Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

5/5/2016
07:15 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

‘Stupid’ Locky Network Breached

For the second time in recent months, a white hat hacker appears to have broken into a C&C server for a major malware threat.

In the few brief months of its existence, the Locky ransomware sample already has established itself as the most prolific malware of its kind. But a recent development suggests there are holes in its operation.

Researchers from German security firm Avira this week reported seeing at least one instance where one of the malware's command-and-control servers was broken into by what appears to have been a white-hat hacker.

According to Avira, someone was able to access and infiltrate a Locky C&C server and replace the ransomware payload with what it described as a dummy file which when downloaded on a victim's computer displays the message "Stupid Locky" rather than encrypting its contents.

“I don’t believe that cybercriminals themselves would have initiated this operation because of the potential damage to their reputation and income stream,” Sven Carlson, team leader of the virus lab disinfection service at Avira, said in a blog post. “I also wouldn’t say that “Locky is dead” after this operation.”

But the infiltration of a Locky C&C server does suggest that the operation is perhaps not as airtight as its operators might want to think, he said.

Carlson pointed to another incident recently where an apparent white hat hacker broke into servers that were being used to distribute and control the Dridex banking Trojan. In that case, several of the malicious links being served up from the servers were replaced with up-to-date Web installers for Avira’s antivirus software.

“[The] examples of Dridex and now Locky … shows that even cybercriminals, masters of camouflage, are also vulnerable,” Carlson wrote.

Carlson told Dark Reading that such white-hat interventions serve as a warning to criminals. “A serious white hat wants to show you in a legal [manner that] ‘you are vulnerable,’” he says. “It’s just a signal to the world that nothing is secure--even [for] cybercriminals that act very professionally.”

Carlson says it is not clear how many servers are being used to distribute and manage Locky. It is possible that only one of its servers was compromised. “But we can’t exclude that [probably] other servers have been affected as well from the network.”

News of the break-in comes even as another security vendor report this week showed that Locky continues to proliferate around the world at an alarming rate.

Cloudmark’s Threat Report for the last quarter--based on data gathered from the company’s threat intelligence database--shows Locky has emerged as one of the biggest security threats. Locky was first spotted in February of this year.

“Encrypting a long list of extensions including .docx, .pptx, .xlsx, .jpeg, etc. to hold as ransom, Locky attempted to spread via malicious email attachments,” Cloudmark said in its report. “During March, Cloudmark detected actors shifting tactics from malicious macros within Microsoft Word documents to heavily obfuscated script files inside of .zip and .rar archives.”

Cloudmark principal threat researcher Greg Leah says the company’s research shows that the US has been hardest hit by Locky in terms of raw volume, accounting for nearly 36% of Locky-related messages. The presence of more IP and email address space, economic factors contributing to better return on investment, and the fact that most technology vendors have a strong customer presence in the country, are all reasons the US gets hit the most in such situations, he says.

Leah says one reason Locky has been able to proliferate so dramatically is its use of Windows Script Files, which are not normally seen in malware distribution. The operators of the Locky campaign appear to have boosted their distribution rates by using innocuous-looking .wsf file attachments containing Jscript code. “This has also been a very aggressive distribution with daily massive email spam campaigns at a very high volume,” he says.

Related stories:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Malicious USB Drive Hides Behind Gift Card Lure
Dark Reading Staff 3/27/2020
How Attackers Could Use Azure Apps to Sneak into Microsoft 365
Kelly Sheridan, Staff Editor, Dark Reading,  3/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "I feel safe, but I can't understand a word he's saying."
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7755
PUBLISHED: 2020-03-30
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
CVE-2020-10560
PUBLISHED: 2020-03-30
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the S...
CVE-2020-5527
PUBLISHED: 2020-03-30
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource co...
CVE-2020-5551
PUBLISHED: 2020-03-30
Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexus (LC, LS, NX, RC, RC F), TOYOTA CAMRY, and TOYOTA SIENNA manufactured in the re...
CVE-2020-10940
PUBLISHED: 2020-03-27
Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.