Orcus – Birth of an unusual plugin builder RAT

Unit 42 has been tracking a new Remote Access Trojan (RAT) being sold for $40 USD since April 2016, known as “Orcus”. Though Orcus has all the typical features of RAT malware, it allows users to build custom plugins and also has a modular architecture for better management and scalability. The objective of this blog is to highlight some of the capabilities of this new RAT family and the impact seen so far.

Background

Before we discuss the details of this RAT family, let’s discuss how Orcus became a commercially sold RAT. Around October 2015, the developer of Orcus, going with the alias of “Sorzus”, posted a thread on a hacker forum about a RAT he was developing, soliciting feedback on how it could be published. The developer had then named the tool as “Schnorchel”, German for “Snorkel”.

Figure 1 Sorzus discusses publishing Orcus

The figure below shows the early versions of Orcus when it was being developed. It is interesting to see that the developer details mentioned on the earlier version indicates “Vincent (Alkalinee)”, and we are also aware that ‘Alkalinee’ was the alias which was being used by the developer before taking the new alias of ‘Sorzus’. (This also suggests that the real name of the Orcus developer may be ‘Vincent’.)

Figure 2 Early version of Orcus which was known as “Schnorchel”

The developer had shared intentions to publish the RAT for free and make it open-source. However, some of the users in the forum responded, advising to make it commercial instead of sharing it for free or making it open source, citing that the source code would eventually be used by others to repackage and sell it as a new RAT. One forum user, alias “Armada”, offered to assist “Sorzus” on helping out with publishing the tool and apparently became Sorzus’ eventual partner.

“Sorzus” and “Armada” are believed to be the two main individuals currently managing the sales and development of Orcus. Brian Krebs published a blog a few weeks ago disclosing details of the individual who has been supposedly known to be the person behind Orcus. Our analysis suggests that ‘Sorzus’ is the main developer of the RAT and ‘Armada’ is mostly responsible for sales and support of the tool.

Architecture

Orcus is developed using C# with the Windows administration/controller component developed using WPS (Windows Presentation Foundation), which is used to render user interfaces in Windows based systems. Orcus has three main components to its architecture: Orcus controller, Orcus Server and the trojan binary which is deployed on a victim machine. The delivery vectors vary, ranging from a spear phishing attack using the malware binary with the email, having a hyperlink with a download link to the Orcus malware binary, or even using drive-by download methods.

In most RAT malware, once a victim has been infected, the malware connects back to the admin panel of the attacker to send data and provide control to the infected machine. However, if a victim machine is infected with an Orcus RAT, it connects back to the Orcus server which does not have the admin panel on it. Orcus has a separate component for the admin panel (Orcus controller) which enables control of all infected machines from the Orcus controller. This set up offers multiple benefits to the cyber criminals using Orcus. For example, they are able to share access to victim machines by accessing a single Orcus server which would enable a group of cyber criminals working together to better manage their infected victim networks and also allow scalability of their Orcus network by deploying multiple ‘Orcus servers’.

Figure 3 Orcus Architecture

The developer not only has a controller build for Windows, but also created an Android app for the admin controller to control the infected machines using an Android device. An Android app for the controller/administration component is also available from Google Play.

Figure 4 Orcus administration component for Android platform

Unique Features

Below are some Orcus features that can enable full control of a victim machine:

  • Keylogger
  • Screengrabs
  • Remote code execution
  • Webcam monitor
  • Disable webcam light
  • Microphone recorder
  • Remote administration
  • Password stealers
  • Denial of Service
  • VM Detection
  • InfoStealer
  • HVNC
  • Reverse Proxy
  • Registry explorer/editor
  • Real Time Scripting
  • Advanced Plugin System

Orcus has many common features of a RAT, however the features which are unique and stand out the most is the ‘Plugin System’ and ‘Real time scripting’. The plugin feature allows users of Orcus to build their own plugins or download plugins which have been developed by the author. If a user has basic knowledge on one of the supported programming languages, which are C#, VB.Net or C++, that user can easily extend and write plugins to build on to the current capabilities of Orcus. The author also provides a developer package to create the plugins with an IDE (Integrated Development Environment), which is an application used by programmers to develop programs.

