Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

05:22 PM
Connect Directly

Stealthy Fobber Malware Takes Anti-Analysis To New Heights

Built off the Tinba banking Trojan and distributed through the elusive HanJuan exploit kit, Fobber info-stealer defies researchers with layers upon layers of encryption.

A stealthy new info-stealing browser injection malware aims to make security researchers' job very difficult. Fobber evades detection and defies anaylsis by sliding from one program to another, using randomly generated filenames, encrypting command-and-control communications with a custom algorithm, and encrypting individual pieces of code within the payload, so that each function must be separately, painstakingly decrypted before it can be run.

Researchers at Malwarebytes discovered Fobber, and Fox-IT researchers have confirmed that it is based off of the Tinba banking Trojan. So far, Malwarebytes has not witnessed Fobber stealing banking credentials, but that may just be a matter of time, according to Malwarebytes senior security researcher Jerome Segura.

"I think they're testing the waters," he says. All infections, thusfar, have been in the Netherlands, so Segura believes the Fobber authors are still testing out the tool before rolling out operations on a larger scale.

Malwarebytes found Fobber by accident when they stumbled across activity by the elusive HanJuan exploit kit. Opportunities to study HanJuan are rare, because it usually takes great pains to hide itself. Malwarebytes simply referred to it as the "Unknown exploit kit" when they first wrote about it in August 2014.

"It's a very discreet exploit kit," says Segura, "so that's what caught our attention."

Considering its usual discretion, the researchers discovered HanJuan acting in a way that seemed out of character. It was being hosted on a legitimate Dutch website that had been compromised, and was being distributed through a malvertising campaign. An embedded ad within the Adf.ly URL shortener service directed victims to the compromised site. 

Once researchers had a look at the payload HanJuan was delivering, they saw "we have something new on our hands," says Segura. "It's very well encrypted. A lot of attention to detail in there."

Written for both Flash and Windows Explorer, Fobber uses a memory stack pivoting exploit. As Segura wrote in a blog post "Unlike a normal Windows program, Fobber makes it a habit to 'hop' between different programs." Fobber.exe itself will eventually terminate, and the malware execution will continue in Verify Class ID, until that terminates and picks up again in Windows Explorer, until that terminates and picks up again in a web browser.

Beginning with the Verify Class ID process, Fobber really frustrates any security researcher's attempts to analyze it. The code for each function must be decrypted before it can be executed; then it re-encrypts itself after completion.

It also encrypts all communication with the command-and-control server, using a custom algorithm. According to Segura's blog "Content sent by the server is signed by its RSA1 key (to prevent botnet hijacking) while the Fobber code has the public key embedded within, notifying the signature before processing the content."

The malware then performs browser injection (it works on Internet Explorer, Google Chrome, and Mozilla Firefox), hooks into certain functions (InternetCloseHandle and HttpSendRequest in IE), and waits to see when interesting credentials are being requested.

Fobber could then act like a man-in-the-middle and lift those credentials, and then use them for a variety of attacks -- including fraudulent banking transactions that would appear to the bank to be completely legitimate requests coming made from a customer's own machine with their valid credentials.

All of these techniques make it difficult for security companies to discover malware, put a name to it, and develop effective countermeasures.

"If you don't make the headlines," says Segura, "you have less scrutiny, and you can keep using" the tool for longer.

Malwarebytes has passed on its information about Fobber, HanJuan, the malvertising campaign and the compromised website to Dutch law enforcement.   

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Zero Trust doesn't have to break your budget!
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-06-16
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the han...
PUBLISHED: 2021-06-16
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and filesystem contain hard-...
PUBLISHED: 2021-06-16
Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This...
PUBLISHED: 2021-06-16
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within th...
PUBLISHED: 2021-06-16
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).