News: 1664715367

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Steganography alert: Backdoor spyware stashed in Microsoft logo

(2022/10/02)


Internet snoops have been caught concealing spyware in an old Windows logo in an attack on governments in the Middle East.

The Witchetty gang used steganography to stash backdoor Windows malware – dubbed Backdoor.Stegmap – in the bitmap image.

"Although rarely used by attackers, if successfully executed, steganography can be leveraged to disguise malicious code in seemingly innocuous-looking image files," researchers at Symantec's Threat Hunter Team [1]wrote this week . "Disguising the payload in this fashion allowed the attackers to host it on a free, trusted service."

[2]

Looks harmless, although sysadmins may disagree ... The pic used for the payload. Source: Symantec

From what we can tell, Witchetty first compromises a network, getting into one or more systems, then downloads this image from, say, a repository on GitHub, unpacks the spyware within it, and runs it.

Hiding the payload in this way, and placing the file somewhere innocuous online, is a big advantage in evading security software, as "downloads from trusted hosts such as GitHub are far less likely to raise red flags than downloads from an attacker-controlled command-and-control (C&C) server," the team said.

[3]

Thus, fetching this pic after gaining initial access is less likely to set off internal alarms.

[4]

[5]

In April analysts at European cybersecurity shop ESET [6]documented Witchetty – which they called LookingFrog at the time – as one of three subgroups within TA410, an espionage group with loose ties to the APT10 (aka Cicada) gang known for targeting enterprises in the US utility sector and diplomatic organizations in the Middle East and Africa.

APT10, also known as Red Apollo and Stone Panda, earlier this year ran a [7]campaign against financial services firms in Taiwan. LookingFrog, FlowingFrog, and JollyFrog are the three subgroups of TA410, with LookingFrog focusing its efforts on the Middle East and a small part of Africa, according to ESET.

[8]

The use of Stegmap is part of a larger update of Witchetty's toolset, the Symantec researchers wrote. The group has been known to use a first-stage backdoor known as X4 and a second-stage payload called LookBack, which ESET said targets governments, diplomatic missions, charities, and industrial and manufacturing organizations.

Malware upgrades make for a more canny foe

Witchetty continues to use LookBack, but has added Stegmap and other malware to its arsenal. To bring Stegmap into a network, a DLL loader is run that downloads the bitmap file of the Windows logo from a GitHub repository. The payload is hiding in the bitmap file and is decrypted with an XOR operation and key.

The payload opens a backdoor to the outside world and can execute a range of commands issued to it by its masters, from copying, moving, or deleting files to removing a directory, starting a new process, or killing an existing one, and creating or deleting a Windows registry key.

[9]Hacked Fast Company sends 'obscene and racist' alerts via Apple News

[10]Noberus ransomware gets info-stealing upgrades, targets Veeam backup software

[11]Significant customer data exposed in attack on Australian telco

[12]Check out this Android spyware, says Microsoft, the home of a gazillion Windows flaws

The Symantec researchers wrote that Witchetty launched an espionage campaign against two Middle Eastern governments and a stock exchange in Africa using Stegmap. Initial access into a target's network is gained by exploiting the ProxyShell (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) and ProxyLogon (CVE-2021-26855 and CVE-2021-27065) vulnerabilities in Microsoft Exchange and installed malicious scripts on public-facing web servers. From that point, the attackers were able to steal login credentials from users, move laterally through the corporate network, and install Stegmap and other software nasties on computers.

Witchetty also makes use of Mimikatz, a port scanner, and other tools. This includes one that adds itself to autostart in the registry, being listed as "Nvidia display core component," to ensure the malicious code is run again on a reboot.

"Witchetty has demonstrated the ability to continually refine and refresh its toolset in order to compromise targets of interest," the researchers wrote.

"Exploitation of vulnerabilities on public-facing servers provides it with a route into organizations, while custom tools paired with adept use of living-off-the-land tactics allow it to maintain a long-term, persistent presence in targeted organizations." ®

Get our [13]Tech Resources



[1] https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/witchetty-steganography-espionage

[2] https://regmedia.co.uk/2022/09/30/windows_malware.jpg

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yzm1mkixwLBn0WnoNHO46QAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yzm1mkixwLBn0WnoNHO46QAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yzm1mkixwLBn0WnoNHO46QAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.eset.com/uk/about/newsroom/press-releases/set-research-reveals-the-workings-of-three-teams-behind-ta410-and-a-new-version-of-flowcloud-their/

[7] https://www.theregister.com/2022/02/23/apt10_operation_cache_panda_taiwan/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yzm1mkixwLBn0WnoNHO46QAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/09/28/fast_company_hack_apple_news/

[10] https://www.theregister.com/2022/09/25/noberus_ransomware_symantec/

[11] https://www.theregister.com/2022/09/23/cyberattack_optus/

[12] https://www.theregister.com/2022/09/22/microsoft_android_spyware_endpoint/

[13] https://whitepapers.theregister.com/



It's a genuine threat

Danny 2

I clicked on a photo of the Prime Minister and my nephew lost his mortgage, my benefits were cut and the Bank of England was scammed out of £65 billion.

XKCD is coming back to London on November the 7th.

IoC

Bitsminer

The Windows logo always was an "indicator of compromise" for some people. For example, some Linux fanbois.

Some hackers took the hint seriously...

Re: IoC

John Robson

The old "I heard that if you play the Windows install CD backwards it plays satanic messages", "That's nothing, I heard if you play it forwards it installs Windows."

Trusted hosts

VoiceOfTruth

-> trusted hosts such as GitHub

Since when is GitHub a trusted host? Perhaps the author of the article has a different definition to me. Trusted to me means somebody or something that I know or I trust. The next level down is somebody who I know and trust says that such a thing is trustworthy - a chain of trust. But GitHub? It is a web site where people submit code. Are we now supposed to trust something just because it is on GitHub?

I know what the author is getting at - GitHub is well known. But that does not automatically make it trustworthy. NPM was considered trustworthy by many, and look what happened. Anyone who just automatically trusts GitHub and therefore anything on it needs a lesson or two.

Re: Trusted hosts

Will Godfrey

"Anyone who just automatically trusts GitHub and therefore anything on it needs a lesson or two."

... and will probably soon get them.

If you keep your mind sufficiently open, people will throw a lot of
rubbish into it.
-- William Orton