Yesterday we posted an analysis report on a novel malware XcodeGhost that modifies Xcode IDE to infect Apple iOS apps. In the report, we mentioned that at least two popular iOS apps were infected. We now believe many more popular iOS apps have been infected, including WeChat, one of the most popular IM applications in the world.
We checked these apps and list them below in this report. As of this writing, we see 39 iOS apps being infected, some of which are extremely popular in China and in other countries around the world, comprising hundreds of millions users.
The infected iOS apps include IMs, banking apps, mobile carrier’s app, maps, stock trading apps, SNS apps, and games. Among the more well-known apps are WeChat (developed by Tencent); Didi Chuxing (developed by Didi Kuaidi) the most popular Uber-like app in China;Railway 12306, the only official app used for purchasing train tickets in China; China Unicom Mobile Office, which is in use by the biggest mobile carrier in China; and Tonghuashun, one of most popular stock trading apps.
Figure 1. WeChat 6.2.5 is also infected
Some apps are also available from the App Store in other countries. For example, CamCard, developed by a Chinese company, is the most popular business card reader and scanner in many countries (including the US) around the world. WeChat is the most popular IM app not only in China but also in many countries or regions in Asia Pacific. Version 6.2.5 of WeChat is what we have verified to be infected. Tencent has updated to 6.2.6, which removed the malicious code.
Palo Alto Networks is cooperating with Apple on the issue and we also suggest all iOS developers be aware and take necessary actions.
Infected iOS apps
网易云音乐 2.8.3
微信 6.2.5
讯飞输入法 5.1.1463
滴滴出行 4.0.0.6-4.0.0.0
滴滴打车 3.9.7.1 – 3.9.7
铁路12306 4.5
下厨房 4.3.2
51卡保险箱 5.0.1
中信银行动卡空间 3.3.12
中国联通手机营业厅 3.2
高德地图 7.3.8
简书 2.9.1
开眼 1.8.0
Lifesmart 1.0.44
网易公开课 4.2.8
马拉马拉 1.1.0
药给力 1.12.1
喜马拉雅 4.3.8
口袋记账 1.6.0
同花顺 9.60.01
快速问医生 7.73
懒人周末
微博相机
豆瓣阅读
CamScanner
CamCard
SegmentFault 2.8
炒股公开课
股市热点
新三板
滴滴司机
OPlayer 2.1.05
电话归属地助手 3.6.5
愤怒的小鸟2 2.1.1
夫妻床头话 1.2
穷游 6.6.6
我叫MT 5.0.1
我叫MT 2 1.10.5
自由之战 1.1.0
Fox-IT (fox-it.com), a Netherlands based security company, checked all C2 domain names from our reports in their network sensors and has found thousands of malicious traffic outside China. According to their data, these iOS apps were also infected:
In this video, Lee Klarich, senior vice president, product management, talks about our new offering, Aperture, which extends the visibility and granular control of our next-generation security platform further into SaaS applications.
On Wednesday, Chinese iOS developers disclosed a new OS X and iOS malware on Sina Weibo. Alibaba researchers then posted an analysis report on the malware, giving it the name XcodeGhost. We have investigated the malware to identify how it spreads, the techniques it uses and its impact.
XcodeGhost is the first compiler malware in OS X. Its malicious code is located in a Mach-O object file that was repackaged into some versions of Xcode installers. These malicious installers were then uploaded to Baidu’s cloud file sharing service for used by Chinese iOS/OS X developers. Xcode is Apple’s official tool for developing iOS or OS X apps and it is clear that some Chinese developers have downloaded these Trojanized packages.
XcodeGhost exploits Xcode’s default search paths for system frameworks, and has successfully infected multiple iOS apps created by infected developers. At least two iOS apps were submitted to App Store, successfully passed Apple’s code review, and were published for public download.
This is the sixth malware that has made it through to the official App Store after LBTM, InstaStock, FindAndCall, Jekyll and FakeTor.
XcodeGhost’s primary behavior in infected iOS apps is to collect information on the devices and upload that data to command and control (C2) servers. The malware has exposed a very interesting attack vector, targeting the compilers used to create legitimate Apps. This technique could also be adopted to attack enterprise iOS apps or OS X apps in much more dangerous ways.
