Risk
3/26/2013
01:26 PM
Connect Directly
RSS
E-Mail
50%
50%

Malware Developers Hijack Chromium Framework

Google Chromium project responds by switching to another download site and promising to put new techniques in place to block automated downloads.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Malware developers have been using a free Web browser control framework to make their malicious code easier to create and maintain.

That warning surfaced Friday after Symantec reported that the latest variant of Tidserv -- a.k.a. TDL -- was designed to use the Chromium Embedded Framework (CEF).

The framework, which is based on the Google Chromium project, allows developers to include Web browser windows in their applications. "The CEF libraries perform all of the functionality required to run the browser, such as parsing HTML or parsing and executing JavaScript," said Symantec security researcher Kevin Savage in a blog post.

[ Beware text spam. Read SMS Spam Delivers More Malware, Scam. ]

"While this may not be the first time a malware has made use of a legitimate framework for nefarious purposes, this new Tidserv variant requires the download of the 50 MB framework to function correctly, which is an unusual thing for a threat to do," he said.

In the wake of Symantec's warning, CEF project participants moved to make it more difficult for Tidserv infections to automatically download the framework. "It has come to our attention that a CEF binary release file (zip archive) hosted on our project page was being directly downloaded by a distributed malware product for illegal purposes," said a notice posted to the Chromium Embedded website.

"The Chromium Embedded Framework (CEF) project and its authors do not condone or promote the use of the CEF framework for illegal or illicit purposes. We will take all actions reasonably within our power to frustrate this use case. For that reason current and future downloads will be hosted externally," said to the notice, which redirected readers to a new download site. "We apologize for any inconvenience that this may cause our users who download CEF for legitimate purposes."

Tidserv was first discovered in 2008, and is one of a number of Trojan applications that employ rootkit techniques to help disguise their behavior on systems they successfully infect.

Like many types of malware, Tidserv is designed to download additional attack modules to provide add-on capabilities. For example, a module called "serf332" handles some types of network operations, such as clickjacking attacks or generating advertising pop-up banners.

The creators behind Tidserv appear to have been attracted to CEF because of its feature set, which Savage said makes it easier for them to create smaller but easier-to-update malware modules. According to CEF's developers, the framework "was designed from the ground up with both performance and ease of use in mind," and includes bindings for a number of other languages, including C, C++, Delphi, Java, .NET and Python. The framework also runs on Linux, Mac OS X and Windows.

As of Friday, Symantec reported seeing a sharp increase -- over an 18-day period -- in downloads of a module called cef32, which is part of the CEF, and which typically requires a full CEF download to access. "While we cannot be certain as to how many of these downloads may relate to Tidserv infection activities, if these downloads are a result of the malware the number of computers compromised with Tidserv would be sizeable," said Savage.

The CEF developers' response -- hosting their framework at a different website address -- should serve as a short-term fix against current versions of Tidserv. "The URL to the CEF zip file for download is currently hardcoded in the serf332 binary, so any change to this URL will require an update to the serf332 module," said Savage.

But what's to stop Tidserv's developers from simply pointing their malware at the new download, or else hosting the CEF framework download elsewhere? Asked that question in a Chromium Embedded Framework support forum, CEF project founder Marshall Greenblatt said, "I'm in the process of developing a new download system that requires verification (puzzle solving and sessions) and will hopefully defeat future attempts at automatic downloads."

One worry is that if too many instances of CEF are being used for malicious purposes, it might lead to the framework being blacklisted by endpoint security products. "Given the large number of companies currently using libcef for legitimate purposes I think it's unlikely that we'll end up on any anti-virus black lists," Greenblatt said. "Companies are also encouraged to sign all of their binaries, including CEF binaries, before distribution."

InformationWeek is conducting a survey on security and risk management. Take the InformationWeek 2013 Strategic Security Survey today. Survey ends March 29.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2012-2588
Published: 2014-09-19
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

CVE-2012-6659
Published: 2014-09-19
Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-3614
Published: 2014-09-19
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

Best of the Web
Dark Reading Radio