The Orcus sellers also provide very well documented tutorials to create plugins, and also maintain a Github page which has a few sample plugins created. Orcus allows seven different types of plugins to be created. Figure 5 shows the current list of plugin types that can be built.

Figure 5 Types of plugins

The libraries are well documented and are currently being hosted on ‘sharpdox.de’. Sharpdox is a tool to create C# code documentations and can be hosted on ‘sharpdox.de’. Figure 6 shows an example of the methods or functions which are available to the Orcus plugin’s ‘ClientController’ class.

Figure 6 Example of a plugin library documentation

The Real Time scripting feature allows Orcus users to write and execute code (C#, VB.Net) in real time while remotely managing the compromised system.

Figure 7 Real time scripting feature on Orcus

Analysis: Orcus Protections

From an incident responder or threat analyst’s perspective, it is important to understand the type of anti-analysis protections a malware family employs so one is able to build an environment to successfully analyze the malware. This blog is not intended to discuss reverse-engineering the RAT in detail; however, it is interesting to see some of the anti-analysis features which Orcus employs to avoid being detected in a standard analysis environment.

We reverse-engineered one of the Orcus samples seen on a recent attack to check and verify some of the configured features. Given Orcus is developed in C# / VB.Net, we can easily peek into the code using a .NET disassembler. If an Orcus user enables the VMDetection feature while building the malware binary, the malware would check if the malware is running within a virtual machine environment. The virtual machines that Orcus detects are ParallelsDesktop, VirtualBox, VirtualPC and VMWare. The figure below shows the code excerpt for detecting the presence of virtual machines.

Figure 8 Virtual Machine detection in Orcus

Orcus also checks for processes of network monitoring tools like Netmon, TCPView and Wireshark as shown in the figure below.

Figure 9 Detection for network analysis tools

Impact

Figure 10 below shows the trending graph seen in Autofocus on the number of malware download sessions for Orcus. Given the feature rich toolset and the scalability Orcus provides, it is not a surprise that the usage and acceptance of the Orcus RAT is growing among cyber criminals since being first sold early this year. Given the increasing popularity of Orcus, it is likely that we will see more cyber crime campaigns where the RAT of choice is Orcus.

Figure 10 Autofocus graph of Orcus download sessions over time

Conclusion

The individuals behind Orcus are selling the RAT by advertising it as a “Remote Administration Tool” under a supposedly registered business and claiming that this tool is only designed for legitimate business use. However, looking at the feature capabilities, architecture of the tool, and the publishing and selling of the tool in hacker forums, it is clear that Orcus is a malicious tool, and that its target customer is cyber criminals. It’s not uncommon but this is an interesting case where a developer with an initial intention to release the code for free or open source, ends up in collaborating with an individual in a hacker forum who has prior experience in building and selling similar malicious tools, and creates a commercial RAT which has started to gain wide acceptance among cyber criminals with its unique feature set and flexible architecture.

Palo Alto Networks WildFire correctly identifies Orcus as malicious and AutoFocus customers can track this threat using the Orcus tag.

IOCs:

The current list of hashes for Orcus samples can be found on the Unit 42 github page here.

[Palo Alto Networks Research Center]

 

Japanese Election Results in Positive Strides for Cybersecurity and Tokyo 2020 Summer Olympics

The two Japanese ruling parties, the Liberal Democratic Party (LDP) and Komeito, won a majority of the 121 contested seats in the election of the Upper House on July 10. The coalition party now has 145 out of 242 total seats. The outcome of the election guarantees the continuation of a stable Abe administration—which will have positive results for the recent momentum in Japan on cybersecurity.

Since December 2012, when Prime Minister Shinzō Abe took office, his administration has been active in expanding bilateral and multilateral cybersecurity cooperation on capacity-building, cyberthreat intelligence sharing, and the protection of critical infrastructure. The Japanese government started cyber dialogues with the U.S. in May 2013; the European Union in October 2014; Israel in November 2014; Estonia, France and the U.K. in December 2014; and Russia in March 2015. Tokyo also started the ASEAN-Japan Ministerial Policy Meeting on Cybersecurity in September 2013 and the ASEAN-Japan Cybercrime Dialogue in May 2014, as well as the trilateral cybersecurity dialogue with China and South Korea in October 2014. These dialogues have strengthened their ties between Japan and other countries because information and communications technology (ICT) now lays the foundation for economy, innovation and national/international security, and cybersecurity is integral part of sound ICT (The Japan-India Cyber Dialogue began in November 2012).