Distributing the Malicious Xcode Build
In China (and in other places around the world), sometimes network speeds are very slow when downloading large files from Apple’s servers. As the standard Xcode installer is nearly 3GB, some Chinese developers choose to download the package from other sources or get copies from colleagues.
By searching for “Xcode 下载” (Xcode downloading) in Google, in the first page of the search results (Figure 1), we found that six months ago someone posted Xcode download links to multiple forums or websites (including Douban, SwiftMi, CocoaChina, OSChina, etc.) that Chinese iOS developers frequently visit.
Figure 1. Google search results for “Xcode downloading” in Chinese
These posts provided links to download all versions of Xcode from 6.0 to 7.0 (including beta versions). All of the links direct to Baidu Yunpan, a cloud based file storage and sharing service.
Figure 2. Malicious Xcode shared in Baidu Yunpan
We downloaded these Xcode installers and found that all versions of Xcode between 6.1 to 6.4 were infected. When attempting to verify the installers’ code signing signature, it’s clear that some extra files were added into the Xcode (Figure 3).
Figure 3. Code signing verification shows some extra files in Xcode
The primary malicious component in the XcodeGhost infected version is “CoreServices”. What is different from all previous OS X and iOS malware instances is that this file is neither a Mach-O executable, nor a Mach-O dynamic library, but is a Mach-O object file that is used by LLVM linker and can’t directly execute in any way. This abnormal file format will cause crashes or errors when analyzing it by format parsers like MachOView, 010 Editor (with Mach-O template) or jtool.
In iOS, the CoreServices contain many of the fundamental system services, and almost all complex iOS apps reply on it. When such an iOS app is compiled, Xcode will search for the CoreServices framework in some pre-defined paths to link with developer’s code.
XcodeGhost implemented malicious code in its own CoreServices object file, and copies this file to a specific position that is one of Xcode’s default framework search paths. Hence, the code in the malicious CoreServices file will be added into any iOS app compiled with the infected Xcode without the developers’ knowledge.
When an infected app is executed, either in an iOS Simulator or on iOS devices, malicious code will collect some system and app information using its UIDevice AppleIncReserved method. The collected information includes:
Current time
Current infected app’s name
The app’s bundle identifier
Current device’s name and type
Current system’s language and country
Current device’s UUID
Network type
Figure 4. Collecting system and app information
Then, XcodeGhost will encrypt the information, and upload it to a C2 server through the HTTP protocol. From different versions of XcodeGhost, we found three C2 domain names:
According to JoeyBlue in Sina Weibo, at least two famous apps were infected by XcodeGhost and successfully landed in the App Store. We have confirmed both.
We downloaded the NetEase Cloud Music App (com.netease.cloudmusic) from Apples App Store (China region). In its latest version (2.8.3), Info.plist shows that it was built with Xcode 6.4 (6E35b). In the main executable file, the malicious XcodeGhost code is present (Figure 7 and Figure 8).
Figure 6. Infected NetEase App in the Apple App Store
Figure 7. XcodeGhost Present in the Infected NetEase App
Figure 8. Decompiled XcodeGhost Functions in the NetEase App
Security Risks
Compiler malware is not a new idea. Starting with the first proof-of-concept written by Ken Thompson 31 years ago, real compiler malware has been discovered in many platforms. Compared with other iOS malware, XcodeGhost’s behaviors are not especially significant or harmful. This is why the code can pass App Store code review.
However, XcodeGhost disclosed a very easy way to Trojanize apps built with Xcode. In fact, attackers do not need to trick developers into downloading untrusted Xcode packages, but can write an OS X malware that directly drops a malicious object file in the Xcode directory without any special permission.
Additionally, although Apple’s code review for App Store submissions is very strict, some applications are never reviewed by Apple.If the iOS app is used by an enterprise internally, for example, it will be distributed in-house and won’t go through the App Store.In the same example, an OS X app can also be infected, and lots of OS X apps are directly distributed via the Internet other than App Stores.
In these situations, Xcode compiler malware can be much more aggressive and risky.
