Risk
3/26/2013
01:26 PM
Connect Directly
RSS
E-Mail
50%
50%

Malware Developers Hijack Chromium Framework

Google Chromium project responds by switching to another download site and promising to put new techniques in place to block automated downloads.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Malware developers have been using a free Web browser control framework to make their malicious code easier to create and maintain.

That warning surfaced Friday after Symantec reported that the latest variant of Tidserv -- a.k.a. TDL -- was designed to use the Chromium Embedded Framework (CEF).

The framework, which is based on the Google Chromium project, allows developers to include Web browser windows in their applications. "The CEF libraries perform all of the functionality required to run the browser, such as parsing HTML or parsing and executing JavaScript," said Symantec security researcher Kevin Savage in a blog post.

[ Beware text spam. Read SMS Spam Delivers More Malware, Scam. ]

"While this may not be the first time a malware has made use of a legitimate framework for nefarious purposes, this new Tidserv variant requires the download of the 50 MB framework to function correctly, which is an unusual thing for a threat to do," he said.

In the wake of Symantec's warning, CEF project participants moved to make it more difficult for Tidserv infections to automatically download the framework. "It has come to our attention that a CEF binary release file (zip archive) hosted on our project page was being directly downloaded by a distributed malware product for illegal purposes," said a notice posted to the Chromium Embedded website.

"The Chromium Embedded Framework (CEF) project and its authors do not condone or promote the use of the CEF framework for illegal or illicit purposes. We will take all actions reasonably within our power to frustrate this use case. For that reason current and future downloads will be hosted externally," said to the notice, which redirected readers to a new download site. "We apologize for any inconvenience that this may cause our users who download CEF for legitimate purposes."

Tidserv was first discovered in 2008, and is one of a number of Trojan applications that employ rootkit techniques to help disguise their behavior on systems they successfully infect.

Like many types of malware, Tidserv is designed to download additional attack modules to provide add-on capabilities. For example, a module called "serf332" handles some types of network operations, such as clickjacking attacks or generating advertising pop-up banners.

The creators behind Tidserv appear to have been attracted to CEF because of its feature set, which Savage said makes it easier for them to create smaller but easier-to-update malware modules. According to CEF's developers, the framework "was designed from the ground up with both performance and ease of use in mind," and includes bindings for a number of other languages, including C, C++, Delphi, Java, .NET and Python. The framework also runs on Linux, Mac OS X and Windows.

As of Friday, Symantec reported seeing a sharp increase -- over an 18-day period -- in downloads of a module called cef32, which is part of the CEF, and which typically requires a full CEF download to access. "While we cannot be certain as to how many of these downloads may relate to Tidserv infection activities, if these downloads are a result of the malware the number of computers compromised with Tidserv would be sizeable," said Savage.

The CEF developers' response -- hosting their framework at a different website address -- should serve as a short-term fix against current versions of Tidserv. "The URL to the CEF zip file for download is currently hardcoded in the serf332 binary, so any change to this URL will require an update to the serf332 module," said Savage.

But what's to stop Tidserv's developers from simply pointing their malware at the new download, or else hosting the CEF framework download elsewhere? Asked that question in a Chromium Embedded Framework support forum, CEF project founder Marshall Greenblatt said, "I'm in the process of developing a new download system that requires verification (puzzle solving and sessions) and will hopefully defeat future attempts at automatic downloads."

One worry is that if too many instances of CEF are being used for malicious purposes, it might lead to the framework being blacklisted by endpoint security products. "Given the large number of companies currently using libcef for legitimate purposes I think it's unlikely that we'll end up on any anti-virus black lists," Greenblatt said. "Companies are also encouraged to sign all of their binaries, including CEF binaries, before distribution."

InformationWeek is conducting a survey on security and risk management. Take the InformationWeek 2013 Strategic Security Survey today. Survey ends March 29.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-6651
Published: 2014-07-31
Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

CVE-2014-2970
Published: 2014-07-31
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5139. Reason: This candidate is a duplicate of CVE-2014-5139, and has also been used to refer to an unrelated topic that is currently outside the scope of CVE. This unrelated topic is a LibreSSL code change adding functionality ...

CVE-2014-3488
Published: 2014-07-31
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

CVE-2014-3554
Published: 2014-07-31
Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

CVE-2014-5171
Published: 2014-07-31
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.

Best of the Web
Dark Reading Radio