News: 1657085230

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Near-undetectable malware linked to Russia's Cozy Bear

(2022/07/06)


Palo Alto Networks' Unit 42 threat intelligence team has claimed that a piece of malware that 56 antivirus products were unable to detect is evidence that state-backed attackers have found new ways to go about the evil business.

Unit 42's analysts [1]assert that the malware was spotted in May 2022 and contains a malicious payload that suggests it was created using a tool called Brute Ratel (BRC4). On its rather brazen [2]website , BRC4 is described as "A Customized Command and Control Center for Red Team and Adversary Simulation". The tool's authors even claim they reverse-engineered antivirus software to make BRC4 harder to detect.

The malware Unit 42 observed starts life as a file that pretends to be the curriculum vitae of a chap named Roshan Bandara. Unusually, Bandara's CV is offered as an ISO file – a disk image file format. If users click on the ISO it mounts as a Windows drive and displays a File Manager window with a sole file: "Roshan-Bandara_CV_Dialog".

[3]

The file looks like a Microsoft Word file but – shockingly – is not really a CV. When double-clicked it opens CMD.EXE and runs the OneDrive Updater, which retrieves and installs BRC4.

[4]SolarWinds attacker on the move: Russia's Nobelium crew has trebled attacks targeting MSPs, cloud resellers, says Microsoft

[5]It was Russia wot did it: SolarWinds hack was done by Kremlin's APT29 crew, say UK and US

[6]Cyber-spies target Microsoft Exchange to steal M&A info

Once the malware is running, many bad things can happen to infected machines.

But Unit 42 is not concerned with those bad things. The technique used to get BRC4 running is what caught the team's eye, because it is so cunning it suggests nation-state actors were behind its development.

[7]

Maybe even APT29 – the Moscow-linked gang also known as Cozy Bear and thought to be involved in the attack on Solar Winds and many other raids. APT29 has used poisoned ISOs in the past.

Unit 42 also notes that the ISO used in this attack was created on the same day a new version of BRC4 appeared, suggesting that state-backed actors could be watching the murky world of commercial malware and quickly putting it to work while the world tries to catch up.

[8]

"The analysis of the two samples described in this blog, as well as the advanced tradecraft used to package these payloads, make it clear that malicious cyber actors have begun to adopt this capability," Unit 42's post states. "We believe it is imperative that all security vendors create protections to detect BRC4 and that all organizations take proactive measures to defend against this tool." ®

Get our [9]Tech Resources



[1] https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/#Conclusion

[2] https://bruteratel.com/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsVdQopTRlSye9ZC3Ix-BgAAAIY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2021/10/25/nobelium_russia_svr_msp_warning_microsoft/

[5] https://www.theregister.com/2021/04/15/solarwinds_hack_russia_apt29_positive_technologies_sanctions/

[6] https://www.theregister.com/2022/05/04/microsoft_exchange_mergers/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsVdQopTRlSye9ZC3Ix-BgAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsVdQopTRlSye9ZC3Ix-BgAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/



Cunning ?

Pascal Monett

Yeah, like I'm going to just open an ISO file from somebody I don't know.

I feel that, when users are going to finally grasp the fact that you do not open attachments from people you don't know , all of these "cunning" attacks are going to become a lot more difficult.

Re: Cunning ?

Neil Barnes

do not open attachments from people you don't know

And that will happen, um, a day or two after the heat death of the universe...

Re: Cunning ?

Eguro

But the email was clearly sent from the CEOs phone!!

Re: Cunning ?

johnfbw

CVs are almost exclusively files sent from people you don't know.

There is basically no alternative because it is private information from non -tech literate people.

Web front end for HR (hideous abominations) usually ask for the file as well

Re: Cunning ?

veti

I've never seen an HR portal that offers ".iso" as a valid file format option.

Re: Cunning ?

Phil O'Sophical

An OS that allows an ordinary user to mount a disk from which privileged programs can be run, just by clicking on an email, isn't fit for purpose.

Re: Cunning ?

