Risk
3/26/2013
01:26 PM
50%
50%

Malware Developers Hijack Chromium Framework

Google Chromium project responds by switching to another download site and promising to put new techniques in place to block automated downloads.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Malware developers have been using a free Web browser control framework to make their malicious code easier to create and maintain.

That warning surfaced Friday after Symantec reported that the latest variant of Tidserv -- a.k.a. TDL -- was designed to use the Chromium Embedded Framework (CEF).

The framework, which is based on the Google Chromium project, allows developers to include Web browser windows in their applications. "The CEF libraries perform all of the functionality required to run the browser, such as parsing HTML or parsing and executing JavaScript," said Symantec security researcher Kevin Savage in a blog post.

[ Beware text spam. Read SMS Spam Delivers More Malware, Scam. ]

"While this may not be the first time a malware has made use of a legitimate framework for nefarious purposes, this new Tidserv variant requires the download of the 50 MB framework to function correctly, which is an unusual thing for a threat to do," he said.

In the wake of Symantec's warning, CEF project participants moved to make it more difficult for Tidserv infections to automatically download the framework. "It has come to our attention that a CEF binary release file (zip archive) hosted on our project page was being directly downloaded by a distributed malware product for illegal purposes," said a notice posted to the Chromium Embedded website.

"The Chromium Embedded Framework (CEF) project and its authors do not condone or promote the use of the CEF framework for illegal or illicit purposes. We will take all actions reasonably within our power to frustrate this use case. For that reason current and future downloads will be hosted externally," said to the notice, which redirected readers to a new download site. "We apologize for any inconvenience that this may cause our users who download CEF for legitimate purposes."

Tidserv was first discovered in 2008, and is one of a number of Trojan applications that employ rootkit techniques to help disguise their behavior on systems they successfully infect.

Like many types of malware, Tidserv is designed to download additional attack modules to provide add-on capabilities. For example, a module called "serf332" handles some types of network operations, such as clickjacking attacks or generating advertising pop-up banners.

The creators behind Tidserv appear to have been attracted to CEF because of its feature set, which Savage said makes it easier for them to create smaller but easier-to-update malware modules. According to CEF's developers, the framework "was designed from the ground up with both performance and ease of use in mind," and includes bindings for a number of other languages, including C, C++, Delphi, Java, .NET and Python. The framework also runs on Linux, Mac OS X and Windows.

As of Friday, Symantec reported seeing a sharp increase -- over an 18-day period -- in downloads of a module called cef32, which is part of the CEF, and which typically requires a full CEF download to access. "While we cannot be certain as to how many of these downloads may relate to Tidserv infection activities, if these downloads are a result of the malware the number of computers compromised with Tidserv would be sizeable," said Savage.

The CEF developers' response -- hosting their framework at a different website address -- should serve as a short-term fix against current versions of Tidserv. "The URL to the CEF zip file for download is currently hardcoded in the serf332 binary, so any change to this URL will require an update to the serf332 module," said Savage.

But what's to stop Tidserv's developers from simply pointing their malware at the new download, or else hosting the CEF framework download elsewhere? Asked that question in a Chromium Embedded Framework support forum, CEF project founder Marshall Greenblatt said, "I'm in the process of developing a new download system that requires verification (puzzle solving and sessions) and will hopefully defeat future attempts at automatic downloads."

One worry is that if too many instances of CEF are being used for malicious purposes, it might lead to the framework being blacklisted by endpoint security products. "Given the large number of companies currently using libcef for legitimate purposes I think it's unlikely that we'll end up on any anti-virus black lists," Greenblatt said. "Companies are also encouraged to sign all of their binaries, including CEF binaries, before distribution."

InformationWeek is conducting a survey on security and risk management. Take the InformationWeek 2013 Strategic Security Survey today. Survey ends March 29.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8802
Published: 2015-01-23
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVE-2014-9623
Published: 2015-01-23
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVE-2014-9638
Published: 2015-01-23
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVE-2014-9639
Published: 2015-01-23
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVE-2014-9640
Published: 2015-01-23
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.