Attacks/Breaches
7/11/2014
02:38 PM
Connect Directly
RSS
E-Mail
50%
50%

Attack Campaign Targets Facebook, Dropbox User Credentials

The goal of the attackers is not fully clear but the credential theft could set up sophisticated targeted attackers.

Researchers at security firm Cyphort have uncovered a five-year-old attack campaign that has quietly gone about the business of stealing user credentials for Dropbox, Facebook, and other applications unnoticed until now.

At this point, it does not appear the attackers are targeting specific organizations or industries, since their tentacles seem to have reached organizations ranging from energy companies to charities. According to Cyphort's McEnroe Navaraj, the intent of the data collection is unknown, but there is no shortage of ways for the credentials to be turned to the attackers' advantage.

The so-called NightHunter attack uses SMTP email for exfiltrating data rather than "more common CnC (command and control) mechanisms that use web protocols," Navaraj said in a blog post:

This could be to simply "hide (and steal data) in the plain sight" as organizations beef up web anomaly detection for dealing with advanced attacks.

It involves several different malware keyloggers, including Predator Pain, Limitless, and Spyrex. The unifying feature is that they all use SMTP (email) for data exfiltration. Email to social networking is like snail-mail is to email … it is outdated and often overlooked, so it can be a more stealthy way of data theft. So we called it NightHunter.

According to Cyphort, the company received a sample through a phishing email. The sample is a .net binary that steals users' credentials and sends them to a remote email server when executed. When researchers examined the sample, they also uncovered other similar samples in the wild as well. Navaraj said in the post:

These samples are delivered mostly through phishing emails. These emails are sent with DOC/ZIP/RAR attachments. You can get infected by opening a malicious document with scripting enabled. Most of the phishing emails are targeted towards personnel in finance/sales/HR departments. Sometimes actors may act as goods resale agents. We have seen cases where it was bundled with fake IDM/7zip installers. Most of these samples used keylogger tools to sniff data from the victim.

Cyphort co-founder Fengmin Gong notes that some of the servers used by the attackers are either private or have access protections that prevented the firm from looking into the upload account, so the actual number of infected machines is higher than the 1,800 compromised machines the company is aware of.

"This attack is ongoing and we continue to monitor it," Gong tells Dark Reading. "The attackers are very aggressive in their data-collection methodology, as well as the intervals of data exfiltration. Given the systematic nature of the actors behind this campaign, we are speculating that they are still in a 'reconnaissance stage' targeting credentials of high-level executives, but at this point it is impossible to speculate on their endgame with any degree of certainty."

Still, he says he believes the attackers may be using big-data techniques to mine the stolen credentials, which would give them the ability to leverage the credentials for targeted attacks. The situation also underscores just how effective phishing still is at hooking victims, he says. The attackers used messages disguised as emails about a variety of topics, with subject lines such as "Purchase Order" and "Inquiry." In addition to the applications mentioned above, the attackers are also targeting credentials for Skype, Amazon, LinkedIn, Google, Yahoo, Hotmail, Rediff, and banks.

Navaraj blogged:

NightHunter is one the more unique campaigns we have researched at Cyphort due to the footprint and complex data collection models it exhibits, furthermore the use of low-signal evasion it is leveraging such as webmail for data exfiltration points to much larger end-goal.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/14/2014 | 10:00:46 AM
Re: next phase
I agree Robert
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/14/2014 | 9:50:29 AM
Re: next phase
Based on the longevity and the fact this campaign has avoided detection until now I wouldn't be surprised if the data collected has already been used in surgical breaches.
Denise J. Wasson
0%
100%
Denise J. Wasson,
User Rank: Apprentice
7/13/2014 | 12:29:25 PM
Re: next phase
There are many rumors about attack Campaign towrds Facebook, Dropbox users credentials, although there is no evidence of stolen data and the other vital signs of accessing od a theif into that platform. The job resume may help to learn more abouth the good and professional resume makimg. 
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/13/2014 | 4:46:21 AM
next phase
Despite there is no evidence of targeted attacks using the stolen data, the most worrying aspect of such operation is the possibility that collected information will be managed with big data techniques to conduct surgical offensives with serious consequences.

Another concerning aspect of the specific campaign is that it goes undetected since 2009 ... and this is just the tip of the iceberg.

Regards

Pierluigi 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3345
Published: 2014-08-28
The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503.

CVE-2014-3347
Published: 2014-08-28
Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid s...

CVE-2014-4199
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

CVE-2014-4200
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.

CVE-2014-0761
Published: 2014-08-27
The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infinite loop or process crash) via a crafted TCP packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.