Like many people, my office tends to be airports and wherever in the world I have traveled. The advent of connected devices, wearable tech and the Internet of Things enables me to be more productive and have more contact with colleagues and friends. This is a good thing.
But at the same time, these amazing advancements are also causing disruption in our lives and workplaces. We don’t always know who has use of or control over our sensitive personal and corporate information. And since new developments are always making their way into the workplace, it is critical that we understand attitudes and actions of consumers as well as the professionals and executives on the front lines of enterprise technology.
ISACA helps build this understanding with its annual IT Risk/Reward Barometer, and the 2014 survey results show some interesting trends with significant implications. For example, 68 percent of US consumers plan to use wearable tech or connected devices at work. But despite the surge in wearable tech at work, only 11 percent of enterprises have a policy that addresses it.
Enterprises need to be aggressively proactive here, and start educating staff on the risks and the opportunities of wearable tech. Devices such as smart watches and glasses collect and transmit information that provides great value. But if this information gets into the wrong hands or is mishandled, it can be used to damage a company’s reputation, financial position, compliance activities and even its existence.
According to the latest IT Risk/Reward Barometer, “increased security threats” and “data privacy issues” are two of the biggest challenges that ISACA members list regarding the Internet of Things.
But along with the inherent risk in the Internet of Things, enterprises are also reaping benefit, such as the 29 percent that have achieved greater accessibility to information and the 26 percent that have used it to improve services. Also 22 percent have gained efficiencies and improved employee productivity. With new technology there is always the need to balance risks and rewards—and there are plenty of both in the case of the Internet of Things.
To keep tabs on evolving perceptions and trends, ISACA has fielded the IT Risk/Reward Barometer for five years. This survey is unique in that it has two components—a consumer survey and an ISACA-member survey. Globally, more than 4,200 consumers and more than 1,600 ISACA members responded this year, giving us an excellent pool of responses.
Wearable tech, connected devices and other cool advancements in the Internet of Things are making their way into every aspect of our lives. The gates are open and the tide is flowing, and we encourage you to take an “embrace and educate” approach. Having an informed and alert customer/employee/stakeholder base is a key aspect of making connected devices work for you and your enterprise.
I invite you to review the full report, infographic and news announcement for the 2014 IT Risk/Reward Barometer. I need to take off now. My smart refrigerator just told my smart watch that I need to pick up some bread on the way home from the airport.
Robert E Stroud, CGEIT, CRISC
2014-2015 ISACA International President
Usually attributed to the ancient treatise The Art of War by Sun Tzu, the phrase “Know your enemy” is often repeated in military and security environments and is given as guidance to junior level staff in these environments. While it is good guidance, this article will explore why it is incomplete and why this is important. One reference gives the full quotation, rendered in modern Chinese script as “故曰:知彼知己,百戰不殆;不知彼而知己,一勝一負;不知彼,不知己,每戰必殆” complete with the English translation:
“So it is said that if you know your enemies and know yourself,
you can win a hundred battles without a single loss.
If you only know yourself, but not your opponent, you may win or may lose.
If you know neither yourself nor your enemy, you will always endanger yourself.”
The full quotation provides much fuller and richer guidance and it is important to consider the meaning and impact of the full text. Below I will examine each sentence from the English translation.
“If you know neither yourself nor your enemy, you will always endanger yourself.”
The third sentence reminds us that lack of knowledge is dangerous. If you do not know your own capabilities, structures, processes, strengths and weaknesses it is unlikely that you will be able to use your resources effectively, or be able to resist your own weaknesses being exploited. A lack of knowledge about your enemy could lead you into a false sense of security—or to overestimate the abilities of your enemy—perhaps leading you to direct defences where the attacker is weakest and the attack least likely to succeed even without your efforts. For example, you would not want to concentrate all your defences on a Windows exploit being run against a Linux server. In short, you are totally unprepared for the battle and you may well contribute to your own defeat by making incorrect decisions!
“If you only know yourself, but not your opponent, you may win or may lose.”
The second sentence reminds us that it is only slightly better to know your own strengths and weaknesses. While you will know what you have to work with, and how best to engage your resources, you will not be prepared for the actions of your opponent so it is unlikely that you will be able to effectively direct them to the best effect against the threat. Your opponent will be able to surprise you and you will thus battle to take the initiative. As you will be unlikely to be able to anticipate the actions of your enemy they will find it easier to exploit your weaknesses. Put another way, you will likely be ‘behind the game’ for much of the time and the enemy will dictate the battle.
