News: 1618333965

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins

(2021/04/13)


Cracked copies of Microsoft Office and Adobe Photoshop are stealing browser session cookies and Monero cryptocurrency wallets from tightwads who install the pirated software, Bitdefender has warned.

As many Reg readers will no doubt be aware, cracked software is a legitimate application that has had its registration or licensing features removed. Often distributed through BitTorrent in the days of yore, cracked software (also known as warez) appeal mainly to freeloaders who are happy to use a particular suite without paying for a licence.

[1]

With Microsoft Office and Adobe Photoshop being two of the most popular software suites in their niches, cracked versions were always going to be popular.

Those cracks come with a price, though: Bitdefender discovered that certain versions of both suites were being distributed with malware that stole browser session cookies (or in the case of Firefox, the user's entire profile history), hijacked Monero cryptocurrency wallets, and exfiltrated other data via BitTorrent, having first opened a backdoor on the target machine and turned off its firewall.

[2]

"Once executed, the crack drops an instance of ncat.exe (a legitimate tool to send raw data over the network) as well as a TOR proxy," said Bitdefender's Bogdan Botezatu, director of threat research and reporting and security researcher Eduard Budaca in a [3]blog post . A batch file, chknap.bat, was also bundled.

"The tools work together to create a powerful backdoor that communicates through TOR with its command and control center: the ncat binary uses the listening port of the TOR proxy ('--proxy 127.0.0.1:9075') and uses the standard '--exec' parameter, which allows all input from the client to be sent to the application and responses to be sent back to the client over the socket (reverse shell behavior)," said the researchers.

Botezatu, told The Register : "The operators behind this attack take quite some time to analyse the environment they have compromised and decide what is worth stealing. We presume that exfiltration of the Firefox profile directory was opportunistic rather than targeted and that attackers would go for any other browser installed on the device."

Pirates of the dodge-the-fee-an

Jake Moore, a cybersecurity consultant at infosec biz ESET, told us: "As illegal as cracked software is, it is still very much commonplace on both home and work devices which makes this even more worrisome. This rather impressive malware may even hide in plain sight as many cracked versions of software come with protection notifications from their antivirus warning their users of the risks.

"Pirated software is never the way to go, however tempting it may be, as the risks tend to always outweigh the benefits."

Reg readers who are long of tooth and grey of hair might recall our coverage of the warez scene back in the 2000s, which saw [4]various software pirates being [5]arrested and handed [6]prison terms .

In the days before as-a-service business models in the cloud were viable, vendors were entirely reliant on physical media being distributed to end users containing the entire program. Copy protection was an immediate and popular target for crackers, leading to illegitimate copies of otherwise fully functional software being sold for way below the normal asking price.

Licence key generators were another popular line of business for pirates, with ESET's Moore observing that they're often flagged as malware (because they, er, contain baked-in malware) and are therefore quarantined by antivirus, "but due to the user choosing to side with their own knowledge and overriding such warnings" bad things tend to happen to systems whose users trusted such nefarious things.

[7]

The rise of aaS produce has squashed, if not wiped out, demand for warez; big vendors have become more adept at ensuring their products only work in the presence of an internet connection where they can phone home to an activation server. ®

Get our [8]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YHYUgkpejw4eBi-fWkIQcQAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YHYUgkpejw4eBi-fWkIQcQAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[3] https://labs.bitdefender.com/2021/04/from-cracks-to-empty-wallets%E2%80%94how-popular-cracks-lead-to-digital-currency-and-data-theft/

[4] https://www.theregister.com/2007/09/05/warez_lands_man_30_months/

[5] https://www.theregister.com/2004/04/22/uk_warez_raids/

[6] https://www.theregister.com/2007/06/23/drink_or_die_ringleader_jailed/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YHYUgkpejw4eBi-fWkIQcQAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://whitepapers.theregister.com/

katrinab

Keygens can also get flagged as malware because they are keygens. Making it difficult to tell the difference between actual malware, and software that merely harms Shantanu Narayen's private yacht fund.

Alien invasion

Anonymous Coward

Is he an alien? He has a huge brain case.

Great advert for LibreOffice and Gimp

JassMan

Best part is you don't even need to install Linux first.

Re: Great advert for LibreOffice and Gimp

TVU

"Great advert for LibreOffice and Gimp"

...and indeed for Paint.net and the venerable Photoshop CS2.

I would still take my chances with the lesser crooks

Anonymous Coward

1) Cracked copies let you keep your computer entirely offline. Much safer than always-online cloud nonsense.

2) Microsoft and Adobe also steal my data. Not entirely sure what the difference is

Re: I would still take my chances with the lesser crooks

CrackedNoggin

For a typical MS Office user the difference is persistent transparent keystroke monitoring vs anything-goes loss of control. Obviously the former is preferable because having your data encrypted is the worst.

For others (the minority) there is no need to use MS Office, or such cloud usage can be isolated when absolutely necessary (e.g., working in collaboration with typical MS office users online).

I think you know that.

Re: I would still take my chances with the lesser crooks

fidodogbreath

Running cracked software means trusting both the original developer and some random cracker. Not sure that's "much safer than always-online cloud nonsense." In either case you have no idea where your personal info will end up.

And who's to say that the cracked software doesn't still send telemetry to MS / Adobe / whoever?

Re: I would still take my chances with the lesser crooks

yetanotheraoc

"And who's to say that the cracked software doesn't still send telemetry to MS / Adobe / whoever?"

You missed the part where he said "offline". An offline machine isn't sending telemetry to anybody. Software that only works online obviously is.

Re: I would still take my chances with the lesser crooks

yetanotheraoc

"Microsoft and Adobe also steal my data. Not entirely sure what the difference is"

Came here to make the same comment.

You're cracked if you're running cracked software

Version 1.0

These days all "free" software is going to make the user pay one way or another - looking at the worldwide market it would seem to be generally more profitable to sell users location and browsing data than their crypto wallets.

Re: You're cracked if you're running cracked software

Joe W

I do beg to differ.

vi is free (as in both "beer" and "speech". I very much doubt it is harvesting any data.

The quotation marks around "free" in your post are likely deliberate (so: sorry, I get your point, could not resist etc), and likely refer to anything G**gle or F'book (F'thagn-book?) or so. Yes, I do agree :)

Re: You're cracked if you're running cracked software

My other car WAS an IAV Stryker

FnordBook.

At least that's the sense of uneasiness and dread I get when I see what my "friends" have been posting.

Re: You're cracked if you're running cracked software

Version 1.0

Sure, free software used to be written to help people do things - but these days "free" software serves the users advertisements, sells their data, and occasionally cracks their wallets if the "free" access is a result of someone hacking the registration. I've got a few free applications out there that people use but they were all written back in the old days to help people.

If I was trying to fund their replacements today then the corporate management would be telling me to harvest user data.

Open options

Anonymous Coward

seams silly for anyone to pirate MS office these days, as there are Open source office apps that are better.

Re: Open options

Blazde

Sadly I've not found a spreadsheet app that will handle very large tables or complex lookup updates with nearly(*) as good performance as Excel. The only sense in which the open source options are better is that if I wanted to fix the performance issues in theory I could.

(*) Not even within an order of magnitude in some cases.

JDPower666

Is there something missing from this sentence cos I can't work it out:

"This rather impressive malware may even hide in plain sight as many cracked versions of software come with protection notifications from their antivirus warning their users of the risks."

"where they can phone home to an activation server"

LDS

Well, today the crack is exactly making them work without that.

Don't try to outweird me, three-eyes. I get stranger things than you free
with my breakfast cereal.
-- Zaphod Beeblebrox