?