“…know your enemies and know yourself…”
The first sentence brings this together and essentially advises that you must know yourself and your enemy. This allows you to predict the strategy and attacks of your enemy and counter them with your defences quickly and effectively. While doing this you should also be able to start active defences. For example, you can implement a honeypot to direct them away from your real assets. You may even be able to counter-attack, directing your strengths at the weak areas of your attacker. For example, you can initiate civil action against the ISP that your attacker is using to launch the attack. At the very least you will keep them guessing and they will have to divert resources from attacking you to try to predict or interpret your actions. At its most effective, this will allow you to deflect or counter most attacks quickly and effectively.
Many organisations expend time and effort conducting threat identification and analysis. This is important but only helps you understand your enemies. Technical vulnerability analysis is slightly better in that it helps you understand your weaknesses. It is equally important but less common for organisations to spend time studying themselves. Your own strengths, weaknesses and vulnerabilities contribute as much to the outcome of any battle as do those of your enemy—but you have far greater ability to know yourself—use the opportunity before an attacker does!
To help you start your journey of discovery, I have listed some recommended activities to help you “Know your enemy” and “Know yourself:”
Know your enemy
Threat identification and analysis
Future threats and trends intelligence gathering
Research hacking and attack tools
Install detection and warning systems (e.g., intrusion detection/prevention systems)
Consider implementing honeypots or honeynets
Know yourself
Conduct vulnerability scans and penetration tests.
Review and test incident process, including staff contact details.
Ensure that asset register and Configuration Management Data Base (CMDB) are current and complete.
Create baselines for normal conditions (e.g. network utilisation, normal traffic flows).
Review patching and anti-malware update process to identify any weaknesses.
Engage specialist incident management/forensic support (on retainer or pre-paid to ensure quick response when needed).
Richard Norman, CGEIT, CISA, CISM, CRISC
Head of Information Security, Risk and Compliance for the British Council
London, England
We recently published a new research paper on WireLurker, a family of malware targeting both Mac OS and iOS systems for the past six months.
Shortly after we released the above research paper, Jaime Blasco from AlienVault Labs notified us about Windows executable file that contains WireLurker’s command and control server address. After analyzing and investigating the sample, it is confirmed that it is an older version of WireLurker. Read the follow on post here.
If you love great cybersecurity books we hope you will get involved in the Cybersecurity Canon by writing a review of your favorite and submitting it for consideration. Rick Howard explains how.
Ask firewall administrators about their day-to-day challenges and sooner or later they will come around to a challenge that Matt Keil describes as policy chaos. Here, he explores bringing a semblance oforder to this policy chaos.
There are many ways to look at cloud computing and what it means for your business. Overall, cloud governance means discovery, control and safe enablement. In this post from Isabelle Dumont, learn tips on doing your security due diligence on cloud services.
We’re on the road with VMware and VMUG in the U.S. and Canada to discuss how you can strengthen your data center security without compromising application performance. Find an event near you to learn best practices for implementing advanced security services in a SDDC, to hear customer insights for deploying VMware NSX with micro-segmentation, and to get hands-on experience test-driving an integrated VMware-Palo Alto Networks solution.
We’re also on the road across North and South America with Citrix and CA for the next few weeks to talk about how enterprises can streamline virtualized data centers, radically simply network services for delivering critical applications and reduce complexity and cost, all without sacrificing performance and security. Join us at an event near you.
Here are upcoming events around the world that you should know about:
The Asprox/Kuluoz malware family has a special place in our hearts at Palo Alto Networks. This botnet-related Trojan malware has evolved from its 2007 roots into a simple and yet robust mass e-mail phishing threat that is the origin of a significant percentage of Internet spam today. This post further explores trends for this malware family, based on October 2014 data from ourWildFire platform.
Some Background
The modern Kuluoz is known for the following:
High distribution volume through geolocation-associated spam e-mail templates
Use of e-mail attachments and Web links that masquerade as document or media files
Distinct, default botnet node roles of spam generator for continued botnet propagation, downloader of additional malware and distributor of generalized commercial spam
Platform-specific malware delivery based on user agent detection
Figure 1 depicts October 2014 WildFire sessions (individual occurrences) that were flagged as Kuluoz, broken out by day.
