Prince of Persia – Game Over

Summary

Unit 42 published a blog at the beginning of May titled “Prince of Persia,” in which we described the discovery of a decade-long campaign using a formerly unknown malware family, Infy, that targeted government and industry interests worldwide.

Subsequent to the publishing of this article, through cooperation with the parties responsible for the C2 domains, Unit 42 researchers successfully gained control of multiple C2 domains. This disabled the attacker’s access to their victims in this campaign, provided further insight into the targets currently victimized in this operation, and enabled the notification of affected parties.

Post Publication

In the week following the publication of the original blog, we observed no unusual changes to the C2 infrastructure. Existing domains did move to new IP addresses, as we had previously seen periodically. Some new install domains were added, adhering to naming conventions of current domains (see appendix for new IOCs).

The attackers developed a new version (31), and we observed this deployed against a single Canadian target.

The file descriptions remained essentially the same (“CLMediaLibrary Dynamic Link Library V3”). Most importantly, there was no change to the encoding key (now using offset 20, and offset 11 for second pass against URL encoding) that we had observed being used for the entire decade-long campaign, and documented in our previous blog. From this we conclude that the attackers were unaware of our initial report.

Sinkhole

Through cooperation with the parties responsible for the C2 domains, we took control of all but one of them, transferring the A records to a server we controlled. This prevented the attackers from being able to subsequently make any further changes to the domain configurations, issue commands to victims, or capture any further data for the majority of victims. An analysis of connections after transfer suggests that the attackers may have used a third-party service to try to understand why they had suddenly lost almost all of their traffic. Figure 1 shows that tool, a geographic representation of victim-C2 traffic, with all but one at that time now communicating with our sinkhole server.

Figure 1 Graphical representation of victim traffic to C2

We have since transferred sinkhole control to Shadowserver, whom we thank for subsequent victim notification & remediation (https://www.shadowserver.org/wiki/pmwiki.php/Involve/GetReportsOnYourNetwork).

Victims

We were able to analyze victim C2 traffic to understand who were victims of the Infy campaign. We identified 456 malware agents installed on 326 victim systems, in 35 countries. Figure 2 shows a geographical breakdown of victim locations. We noted in our original blog the large amount of targeting of Iranian citizens in this campaign, we observed almost one-third of all victims to be Iranian. Also of note was the low overall volume of victims, compared to, for example, crimeware campaigns.

Figure 2 Geographic location of victims. Please note that New Zealand has been omitted from this map only because we observed no victim activity there.

Versions

In our original blog, we noted two distinct primary variants of the Infy malware. In addition to the original “Infy” variant, we also see the newer, more sophisticated, interactive, and fuller-featured “Infy M” variant deployed against apparently-higher-value targets. Overall, 93% of all victims were infected with Infy, and 60% with Infy “M” (Figure 3). Combined with the low total number of victims, this suggests a great deal of care given to each individual campaign target. The large number of victims with both variants may relate to their complimentary feature set, or represent an “upgrade” path on victims from the original variant infection, later adding the “M” variant as targets appeared more compelling to the attackers.

Figure 3 Breakdown of Infy vs. Infy “M” infections

For the Infy “M” variant, we note that the majority of targets are using the latest version (7.8), and that none are using the older 6.x versions at all (Figure 4). This suggests that these higher-value targets are paid much more attention, being kept up-to-date with the latest version.

In contrast, for the more basic original Infy variant, we note a full spectrum of versions installed (Figure 5), with many victims on older versions – including the original, decade-old V1 – suggesting much less concern is paid to these individual targets (note that we did observe a small number of the older 6.x versions but these do not announce their version when connecting).

Figure 4 Infy “M” Victim versions

Figure 5 Infy”Original” Victim versions

Game Over

Shortly after the takedown, as well as a new Infy version (31), we also observed the registration of multiple domains using a previously-seen pattern, against known campaign IP addresses. Almost every domain in the pattern-range box4035[.]net – box4090[.]net (138.201.0.134). These were not observed in any sample C2 lists however. Bestwebstat[.]com was sinkholed by another operator.