Anonymous Coward

It's not a disk. It's a file. Whether it's called .iso, .zip or .tar, it's just an archive of files whose content can be extracted. The OS just makes it easy. And there's no special privilege attached to the content.

This appears to mean that antivirus are less careful about scanning the content of .iso files than .zip files, which sounds rather dumb of them.

sebacoustic

Well I for one hope that Roshan Bandara finds a job once his CV was widely distributed

“Roshan Bandara” you say

Anonymous Coward

So this unexpected .exe file from Svetlana Getyagearoff is perfectly OK then?

Re: “Roshan Bandara” you say

Anonymous Coward

Nah, that's dubious, as the last name should be in the correct grammatical genus - should be Getyagearoffa...

Come back Windows ...

Andy The Hat

The change of Windows direction from application-centric to data-centric was always going to be, was, and still is a pain in the crackers for *basic* security, especially if the user can't even see what's going to happen without further investigation. At least give users the ability to peek under their blindfold ... even if their wrists are still bound, they're being hypnotised by a telepathic rotating-circley thing and Margret on Facebook (nail operative, global pandemic expert and IT security professional) says "click it ... click it ...it'll be ok".

A simple information/dialog box that says "file xyz.yyy is trying to open in / execute / mount - ok?" would provide a one click buffer - a whole click more but wouldn't it be worth the effort.

Re: Come back Windows ...

veti

Err... That sounds like the kind of security that has been rightly derided as ineffective before. Any check that amounts to "add a click to the workflow" is not going to make anything better.

I'm quite baffled by this report. It requires the victim to click on unknown files, not once, but twice. This is the standard for "so clever that only a state actor could come up with it"?

Re: Come back Windows ...

thondwe

Just tried to open a couple of ISOs on my Windows 11 machine - all give me a "Security Warning" "Unknown Publisher" dialog (Even on a Windows Server ISO) - BUT there is a tick box to "Always Ask" - which clearly can be unticked - maybe a GPO for disabling, but - only requires a one Dories in an org to just click through...

Re: Come back Windows ...

naive

It is not specifically Windows, it is the one dimensional security model going back to the founding days of operating systems in the early 60's. A logged in user has full access to all services and files the OS has on offer based on a privilege model. There are no provisions for sand boxing or controlled access to resources within the privileges the user has on the OS. This worked well on mainframes of old where is was close to impossible to download and deploy new apps. In the internet age this model causes the world enormous headaches in the shape of virus scanners, gigantic databases of good and bad websites and the issues resulting from security breaches.

In Windows the one dimensional model bites users hard, since Windows is eager to be easy for the user, happily auto executing things based on file types or contents. Maybe Intel is to blame a bit as well, easy creation of VM's on Android/ARM phones made online banking apps popular on smart phones. If Intel had done more to support easy VM creation on its x86 things decade ago, MS could have used the security benefits of this approach.

The model Android uses holds some potential, there apps get specific rights on objects, combined with sand boxing this limits what apps can leak to bad actors.

The 60's security model in Linux and Windows will be hard to replace with a multi layered model, where apps are more isolated from drives other resources either by sand boxing or messaging techniques instead of direct read/write access to everything once a foothold. is gained.

About The Email Store-And-Forward Process....

Anonymous Coward

Quote: "...Bandara's CV is offered as an ISO file..."

....so.....umpty-ump email servers (many at places like M$, Google, Yahoo....and so on)....all these email servers have passed on an email with an ISO file attached....and none of these technically sophisticated organisations....all of them supposedly taking "security very seriously"......none of these organisations do diddly-squat about this malware ISO file....

....instead they proceed to deliver the email and the ISO attachment......and they leave the end user to decide...."Should I click on this?"

What am I missing here?

insistently dumb

DaemonProcess

Every week I hear of users who _demand_ to open any email and attachment they receive. Regardless of all the security training they get. Then they say it's our fault for allowing malware through. The question is... what legally constitutes enough protection these days - 3 different AV scanners, sandboxes, what else?

win-nt from the people who invented edlin.
-- MaDsen Wikholm, mwikholm@at8.abo.fi