Figure 1: WildFire-detected Kuluoz sessions, by day, for October 2014
An interesting pattern emerges for significant session count valleys spaced roughly seven days apart, which are followed by major peaks two to five days out. These valleys correspond with weekends, while the peaks occur mid-week. This makes sense in the context of the standard business workweek and the broad swath of enterprises included in Kuluoz targeting.
Figure 2 displays WildFire unique Kuluoz sample counts (based on SHA256 hash) for the same period.
Figure 2: Unique WildFire-detected Kuluoz samples, by day, for October 2014
This second figure matches the general valleys and peaks trend for total sessions detected by WildFire. Note that this figure does not represent new/never-seen-before sample detections, but instead represents all unique Kuluoz samples detected for a given day. Kuluoz employs low-effort but effective methods of altering binaries enough to evade detection by hash alone, which significantly increases unique sample counts when comparing standard binary hashes. Accordingly, the above figure demonstrates the cumulative effect and possible escalation in unique Kuluoz sample generation, a trend previously noted by FireEye in June.
Closer inspection of WildFire session delivery/receipt for Kuluoz reveals the expected leader: e-mail/webmail (Figure 3).
Figure 3: WildFire-detected Kuluoz delivery/receipt for October 2014
Most of the remaining sessions were delivered via the Web, which includes cloud and file sharing services. A relatively small number of Kuluoz sessions leveraged File Transfer Protocol (FTP). Finally, WildFire also received a number of Kuluoz samples through user submission.
Over 98% of WildFire-detected Kuluoz filenames for October 2014 employed one of the following six themes, ordered by prevalence:
Notice to Appear in Court
Delta Airline Ticketing
Purchase Order / Invoice / Shipping
Voicemail Message
Starbucks eGift
Pizza Hut Coupon
Conclusion
Kuluoz continues to thrive, employing various social engineering pressure tactics to successfully propagate and serve as a bridge for other malware families.
Thorough mitigation of this threat includes several layers:
User awareness: Awareness and training for users is a good idea to reduce the impact of any type of e-mail phishing. A number of Kuluoz variants require extra steps to be performed by a user (e.g., unzipping of a ZIP archive and then running a malicious binary). Encourage users to be wary of unexpected/unsolicited e-mails, especially those that employ any sort of pressure tactic and/or leverage the themes cited above.
Protocol monitoring and control: Visibility into the protocols used by Kuluoz for delivery and Command and Control (HTTP, SMTP, IMAP, FTP) with structured and clearly defined response actions (most of which can and should be automated) prevent or reduce associated impacts. Palo Alto Networks Next Generation Firewall solutions offer this level of granular application monitoring and control.
Automated analysis: Automation of static and dynamic analysis for unknown samples addresses the natural gap between the development of a variant for a threat and its coverage through signature-based technology. Anti-virus and other security control related signatures fall short. Solutions such as Palo Alto Networks WildFire platform allow for enterprises to identify new and emerging threats that remain unknown to other security controls in the environment.
Intelligence fusion: Leveraging actionable intelligence is a cornerstone of Computer Network Defense (CND) operations. Threats such as Kuluoz rely heavily on embedded initial Command and Control (C2) communications to fully realize the potential of its role(s) within the botnet. Up-to-date feeds on malicious domains, IPs, file signatures and hashes, as well as integration of intelligence gleaned from automated solutions in the environment, enable robust security solutions that empower network defenders.
Yesterday we published a whitepaper introducing WireLurker, the first malware attacking both non-jailbroken and jailbroken iOS devices from a Mac OS X system. Shortly after we released the paper, Jaime Blasco from AlienVault Labs notified us that he’d found a Windows executable file that contains WireLurker’s command and control server address. We analyzed and investigated the sample and have confirmed that it is an older version of WireLurker.
This variant is being distributed by a different Chinese source that is hosting 180 Windows executables and 67 Mac OS X applications, each of which contains a version of the WireLurker Trojan. The Windows variant opens a new vector for iOS users to be infected with WireLurker, but appears to have been less successful than its Mac OS X descendent.
Samples of this older variant display a user interface and are advertised as an installer for specific pirated iOS apps. Between March 13 and today these programs have been downloaded 65,213 times, with 97.7% of the downloads being the Windows version. Like the latest WireLurker, this variant tries to infect jail-broken iOS devices with the WireLurker iOS malware.