Some victims infected with Infy versions 15-24 still used the C2 server us1s2[.]strangled[.]net, which remained in the hands of the attacker. In early June the attackers used this C2 to issue instructions to download new Infy “M” version 8.0 from us1s2[.]strangled[.]net/bdc.tmp. This was the first time we had observed an Infy variant being directly updated to Infy “M”. This used camouflage name “Macromedia v4”, changed from “v3” seen in Infy v31. They also removed the voice recording capability in this version.

uvps1[.]cotbm[.]com was used for data exfiltration, previously at 138.201.47.150, after publishing of our original blog moving to 144.76.250.205. It was also hosting malware updates at /themes/u.php.

They also added a curious C2 entry “hxxp://box” (note: defanged for publishing). It’s unclear how this should function; possibly a compromised victim intranet device, or the attackers have modified the HOSTS file on the victim computer.

After the take-down, the attackers began to add server IP addresses as well as domain names to their malware C2 list. They also slightly modified their ZIP password from “Z8(2000_2001ul” to “Z8(2000_2001uIEr3”. Their new malware version added antivirus checks for Kaspersky Labs, Avast, and Trend Micro. The malware data capture now searches for file extensions:

.doc, .docx, .xls, .xlsx, .xlr, .pps, .ppt, .pptx, .mdb, .accdb, .db, .dbf, .sql, .jpg, .jpeg, .psd, .tif, .mp4, .3gp, .txt, .rtf, .odt, .htm, .html, .pdf, .wps, .contact, .csv, .nbu, .vcf, .pst, .zip, .rar, .7z, .zipx, .pgp, .tc, .vhd, .p12, .crt.pem,.key.pfx, .asc, .cer, .p7b, .sst, .doc, .docx, .xls, .xlsx, .xlr, .pps, .ppt, .pptx.

and folder locations:

:\$recycle.bin, :\documents and settings, :\msocache, :\program files, :\program files (x86), :\programdata, :\recovery, :\system volume information:\users, :\windows, :\boot, :\inetpub, :\i386.

The malware continued to use the identical decryption key seen over the entire history of this campaign.

Mid-June, through cooperation with the parties responsible for the C2 domains and law enforcement, we were able to get the remaining C2 domains null-routed and the directly-IP-addressed server disabled. This is the end of a decade-long campaign, though we naturally expect to see this actor back in some other guise before long.

Thanks to the Malware research team – Yaron Samuel, Artiom Radune, Mashav Sapir, Netanel Rimer – for assistance in the takedown.

Appendix 1 – Exfiltration Algorithm

The malware uses a different algorithm than that used for encrypting the malware strings to encrypt the exfiltration data, including:

  1. Keylogger data + language.
  2. Malware logs – installation time, DLL path and name, log path, number of downloads, number of successful/failed connections.
  3. Information about the victim computer: Time zone, list of drives and types, running processes, disk info.

First the malware adds 1 to all bytes, then an encryption key is initialized based on the victim computer name (the offset in the key is calculated by sum of the computer name letters %key length). Then the key is used to encrypt the data (see decrypt function). The encrypted data is then base64 encoded.

Exfiltration data decryption python code:

Appendix 2 –IoCs

Infy version 31: f07e85143e057ee565c25db2a9f36491102d4e526ffb02c83e580712ec00eb27

Infy “M” version 8.0: 583349B7A2385A1E8DE682A43351798CA113CBBB80686193ECF9A61E6942786A

