Want to stay under the radar for a decade or more? This Chinese hacking crew did it... by aiming for Linux servers
- Reference: 1586260808
- News link: https://www.theregister.co.uk/2020/04/07/winnti_linux_hacking/
- Source link:
[2]A report from BlackBerry outlines how the group, actually a collection of five smaller crews of hackers thought to be state-sponsored, assembled in the wake of Winnti and exploited Linux servers, plus the occasional Windows Server box and mobile device, for years.
"The APT groups examined in this report have traditionally pursued different objectives and focused on a wide array of targets," BlackBerry noted.
China's Winnti hackers (apparently): Forget the money, let's get political and start targeting Hong Kong students for protest info [3]READ MORE
"However, it was observed that there is a significant degree of coordination between these groups, particularly where targeting of Linux platforms is concerned, and it is assessed that any organization with a large Linux distribution should not assume they are outside of the target sets for any of these groups."
[4]First chronicled by researchers back in 2013, the Winnti hacking operation is thought to date back as far as 2009. These groups, described by BlackBerry as "offshoots" of that hacking outfit, have been around for nearly as long and use similar tactics.
Part of the reason the attack has gone unnoticed for so long, BlackBerry reckons, is due to their preference for Linux servers. It is believed the hackers use three different backdoors, two rootkits, and two other build tools that can be used to construct additional rootkits on a per-target basis for open-source servers.
This in addition to the command-and-control tools and what is described as a "massive botnet" of compromised Linux servers and devices. Some of the malware has been in use dating back to 2012.
"In the attacks BlackBerry observed, the open Linux platform has enabled Chinese actors to develop backdoors, kernel rootkits, and online-build environments at a high level of complexity and specificity, with the end result being a toolset specifically designed to be harder to detect," the report noted.
"Compounding low detection rates inherent in the malware design is the relative lack of coverage quality and features in malware detection solutions for Linux available on the market today."
Going after Linux servers also has the added benefit of yielding massive caches of data when an attack is successful.
"The fact that this new Linux malware toolset has been in the wild for the better part of the last decade," said BlackBerry, "without having been detected and publicly documented prior to this report, makes it highly probable that the number of impacted organizations is significant and the duration of the infections lengthy." ®
Sponsored: [5]How to Build Your Digital Experience Portfolio
[1] https://www.theregister.co.uk/2020/03/26/fireeye_apt41_chinese_hackers_zoho_citrix_cisco/
[2] https://blogs.blackberry.com/en/2020/04/decade-of-the-rats
[3] https://www.theregister.co.uk/2020/01/31/winnti_hackers_students/
[4] https://www.theregister.co.uk/2013/04/11/video_game_cyberespionage/
[5] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936
@Tom 7 - Re: Penetration?
That's the question to be asked. All news on this matter mysteriously lack this crucial detail. They only describe in detail what happens after the attacker has managed to get in and obtain root privileges.
I suspect the attackers are using flaws in Internet facing applications as well as sysadmin incompetence, especially when servers and applications are being managed by developers themselves.
Re: @Tom 7 - Penetration?
The simplest thing to do is to block ports unless necessary and to not allow SSH or other services to any unknown addresses.
So, one Linux myth bites the dust
Not the one where Linux didn't have any viruses. That myth has sunk a while ago already. But the myth that Linux, being a niche product, did not attract hacker attention.
With hindsight, that myth couldn't hold water as soon as half of the Internet started running on Linux. Linux on the desktop is still a pipe dream, but Linux in the server rooms is very real, and I'll wager there are more Linux server than there are Windows servers at this point in time.
And those hackers were attracted to the servers, and their sweet, sweet data.
I'm sure that admins that are on the ball already have proper firewalls and anti-virus tools in place, plus maybe monitoring and intrusion detection for the best of them, Linux or no. For the rest of you, this is your wake-up call. Linux _is_ vulnerable.
So patch and fortify your defenses.
Re: So, one Linux myth bites the dust
But aren't most Firewalls Linux based?
Hmmmmm.
Re: So, one Linux myth bites the dust
BSD is quite a bit more common
@Pascal Monett - Re: So, one Linux myth bites the dust
I'll start by addressing your statement about Linux viruses. As long as you don't give us some serious examples of viruses actively infecting Linux servers, the myth still stands. Proof is that actually nobody runs antivirus on Linux servers, except of course for those managed by Windows admins in Windows shops since they can't trust anything that doesn't run an anti-virus.
