Attacks/Breaches
8/11/2017
01:58 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

APT28 Uses EternalBlue to Spy on Hotel Wifi Networks

Hacker group APT28 is using the EternalBlue hacking tool to spread throughout hotel networks and collect guests' information.

If you're not yet skeptical of hotel wifi networks, APT28 is giving you a good reason to think twice before logging on. The Russian hacker group, otherwise known as Fancy Bear, is reportedly gaining control of those networks and using its access to spy on guests.

FireEye, which has been watching the group, saw signs indicating APT28 is trying to compromise government and business travelers through access to hotels' guest wifi networks. The security firm attributes this campaign to APT28 "with moderate confidence."

APT28 is using a few notable techniques in these attacks against the hospitality sector, including sniffing passwords from wifi traffic and poisoning the NetBIOS Name Service. This time it's also using the EternalBlue exploit, an alleged NSA hacking tool leaked by ShadowBrokers and recently used to spread WannaCry and NotPetya malware campaigns.

It's a new move for the group, says Ben Read, FireEye's manager for cyberespionage analysis. This is the first time APT28 has used EternalBlue, which "makes it easy to move to vulnerable systems," he explains.

Attackers use spearphishing to enter hotel networks. FireEye uncovered a malicious document targeting hospitality businesses, including hotels in seven European countries and one in the Middle East. The document, called Hotel_Reservation_Form.doc, is likely opened by someone at the reservation desk. If successfully executed, the macro installs APT28's Gamefish malware.

Once inside, attackers move laterally to detect machines that control both guest and internal wifi networks. When they find them, they deploy Responder, which simplifies credential theft.

"Responder is deployed manually," says Read. "The reason you deploy Responder is to steal passwords from people who are connected to the network."

Responder is an open-source tool that enables NetBIOS Name Service poisoning, which looks for computers attempting to connect to network resources. When it detects a victim trying to connect to a printer or shared file, for example, it pretends to be that resource and causes the victim machine to send its username and hashed passwords.

APT28 used Responder to steal credentials, which allowed them to escalate privileges within the victim network. It leveraged EternalBlue to spread laterally throughout the network and find target machines. Victims' credentials could be stolen remotely or by using a machine in physical proximity to, and on the same network as, the target device.

"Once they have credentials, what they can get into depends on how the network is set up," says Read. Under the right circumstances, attackers could remotely log into a victim's computer and deploy malware, or log into a target Outlook account. This would be possible using single-factor authentication and no interaction with the victim.

However, it may be impossible to use credentials for accessing these accounts if the victim is using a VPN or has enabled two-factor authentication.

Cyberattacks on the hospitality industry can be used to collect information on target hotels but usually aim to steal data from guests. Read believes this is the case with APT28's recent activity, though researchers have not determined the ultimate purpose of the targeting in this campaign.

"The hotels targeted were middle-to-upper market in European capitals," he explains. "This was likely targeting the type of people staying there, like diplomats or business leaders."

It's a warning for travelers, especially business or government personnel, to buckle down on security. "You run a risk any time you connect to a wifi network not controlled by your company," Read warns. He advises travelers to avoid opening suspicious documents or enabling macros, and to travel with a hotspot rather than rely on hotel wifi.

Related Content:

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: No, no, no! Have a Unix CRON do the pop-up reminders!
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The Impact of a Security Breach 2017
The Impact of a Security Breach 2017
Despite the escalation of cybersecurity staffing and technology, enterprises continue to suffer data breaches and compromises at an alarming rate. How do these breaches occur? How are enterprises responding, and what is the impact of these compromises on the business? This report offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.