5.9.94.34
138.201.0.134
138.201.47.150
144.76.250.205
138.201.47.158
138.201.47.153
us1s2[.]strangled[.]net
uvps1[.]cotbm[.]com
gstat[.]strangled[.]net
secup[.]soon[.]it
p208[.]ige[.]es
lu[.]ige[.]es
updateserver1[.]com
updateserver3[.]com
updatebox4[.]com
bestupdateserver[.]com
bestupdateserver2[.]com
bestbox3[.]com
safehostline[.]com
youripinfo[.]com
bestupser[.]awardspace[.]info
box4035[.]net
box4036[.]net
box4037[.]net
box4038[.]net
box4039[.]net
box4040[.]net
box4041[.]net
box4042[.]net
box4043[.]net
box4044[.]net
box4045[.]net
box4046[.]net
box4047[.]net
box4048[.]net
box4049[.]net
box4050[.]net
box4051[.]net
box4052[.]net
box4053[.]net
box4054[.]net
box4055[.]net
box4056[.]net
box4057[.]net
box4058[.]net
box4059[.]net
box4060[.]net
box4061[.]net
box4062[.]net
box4063[.]net
box4064[.]net
box4065[.]net
box4066[.]net
box4067[.]net
box4068[.]net
box4069[.]net
box4070[.]net
box4071[.]net
box4072[.]net
box4075[.]net
box4078[.]net
box4079[.]net
box4080[.]net
box4081[.]net
box4082[.]net
box4083[.]net
box4084[.]net
box4085[.]net
box4086[.]net
box4087[.]net
box4088[.]net
box4089[.]net
box4090[.]net

, and

[Palo Alto Networks Research Center]

William Saito: Industry 4.0, IoT and Security By Design

During the World Economic Forum’s Annual Meeting of the New Champions, taking place this week in Tianjin, China, about 1,500 policy makers and experts from more than 90 countries are gathering to discuss Industry 4.0.

William Saito, Vice Chairman, Japan, for Palo Alto Networks, explains in his latest column for the World Economic Forum that the potential for Industry 4.0 — specifically how technologies such as cloud computing and big data join with the Internet of Things and algorithms from machine learning to govern new processes — requires preventive security by design, not as an add-on. 

“It’s worth remembering,” notes William, “that cloud services, big data, IoT, block chain, AI, fin tech and all the other buzzwords are possible not only because of the Internet, but because of security.”

Read the full article for William’s thoughts and check out more of his regular contributions to theWorld Economic Forum and Forbes.

[Palo Alto Networks Research Center]

June’s COBIT 5 Poster Details Process Capability

The June edition of the monthly COBIT 5 poster series features a graphic summary of the six levels of process capability and their related attributes. These capability levels attributes are aligned with ISO/IEC 15504.

The poster charts the six levels of capability that a process can achieve, from an incomplete process that is not implemented or fails, to an optimized process.

Each capability level can only be achieved after the previous level has been fully met. For example, before assessing a process as an established process (process capability level 3) attributes of a managed process (level 2) must first be fully achieved.

Achieving level 1 differs from higher capability levels in that it is at least partially achieved once there is evidence that the process simply exists and has only one process capability attribute to assess. Each higher level adds different attributes so enterprises can choose a target level based on cost-benefit and feasibility. Rarely will enterprises choose the highest process level (level 5), which is a predictable process that is continuously improved to meet current and projected business goals.

The six process capability levels include:

  • 0 Incomplete
  • 1 Performed
  • 2 Managed
  • 3 Established
  • 4 Predictable
  • 5 Optimizing

Previous COBIT 5 posters of the month include:

May 2016: COBIT 5—Process Reference Model
April 2016: COBIT 5—Governance and Management Key Areas
March 2016: COBIT 5—Enterprise Enablers
February 2016: Roles, Activities and Relationships
January 2016: Goals Cascade
December 2015: Governance Objective: Value Creation
November 2015: COBIT 5 Principles

For more information on COBIT 5 click here, and to see/download all of the COBIT 5 posters, click here .

