Vulnerabilities / Threats
11/6/2012
06:36 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Spooky Link Found Between Gh0st RAT, DDoS Botnet

FireEye researchers detail findings of a combination cyberespionage-DDoS Trojan infection

The infamous Gh0st remote access Trojan (RAT) has been spotted working alongside a new backdoor Trojan that steals Firefox stored passwords and operates in DDoS attacks.

Researchers at FireEye discovered infected machines running both the cyberespionage-linked Gh0st and the so-called Backdoor.ADDNEW malware, with each also phoning home to the same command-and-control (C&C) IP address. "We saw the machines getting infected with Gh0st within one week of them getting infected with ADDNEW. The machines used the "Gh0st" magic keyword to beacon back to their CnCs," wrote Vinay Pidathala, security content researcher for FireEye.

Gh0stNet is best known for widespread cyberespionage attacks targeting high-profile diplomatic, military, political, and economic systems around the world, including in Iran, India, South Korea, Thailand, Germany, and other parts of Asia. One of its main targets was the Dalai Lama and related Tibetan operations, and researchers say signs point to a Chinese connection.

Backdoor.ADDNEW is based on Russian malware called DaRK DDoSer, which can steal stored passwords in the Firefox browser and use the compromised machines in DDoS attacks.

Pidathala says Backdoor uses a custom protocol via TCP in its C&C communications. "The malware also communicates to its CnC about the port it's listening on," he wrote. "We also noticed another type of communication where the malware clearly informs its CnC that it is awaiting further commands for it to take actions on the compromised machine."

FireEye is still studying elements of the commands being issued by the attackers in the malware, but provides several screen shots of how the malware is communicating with the C&C infrastructure in its post.

"More importantly though, there are strings in the binary referencing "DarkDDOSER." One can only speculate if in some way "DarkDdoser" and the Gh0st RAT complement each other," Pidathala said in the blog post today.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

CVE-2014-8154
Published: 2015-01-27
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overf...

CVE-2014-9197
Published: 2015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

CVE-2014-9198
Published: 2015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

CVE-2014-9646
Published: 2015-01-27
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.