News: 1612355405

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Tiny Kobalos malware seen backdooring SSH tools, menacing supercomputers, an ISP, and more – ESET

(2021/02/03)


ESET researchers say they have found a lightweight strain of malware that targets multiple OSes and has hit supercomputers, an ISP, and other organisations.

Nicknamed Kobalos, the software nasty [1]is said to be portable to Linux, the BSDs, Solaris, and possibly AIX and Windows. ESET researchers Marc-Etienne M.Léveillé and Ignacio Sanmillan appear to have analysed primarily the Linux version of the code. Here's a summary of the key findings from their research:

How it gets onto servers is unclear though systems infected by Kobalos have their SSH client tampered with to steal usernames and passwords, and presumably server addresses, that are typed into it. These details could be used by the malware's masterminds to log into those systems to propagate their malware. This would be especially possible if the stolen username-password combos were for superuser-level or sudoers accounts. Thus, miscreants can gradually take over more and more machines, one account at a time, from just one compromised computer. Changing the SSH client will need admin-level access, we note, or some PATH shenanigans.

Kobalos is typically hidden in an infected machine's OpenSSH server executable and activates a backdoor if it receives a connection from a particular source TCP port, [2]usually 55201 . Once an encrypted connection is established, this backdoor can be used like a remote terminal, executing arbitrary commands entered by its operators.

The malware can also connect to a command-and-control (C2) server that links the software to its masterminds. An infected server can also act as a proxy between the operators and another compromised box. Public-facing IP addresses and port numbers for these C2 machines may be hardcoded into the next Kobalos build.

According to ESET, a large Asian ISP, a North American endpoint security vendor, a European marketing agency, university networks, people's personal servers, and other kit were found to be hit by the malware as well supercomputer clusters.

ESET was separately working with CERN's computer security team to protect the super-lab's networks from whoever it was going around installing cryptocurrency miners and the like on high-performance rigs.

The ESET duo also hat-tipped Maciej Kotowicz of MalwareLab.pl for also analysing the malware. The above-linked advisory includes details on how to detect the backdoor and how to thwart its spread. Using multi-factor authentication for SSH is a recommended option as it should prevent the use of stolen usernames and passwords. Plenty more technical details and reverse-engineering of the code and its use of encryption can be found [3]here [PDF].

ESET was unwilling to attribute the malware to any known group of hackers or nation states. And what's in a name? Léveillé and Sanmillan said: "We have named this malware Kobalos for its tiny code size and many tricks; in Greek mythology, a kobalos is a small, mischievous creature."

Linux malware is uncommon but far from unknown. Last year Microsoft declared its support for hunting down [4]in-memory malware targeting Linux servers while China's APT41 was revealed to have [5]spent five years poking around various Linux boxen. ®

[6]

[7]

[8]

Get our [9]Tech Resources



[1] https://www.welivesecurity.com/2021/02/02/kobalos-complex-linux-threat-high-performance-computing-infrastructure/

[2] https://github.com/eset/malware-ioc/tree/master/kobalos

[3] https://www.welivesecurity.com/wp-content/uploads/2021/01/ESET_Kobalos.pdf

[4] https://www.theregister.com/2020/02/25/fileless_attack_microsoft_linux/

[5] https://www.theregister.com/2020/04/07/winnti_linux_hacking/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YBrWqrQLB1m-8HuAP0abSQAAAAg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YBrWqrQLB1m-8HuAP0abSQAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YBrWqrQLB1m-8HuAP0abSQAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/

Potemkine!

They should have installed Linux instead!

Oh, wait...

don't you hate it when you lose your account

Assuming your OS is (any OS) is safe is the fail. While the info given is useful, I'm more interested in the initial attack vector.

Aquavit is also considered useful for medicinal purposes, an essential
ingredient in what I was once told is the Norwegian cure for the common
cold. You get a bottle, a poster bed, and the brightest colored stocking
cap you can find. You put the cap on the post at the foot of the bed,
then get into bed and drink aquavit until you can't see the cap. I've
never tried this, but it sounds as though it should work.
-- Peter Nelson