During the election campaign, cybersecurity slipped through unnoticed, as discussions mostly focused on Abenomics and the possibility of the Japanese Constitution revision (to be fair, cybersecurity has not been a primary topic in many elections around the world). Yet, the current Abe administration has made significant progress in cybersecurity policy, public-private partnerships, and international cooperation. The election of the ruling parties means the continuation of Japan’s healthy cybersecurity development. They are crucial elements for the success of the Tokyo 2020 Summer Olympics.

Since Tokyo was chosen as the host of the 2020 Summer Olympic Games in September 2013, the Japanese government has been keen to develop cybersecurity policies to raise the country’s cyber resilience in an effort to make the event successful. It’s a priority for Japan as Olympics are special in terms of the scale of the event and stakeholders and the sensitivity of relationship-building and reputation management. The Cybersecurity Basic Act, issued in November 2014, provided legal authorities to the National Center of Incident Readiness and Strategy for Cybersecurity under the Cabinet Secretariat to craft national policies, serve as the point of contact for international collaboration, gather and analyze cyberthreat intelligence, move forward public-private partnerships for the protection of critical infrastructure, and evaluate cybersecurity measures taken by governmental agencies and ministries.

Under the Act, the Cabinet adopted the Cybersecurity Strategy in September 2015 to enhance cybersecurity without thwarting economic growth toward Tokyo 2020. Then, the LDP “Special Mission Committee on IT Strategy” issued the Digital Japan 2016 in May this year to provide the Japanese government with a list of recommendations about how to achieve social welfare by promoting cutting-edge IT technologies, including artificial intelligence and FinTech (rather than regulating the industry, as Japan has tended to do). The Committee believes cybersecurity and IoT security will play a key role to ensure citizens can appreciate the convenience of IT services and companies, ensuring efforts for security will be respected and valued.

The Japanese government reportedly sent delegations to the U.K. and Brazil to learn lessons from London 2012 and Rio 2016 Olympics about preparing for and running the events, in terms of cybersecurity, and plans to use lessons learned to prepare for Tokyo 2020. Discussions about sensitive information, like prevention tips and threat intelligence, require mutual trust and information assurance—thus, sharing the Olympics’ experiences and relationship-building will be helpful to reinforce Japan’s existing ties with the U.K. and Brazil. The U.K. is going through a difficult time after the national referendum for Brexit. While Japan needs to pay close attention to potential global economic and political consequences, the importance of cybersecurity cooperation between the two countries will not go away.

Japan’s three visions of Tokyo 2020 are “achieving personal best,” “unity in diversity,” and “connecting to tomorrow” to “leave a positive legacy for future generations.” The victory of the ruling parties is expected to allow Japan to continue its important and impactful activities of the last four years. The industry will contribute to those efforts by innovating cybersecurity solutions and increasing cyber resilience in Japan. This would ultimately help the cybersecurity of other countries Japan works with and lead to a good cybersecurity legacy in 2020 and beyond.

[Palo Alto Networks Research Center]

Mark McLaughlin Named to CRN’s Top 100 Executives List

August is off to a great start for Palo Alto Networks as our CEO Mark McLaughlin has been named to CRN’s Top 100 executives list. Published annually, CRN’s Top 100 executives list honors executives from companies that are leveraging the channel most effectively leaders who play an integral role in shaping the industry, whether by driving huge cultural shifts or forging innovative new routes to success.

Executives named to the list are recognized in one of four categories: Most Influential, Top Innovators, Top Disruptors and Sales Leaders. Mark was included in the Most Influential list, where he was praised for having Palo Alto Networks “firing on all cylinders and delivering more and more security functionality across its platform, including stellar growth for its Traps endpoint product. And Palo Alto Networks NextWave partner program has many partners shifting their business away from legacy vendors.”

Together with our partners, we are transforming the security market from detection to prevention. Since day one, Palo Alto Networks has been a channel-centric company and our channel mission has never been clearer — to build an ecosystem of next-generation security innovators, with coverage, capacity and capabilities to elevate our leadership position in the enterprise security market.

You can take a look at the list here. Congratulations, Mark!