When you're talking about Linux on the desktop as a pipe dream, are you talking about widespread adoption or Linux as a desktop alternative. That 1% at planetary scale still makes for millions of Linux desktops, sorry if this is upsetting your stomach.
Third, as long as I don't have the attack vector, I can't tell if Linux itself is vulnerable. Is it the kernel, the user-land, applications, we don't know yet. And the same is to be said about Linux viruses, those few that are known so far lack any mention of infection mechanism (it seems they rely on goodwill of half-competent sysadmins).
So hold your horses for a while!
Re: @Pascal Monett - So, one Linux myth bites the dust
"Proof is that actually nobody runs antivirus on Linux servers"
Absence of evidence is not evidence of absence
Re: @Pascal Monett - So, one Linux myth bites the dust
I've done AV checks on many machines. Its only ever windows generated content that has ever tested positive.
Now this 'new' method has been highlighted I will test all my local machines when I can find a sure way of doing so but given Blackberrys reluctance to provide evidence of its spread in the field I'm not sure if its common enough not to be more of problem testing for it.
Re: @Pascal Monett - So, one Linux myth bites the dust
The best bet is to keep Linux servers at least two metres away from the internet.
Re: @Pascal Monett - So, one Linux myth bites the dust
I believe that the Chinese sports federation have been training paclets to leap small air gaps.
Interesting, and worrying, that they were able to avoid being noticed by going for Linux. Also a good reminder that no matter how good the security of the OS, it can still be compromised, and companies still need fairly rigorous security procedures in place.
More like they targeted the multitude of Chinese made devices with defective linux preinstalled...
set top boxes... usb powered computers....., medical equipment.... IOT....
Cameras.....
Seen this pre-2010......... which is why i wont have any Chinese devices near my home... unless the firmware is replaced........
Ok Donald you can go back to sleep now.
In Free AI Spaces of Quiet Contemplation ....
.... Do New Life Forces Spring into NEUKlearer HyperRadioProACTive IT
Do state sponsored hackers break down or more simply open novel doors onto platforms and into applications granting full access to the treasures and temptations therein, uncovered and discovered for exercising and fine tuning to a Base Master Root Mutually Satisfying Perfection Assuring and Ensuring All Heavenly Performance?
If you be of the latter persuasion with a passionate unbridled desire for the delivery and sharing/co-hosting of Such Almighty Satisfactory ACTivity, .... Pleased to See You, To See you Nice. :-) Be Sure to Not Leave a Stranger if Never Tempted to be Fully Satisfied by Heavenly Performance with a Universal Power in Energy Command and Control ...... for it would suggest there be Alternate Fully Satisfying Routes in Other AIMarkets which one may or may not yet have any knowledge of. And that's a hell of a lot to have many much further and deeper chats about. You know some such are Enlightening and Prone to Non-Priming of Viable Defence Counter Measures.
They used to be thought Problematical rather than considered Virtually Ideal and Practically Perfect. :-) Honest. I Kid U Not.
Meaningless Group Of Statements Made Up Out of the Air
The entire article is BS!
> Going after Linux servers also has the added benefit of yielding massive caches of data when an attack is successful.
Really, any evidence to back that statement? Or any other statement in the article?
Not even close to El Reg's usual carrion quality.
A very disappointed AAC
Re: Meaningless Group Of Statements Made Up Out of the Air
If they're anything like our BOFHs they haven't really got a clue what's running.
Rogue processes mounting NFS shared drives and running rampant deleting files? No problem, you're on your own, that must be unsupported software because we don't have anything that does that.
Tivoli filling up disk space because the event logs haven't been transferred to another system for processing and storage in months? No problem, just disable Tivoli and delete the logs.
No operating system can cope with stuff like that. I wouldn't be surprised if one day they said they'd found a Counterstrike server hosting games held between Russian and Chinese teams with the NSA spectating.
Patch / update / keep current / monitor / check logs
Nothing new here - the report suggests Red Hat / CentOS / Ubuntu versions - the kernel versions they suggest are mostly CentOS 6 era. Patch / update / keep current. Red Hat licences persist across versions: there's no penalty for moving from one version to the next. Just do it, people. Sysadmin 101. If you don't need a GUI - NEVER install one. Limit the number of services you run: audit logs : baseline to find out what's anomalous -tedious, but nothing unexpected.
Penetration?
Any idea how many machines may have been compromised?