Risk
3/26/2013
01:26 PM
50%
50%

Malware Developers Hijack Chromium Framework

Google Chromium project responds by switching to another download site and promising to put new techniques in place to block automated downloads.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
Malware developers have been using a free Web browser control framework to make their malicious code easier to create and maintain.

That warning surfaced Friday after Symantec reported that the latest variant of Tidserv -- a.k.a. TDL -- was designed to use the Chromium Embedded Framework (CEF).

The framework, which is based on the Google Chromium project, allows developers to include Web browser windows in their applications. "The CEF libraries perform all of the functionality required to run the browser, such as parsing HTML or parsing and executing JavaScript," said Symantec security researcher Kevin Savage in a blog post.

[ Beware text spam. Read SMS Spam Delivers More Malware, Scam. ]

"While this may not be the first time a malware has made use of a legitimate framework for nefarious purposes, this new Tidserv variant requires the download of the 50 MB framework to function correctly, which is an unusual thing for a threat to do," he said.

In the wake of Symantec's warning, CEF project participants moved to make it more difficult for Tidserv infections to automatically download the framework. "It has come to our attention that a CEF binary release file (zip archive) hosted on our project page was being directly downloaded by a distributed malware product for illegal purposes," said a notice posted to the Chromium Embedded website.

"The Chromium Embedded Framework (CEF) project and its authors do not condone or promote the use of the CEF framework for illegal or illicit purposes. We will take all actions reasonably within our power to frustrate this use case. For that reason current and future downloads will be hosted externally," said to the notice, which redirected readers to a new download site. "We apologize for any inconvenience that this may cause our users who download CEF for legitimate purposes."

Tidserv was first discovered in 2008, and is one of a number of Trojan applications that employ rootkit techniques to help disguise their behavior on systems they successfully infect.

Like many types of malware, Tidserv is designed to download additional attack modules to provide add-on capabilities. For example, a module called "serf332" handles some types of network operations, such as clickjacking attacks or generating advertising pop-up banners.

The creators behind Tidserv appear to have been attracted to CEF because of its feature set, which Savage said makes it easier for them to create smaller but easier-to-update malware modules. According to CEF's developers, the framework "was designed from the ground up with both performance and ease of use in mind," and includes bindings for a number of other languages, including C, C++, Delphi, Java, .NET and Python. The framework also runs on Linux, Mac OS X and Windows.

As of Friday, Symantec reported seeing a sharp increase -- over an 18-day period -- in downloads of a module called cef32, which is part of the CEF, and which typically requires a full CEF download to access. "While we cannot be certain as to how many of these downloads may relate to Tidserv infection activities, if these downloads are a result of the malware the number of computers compromised with Tidserv would be sizeable," said Savage.

The CEF developers' response -- hosting their framework at a different website address -- should serve as a short-term fix against current versions of Tidserv. "The URL to the CEF zip file for download is currently hardcoded in the serf332 binary, so any change to this URL will require an update to the serf332 module," said Savage.

But what's to stop Tidserv's developers from simply pointing their malware at the new download, or else hosting the CEF framework download elsewhere? Asked that question in a Chromium Embedded Framework support forum, CEF project founder Marshall Greenblatt said, "I'm in the process of developing a new download system that requires verification (puzzle solving and sessions) and will hopefully defeat future attempts at automatic downloads."

One worry is that if too many instances of CEF are being used for malicious purposes, it might lead to the framework being blacklisted by endpoint security products. "Given the large number of companies currently using libcef for legitimate purposes I think it's unlikely that we'll end up on any anti-virus black lists," Greenblatt said. "Companies are also encouraged to sign all of their binaries, including CEF binaries, before distribution."

InformationWeek is conducting a survey on security and risk management. Take the InformationWeek 2013 Strategic Security Survey today. Survey ends March 29.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6090
Published: 2015-04-27
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix...

CVE-2014-6092
Published: 2015-04-27
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause...

CVE-2015-0113
Published: 2015-04-27
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation...

CVE-2015-0174
Published: 2015-04-27
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2015-0175
Published: 2015-04-27
IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.