It’s difficult for iOS users or developers to be aware of this malware (or similar attacks) because it is deeply hidden, bypassing App Store code review. Because of these characteristics, Apple developers should always use Xcode directly downloaded from Apple, and regularly check their installed Xcode’s code signing integrity to prevent Xcode from being modified by other OS X malware.
When you consider that the GTDC members are some of the biggest and most successful distribution companies in the world, accounting for more than $135 billion in product sales globally, it makes receiving this award a huge honor.
This recognition also puts us in an elite group of U.S. Rising Star companies. We were one of only 12 2015 award winners, one of only six repeat winners and one of only three companies to be competing in a new higher revenue category (we moved from $25M-$100M in annual revenue to $100M-$500M in annual revenue).
Todd Palmer, VP of Americas Channels and Anne Stoken, Distribution Business Manager North America at Palo Alto Networks were both on hand to receive our 2015 U.S. Rising Star Silver Award in the Hardware Companies with revenue of $100M-$500M category.
This award highlights the vital role distribution plays in our ability to grow. We want to thank the GTDC for the recognition and we want our distributors to know we are hard at work to make sure we are a 2016 U.S. Rising Star winner.
As cyberthreats increase in both volume and sophistication, securing industrial control systems (ICS) becomes that much more challenging. Despite the varied nature of critical infrastructure, however, most weaknesses in current ICS security fall into one or more of five categories.
Let’s look at these ICS security pitfalls and how to address them.
Weak passwords
Where possible you should establish and implement policies that require the use of strong passwords. This could include account lockout policies to reduce the chase of someone attempting brute force attacks though not ideal in a ICS environment, this would be more for a system that has to be internet facing.
If strong password enforcement is not something that can be done without risking safety, look at placing some other remediating factor in place like a firewall or terminal server that can facilitate strong password enforcement without impacting the ICS system itself.
Poor patch management
As we’ve previously discussed, patch management is a tricky endeavor at best. If machines in an ICS infrastructure are properly implemented, all necessary ports and protocols have been identified to allow for proper software functions. In that case, frequent patching usually isn’t necessary because those systems are, for the most part, static in nature.
But that doesn’t mean you can ignore a patch management policy. Your ICS environment requires a plan and process by which apply patches as needed and when possible to help mitigate known vulnerabilities that constitute a threat to your environment. Keep in mind that not all vulnerabilities are a threat to your systems. For example, if you do not run web services on your system, it’s not necessary to patch web services – by doing so, you just increase the risk of damage to your system.
Flat network design and/or unnecessary exposure to corporate resources and Internet.
Looking back, PCN, ICS, SCADA and other control type networks were designed at a time when network connectivity was not a concern. These system had true air gaps, and it was not until recent times that the increased need for data from these systems did necessitated that IT/OT start looking at providing network connectivity to the enterprise.
One important thing is to introduce ISA 62433 or network segmentation to your environment as as soon as possible. This act alone makes for easy of isolation of your critical assets and provides a clearly defined line of demarcation.
Another best practice is, if possible, to keep these systems from facing the Internet. You can minimize network exposure to control systems by locating them behind firewalls and isolate them from all unnecessary the business network services.
If your systems require remote access, look at employing secure methods that will allow for more granular control over access and provide record or log of enter into the system.
No authentication to resources
If you isolate ICS behind a firewall you are able to enforce a higher level of access control. If firewalling the system is not an option, you should look at placing some other form of remediating system or device that requires login access.
Default user accounts with default password
Last but definitely not least, when and where possible disable and or change the default user ID and password for your environment. It is understood that in the controls world safety is paramount and it is understood that when things go wrong you don’t want to have look through a long list of passwords and that you have 50 of these units and they aren’t centrally managed.
Sure, you’re saying: “It will take forever to change all the passwords on the units.” But you should come up with a password for those 50 and change them all, especially on intra/internet-facing assets. The time and energy it takes to make the change in the beginning is a lot less effort than tracking down and dealing with a break, let alone reporting up to C-level why the environment was compromised because of a password issue.
For more on Palo Alto Networks solutions for ICS, head here.