News: 1702318095

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Memory-safe languages so hot right now, agrees Lazarus Group as it slings DLang malware

(2023/12/11)


Research into Lazarus Group's attacks using Log4Shell has revealed novel malware strains written in an atypical programming language.

DLang is among the newer breed of memory-safe languages being [1]endorsed by Western security agencies over the past few years, the same type of language that cyber criminals are switching to.

At least three new DLang-based malware strains have been used in attacks on worldwide organizations spanning the manufacturing, agriculture, and physical security industries, Cisco Talos revealed today.

[2]

The attacks form part of what's being called "Operation Blacksmith" and are attributed to a group tracked as Andariel, believed to be a sub-division of the Lazarus Group – North Korea's state-sponsored offensive cyber unit.

[3]

[4]

Operation Blacksmith saw the regular targeting of organizations exposed to n-day vulnerabilities, such as the [5]critical log4j vulnerability disclosed in December 2021 (CVE-2021-44228).

NineRAT was associated with attacker activity after exploiting public-facing VMware Horizon servers with [6]Log4Shell – the industry-coined term for exploits of the log4j vulnerability – and uses Telegram bots and channels for its C2 infrastructure.

[7]

Through unpicking the remote access trojan (RAT), researchers at Cisco Talos discovered that it was first built around May 2022 but was only used in attacks starting in March 2023 [8]through to October .

The October attacks on JetBrains' TeamCity CI/CD tool were also attributed to Andariel. The group itself is typically tasked with gaining access to organizations and long-term access for cyber espionage campaigns, but has been known to carry out ransomware attacks.

The attacks it carried out using NineRAT shared similar tactics, techniques, and procedures (TTPs) to those seen in prior attacks, with a common finding being the use of the HazyLoad proxy tool previously only seen in the TeamCity attacks.

[9]

NineRat's use of Telegram is understood to be for the purposes of evading detection from network and host-based measures. Running malicious traffic through a legitimate service is a common tactic used by cybercriminals who have used other social platforms such as [10]Discord for the same purposes.

BottomLoader was the second strain identified by researchers and acts as a downloader for second-stage attacks, like the HazyLoad tool. It downloads payloads from a hardcoded URL via a PowerShell command, and can upload files also via a PowerShell command.

It can also establish persistence for follow-up payloads by creating a .URL file in the Startup directory, relying on PowerShell again to download any follow-up packages.

Finally, DLRAT acts as a downloader for additional malware payloads, gathers session information before returning it to the attackers, and also has RAT capabilities.

Moving to memory safety

The researchers noted that DLang is an uncommon choice for writing malware, but a shift towards newer languages and frameworks is one that's been accelerating over the last few years – in malware coding as in the larger programming world.

Rust, however, has often shown itself to be the preferred choice out of what is a fairly broad selection of languages deemed to be memory-safe.

AlphV/BlackCat was the first ransomware group to [11]make such a shift last year, re-writing its payload in Rust to offer its affiliates a more reliable tool. A month later, the now-shuttered Hive group [12]did the same thing , and many others followed after that.

Other groups to snub Rust include China-based Sandman which was [13]recently observed using Lua-based malware, believed to be part of a wider shift toward Lua development from Chinese attackers.

Rust is the "most loved" of all the development languages, according to Stack Overflow's annual developer surveys, and that's consistently been the case for the last seven years.

[14]After six days and thousands of pwned users, Cisco poised to patch IOS XE flaw

[15]Windows breaks under upgraded IceXLoader malware

[16]Dump C++ and in Rust you should trust, Five Eyes agencies urge

[17]Small but mighty, 9Front's 'Humanbiologics' is here for the truly curious

It's frequently [18]mentioned in the same breath as the likes of Go, Ruby, Swift, and others for their memory safety, but developers often report enjoying the experience of writing in Rust more than other languages.

It also performs better than some of its peers, like Go, which is sometimes criticized for its garbage collector slowing applications down. Rust binned its garbage collector years ago, and as a result runs comparatively faster than some other languages like it.

DLang also has a garbage collector, meaning that in some cases it may run slower than Rust, but a benefit of languages like DLang and Go is that they have faster compile times, so it can be a trade-off developers make based on their preferences. ®

Get our [19]Tech Resources



[1] https://www.theregister.com/2023/12/07/memory_correction_five_eyes/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXeUmvWVzjd5CE6IhsRj7wAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXeUmvWVzjd5CE6IhsRj7wAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXeUmvWVzjd5CE6IhsRj7wAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/12/10/log4j_remote_code_execution_vuln_patch_issued/

[6] https://www.theregister.com/2023/12/11/log4j_vulnerabilities/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXeUmvWVzjd5CE6IhsRj7wAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/10/22/in_brief_security/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXeUmvWVzjd5CE6IhsRj7wAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/07/23/discord_malware_channel/

[11] https://www.theregister.com/2022/06/15/blackcat-ransomware-microsoft/

[12] https://www.theregister.com/2022/07/06/hive-ransomware-rust-microsoft/

[13] https://www.sentinelone.com/labs/sandman-apt-china-based-adversaries-embrace-lua/

[14] https://www.theregister.com/2023/10/22/in_brief_security/

[15] https://www.theregister.com/2022/11/10/icexloader_malware_microsoft_users/

[16] https://www.theregister.com/2023/12/07/memory_correction_five_eyes/

[17] https://www.theregister.com/2023/12/01/9front_humanbiologics/

[18] https://www.theregister.com/2022/11/11/nsa_urges_orgs_to_use/

[19] https://whitepapers.theregister.com/



Paul Crawford

Are they really using it for memory-safety, or is it due to a greater difficulty in reverse-engineering captured malware in those languages?

Lazy Meta-Curry

HuBo

Wow! DLang sounds almost like a faster, compiled, LISP, the language that " freed ITS's hackers to think in unusual and creative ways " back in 1969. I'd congratulate the Norks' Lazarus Blacksmiths on this choice of PL but they're the bad guys so let's hope they either become more friendly through its use (via the mind-expanding side-effects of dynamic programming languages), or just plain choke on it (in the nicest possible way).

Re: Lazy Meta-Curry

Blazde

Those side-effects are the worst part of malware. If only the bad guys would stick to purely functional code the world would be a better place

karlkarl

DLang is more important in this area in that it can directly consume C APIs (which is fairly important for malware accessing various operating system subsystems, almost exclusively exposed as C APIs).

Rust via bindgen to generate a fairly rough 80% of bindings and then fetching the rest of the bloat from NPM-style crates.io is less than ideal for anyone's software development pipeline, including malware authors.

C and C++ are still the malware language of choice though. It mirrors much of the industry at a systems-level to be fair.

Pie are not square. Pie are round. Cornbread are square.