This version of the malware also installs the sfbase.dylib tweak to the iOS file system, which is an earlier version of the malicious iOS binary file mentioned in our earlier report. These samples also indicate that the creator of WireLurker may have a direct relationship with the Maiyadi App Store.
Palo Alto Networks has released protections for all versions of WireLuker in our Antivirus, WildFire, IPS, and URL Filtering products. We’ve updated our detection code in Github to detect the older Mac OS versions of the malware and plan to release a tool to detect the Windows variant.
Early Versions of WireLurker for Windows and OS X
A Different Source
Previously we knew the WireLurker was distributed through the Maiyadi App Store. However, the newly revealed samples were directly uploaded to Baidu YunPan (a public cloud storage service of Baidu) by user “ekangwen206” (Figure 1). When we investigated this source we found the user had uploaded 247 samples in total, of which 180 are Windows software and the other 67 are OS X applications. All OS X samples were uploaded on March 12 and all Windows samples on March 13, over a month before the Mayaidi App store infections.
We downloaded and confirmed that all of these files belong to a new variant of WireLurker and should be classified as Trojan malware.
Figure 1: Samples of WireLurker list in the Baidu cloud storage system
These samples are listed as “green” (e.g. good or clean) IPA installers for specific pirated iOS apps. Some of the named iOS apps are extremely popular, while some of the others are pre-installed iOS system apps, including the following:
Facebook
WhatsApp Messenger
Twitter
Instagram
Minecraft
Flappy Bird
Bible
GarageBand
Calculator
Keynote
iPhoto
Find My iPhone
iMovie
iBooks
Baidu YunPan provides statistics of views and downloads for every single file. Through this feature, we found that in the past eight months, the 247 samples were downloaded a total of 65,213 times. Also according to their statistics, 97.7% of the downloads were Windows samples, which is consistent with the market share of Windows in China.
File Information and Structures
Based on the file information in PE structure, all of the Windows samples of were created on March 13 on a Windows XP computer. Each Windows sample contains a malicious PE executable file, six normal DLL files and a manual TXT file.
Each PE executable file has two extra IPA files (iOS app’s installation bundle file) appended to them, shown in Figure 2. The first IPA file, named “apps.ipa”, is a malicious iOS application; the second one, named “third.ipa”, is the pirated iOS app advertised by the sample. These two IPA files will be dropped to “C:\Documents and Settings\<USER>\Local Settings\Temp\” directory after the installer is executed.
Figure 2: Two IPA files were appended to the PE executable file
OS X samples of this variant have a fixed bundle executable name “appinstaller”. The IPA files are packed in the Resources directory in the OS X applications: one is named “infoplistab” for “apps.ipa”; the other is “third.ipa”.
User Interaction
After users download the samples and run them on Windows or OS X, a GUI appears as Figure 3 and Figure 4. If iTunes isn’t installed on the Windows system, the malware guides users to an official site of Apple China to download and install it.
Figure 3: GUI of a Windows sample
Figure 4: GUI of a OS X sample
If iTunes is installed the user interface shows a message of waiting for iOS device connection. After the user connects their device to the computer, the device’s name will appear in the GUI and a “click to install” button becomes available.
Install iOS application and iOS malware
If the user runs the samples and clicks the installation button the pirated iOS application shown in the interface will be installed on the device, but only if the device is jailbroken. At the same time the program will secretly install the apps.ipa file.
During our analysis, we connected an iPhone 5s running iOS 7.1 (jailbroken) and a 3rd gen iPad running iOS 6 (jailbroken) to infected Windows 7 and Windows XP systems. When using the iPhone 5s/iOS 7.1, the installer crashed after clicking the button; with the iPad, the interface shows “installation is successful”, but we did not find any new icon in the iPad display. We believe this failure was caused by poor coding quality and incompatibility between the malware and the iOS device, but the malware code does attempt the installation.
Pirated iOS Apps
The pirated iOS apps that the malware attempts to install are cracked versions of legitimate iOS apps. Their code signatures and DRM protection were removed before the IPA files were appended to EXE files or packed into OS X applications.
For example, in Figure 5, we can see the pirated WhatsApp has cryptid value 0, which means DRM encryption by Apple was removed by the attacker, something that can be easily achieved through many publicly available automatic hacker tools.