Peter Tessin, Technical Research Manager, ISACA

[ISACA Now Blog]

In Cybersecurity, Professional Practice Transcends Politics

As Europe absorbs the news that the United Kingdom (UK) has voted to leave the European Union (EU), questions inevitably rise around the impact this decision will have on our profession. During the campaign running up to the vote, I fielded several queries from journalists on the relevance of pending European regulation, and whether the UK would undermine its ability to face cyber threat if voters chose to leave.

In or out, I believed, our professional challenges would be unaffected by the result. Earlier this month, as the referendum debates headed into the final weeks, these thoughts were reinforced as London played host to Infosecurity Europe, our region’s largest information security event. This year, the show attracted nearly 14,000 delegates from 80 different countries.

On the (ISC)2 stand, we heard from (ISC)2 members and other delegates alike that it seemed particularly vibrant this year, with many of the largest stands on the exhibition floor having been the start-ups featured in the innovators section not so long ago. The sessions reflected very current concerns that were being debated around the world. The many sessions that were focussed on European issues were very well attended, including one on the last day presented by the president of our (ISC)2 Germany Chapter Rainer Rehm.

Now that the referendum results are in, I believe the Brexit vote will serve to highlight our profession’s value as that vibrant international community. Our challenges and (therefore) inherent instincts have motivated levels of co-operation that already transcend national boundaries and politics. There is no reason to believe that this will come to an end, or even be significantly interrupted by the UK’s political decision to leave the European Union.

Practicing professionals in the UK and across Europe have at least two years ahead of them to understand the practicalities that will affect their day-to-day job. Also, there’s a good chance that quite a lot of what was anticipated over this time will not change. The need in the UK to comply with the EU’s General Data Protection Regulation (GDPR), for example, will remain the same, as we can expect UK businesses to continue handling EU citizen data. The march of technical innovation will continue to shape the challenges we face on the front lines. Indeed, we all understand that threats and attacks are international. We as a community have evolved to become incredibly influential in raising the profile of key developments and risks, the shaping of standards, and organizing events and forums that bring this community together at national, regional and international levels.

Looking again to Infosecurity Europe, we have observed that this show has become an important forum for our members to meet. We know of nearly 1,000 who made themselves known at registration and anticipate there were many, many more.

Day two referred to as ‘Member Day’ by the (ISC)2 EMEA team played host to a meeting of chapter leaders and our EMEA Advisory Council members, who had travelled from Switzerland, Algeria, Kuwait, France, Croatia, Germany and various corners of the UK. The discussions covered our members’ readiness to manage GDPR, gaps in the existing security discussion around IoT and proposals to enhance our ability to share experience across our region’s network of 32 chapters. Our member reception later that day featured an interactive Town Hall discussion with about 200 attendees where our CEO David Shearer discussed new tools, programmes and benefits to help our global membership develop their skills, elevate the discussions we have with business, and serve as ambassadors to society.

Information security is appreciated as an international concern. The way we behave and the work we do as a profession already ensures that the standards and practices required to face these concerns account for differences in markets and regulatory expectations. I’m confident that, as a community, information security professionals right across Europe will continue to work together.

–Dr. Adrian Davis, CISSP, managing director, EMEA, (ISC)²

[(ISC)² Blog]

Do ISACA Certifications Benefit Employers, Professionals?

ISACA’s website states that “membership sets you apart from other IT professionals by signifying that you are:

  1. Dedicated to best practices and successful results
  2. Committed to professional growth and advancement
  3. Helping to advance your profession
  4. A seeker of professional knowledge and a problem solver
  5. Serious about continuing education
  6. Connected with a highly regarded organization
  7. Part of a global network of peers”I wanted to see if this was true in the UK.

My reason is that CISA and CISM are widely known—more so than ISACA itself. Many organizations know COBIT and many additional firms use the framework but may not know it comes from ISACA. CGEIT and CRISC are not quite as well known, in comparison, but as a professional organization we have an opportunity to promote these as a substantial solution to better manage cyber-security threats, which have finally hit the board agenda.

