Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile Security

10/31/2019
04:00 PM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

Chinese-Linked APT41 Can Read Your Texts

New malware family is designed to have the ability to monitor as well as save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft.

FireEye Mandiant says that it has recently discovereda new malware family being used by APT41 (a Chinese APT group) that is designed to have the ability to monitor as well as save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft. They say the malware, MESSAGETAP, was deployed as part of Chinese espionage efforts.

APT41 has previously been described by FireEye in a report as a dual cybercrime (finanacially motivated) and espionage operation.

The current operation was found during an August 2019 FireEye investigation at a telecommunications network provider within a cluster of Linux servers. This is an efficient location to place a data stealer because of the high amount of SMS traffic that goes through this part of the system.

Initially loaded by an installation script, MESSAGETAP is a 64-bit ELF data miner. Once installed, the malware checks for the existence of two files: keyword_parm.txt and parm.txt. It attempts to read the configuration files every 30 seconds. If either exist, the contents are read and XOR decoded.

The researchers say that, "The first file (parm.txt) is a file containing two lists:

      1) imsiMap: This list contains International Mobile Subscriber Identity (IMSI) numbers. IMSI numbers identify subscribers on a cellular network.

 

               2) phoneMap: The phoneMap list contains phone numbers.

The second file (keyword_parm.txt) is a list of keywords that is read into keywordVec."

Once loaded into memory, both files are deleted. Then, the serious eavesdropping begins.

It uses the libpcap library to listen to all traffic and parses network protocols, starting with Ethernet and IP layers. It continues parsing protocol layers including SCTP, SCCP and TCAP. Finally, the malware parses and extracts SMS message data from the network traffic.

FireEye says that the malware will search the SMS message contents for keywords found in the keywordVec list, compares the IMSI number with numbers from the imsiMap list, and checks the extracted phone numbers with the numbers in the phoneMap list. The presence of both the phone number and the IMSI number used together signifies a highly targeted attack. The keyword list was composed of terms that the Chinese would find interesting, such as the names of political \r\nleaders, military and intelligence organizations as well as political movements at odds with the Chinese government.

But more is going on here. FireEye found that the threat actor was interacting with call detail record (CDR) databases to query, save and steal records during this same intrusion. The CDR records corresponded to foreign high-ranking individuals of interest to the Chinese intelligence services.

It doesn't seem surprising that a nation-state threat actor would have this sort of interception capability. It is unusual to find such a detailed look at an operational tool as FireEye has provided. They see an evolving Chinese targeting trend focused on both upstream data and targeted surveillance. It is only prudent that due to tools like MESSAGETAP both users and organizations consider the risk of unencrypted data being intercepted several layers upstream in their cellular communication chain.

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-22864
PUBLISHED: 2021-10-26
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.
CVE-2021-23877
PUBLISHED: 2021-10-26
Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.
CVE-2021-41866
PUBLISHED: 2021-10-26
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
CVE-2019-3556
PUBLISHED: 2021-10-26
HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which specifies where o...
CVE-2021-35499
PUBLISHED: 2021-10-26
The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim...