Attacks/Breaches

7/26/2012
08:53 AM
50%
50%

Mahdi Malware Makers Push Anti-American Update

Spy malware, seemingly built by Iranians, gets update that searches for "USA" and "gov" on targeted machines, security researcher says at Black Hat.

Mounting evidence suggests that the Mahdi malware was built by Iranians, for the primary purpose of spying on people inside Iran.

Notably, while the four command-and-control (C&C) servers controlling Mahdi-infected PCs are based in Canada, the oldest sample of the Mahdi malware discovered thus far--dating from December 2011--interfaced with a C&C server located in Tehran, Iran.

What accounts for the Iran-based C&C server? "I think it was a mistake," said Aviv Raff, CTO of Israel-based Seculert, in an interview at Black Hat 2012 in Las Vegas. That is, whoever developed Mahdi may have inadvertently released into the wild versions which still connected to a test server, rather than production servers that had been set up overseas and meant to disguise the malware's origins.

But the target of Mahdi could be changing. According to Kasperksy, whoever is behind the malware launched a new variant Wednesday, which appeared to have been compiled the same day. "Following the shutdown of the Madi command and control domains last week, we thought the operation is now dead. Looks like we were wrong," said Nicolas Brulez, a security researcher at Kaspersky Lab, in a blog post. (Kaspersky refers to the malware as "Madi.")

[ Strengthen corporate security with tips from the FBI's terrorism-combating campaign. See Black Hat: 6 Lessons To Tighten Enterprise Security. ]

The new malware contains a number of refinements, such as not waiting for instructions from a C&C server. Instead, the malware simply grabs all targeted information and uploads it to a designated server, which, as with previous versions of the malware, is also hosted in Canada. In addition, the malware has been revamped to watch for a number of keywords, including "USA" and "gov."

"The Madi campaign is still ongoing and its perpetrators are busy shipping out new versions with improved features and new tricks," said Brulez. "The additional checks for 'USA' and 'gov' might indicate a shift of focus from targets in Israel to the USA."

Seculert first spotted Mahdi several months ago, as a malicious Trojan application hidden inside a Word document that was distributed via a spear-phishing attack. The email claimed that the attachment contained information about Israel's potential electronic warfare capabilities against Iran. The malware earned its name via a string of text inside the code, spotted by Seculert researchers, that included the word "Mahdi," which in Islamic eschatology is synonymous with Messiah.

After Kaspersky Lab went public last month with its discovery of the Flame malware, Seculert reached out, asking whether Mahdi might in any way relate to Flame, which researchers later linked to Stuxnet. The two companies' researchers then worked together, sinkholing the botnet to study it, and announced their Mahdi-related findings last week.

"The Madi info-stealing Trojan enables remote attackers to steal sensitive files from infected Windows computers, monitor sensitive communications such as email and instant messages, record audio, log keystrokes, and take screenshots of victims' activities," according to Kaspersky. "Common applications and websites that were spied on include accounts on Gmail, Hotmail, Yahoo Mail, ICQ, Skype, Google+, and Facebook."

The two security firms found no apparent connections between Mahdi and Flame. "We started sinkholing Mahdi and we found that most of the targeted entities were coming from Iran and Israel, very similar to Flame, but that was it with the similarities," said Raff. "But we didn't find anything specific about the malware itself that would say there was something similar between those campaigns."

Wednesday, Seculert also released a blog post with updated Mahdi research, based on its ongoing teardown of the Mahdi malware and its associated C&C servers, as well as a free tool for spotting whether a PC is infected by the malware.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Why Security Leaders Can't Afford to Be Just 'Left-Brained'
Bill Bradley, SVP, Cyber Engineering and Technical Services, CenturyLink,  10/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.