[Palo Alto Networks Research Center]

Introducing MineMeld: Simplified, Open-source Threat Intelligence Sharing

As an industry, we must do everything in our power to prevent successful data breaches, maintaining trust in our digital way of life. Many organizations now share threat intelligence among peers, through information sharing organizations, or with government-based programs, to leverage community-based visibility into malicious activity on the Internet.

The vision is clear: the more data you ingest, the more you can improve your risk posture. But a data pile alone isn’t actionable. In order to achieve the desired outcome of preventing cyberattacks, organizations must be able to action on collected Indicators of Compromise (IOCs), automatically transforming them into prevention-based controls for enforcement on security devices.

Traditional approaches have challenged security teams with complex workflows, across multiple tools, to aggregate a growing number of threat intelligence source, and drive enforcement down to local devices. As part of our commitment to the security community, and mission of driving a new era of threat intelligence sharing, Palo Alto Networks is announcing the public availability of MineMeld to the entire security community. Previously available as a limited beta, MineMeld is an open source tool that simplifies the aggregation, enforcement, and sharing of threat intelligence.

Through MineMeld, organizations can integrate public, private, and commercial intelligence feeds, including results from other intelligence platforms, into a unified framework that natively feeds new prevention-based controls to Palo Alto Networks and other security devices. An an open-source tool, MineMeld was built to be extensible, allowing organizations to tailor the input, processing, and output of information for their environments. We have made the source code available on GitHub, as well as well as pre-built virtual machines (VMs) for easy deployment.

As part of the MineMeld release, we have been privileged to partner with a number of leading organizations to build a threat intelligence sharing ecosystem, with native support built into MineMeld from the very beginning, including: Anomali, The Media Trust, Proofpoint, Recorded Future, Soltra, SpamHaus, as well as our own AutoFocus service. MineMeld also supports a wide variety of open source intelligence providers. We encourage others in the security community to take up the banner and join our ecosystem by contributing a new Miner to the tool.

Together, we can simplify the sharing of threat intelligence for organizations across the globe, creating a stronger community that drives adoption of intelligence as a core element of a prevention-based strategy. Help us make successful cyber attacks more costly, and less effective than ever before. You can get started with MineMeld on the Palo Alto Networks Livecommunity, GitHub, or Wiki.

[Palo Alto Networks Research Center]

Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky

By mid-July 2016, the Afraidgate campaign stopped distributing CryptXXX ransomware. It is now distributing the “.zepto” variant of Locky. Afraidgate has been using Neutrino exploit kit (EK) to distribute malware after Angler EK disappeared in early June 2016. As we previously reported, this campaign continues to utilize gate domains using name servers from afraid.org.

Changing Payloads

As early as June 29, 2016, we saw the Afraidgate campaign deliver Locky ransomware. This campaign switched between delivering CryptXXX and Locky ransomware during the next two weeks. July 11, 2016, was the last time we saw Afraidgate deliver CryptXXX. Since then, this campaign has been consistently delivering Locky.

Figure 1: Flow chart for an infection from the Afraidgate campaign.

This variant of Locky uses a .zepto file extension for any encrypted files. We started seeing this Zepto variant of Locky after a three-week outage of the Necurs botnet ended on June 21, 2016. Locky had been absent during the outage, but after the botnet returned, Locky also reappearedwith new anti-sandboxing and evasion techniques.

Some security vendors have named this new variant Zepto ransomware, but they still highlight its similarities with the previous Locky variant.

Figure 2: Desktop of a Windows host infected with the Zepto variant of Locky.

From Angler EK to Neutrino

Like most campaigns, Afraidgate switched to Neutrino EK after Angler EK disappeared in early June 2016. We have seen two other large-scale campaigns also move from Angler to Neutrino EK: the EITest and pseudo-Darkleech campaigns. For now, Neutrino appears to be distributing the majority of ransomware for EK-based infections. Outliers still exist, like Magnitude EK distributing Cerber ransomware. Rig EK has also been noted for an occasional ransomware infection. But the bulk of EK-based ransomware infections are most often attributed to Neutrino EK.

Example of an Afraidgate Infection

Figure 3: Traffic from an Afraidgate infection filtered in Wireshark.

As noted in our previous post on EK fundamentals, EK-based campaigns start with a compromised website. Pages from the compromised site have injected script that, in this case, lead to an Afraidgate domain behind the scenes.

