Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile Security

10/31/2019
04:00 PM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

Chinese-Linked APT41 Can Read Your Texts

New malware family is designed to have the ability to monitor as well as save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft.

FireEye Mandiant says that it has recently discovereda new malware family being used by APT41 (a Chinese APT group) that is designed to have the ability to monitor as well as save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft. They say the malware, MESSAGETAP, was deployed as part of Chinese espionage efforts.

APT41 has previously been described by FireEye in a report as a dual cybercrime (finanacially motivated) and espionage operation.

The current operation was found during an August 2019 FireEye investigation at a telecommunications network provider within a cluster of Linux servers. This is an efficient location to place a data stealer because of the high amount of SMS traffic that goes through this part of the system.

Initially loaded by an installation script, MESSAGETAP is a 64-bit ELF data miner. Once installed, the malware checks for the existence of two files: keyword_parm.txt and parm.txt. It attempts to read the configuration files every 30 seconds. If either exist, the contents are read and XOR decoded.

The researchers say that, "The first file (parm.txt) is a file containing two lists:

      1) imsiMap: This list contains International Mobile Subscriber Identity (IMSI) numbers. IMSI numbers identify subscribers on a cellular network.

 

               2) phoneMap: The phoneMap list contains phone numbers.

The second file (keyword_parm.txt) is a list of keywords that is read into keywordVec."

Once loaded into memory, both files are deleted. Then, the serious eavesdropping begins.

It uses the libpcap library to listen to all traffic and parses network protocols, starting with Ethernet and IP layers. It continues parsing protocol layers including SCTP, SCCP and TCAP. Finally, the malware parses and extracts SMS message data from the network traffic.

FireEye says that the malware will search the SMS message contents for keywords found in the keywordVec list, compares the IMSI number with numbers from the imsiMap list, and checks the extracted phone numbers with the numbers in the phoneMap list. The presence of both the phone number and the IMSI number used together signifies a highly targeted attack. The keyword list was composed of terms that the Chinese would find interesting, such as the names of political \r\nleaders, military and intelligence organizations as well as political movements at odds with the Chinese government.

But more is going on here. FireEye found that the threat actor was interacting with call detail record (CDR) databases to query, save and steal records during this same intrusion. The CDR records corresponded to foreign high-ranking individuals of interest to the Chinese intelligence services.

It doesn't seem surprising that a nation-state threat actor would have this sort of interception capability. It is unusual to find such a detailed look at an operational tool as FireEye has provided. They see an evolving Chinese targeting trend focused on both upstream data and targeted surveillance. It is only prudent that due to tools like MESSAGETAP both users and organizations consider the risk of unencrypted data being intercepted several layers upstream in their cellular communication chain.

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/14/2020
Lock-Pickers Face an Uncertain Future Online
Seth Rosenblatt, Contributing Writer,  8/10/2020
Hacking It as a CISO: Advice for Security Leadership
Kelly Sheridan, Staff Editor, Dark Reading,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 New Cybersecurity Vulnerabilities That Could Put Your Enterprise at Risk
In this Dark Reading Tech Digest, we look at the ways security researchers and ethical hackers find critical vulnerabilities and offer insights into how you can fix them before attackers can exploit them.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17475
PUBLISHED: 2020-08-14
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
CVE-2020-0255
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10751. Reason: This candidate is a duplicate of CVE-2020-10751. Notes: All CVE users should reference CVE-2020-10751 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-14353
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-18270. Reason: This candidate is a duplicate of CVE-2017-18270. Notes: All CVE users should reference CVE-2017-18270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta...
CVE-2020-17464
PUBLISHED: 2020-08-14
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2020-17473
PUBLISHED: 2020-08-14
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.