Attacks/Breaches
7/11/2014
02:38 PM
Connect Directly
RSS
E-Mail
50%
50%

Attack Campaign Targets Facebook, Dropbox User Credentials

The goal of the attackers is not fully clear but the credential theft could set up sophisticated targeted attackers.

Researchers at security firm Cyphort have uncovered a five-year-old attack campaign that has quietly gone about the business of stealing user credentials for Dropbox, Facebook, and other applications unnoticed until now.

At this point, it does not appear the attackers are targeting specific organizations or industries, since their tentacles seem to have reached organizations ranging from energy companies to charities. According to Cyphort's McEnroe Navaraj, the intent of the data collection is unknown, but there is no shortage of ways for the credentials to be turned to the attackers' advantage.

The so-called NightHunter attack uses SMTP email for exfiltrating data rather than "more common CnC (command and control) mechanisms that use web protocols," Navaraj said in a blog post:

This could be to simply "hide (and steal data) in the plain sight" as organizations beef up web anomaly detection for dealing with advanced attacks.

It involves several different malware keyloggers, including Predator Pain, Limitless, and Spyrex. The unifying feature is that they all use SMTP (email) for data exfiltration. Email to social networking is like snail-mail is to email … it is outdated and often overlooked, so it can be a more stealthy way of data theft. So we called it NightHunter.

According to Cyphort, the company received a sample through a phishing email. The sample is a .net binary that steals users' credentials and sends them to a remote email server when executed. When researchers examined the sample, they also uncovered other similar samples in the wild as well. Navaraj said in the post:

These samples are delivered mostly through phishing emails. These emails are sent with DOC/ZIP/RAR attachments. You can get infected by opening a malicious document with scripting enabled. Most of the phishing emails are targeted towards personnel in finance/sales/HR departments. Sometimes actors may act as goods resale agents. We have seen cases where it was bundled with fake IDM/7zip installers. Most of these samples used keylogger tools to sniff data from the victim.

Cyphort co-founder Fengmin Gong notes that some of the servers used by the attackers are either private or have access protections that prevented the firm from looking into the upload account, so the actual number of infected machines is higher than the 1,800 compromised machines the company is aware of.

"This attack is ongoing and we continue to monitor it," Gong tells Dark Reading. "The attackers are very aggressive in their data-collection methodology, as well as the intervals of data exfiltration. Given the systematic nature of the actors behind this campaign, we are speculating that they are still in a 'reconnaissance stage' targeting credentials of high-level executives, but at this point it is impossible to speculate on their endgame with any degree of certainty."

Still, he says he believes the attackers may be using big-data techniques to mine the stolen credentials, which would give them the ability to leverage the credentials for targeted attacks. The situation also underscores just how effective phishing still is at hooking victims, he says. The attackers used messages disguised as emails about a variety of topics, with subject lines such as "Purchase Order" and "Inquiry." In addition to the applications mentioned above, the attackers are also targeting credentials for Skype, Amazon, LinkedIn, Google, Yahoo, Hotmail, Rediff, and banks.

Navaraj blogged:

NightHunter is one the more unique campaigns we have researched at Cyphort due to the footprint and complex data collection models it exhibits, furthermore the use of low-signal evasion it is leveraging such as webmail for data exfiltration points to much larger end-goal.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/14/2014 | 10:00:46 AM
Re: next phase
I agree Robert
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/14/2014 | 9:50:29 AM
Re: next phase
Based on the longevity and the fact this campaign has avoided detection until now I wouldn't be surprised if the data collected has already been used in surgical breaches.
Denise J. Wasson
0%
100%
Denise J. Wasson,
User Rank: Apprentice
7/13/2014 | 12:29:25 PM
Re: next phase
There are many rumors about attack Campaign towrds Facebook, Dropbox users credentials, although there is no evidence of stolen data and the other vital signs of accessing od a theif into that platform. The job resume may help to learn more abouth the good and professional resume makimg. 
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/13/2014 | 4:46:21 AM
next phase
Despite there is no evidence of targeted attacks using the stolen data, the most worrying aspect of such operation is the possibility that collected information will be managed with big data techniques to conduct surgical offensives with serious consequences.

Another concerning aspect of the specific campaign is that it goes undetected since 2009 ... and this is just the tip of the iceberg.

Regards

Pierluigi 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6278
Published: 2014-09-30
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and m...

CVE-2014-6805
Published: 2014-09-30
The weibo (aka magic.weibo) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6806
Published: 2014-09-30
The Thanodi - Setswana Translator (aka com.thanodi.thanodi) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6807
Published: 2014-09-30
The OLA School (aka com.conduit.app_00f9890a4f0145f2aae9d714e20b273a.app) application 1.2.7.132 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6808
Published: 2014-09-30
The Active 24 (aka com.zentity.app.active24) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.