Figure 4: Injected script in page from a compromised website.

After the victim’s computer connects to the URL on an Afraidgate domain, the server returns more Javascript with an iframe leading to a Neutrino EK landing page.

Figure 5: Afraidgate domain leading to the Neutrino EK landing page.

Neutrino EK domains for this campaign tend to use .top as the top level domain (TLD). Otherwise, we see no surprises. Neutrino is a well-known EK that has been documented by others.

Conclusion

Domains, IP addresses, and other indicators associated with Neutrino EK and Locky are constantly changing. We continue to investigate this activity for applicable indicators to inform the community and further enhance our threat prevention platform.

WildFire continues to detect submitted samples of Locky ransomware, and AutoFocus identifies this threat under the Unit 42 Locky tag.

Indicators of Compromise

So far in July 2016, we have seen the following indicators of compromise associated with the Afraidgate campaign:

Gates:

  • 46.101.26.161 port 80 – ƒleon.stmaryschooldmt[.]com – GET /scripts/jquery.form.js
  • 46.101.26.161 port 80 – motor.atchisoncountyrecorder[.]com – GET /js/blog.js
  • 46.101.26.161 port 80 – motor.atchisoncountyrecorder[.]com – GET /scripts/custom.js
  • 46.101.26.161 port 80 – oskol.migustapizza.com[.]br – GET /gantry-totop.js
  • 46.101.26.161 port 80 – snow.blautechnology[.]com – GET /scripts/libs.js
  • 46.101.26.161 port 80 – start.puterasyawal[.]com – GET /js/addOnLoad.js
  • 188.166.38.125 port 80 – nepal.laderatutors[.]com – GET /rokmediaqueries.js
  • 188.166.38.125 port 80 – siber.activebeliever[.]com – GET /plugins/fancybox-for-wordpress/js/jquery.easing.1.3.min.js?ver=1.3
  • 188.166.38.125 port 80 – zine.polatoglumimarlik[.]com – GET /scripts/jquery.sliderkit.1.9.2.pack.js
  • 188.166.38.125 port 80 – zine.polatoglumimarlik[.]com – GET /html5shiv.js
  • 188.166.38.125 port 80 – zine.polatoglumimarlik[.]com – GET /to_top.js

Neutrino EK:

  • 5.2.72.236 port 80 – avukytj.oautumnyellow[.]top
  • 5.2.72.236 port 80 – azbepfasz.yintored[.]top
  • 5.2.72.236 port 80 – bkubf.bsuperpink[.]top
  • 5.2.72.114 port 80 – iynwzttqd.hautumngreen[.]top
  • 5.2.72.236 port 80 – mxoug.yintored[.]top
  • 5.2.72.236 port 80 – yegoxmvzpx.bsuperpink[.]top
  • 185.140.33.76 port 80 – erfxsnvj.mafterred[.]top
  • 185.140.33.76 port 80 – hxmst.rautumngreen[.]top
  • 185.140.33.99 port 80 – bkhrdfngwg.blueelizabeth[.]top
  • 185.140.33.99 port 80 – clfdkbl.bluechristian[.]top
  • 185.140.33.99 port 80 – drhffhveq.greenjessica[.]top
  • 185.140.33.99 port 80 – rklfdprel.blueelizabeth[.]top

Locky post-infection traffic:

  • 5.9.253.173 port 80 – 5.9.253.173 – POST /upload/_dispatch.php
  • 5.187.0.137 port 80 – 5.187.0.137 – POST /upload/_dispatch.php
  • 77.222.54.202 port 80 – 77.222.54.202 – POST /upload/_dispatch.php
  • 185.5.250.135 port 80 – 185.5.250.135 – POST /upload/_dispatch.php
  • 185.117.153.176 port 80 – 185.117.153.176 – POST /upload/_dispatch.php
  • 185.118.66.83 port 80 – 185.118.66.83 – POST /upload/_dispatch.php

Domains from the decryption instructions:

  • mphtadhci5mrdlju.tor2web[.]org
  • mphtadhci5mrdlju.onion[.]to
  • zjfq4lnfbs7pncr5.tor2web[.]org
  • zjfq4lnfbs7pncr5.onion[.]to

[Palo Alto Networks Research Center]

English
Exit mobile version