Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

8/7/2014
03:45 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Attack Harbors Malware In Images

'Lurk' click-fraud campaign now employing steganography.

BLACK HAT USA -- Las Vegas -- Steganography long has been a tool in the intelligence community and most recently terror groups, but a cyber crime gang has been spotted using the stealth technique of embedding information or code inside digital images.

A researcher at Dell SecureWorks investigating an attack in an incident response engagement at a customer site discovered that the malware involved--Lurk--had been spread via a phony digital image as part of a click-fraud campaign. Steganography typically is used in targeted attack scenarios, so the use of the method of hiding and slipping malware onto machines for click-fraud purposes is rare, says Brett Stone-Gross, a researcher with Dell SecureWorks' Counter Threat Unit.

The attackers have infected some 350,000 victims in less than a year's time, amassing a quarter of a million dollars in profit in just a few months, according to Dell SecureWorks.

Most intrusion detection and intrusion prevention products can't detect malware hidden with steganography, so the stealth method of spreading malicious code within an image is tough to catch, according to Stone-Gross. "This is something that's not very complex, but difficult to detect," he says.

Lurk was reported earlier this year by researcher Kafeine, which found the downloader malware spreading via iFrames on websites via an Adobe Flash exploit. Among the websites compromised in that campaign were eHow and Livestrong.

The attack requires the victim have a vulnerable version of Adobe Flash, triggering the exploit which then downloads Lurk. In the case of the steganography payload, the malware is downloaded as a plain white image, which contains an encrypted URL that downloads a second payload.

Researchers at Symantec three years ago spotted the cyber espionage gang behind Operation Shady RAT using steganography to hid commands controlling infected machines. Images of a pastoral waterside scene to a suggestive photo of a woman in a hat were used to mask commands ordering the infected machines to phone home to the command-and-control (C&C) server.

"In general, steganography is becoming a much more popular trend," Stone-Gross says. The KINS variant of Zeus, for instance, uses non-digital steganography file to append a configuration file or command to an image file, he says.

Digital steganography, which was used in the Lurk click-fraud campaign, is more difficult to detect. The attack campaign remains active.

Defending against steganography-borne malware is more about prevention: "Make sure you don't get infected in the first place. Basic techniques--make sure your software is updated," Stone-Gross says. The method of hiding and spreading malware will grow, he says.

A full technical analysis of the attack is here.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-20331
PUBLISHED: 2021-05-13
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when commands such as "saslStart", "saslContinue", "i...
CVE-2021-31215
PUBLISHED: 2021-05-13
SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.
CVE-2020-36197
PUBLISHED: 2021-05-13
An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security of the software by gaining privileges, reading sensitive information, executing commands, evading detection, etc. This ...
CVE-2020-36198
PUBLISHED: 2021-05-13
A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP...
CVE-2021-28799
PUBLISHED: 2021-05-13
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3...