Modified version of Tor Browser spies on Chinese users
(2022/10/05)
- Reference: 1664969526
- News link: https://www.theregister.co.uk/2022/10/05/tor_browser_china_spy_kasperksy_research/
- Source link:
Cybersecurity biz Kaspersky has spotted a modified version of the Tor Browser it says collects sensitive data on Chinese users.
The data collected by the browser itself includes internet history and data entered into website forms, said the threat hunter. More spyware was hidden in an accompanying library that collected further data, including computer name and location, user name, and MAC addresses of network adapters, before sending it to a command and control server.
The icing on the cake is an embedded functionality to execute shell commands, thus giving the attacker full control over the machine. The Tor Browser is designed for anonymity and enables use of the dark web. While some of the activity it facilitates is illegal, it is also often used for legitimate purposes. However, it is blocked in China.
[1]
Which is why Chinese residents sometimes resort to creative ways of downloading it, usually from third-party websites. In the case of the malicious version found by [2]Kaspersky, a link was posted in January 2022 on a YouTube channel that advocates internet anonymity in the Chinese language.
[3]
[4]
YouTube is also banned in China, though people can access the site through a VPN.
The malicious Tor Browser installer was hosted on a Chinese cloud sharing service and appears identical in terms of user interface to the authentic one. However, it did not have a digital signature and some of the files obviously differed from the original, said Kaspersky.
[5]
The Tor project does [6]offer some tips on using the product while in China and it begins with emailing it for an updated version of Tor Browser. For the record, The Reg is not advocating doing this nor for breaking any laws in China.
[7]Two years on, Apple iOS VPNs still leak IP addresses
[8]Tor onion hardening will be tear-inducing for feds
[9]BreachForums booms on the back of billion-record Chinese data leak
[10]Tor blimey, Auntie! BBC launches dedicated dark web mirror site
"We decided to dub this campaign 'OnionPoison', naming it after the onion routing technique that is used in Tor Browser," said Kaspersky. Onion routing earned its name as it is a method for encapsulating messages in layers of encryption as if the messages are the center of an onion.
Kaspersky confirmed the threat actors were targeting victims in China as attempts to communicate with the C2 server and retrieve a second stage DLL only worked when faking a Chinese IP address. It is also difficult to access using automated malware analysis sandboxes.
"Curiously, unlike common stealers, OnionPoison implants do not automatically collect user passwords, cookies or wallets. Instead, they gather data that can be used to identify the victims, such as browsing histories, social networking account IDs and Wi-Fi networks," said Kaspersky.
"The attackers can search the exfiltrated browser histories for traces of illegal activity, contact the victims via social networks and threaten to report them to the authorities," added the cybersecurity company.
[11]
Modified Tor Browsers are not new, they've been used by attackers in the past and law enforcement has been accused of deploying them as well.
"Regardless of the actor's motives, the best way to avoid getting infected with OnionPoison implants is to always download software from official websites," warned Kaspersky. "If that's not an option, verify the authenticity of installers downloaded from third-party sources by examining their digital signatures." ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://support.torproject.org/censorship/connecting-from-china/
[7] https://www.theregister.com/2022/08/19/apple_ios_vpn/
[8] https://www.theregister.com/2016/06/23/tot_project_selfrando/
[9] https://www.theregister.com/2022/07/29/breachedforums_popularity_surge/
[10] https://www.theregister.com/2019/10/24/beeb_launches_dedicated_dark_web_site/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
The data collected by the browser itself includes internet history and data entered into website forms, said the threat hunter. More spyware was hidden in an accompanying library that collected further data, including computer name and location, user name, and MAC addresses of network adapters, before sending it to a command and control server.
The icing on the cake is an embedded functionality to execute shell commands, thus giving the attacker full control over the machine. The Tor Browser is designed for anonymity and enables use of the dark web. While some of the activity it facilitates is illegal, it is also often used for legitimate purposes. However, it is blocked in China.
[1]
Which is why Chinese residents sometimes resort to creative ways of downloading it, usually from third-party websites. In the case of the malicious version found by [2]Kaspersky, a link was posted in January 2022 on a YouTube channel that advocates internet anonymity in the Chinese language.
[3]
[4]
YouTube is also banned in China, though people can access the site through a VPN.
The malicious Tor Browser installer was hosted on a Chinese cloud sharing service and appears identical in terms of user interface to the authentic one. However, it did not have a digital signature and some of the files obviously differed from the original, said Kaspersky.
[5]
The Tor project does [6]offer some tips on using the product while in China and it begins with emailing it for an updated version of Tor Browser. For the record, The Reg is not advocating doing this nor for breaking any laws in China.
[7]Two years on, Apple iOS VPNs still leak IP addresses
[8]Tor onion hardening will be tear-inducing for feds
[9]BreachForums booms on the back of billion-record Chinese data leak
[10]Tor blimey, Auntie! BBC launches dedicated dark web mirror site
"We decided to dub this campaign 'OnionPoison', naming it after the onion routing technique that is used in Tor Browser," said Kaspersky. Onion routing earned its name as it is a method for encapsulating messages in layers of encryption as if the messages are the center of an onion.
Kaspersky confirmed the threat actors were targeting victims in China as attempts to communicate with the C2 server and retrieve a second stage DLL only worked when faking a Chinese IP address. It is also difficult to access using automated malware analysis sandboxes.
"Curiously, unlike common stealers, OnionPoison implants do not automatically collect user passwords, cookies or wallets. Instead, they gather data that can be used to identify the victims, such as browsing histories, social networking account IDs and Wi-Fi networks," said Kaspersky.
"The attackers can search the exfiltrated browser histories for traces of illegal activity, contact the victims via social networks and threaten to report them to the authorities," added the cybersecurity company.
[11]
Modified Tor Browsers are not new, they've been used by attackers in the past and law enforcement has been accused of deploying them as well.
"Regardless of the actor's motives, the best way to avoid getting infected with OnionPoison implants is to always download software from official websites," warned Kaspersky. "If that's not an option, verify the authenticity of installers downloaded from third-party sources by examining their digital signatures." ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://support.torproject.org/censorship/connecting-from-china/
[7] https://www.theregister.com/2022/08/19/apple_ios_vpn/
[8] https://www.theregister.com/2016/06/23/tot_project_selfrando/
[9] https://www.theregister.com/2022/07/29/breachedforums_popularity_surge/
[10] https://www.theregister.com/2019/10/24/beeb_launches_dedicated_dark_web_site/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yz2qH2Jx@cS1nqKipBF0bgAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Potemkine!
For the record, The Reg is not advocating doing this nor for breaking any laws in China.
Making in your pants, pals? :-P
There was a time people in UK were not afraid of dictatorships...
== Bring us Dabbsy back! ==
Anonymous Coward
Its part of the standardisation on USA-speak.
Sounds familiar. . .
SotarrTheWizard
. . .just another version of the milspeak "We can neither confirm nor deny <$foo>" . . .
Authenticity verification
regadpellagru
"If that's not an option, verify the authenticity of installers downloaded from third-party sources by examining their digital signatures."
Well, how to do that in China, since Tor's site is blocked ?
The best way I could think of, would be to phone a pal outside of china, to give you the signature by phone ...
Digital signature?
the original Tor browser has no digital signatures in the file properties either (when it is installed) and its files even have a fake timestamp of 01-01-2000.
Since they have practically "trained" their users not to bother with checking file properties for a signature on the main browser executable, it is no wonder they do as they were told and will not even bother checking installers either.