Attacks/Breaches
12/18/2012
09:49 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Data-Destruction Attack Targeted 'Few' Select Iranian Computers

'Simplistic' data-destroying malware found on small number of targeted computers in Iran

It's no Stuxnet or Wiper, but the latest data-destroying malware targeting specific computers in Iran still wreaks some serious damage.

Iran's CERT on Sunday first issued an alert about the relatively rudimentary malware, which was discovered to delete data off of various drives at specific times and dates. The malware is a "very simple" knockoff of other wiping malware with no relation to those previously discovered malware attacks, and "very few machines" were infected by it, according to the CERT.

Researchers from Symantec, Kaspersky Lab, AlienVault Labs, and SophosLabs all have studied a sample of the malware, a.k.a. Batchwiper or GrooveMonitor. They concur that it's a simplistic yet lethal piece of malware that doesn't appear to be related to the nation-state built Stuxnet and Wiper that hit Iran's nuclear facility, or the destructive Shamoon that wiped 30,000 workstations of their data at Saudi Aramco, and deleted files at the Iranian oil ministry.

It's the latest in a series of data-destroying malware attacks targeting specific organizations in the Middle East. This return to 1980s and early-'90s malware that damages or deletes data puzzles researchers. "It's not the kind of thing you'd expect a nation-state [to create]," says Chester Wisniewski, a senior security adviser for Sophos.

He says it's odd that Iran sounded the alarm about such an unsophisticated attack. "This [malware] is something anybody could have done," he says.

Batchwiper/GrooveMonitor uses a DOS BAT file that was converted to a Windows Portable executable file. It wipes data off of drivers lettered D through I, as well as files on the user's desktop, and is set to do its dirty deed during specific dates, including between Dec. 10 and 12, and Jan. 21 and 23, as well as various dates that run through 2015.

"That's not something we see almost ever," Wisniewski says. "It's one of the few things that suggests that it's a targeted attack. It's very weird: Why would you care if it's Dec. 12? What those dates mean is a mystery."

The author of the malware even made an obvious typo in the code that prevents one feature from functioning. SophosLabs found a second variant of the malware, but it's still the same basic code.

Kaspersky Lab also saw an error in the code. "Other than the geographic region there doesn't seem to be any commonality with this file-deleting malware and the previous attacks we've seen. Even though the code is extremely simplistic it looks like the author managed to slip in a mistake, by not deleting a line of old code," says Roel Schouwenberg, senior researcher for global research and analysis at Kaspersky Lab, in a blog post.

Just how it spread is unclear. Jaime Blasco, labs manager at AlienVault Labs, thinks it may be via USB. "We don’t have details about the infection vector but based on the dropper it could be deployed using USB drives, internal actors, SpearPhishing or probably as the second stage of a targeted intrusion," Blasco says in a blog post.

The Iranian CERT initially reported that the malware was efficient yet simple, and was wiping out disk partitions and user profile directories without being detected by antivirus software.

"This is as basic as it gets. But if it was effective, that doesn't matter. If it wasn't clear already -- the era of cybersabotage has arrived. Be prepared," Schouwenberg says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.