Figure 5: Pirated iOS apps haven’t DRM protection
The iOS Malware
The iOS malware these samples attempt to install into iOS devices contains both sfbase.dylib and sfbase.plist files. In our previous report on WireLurker, we mentioned that sfbase.dylib is a MobileSubstrate tweak that steals the user’s contacts information and other private data and sends it to a C2 server.
Figure 6: The iOS malware contains code for ARM64
The main executable of this malware is named “apps”. It’s a Mach-O universal binary file that contains binary code for three different architectures and CPU types:
32-bit ARMv7
32-bit ARMv7s
64-bit ARM64
As far as we know, this is the first iOS malware that attacks the ARM64 architecture.
The main functionality of this malware is to copy sfbase.dylib and sfbase.plist in its Resources directory to specific locations to make them perform as a MobileSubstrate tweak, shown in Figure 7. Additionally, the malware will communicate with the C2 server “www.comeinbaby.com”, the same server used by the version of WireLurker we revealed yesterday.
Figure 7: The iOS malware copies sfbase.dylib to a specific location
The dropped sfbase.dylib has nearly identical code and functionalities as the sample we detailed in our previous report. However, the earlier version was listed as 4.0.0, 4.0.1 or 4.0.2. This sfbase.dylib is version 2.0.0 as shown by its [mydUtils getCurrentVersion] method.
Another difference in this older version is that it uses the following URL when checking for updated code (Figure 8):
Figure 8: Earlier version of sfbase.dylib check for update from Maiyadi
Note that, this domain name is that of the Maiyadi App Store which spread later versions of WireLurker. Later versions of WireLurker used the domain www[.]comeinbaby.com but accessed the exact same GET request path.
Similarly, when uploading the user’s contacts information and other private data, this version of sfbase.dylib uses this URL:
Based on our analysis of this earlier version of sfbase.dylib, we suspect that Maiyadi has a close relationship with the creator of WireLurker. Beyond the link to the command and control server we’ve found additional clues.
First, all OS X samples in this variant have a bundle identifier named “com.maiyadi.installer”, as well as a copyright information that contains a reference to Maiyadi (Figure 9).
Figure 9: Copyright information in the OS X malware
Second, in the malicious iOS app, we found a certificate that belongs to “li fei” which was issued by Apple on March 6th, 2014 (Figure 10).
Additionally, the name “li fei” exists in all Windows malware samples and sfbase.dylib in the following strings:
These two strings are automatically generated by Visual Studio on Windows and Xcode on OS X for debugging when the developer built appinstaller and sfbase.dylib.
Figure 10: Attacker’s certificate in the iOS malware
Solutions
Palo Alto Networks has updated our signatures for Antivirus, WildFire, IPS, and URL Filtering products to protect our customers by blocking associated malicious URLs and traffic patterns of all known versions of WireLurker.
We have also open sourced a project on Github to help everyone in detecting WireLurker on their desktop computers. That project is available here:
We’ve already updated our OS X script to cover this newly discovered variant and we’re planning to release another tool to help Windows users scan their computers for WireLurker.
Updates on the Threat from WireLurker
After we published the WireLurker report and related detection tool, some OS X users in China discovered that their Mac computers were infected by WireLurker and posted screenshots on Weibo (Chinese social network similar to Twitter), shown in Figure 11. One of the users contacted us and provided all detected samples on his Mac, which we identified as the newest known version of WireLurker (version C).
Figure 11: A Chinese victim reporting their Mac was infected by the WireLurker
As we were writing this blog, Apple also announced that they’ve “blocked the identified apps to prevent them from launching” and we noted that the command and control domain, www[.]comeinbaby.com no longer resolves to the command and control server IP.
Nick Arnott mentioned to us on Twitter that in iOS 8, the system no longer shows distribution profiles in the settings menu; users may need to use Xcode or the iPhone Configuration Utility to check or remove these abused enterprise distribution profiles.
Acknowledgements
Jaime Blasco from AlienVault first found a Windows variant of WireLurker and sent to us. Thank you Jaime!
We would like to thank Laura Hartmann, Zhi Xu, Wei Xu, Yanxin Zhang and Suli Xu at Palo Alto Networks for quickly processing this new variant and updating our products. It’s their work that ensures our products defend our customers from the latest threats.
We would also like to thank all people who have shared comments on the report and detection code or shared more information with us through Twitter, Github and email.