02:38 PM

Attack Campaign Targets Facebook, Dropbox User Credentials

The goal of the attackers is not fully clear but the credential theft could set up sophisticated targeted attackers.

Researchers at security firm Cyphort have uncovered a five-year-old attack campaign that has quietly gone about the business of stealing user credentials for Dropbox, Facebook, and other applications unnoticed until now.

At this point, it does not appear the attackers are targeting specific organizations or industries, since their tentacles seem to have reached organizations ranging from energy companies to charities. According to Cyphort's McEnroe Navaraj, the intent of the data collection is unknown, but there is no shortage of ways for the credentials to be turned to the attackers' advantage.

The so-called NightHunter attack uses SMTP email for exfiltrating data rather than "more common CnC (command and control) mechanisms that use web protocols," Navaraj said in a blog post:

This could be to simply "hide (and steal data) in the plain sight" as organizations beef up web anomaly detection for dealing with advanced attacks.

It involves several different malware keyloggers, including Predator Pain, Limitless, and Spyrex. The unifying feature is that they all use SMTP (email) for data exfiltration. Email to social networking is like snail-mail is to email … it is outdated and often overlooked, so it can be a more stealthy way of data theft. So we called it NightHunter.

According to Cyphort, the company received a sample through a phishing email. The sample is a .net binary that steals users' credentials and sends them to a remote email server when executed. When researchers examined the sample, they also uncovered other similar samples in the wild as well. Navaraj said in the post:

These samples are delivered mostly through phishing emails. These emails are sent with DOC/ZIP/RAR attachments. You can get infected by opening a malicious document with scripting enabled. Most of the phishing emails are targeted towards personnel in finance/sales/HR departments. Sometimes actors may act as goods resale agents. We have seen cases where it was bundled with fake IDM/7zip installers. Most of these samples used keylogger tools to sniff data from the victim.

Cyphort co-founder Fengmin Gong notes that some of the servers used by the attackers are either private or have access protections that prevented the firm from looking into the upload account, so the actual number of infected machines is higher than the 1,800 compromised machines the company is aware of.

"This attack is ongoing and we continue to monitor it," Gong tells Dark Reading. "The attackers are very aggressive in their data-collection methodology, as well as the intervals of data exfiltration. Given the systematic nature of the actors behind this campaign, we are speculating that they are still in a 'reconnaissance stage' targeting credentials of high-level executives, but at this point it is impossible to speculate on their endgame with any degree of certainty."

Still, he says he believes the attackers may be using big-data techniques to mine the stolen credentials, which would give them the ability to leverage the credentials for targeted attacks. The situation also underscores just how effective phishing still is at hooking victims, he says. The attackers used messages disguised as emails about a variety of topics, with subject lines such as "Purchase Order" and "Inquiry." In addition to the applications mentioned above, the attackers are also targeting credentials for Skype, Amazon, LinkedIn, Google, Yahoo, Hotmail, Rediff, and banks.

Navaraj blogged:

NightHunter is one the more unique campaigns we have researched at Cyphort due to the footprint and complex data collection models it exhibits, furthermore the use of low-signal evasion it is leveraging such as webmail for data exfiltration points to much larger end-goal.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
7/14/2014 | 10:00:46 AM
Re: next phase
I agree Robert
Robert McDougal
Robert McDougal,
User Rank: Ninja
7/14/2014 | 9:50:29 AM
Re: next phase
Based on the longevity and the fact this campaign has avoided detection until now I wouldn't be surprised if the data collected has already been used in surgical breaches.
Denise J. Wasson
Denise J. Wasson,
User Rank: Apprentice
7/13/2014 | 12:29:25 PM
Re: next phase
There are many rumors about attack Campaign towrds Facebook, Dropbox users credentials, although there is no evidence of stolen data and the other vital signs of accessing od a theif into that platform. The job resume may help to learn more abouth the good and professional resume makimg. 
User Rank: Ninja
7/13/2014 | 4:46:21 AM
next phase
Despite there is no evidence of targeted attacks using the stolen data, the most worrying aspect of such operation is the possibility that collected information will be managed with big data techniques to conduct surgical offensives with serious consequences.

Another concerning aspect of the specific campaign is that it goes undetected since 2009 ... and this is just the tip of the iceberg.


Register for Dark Reading Newsletters
White Papers
Current Issue
E-Commerce Security: What Every Enterprise Needs to Know
The mainstream use of EMV smartcards in the US has experts predicting an increase in online fraud. Organizations will need to look at new tools and processes for building better breach detection and response capabilities.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio