Risk
3/26/2013
01:26 PM
50%
50%

Malware Developers Hijack Chromium Framework

Google Chromium project responds by switching to another download site and promising to put new techniques in place to block automated downloads.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Malware developers have been using a free Web browser control framework to make their malicious code easier to create and maintain.

That warning surfaced Friday after Symantec reported that the latest variant of Tidserv -- a.k.a. TDL -- was designed to use the Chromium Embedded Framework (CEF).

The framework, which is based on the Google Chromium project, allows developers to include Web browser windows in their applications. "The CEF libraries perform all of the functionality required to run the browser, such as parsing HTML or parsing and executing JavaScript," said Symantec security researcher Kevin Savage in a blog post.

[ Beware text spam. Read SMS Spam Delivers More Malware, Scam. ]

"While this may not be the first time a malware has made use of a legitimate framework for nefarious purposes, this new Tidserv variant requires the download of the 50 MB framework to function correctly, which is an unusual thing for a threat to do," he said.

In the wake of Symantec's warning, CEF project participants moved to make it more difficult for Tidserv infections to automatically download the framework. "It has come to our attention that a CEF binary release file (zip archive) hosted on our project page was being directly downloaded by a distributed malware product for illegal purposes," said a notice posted to the Chromium Embedded website.

"The Chromium Embedded Framework (CEF) project and its authors do not condone or promote the use of the CEF framework for illegal or illicit purposes. We will take all actions reasonably within our power to frustrate this use case. For that reason current and future downloads will be hosted externally," said to the notice, which redirected readers to a new download site. "We apologize for any inconvenience that this may cause our users who download CEF for legitimate purposes."

Tidserv was first discovered in 2008, and is one of a number of Trojan applications that employ rootkit techniques to help disguise their behavior on systems they successfully infect.

Like many types of malware, Tidserv is designed to download additional attack modules to provide add-on capabilities. For example, a module called "serf332" handles some types of network operations, such as clickjacking attacks or generating advertising pop-up banners.

The creators behind Tidserv appear to have been attracted to CEF because of its feature set, which Savage said makes it easier for them to create smaller but easier-to-update malware modules. According to CEF's developers, the framework "was designed from the ground up with both performance and ease of use in mind," and includes bindings for a number of other languages, including C, C++, Delphi, Java, .NET and Python. The framework also runs on Linux, Mac OS X and Windows.

As of Friday, Symantec reported seeing a sharp increase -- over an 18-day period -- in downloads of a module called cef32, which is part of the CEF, and which typically requires a full CEF download to access. "While we cannot be certain as to how many of these downloads may relate to Tidserv infection activities, if these downloads are a result of the malware the number of computers compromised with Tidserv would be sizeable," said Savage.

The CEF developers' response -- hosting their framework at a different website address -- should serve as a short-term fix against current versions of Tidserv. "The URL to the CEF zip file for download is currently hardcoded in the serf332 binary, so any change to this URL will require an update to the serf332 module," said Savage.

But what's to stop Tidserv's developers from simply pointing their malware at the new download, or else hosting the CEF framework download elsewhere? Asked that question in a Chromium Embedded Framework support forum, CEF project founder Marshall Greenblatt said, "I'm in the process of developing a new download system that requires verification (puzzle solving and sessions) and will hopefully defeat future attempts at automatic downloads."

One worry is that if too many instances of CEF are being used for malicious purposes, it might lead to the framework being blacklisted by endpoint security products. "Given the large number of companies currently using libcef for legitimate purposes I think it's unlikely that we'll end up on any anti-virus black lists," Greenblatt said. "Companies are also encouraged to sign all of their binaries, including CEF binaries, before distribution."

InformationWeek is conducting a survey on security and risk management. Take the InformationWeek 2013 Strategic Security Survey today. Survey ends March 29.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-5075
Published: 2014-12-27
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.

CVE-2011-4720
Published: 2014-12-27
Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation.

CVE-2011-4722
Published: 2014-12-27
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.

CVE-2012-1203
Published: 2014-12-27
Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts via a save_user action.

CVE-2012-1302
Published: 2014-12-27
Multiple cross-site scripting (XSS) vulnerabilities in amMap 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file parameter to ammap.swf, or (3) the data_file parameter to amtimeline.swf.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.