Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

7/11/2014
02:38 PM
50%
50%

Attack Campaign Targets Facebook, Dropbox User Credentials

The goal of the attackers is not fully clear but the credential theft could set up sophisticated targeted attackers.

Researchers at security firm Cyphort have uncovered a five-year-old attack campaign that has quietly gone about the business of stealing user credentials for Dropbox, Facebook, and other applications unnoticed until now.

At this point, it does not appear the attackers are targeting specific organizations or industries, since their tentacles seem to have reached organizations ranging from energy companies to charities. According to Cyphort's McEnroe Navaraj, the intent of the data collection is unknown, but there is no shortage of ways for the credentials to be turned to the attackers' advantage.

The so-called NightHunter attack uses SMTP email for exfiltrating data rather than "more common CnC (command and control) mechanisms that use web protocols," Navaraj said in a blog post:

This could be to simply "hide (and steal data) in the plain sight" as organizations beef up web anomaly detection for dealing with advanced attacks.

It involves several different malware keyloggers, including Predator Pain, Limitless, and Spyrex. The unifying feature is that they all use SMTP (email) for data exfiltration. Email to social networking is like snail-mail is to email … it is outdated and often overlooked, so it can be a more stealthy way of data theft. So we called it NightHunter.

According to Cyphort, the company received a sample through a phishing email. The sample is a .net binary that steals users' credentials and sends them to a remote email server when executed. When researchers examined the sample, they also uncovered other similar samples in the wild as well. Navaraj said in the post:

These samples are delivered mostly through phishing emails. These emails are sent with DOC/ZIP/RAR attachments. You can get infected by opening a malicious document with scripting enabled. Most of the phishing emails are targeted towards personnel in finance/sales/HR departments. Sometimes actors may act as goods resale agents. We have seen cases where it was bundled with fake IDM/7zip installers. Most of these samples used keylogger tools to sniff data from the victim.

Cyphort co-founder Fengmin Gong notes that some of the servers used by the attackers are either private or have access protections that prevented the firm from looking into the upload account, so the actual number of infected machines is higher than the 1,800 compromised machines the company is aware of.

"This attack is ongoing and we continue to monitor it," Gong tells Dark Reading. "The attackers are very aggressive in their data-collection methodology, as well as the intervals of data exfiltration. Given the systematic nature of the actors behind this campaign, we are speculating that they are still in a 'reconnaissance stage' targeting credentials of high-level executives, but at this point it is impossible to speculate on their endgame with any degree of certainty."

Still, he says he believes the attackers may be using big-data techniques to mine the stolen credentials, which would give them the ability to leverage the credentials for targeted attacks. The situation also underscores just how effective phishing still is at hooking victims, he says. The attackers used messages disguised as emails about a variety of topics, with subject lines such as "Purchase Order" and "Inquiry." In addition to the applications mentioned above, the attackers are also targeting credentials for Skype, Amazon, LinkedIn, Google, Yahoo, Hotmail, Rediff, and banks.

Navaraj blogged:

NightHunter is one the more unique campaigns we have researched at Cyphort due to the footprint and complex data collection models it exhibits, furthermore the use of low-signal evasion it is leveraging such as webmail for data exfiltration points to much larger end-goal.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/14/2014 | 10:00:46 AM
Re: next phase
I agree Robert
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/14/2014 | 9:50:29 AM
Re: next phase
Based on the longevity and the fact this campaign has avoided detection until now I wouldn't be surprised if the data collected has already been used in surgical breaches.
Denise J. Wasson
0%
100%
Denise J. Wasson,
User Rank: Apprentice
7/13/2014 | 12:29:25 PM
Re: next phase
There are many rumors about attack Campaign towrds Facebook, Dropbox users credentials, although there is no evidence of stolen data and the other vital signs of accessing od a theif into that platform. The job resume may help to learn more abouth the good and professional resume makimg. 
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/13/2014 | 4:46:21 AM
next phase
Despite there is no evidence of targeted attacks using the stolen data, the most worrying aspect of such operation is the possibility that collected information will be managed with big data techniques to conduct surgical offensives with serious consequences.

Another concerning aspect of the specific campaign is that it goes undetected since 2009 ... and this is just the tip of the iceberg.

Regards

Pierluigi 
AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14540
PUBLISHED: 2019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
CVE-2019-16332
PUBLISHED: 2019-09-15
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
CVE-2019-16333
PUBLISHED: 2019-09-15
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
CVE-2019-16334
PUBLISHED: 2019-09-15
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.
CVE-2019-16335
PUBLISHED: 2019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.