Attacks/Breaches
12/2/2014
02:40 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
100%
0%

FBI Warning Shows Targeted Attacks Don't Just Steal Anymore

An FBI advisory points to an increasing trend of destructive malware for activist, anti-forensics purposes.

As rumors and hazy news about the hack against Sony Pictures Entertainment continue to gel into credible theories about what exactly happened and who carried out the attack, one solid detail has emerged out of the mess. In the wake of the attack, the FBI has issued a warning against "destructive" malware that some experts believe could be tied to discoveries from the Sony attack.

A Reuters report this morning first broke news of the confidential FBI "flash" warning issued to a number of businesses yesterday. The agency counsels organizations to be on the lookout for malware that wipes data from infected machines. The malicious software even deletes the master boot record, effectively bricking systems and keeping them from booting up.

The FBI did not confirm whether the warning had anything to do with the Sony attack, but the timing suggests a connection. It came very soon after news broke that Sony's email systems were down for a week following an attack that stole unreleased motion pictures and potentially even pilfered employee healthcare and salary data, according to a report today from Krebs On Security. Some theorize that the attack may have been politically motivated to punish the studio for its impending release of The Interview, a movie about two journalists enlisted by the CIA to assassinate North Korea's Kim Jong Un.

Regardless of what really happened at Sony, the FBI warning stands in its own right as a caution to be doubly wary of attacks that could not only steal or leak information, but also threaten an organization's operational continuity. Such destructive malware capabilities are hardly new; researchers have been tracking wiper behavior for some time. One of the biggest examples of this was the attack against the Saudi Aramco oil company two years ago, which wiped 30,000 PCs clean using the Shamoon malware family. However, Shamoon was just a continuation of this class of data-destroying malware.

"This ability to destroy people's computers and wipe them clean has been around a couple of decades, but it has taken mass events, probably caused by the Iranian government and its proxies, to wake people up," Richard Bejtlich, then with Mandiant and now with FireEye, told Dark Reading at the time of the Aramco attack.

That trend only seems to continue. Tom Kellermann, chief cyber security officer for Trend Micro, says the North Koreans used similar tactics last year.

"The North Koreans began this type of campaign in 2013 with the detonation of MBR Wipers. Logic bombed throughout South Korea during the 'Dark Seoul' campaign," he says. This kind of nation-state activity could be just a taste of what's to come from both terror groups and financially motivated attackers. "Elite hacker crews have used wipers as anti-forensics countermeasures. In some unique instances, they initiate the counter measure from a secondary backdoor once the initial [command-and-control] is terminated."

Though wipers are still present in a relatively small proportion of attacks, the warning from the FBI is evidence that the trend may be snowballing quickly. According to Jeff Horne, vice president of emerging solutions for Accuvant, the use of wiper functionality is "more present today than it has ever been." He says that enterprises must factor this into their incident response procedures, because dealing with this kind of malware requires a much different touch than that given to targeted attacks in the past.

"It completely changes our remediation strategy if we find a piece of code that has a kill switch inside that controls the code and destroys the network if attackers don't maintain control of the code," says Horne. "A lot of energy companies, for example, cut off their Internet connection at the first sign of attack. But they need to be cognizant that some things have a time delay in them that says, 'If I can't connect to my server after 20 hours, then I'm going to blow up.'"

That's problematic, says Ron Gula, CEO and CTO at Tenable Network Security, considering that most organizations are just now tooling up to battle malware that simply steals information.

"If attacks like those against Sony continue against other US companies, 2015 will be a year of disrupted services," he says. "Most US-based companies have been preparing to avoid an embarrassing and financially damaging loss of sensitive data through exfiltration, such as the Target breach. They are not prepared for pure destruction of data."

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: You are infected!  @malwareunicorn to the rescue...  
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.