ISACA certifications provide a virtuous circle. By getting the governance framework right, it is easier to identify the risks to implement solutions, many based on security controls, and provide value-added assurance from executives and auditors.

The ISACA London Chapter works with Hays, a recruiting firm, to connect professionals and employers. Their UK IT job websiteshows CISA, CISM and ITIL are ‘must haves.’

This means ISACA reason #3 is true, but do employers recognize the rest?

I asked Hays staff what they thought. They see the expectation for IT audit and security employees at all levels to possess relevant certification. The weighting of certifications depends on several factors:

  • Internal audit divisions expect CISA or CISM of their IT auditors to ensure teams have sufficient IT-related knowledge to hold useful conversations with auditees.
  • More stress is placed on certifications if the team is lean, but…
  • … less if the role is senior management, where others skills and experiences come into play.
  • The certifications requested often reflect those held by the hiring manager.
  • CRISC is becoming important for second line of defense roles, but…
  • CSX is not as well known yet since it is early days

It also seems that, in the UK, salaries are related to the role, not the certification. Certifications provide opportunities to obtain roles rather than salary increases. A variation on this is that a strong candidate for a junior role, without certification, may be encouraged to study for one through company sponsorship in lieu of a lower salary. A lapsed certification counts for nothing and is seen as not being committed to the industry. It is worse than not having had it.

An interesting UK trend is an increasing demand for focused, technical knowledge mixed with interpersonal and business knowledge. A range of certifications help here, as IT auditors grapple with complex security controls, for example, or go beyond efficiency in ‘value-for-money’ reviews, such as safety, quality and relevance. In banking, this trend happens at a junior level because the regulatory environment demands assurance and compliance. Outside that industry, a mix of management, professional and business skills happens at a more senior level.

COBIT is well-loved but sometimes treated as a teddy bear—there when you need it and tragic if lost. Thus, the explicit need to show COBIT qualifications is rarely part of the job spec. But it turns out that COBIT is the de facto standard, so deeply entrenched in corporate assurance that there is no need to shout about it. That means experienced IT auditors are expected to be well-versed in COBIT.

Globally, recognition and employer demand for globally recognized certifications seems greater than in the UK. This may be cultural or due to regulatory requirements. In some cases, if opportunities to gain relevant experience are limited, certification is proof of knowledge not obtainable elsewhere.
All well and good, but this is a recruiter’s view. I wanted the employer’s view, which I found at a CISO meeting in London. They said that having no certifications would not automatically exclude a candidate. The choice of certification, and how many, came down to the individual, their aspirations and complementary skillsets.

Slightly contradictory was the expectation that staff with four years’ experience have certifications. They expected less experienced staff not to have them – no time or experience to obtain them – but expected junior staff to study for certifications. More senior roles required broader and/or deeper skillsets. For management, MBAs and professional management programs can help broaden skillsets. The issue was those remaining in technical roles – what professional qualifications were there outside a master’s or doctorate? There seemed to be a gap in the ‘professional training’ market for experienced staff.

The CISOs said the increasing integration between IT and non-IT activity has narrowed so most IT professionals need to understand business and develop interpersonal and communication skills. Knowing how the business runs—being able to have conversations between IT and non-IT—help get IT right.

It comes down to keeping up to date with trends. Employers look for knowledgeable, experienced professionals who keep abreast of daily organizational IT changes and challenges. Continuing professional education, which is demanded of certification holders, provides comfort to employers. Their staff not only stays up to date, but also have many resources to apply within the organization. ISACA membership benefits support this. We should take full advantage of them.

Editor’s note:  As part of ISACA’s celebration of Women in Technology Month this June ISACA is seeking women in tech to guest blog on the subject of their choice. If you are interested in learning more, please contact news@isaca.org.

Sue Milton, Managing Director, SSM Governance Associates, and Past President, ISACA London Chapter

[ISACA Now Blog]

English
Exit mobile version