New “Undetected” Backdoor Runs Across Three OS Platforms

New “Undetected” Backdoor Runs Across Three OS Platforms

Security experts are warning of new backdoor malware designed to work across Windows, Mac and Linux, some versions of which are currently undetected in Virus Total.

Dubbed “SysJoker” by researchers at Intezer, the malware was discovered during an attack on a Linux web server running in an education sector organization. It’s believed to date back to the second half of 2021.

“SysJoker masquerades as a system update and generates its C2 [command and control] by decoding a string retrieved from a text file hosted on Google Drive,” the vendor explained in a blog post.

“During our analysis the C2 changed three times, indicating the attacker is active and monitoring for infected machines. Based on victimology and malware’s behavior, we assess that SysJoker is after specific targets.”

The malware is written in C++, with each sample customized for the OS it targets. Worryingly, the Linux and macOS versions were fully undetected in VirusTotal at the time of writing.

Aside from the Windows version containing a first-stage dropper, all three variants work the same. After execution, the malware sleeps for up to 120 seconds, then creates a directory and copies itself under this directory, pretending to be an Intel graphics common user interface service executable.

It then covertly gathers information about the machine and achieves persistence, sleeping between these steps.

Communication with the C2 server is achieved by decoding a hardcoded Google Drive link containing a text file with an encoded C2.

The C2 might download additional malware or run other commands on the victim machine.

Intezer claimed there are several reasons why SysJoker may be the work of a sophisticated actor. It was written from scratch and hadn’t been seen before in other attacks in the wild – apparently a rarity for Linux malware.

The attacker registered at least four separate domains and wrote the malware for three discrete platforms.

“During our analysis, we haven’t witnessed a second stage or command sent from the attacker,” Intezer concluded. “This suggests that the attack is specific which usually fits for an advanced actor.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US: MuddyWater is Iranian State-Backed Group

US: MuddyWater is Iranian State-Backed Group

The US authorities have, for the first time, explicitly identified the prolific MuddyWater hacking group as an Iranian state-sponsored entity, revealing several open-source tools used by the group to target victims.

US Cyber Command’s Cyber National Mission Force said in a post yesterday that the actors associated with MuddyWater are “a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).”

According to the Congressional Research Service (CRS), the MOIS “conducts domestic surveillance to identify regime opponents.” It also “surveils anti-regime activists abroad through its network of agents placed in Iran’s embassies,” the CRS said.

Among the tools attributed to the Iranian APT group were variants of the PowGoop DLL side-loader. These are used “to trick legitimate programs into running malware and obfuscate PowerShell scripts to hide command and control functions,” the post noted.

US Cyber Command also pointed to various JavaScript samples used to establish connections to malicious infrastructure and a Mori backdoor used for DNS tunneling to communicate with command and control servers.

“Should a network operator identify multiple of the tools on the same network, it may indicate the presence of Iranian malicious cyber actors,” it warned.

Threat intelligence vendor Mandiant said it had been tracking MuddyWater, or “Seedworm,” since at least May 2017.

“Iran fields multiple teams that conduct cyber espionage, cyberattack, and information operations,” explained Sarah Jones, Mandiant senior principal analyst, threat intelligence. “The security services that sponsor these actors, the MOIS and the IRGC, are using them to get a leg up on Iran’s adversaries and competitors all over the world.”

MuddyWater is best known for attacks on targets in the Middle East, including telecommunications, government and oil sectors. However, it has previously detected attacking victims in Europe and North America.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Report Identifies Weaknesses in Online Banking Security

Report Identifies Weaknesses in Online Banking Security

Some UK banks are letting their customers down with poor authentication and web security issues, according to a consumer rights group.

Which? once again teamed up with independent security consultants 6point6 to appraise the “front-end” security of 15 current account providers. It looked at four criteria: encryption and protection, login, account management and navigation.

The report found that, while all lenders followed strong customer authentication (SCA) rules as laid down in European banking regulations, some exposed their customers to SIM swapping attacks.

That’s because they used two-factor checks using SMS, which hackers can intercept if they have tricked the victim’s network operator into transferring their mobile phone number to a SIM under the attacker’s control.

Lloyds, Metro, Nationwide, TSB, Santander and The Co-operative Bank all dropped points in the tests for this, although the latter two claimed they’re “looking to move away from SMS,” according to Which?.

The report also highlighted issues with insecure passwords.

“We were shocked to find that Triodos lets customers set insecure security words, including ‘password’, ‘1234567’ and ‘admin.’ The risk is mitigated by a two-factor authentication at login (using its physical ‘Digipass’ device) but there is no excuse for a bank to allow such weak credentials,” it argued.

“Six banks (HSBC, NatWest, Santander, Starling, The Co-operative Bank, and Virgin Money) let you choose passwords that include your first name and/or surname. Santander told us this is being phased out, and NatWest and Virgin Money said they might increase password limitations after our investigation.”

Virgin Money was also singled out for allowing the researchers to set up a new payee without additional security steps.

The report also revealed three banks with vulnerable subdomains that could potentially be compromised, and one banking app which doesn’t require users to log in each time.

Overall, HSBC came top in the online banking security tests with a score of 81%, and First Direct was in first place for mobile banking security, with a score of 77%.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Using Foreign Nationals to Bypass US Surveillance Restrictions

Remember when the US and Australian police surreptitiously owned and operated the encrypted cell phone app ANOM? They arrested 800 people in 2021 based on that operation.

New documents received by Motherboard show that over 100 of those phones were shipped to users in the US, far more than previously believed.

What’s most interesting to me about this new information is how the US used the Australians to get around domestic spying laws:

For legal reasons, the FBI did not monitor outgoing messages from Anom devices determined to be inside the U.S. Instead, the Australian Federal Police (AFP) monitored them on behalf of the FBI, according to previously published court records. In those court records unsealed shortly before the announcement of the Anom operation, FBI Special Agent Nicholas Cheviron wrote that the FBI received Anom user data three times a week, which contained the messages of all of the users of Anom with some exceptions, including “the messages of approximately 15 Anom users in the U.S. sent to any other Anom device.”

[…]

Stewart Baker, partner at Steptoe & Johnson LLP, and Bryce Klehm, associate editor of Lawfare, previously wrote that “The ‘threat to life; standard echoes the provision of U.S. law that allows communications providers to share user data with law enforcement without legal process under 18 U.S.C. § 2702. Whether the AFP was relying on this provision of U.S. law or a more general moral imperative to take action to prevent imminent threats is not clear.” That section of law discusses the voluntary disclosure of customer communications or records.

When asked about the practice of Australian law enforcement monitoring devices inside the U.S. on behalf of the FBI, Senator Ron Wyden told Motherboard in a statement “Multiple intelligence community officials have confirmed to me, in writing, that intelligence agencies cannot ask foreign partners to conduct surveillance that the U.S. would be legally prohibited from doing itself. The FBI should follow this same standard. Allegations that the FBI outsourced warrantless surveillance of Americans to a foreign government raise troubling questions about the Justice Department’s oversight of these practices.”

I and others have long suspected that the NSA uses foreign nationals to get around restrictions that prevent it from spying on Americans. It is interesting to see the FBI using the same trick.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains