An emerging area of inquiry in security research is the blurring boundaries between cybercrime and other, more targeted forms of attack, and more specifically attacks that appear to be politically motivated. These attacks often take the form of targeted malware attacks that act as a form of surveillance in which sensitive documents and communications are captured from the targeted organizations and individuals or politically motivated Denial of Service attacks that aim to punish, disrupt and/or censor the ability of the targets to communicate to the world.
One of the themes that informed the "Shadows in the Cloud" report was the (potential) relationship between crimeware networks and cyber-espionage. The boundaries between the two appear to be blurring making issues of attribution increasingly more complex. It may also indicate that there is an emerging market for sensitive information and/or politically motivated attacks as crimeware networks seek to monetize such information and capabilities.
I explored this theme in a report on a case related to Kneber botnet documented by NetWitness in which a known ZeuS-based botnet, typically used to steal banking information and other credentials, was specifically targeting .mil and .gov email addresses with spearphishing attacks and then dropping a second piece of malware, an infostealer, on the compromised systems that uploaded sensitive documents to a drop zones in Belarus and Russia. This botnet was engaged in all sorts of other malicious activity associated with cybercrime.
When it comes to DDoS attacks a similar pattern is observed. Jose Nazario of Arbor Networks wrote a very interesting paper that analyzed politically motivated DDoS attacks (and is basically the inspiration for this blog post). The numerous DDoS attacks described in this paper are very interesting, some are punitive attacks others appear to be an effort to censor political speech (something I worked on at ONI in the past with Kyrgyzstan in 2005 and Belarus in 2006). In the paper Nazario dicusses the role that well known BlackEnergy-based botnets played in the DDoS attacks on Georgian websites during the Russia-Georgia conflict in 2008. In a really amazing presentation Jose Nazario and Andre DiMino of Shadowserver document the attacks on Georgia. But what is most interesting, in this context, are the other unrelated targets that the same botnets also attacked. The RU-GE case is a great example of the blurring boundaries between crimeware networks, politically motivated attacks a censorship.
On a much smaller scale, I observed some recent attacks in which a BlackEnergy-based botnet attacked a variety of unrelated targets but eventually attacked political websites. The botnet was discovered while analyzing data captured from the computer of a Tibetan political figure. Due to the character of the network Greg Walton and I concluded that the attack was not targeted and was not related to the Tibet or to the political activities of the individual who was compromised. However, I continued to monitor the botnet.
The botnet had two command and control domain names 091809.ru and sexiland.ru both hosted on the same IP address (210.51.166.238, China Netcom). The command and control interface was not password protected and I was able to access it and determine the size of the botnet. According to the statistics in the interface, 091809.ru had 2044 active bots, an average of 2418 per hour and 8105 per day. In total the 091809.ru recorded 64346 infections. According to the statistics in the interface, sexiland.ru (210.51.166.238) had 3623 active bots, an average of 4869 per hour and 12749 per day. In total the sexiland.ru recorded 51813 infections. This is not a particularly large botnet at all, but the attackers could access at least 6000 bots at any given time.
This botnet attacked a variety of websites, however, four of them caught my attention.
1. bachuna.net
2009-12-15 05:00:01
flood http bachuna.net
The attackers began flooding bachuna.net on 2009-12-15. The attacks appear to relate to Ukrainian news stories (here, here, here and here) which broke around the same time as the attacks started involving a judge named Oleg Bachun and two competing websites bachuna.net and bachun.net. While the former was supportive of the judge the latter implicated him in illegal activities. Since I am relying on Google Translate it would be great of some Russia and Ukrainian speakers could provide a more in-depth assessment of what happened in the case as well as to the domain names involved as it appears from the reports that bachun.net was transfered to the owner of bachuna.net.
2. ingushetiyaru.org
2010-01-16 18:00:01 - 2010-01-20 06:00:02
flood http www.ingushetiyaru.org
Rights in Russia reported that "a website run by an opposition group in Ingushetia, Ingushetiyaru.org, suffered a DDoS attack after publishing comments critical of the region’s authorities." Ingushetia is located near Chechnya and is a politically sensitive area. Ingushetiyaru.org reported the DDoS on their livejournal site and the broader implications in this article. This is not the first time there have DDoS attacks related to this region. Jeff Carr reported on another DDoS attack and implicated the RBN in the attack.
3. angusht.com
2010-01-22 12:00:01 - 2010-01-26 15:00:02
flood http angusht.com
This website, angusht.com, is also related to Ingushetia and reported DDoS attacks (here too) earlier this year. Several other related sites were also reported to be inacessible. The timing of the inaccessibility of the sites and the DDoS attacks on angusht.com and ingushetiyaru.org also correlate with reports of an explosion of a gas pipeline in Ingushetia.
4. kadyrov2012.com
2010-01-25 08:00:02 - 2010-01-27 02:00:01
flood http kadyrov2012.com
The website kadyrov2012.com was a satirical website claiming that the Russian-backed Chechen leader Ramzan Kadyrov was going to run in for president in Russia's elections. Reuters reported the story on January 24 which correlate with the timing of the DDoS attacks.
These attacks are fairly small when compared with others and fly under the radar screen of most. They show that small scale attacks designed to censor opposing views occur with frequency against key websites and during critical time periods. It is clear that those engaged in political activities and those who vocally oppose repressive policies such as censorship may be subjected to a complex set of threats from targeted malware through to DDoS and not simply censorship in the form of Internet filtering. Finally, these attacks demonstrate that botnets involved with criminal activity are being used to conduct both political and apolitical DDoS attacks
Sites DDoS'd by this botnet:
flood http 195.216.243.39
flood http 208.64.123.225
flood http 213.155.12.120
flood http 217.107.35.35
flood http 217.17.158.55
flood http 217.20.163.4
flood http 62.149.24.2
flood http 72.20.34.140
flood http 80.93.54.57
flood http 82.146.43.3
flood http 89.108.126.2
flood http 94.198.51.216
flood http angusht.com
flood http angusht.com index.php
flood http angusht.com personal subscribe subscr_edit.php
flood http antiddos.org
flood http asterios.tm
flood http asterios.tm index.php
flood http asteriys.com index.php?f=stat&act=online&server=0
flood http attackers.ru
flood http bachuna.net
flood http bankunet.com
flood http barbars.ru
flood http blud.net
flood http carderfix.ru
flood http carder.info
flood http carder.info index.php
flood http carder.info,l2.theonline.ru
flood http carder.su
flood http carder.su showgroups.php
flood http ddef.ru
flood http do-finance.com
flood http fan-age.ru,l2.exsade.com,forum.exsade.com,final-zone.ru
flood http filebase.to
flood http forum.notebook812.ru
flood http forum.timesgame.ru,timesgame.ru
flood http internet-guard.net index.php
flood http kadyrov2012.com
flood http kadyrov2012.com
flood http kadyrov2012.com index
flood http karyatour.com.ua
flood http l2jfree.com
flood http la2.100nt.ru
flood http la2.timesgame.ru
flood http lineage.cn.km.ua
flood http ll2.su
flood http meridian-express.ru
flood http modcam.ru
flood http notebook812.ru
flood http notebook812.ru
flood http ohah.ru
flood http ohah.ru index.php
flood http planety-hackeram.ru
flood http portal27.ru
flood http pupsa.net
flood http rodi.ru
flood http rosban.su
flood http sever.ru
flood http slineage.ru
flood http smsdeal.ru index.php
flood http takwap.ru
flood http takwap.ru 111 XXX_DETKA
flood http takwap.ru 157 xxx ohah.ru
flood http teamsteam.ru
flood http vpotoke.com
flood http wapfan.org index.php
flood http wow.cln.ru
flood http www.2simtv.ru index.php
flood http www.angusht.com index.php
flood http www.art-taxi.ru
flood http www.glazey.ru
flood http www.ingushetiyaru.org
flood http www.notebook812.ru
flood http www.prado-club.su
flood http www.prado-club.su forum
flood http www.ripoffreport.com
flood http xaknet.ru
flood icmp forum.antichat.ru
flood syn www.ripoffreport.com 80
Saturday, April 10, 2010
Monday, April 5, 2010
Shadows in the Cloud
Last year, at just about this time, the InfoWar Monitor (IWM) released the "Tracking GhostNet" report which detailed our investigation into a cyber-espionage network that has compromised 1200+ computer systems spread across 103 countries, including ministries of foreign affairs, embassies, international organizations, news organizations, and even a computer located at NATO headquarters.
I remember when I stumbled upon the GhostNet attacker's command and control interface by Googling a string of text from the network traffic obtained during our field investigation from a compromised computer at the Dalai Lama's office in Dharamsala , India. To my surprise Google returned several results, which I clicked, and was suddenly looking at an interface that allowed the attackers to fully control a network of compromised computer system. When the report came out and I realized the significance of the find I thought that there was no way it would happen again. I was wrong.
Today the IWM and the Shadowserver Foundation have released a report "Shadows in the Cloud: An investigation into cyber espionage 2.0" (mirror) in which we document another targeted malware network. (NYT coverage here). We started by exploring one of the malware networks described in the GhostNet report but was an entirely separate malware network that had also compromised computers at the Dalai Lama's office. I cannot stress just how important the trust, collaboration and information sharing across all those involved in this report from the Citizen Lab, SecDev , and Shadowserver, along with the Dalai Lama's Office were to the success of the project.
As a result we were able to document another network of compromised government, business, and academic computer systems in India, the Office of the Dalai Lama, and the United Nations as well as numerous other institutions, including the Embassy of Pakistan in the United States.
In the report we enumerated a complex and tiered command and control infrastructure. The attackers misused a variety of services including Twitter, Google Groups, Blogspot, Baidu Blogs, blog.com and Yahoo! Mail in order to maintain persistent control over the compromised computers. This top layer directed compromised computers to accounts on free web hosting services, and as the free hosting servers were disabled, to a stable core of command and control servers located in China.
This time, unlike GhostNet, we were able to recover data, some of which are highly sensitive, from a drop zone used by the attackers. One day, while exploring open directories on one of the command and control servers I noticed that there were files in a directory that was normally empty. It turned out that the attackers were directing compromised computers to upload data to this directory; the attackers subsequently moved the data off to another location and deleted the files at fairly rapid, but intermittent time intervals.
We recovered a wide variety of documents including one document that appears to be encrypted diplomatic correspondence, two documents marked "SECRET", six as "RESTRICTED" and five as "CONFIDENTIAL" which appear to belong to the Indian government. We also recovered documents including 1,500 letters sent from the Dalai Lama's office between January and November 2009.
Based on the character of the documents (and not IP addresses) we assessed that we recovered documents from the National Security Council Secretariat (NSCS) of India, the Embassy of India, Kabul, the Embassy of India, Moscow, the Consulate General of India, Dubai, and the High Commission of India in Abuja, Nigeria. In addition, we recovered documents from India's Military Engineer Services (MES) and other military personnel as well as the Army Institute of Technology in Pune, Maharashtra and the Military College of Electronics and Mechanical Engineering in Secunderabad, Andhra Pradesh. Documents from a variety of other entities including the Institute for Defence Studies and Analyses as well as India Strategic defence magazine and FORCE magazine were compromised.
Questions regarding those who are ultimately responsible for this cyber-espionage network remain unanswered. We were, however, able to benefit from a great investigation by The Dark Visitor who tracked down lost33, the person who registered some of the Shadow network's domain names that we published in the GhostNet report and his connections ot the underground hacking community in China. Based on the IP and email addresses used by the attackers we were able to link the attackers to several posts on apartment rental sites in Chengdu.
This, of course, does not reveal the role of these specific individuals nor the motivation behind the attacks. However, the connection that The Dark Visitor drew between lost33 and the underground hacking community in China does indicate that motivations such as patriotic hacking and cybercrime may have played a role. Finally, the nature of the data stolen by the attackers does indicate correlations with the strategic interests
of the Chinese state. But, we were unable to determine any direct connection between these attackers and elements of the Chinese state. However, it would not be implausible to suggest that the stolen data may have ended up in the possession of some entity of the Chinese government.
Now having reported this incident to the China CERT -- which handles security incidents in China -- I look forward to working with them to shut down this malware network.
This is an investigation in progress. There are many threads in this investigation that have still to be fully explored. I hope that this report provides enough detail to allow others with different specializations to continue to explore aspects of the Shadow network enriching our collective understanding of this incident and the broader implications regarding both cyber-crime and cyber-espionage.
I remember when I stumbled upon the GhostNet attacker's command and control interface by Googling a string of text from the network traffic obtained during our field investigation from a compromised computer at the Dalai Lama's office in Dharamsala , India. To my surprise Google returned several results, which I clicked, and was suddenly looking at an interface that allowed the attackers to fully control a network of compromised computer system. When the report came out and I realized the significance of the find I thought that there was no way it would happen again. I was wrong.
Today the IWM and the Shadowserver Foundation have released a report "Shadows in the Cloud: An investigation into cyber espionage 2.0" (mirror) in which we document another targeted malware network. (NYT coverage here). We started by exploring one of the malware networks described in the GhostNet report but was an entirely separate malware network that had also compromised computers at the Dalai Lama's office. I cannot stress just how important the trust, collaboration and information sharing across all those involved in this report from the Citizen Lab, SecDev , and Shadowserver, along with the Dalai Lama's Office were to the success of the project.
As a result we were able to document another network of compromised government, business, and academic computer systems in India, the Office of the Dalai Lama, and the United Nations as well as numerous other institutions, including the Embassy of Pakistan in the United States.
In the report we enumerated a complex and tiered command and control infrastructure. The attackers misused a variety of services including Twitter, Google Groups, Blogspot, Baidu Blogs, blog.com and Yahoo! Mail in order to maintain persistent control over the compromised computers. This top layer directed compromised computers to accounts on free web hosting services, and as the free hosting servers were disabled, to a stable core of command and control servers located in China.
This time, unlike GhostNet, we were able to recover data, some of which are highly sensitive, from a drop zone used by the attackers. One day, while exploring open directories on one of the command and control servers I noticed that there were files in a directory that was normally empty. It turned out that the attackers were directing compromised computers to upload data to this directory; the attackers subsequently moved the data off to another location and deleted the files at fairly rapid, but intermittent time intervals.
We recovered a wide variety of documents including one document that appears to be encrypted diplomatic correspondence, two documents marked "SECRET", six as "RESTRICTED" and five as "CONFIDENTIAL" which appear to belong to the Indian government. We also recovered documents including 1,500 letters sent from the Dalai Lama's office between January and November 2009.
Based on the character of the documents (and not IP addresses) we assessed that we recovered documents from the National Security Council Secretariat (NSCS) of India, the Embassy of India, Kabul, the Embassy of India, Moscow, the Consulate General of India, Dubai, and the High Commission of India in Abuja, Nigeria. In addition, we recovered documents from India's Military Engineer Services (MES) and other military personnel as well as the Army Institute of Technology in Pune, Maharashtra and the Military College of Electronics and Mechanical Engineering in Secunderabad, Andhra Pradesh. Documents from a variety of other entities including the Institute for Defence Studies and Analyses as well as India Strategic defence magazine and FORCE magazine were compromised.
Questions regarding those who are ultimately responsible for this cyber-espionage network remain unanswered. We were, however, able to benefit from a great investigation by The Dark Visitor who tracked down lost33, the person who registered some of the Shadow network's domain names that we published in the GhostNet report and his connections ot the underground hacking community in China. Based on the IP and email addresses used by the attackers we were able to link the attackers to several posts on apartment rental sites in Chengdu.
This, of course, does not reveal the role of these specific individuals nor the motivation behind the attacks. However, the connection that The Dark Visitor drew between lost33 and the underground hacking community in China does indicate that motivations such as patriotic hacking and cybercrime may have played a role. Finally, the nature of the data stolen by the attackers does indicate correlations with the strategic interests
of the Chinese state. But, we were unable to determine any direct connection between these attackers and elements of the Chinese state. However, it would not be implausible to suggest that the stolen data may have ended up in the possession of some entity of the Chinese government.
Now having reported this incident to the China CERT -- which handles security incidents in China -- I look forward to working with them to shut down this malware network.
This is an investigation in progress. There are many threads in this investigation that have still to be fully explored. I hope that this report provides enough detail to allow others with different specializations to continue to explore aspects of the Shadow network enriching our collective understanding of this incident and the broader implications regarding both cyber-crime and cyber-espionage.
Vietnam & Aurora
[UPDATE: See "Vecebot Trojan Analysis" by SecureWorks.]
A while back I wrote a post about "Aurora Mess" in which I tried, unsuccessfully, to make sense of the different assessments of the attacks on Google and at least 20 other companies within the security community. I was trying to grapple with the way in which Google and McAfee were characterizing the attacks as sophisticated while Damballa labeled them amateurish and connected them to some common cybercrime activities. Well, it turns out that it was a confusing for a reason. (And is still confusing, check out Damballa's reaction to "Aurora Lite")
Some of the domain names included as part of Aurora turned out to be not part of Aurora. McAfee explains:
Turns out that these domain names (google.homeunix.com tyuqwer.dyndns.org blogspot.blogsite.org voanews.ath.cx ymail.ath.cx), once included as part of Aurora - an attack traced to China -- were now traced Vietnam. It looks the domains were erroneously included as part of Aurora because they were discovered during the Aurora investigation:
Neel Mehta of Google noted that there may be a political dimension to the attacks:
In terms of the attack vector, McAfee's Kurtz stated:
To Summarize, from Google and McAfee, we have:
The website that may have been DDoS'd in connection with the bauxite mine may have been bauxitevietnam.info.
The AP's Ben Stocking reports that:
Stocking also reported:
OK, so maybe there is a China connection. Or maybe not.
McAfee points out that:
Ok, back to the Aurora mess. Damballa found a sample on 2009-08-19 which they classified as Fake AV / Scareware masquerading as Microsoft Antispyware Services. This malware used several of the same command and control servers as noted by McAfee (google.homeunix.com
voanews.ath.cx ymail.ath.cx) along with more yahoo.blogdns.net, ec2-79-125-21-42.eu-west-1.compute.amazonaws.com, and ip-173-201-21-161.ip.secureserver.net inekoncuba.inekon.co.cu.
8 April 2009 - bb2aa6bf91388242dcff552eb476c545
16 April 2009 - 4488dea2071f0818d3b6269a061c2df6
3 December 2009 - 69baf3c6d3a8d41b789526ba72c79c2d
20 January 2010 - 7ee6628b8caeef57607e5426261b8c0c
McAfee has the date for W32/Vulcanbot as 01/23/2010 nine months after a sample was submitted to a ThreatExpert with common command and control servers. Is this really a new botnet? What are the apparently politically motivated attacks doing with rogue AV and typical crimeware junk? Without detailed information about the Vietnamese case its very difficult to make an accurate assessment.
A while back I wrote a post about "Aurora Mess" in which I tried, unsuccessfully, to make sense of the different assessments of the attacks on Google and at least 20 other companies within the security community. I was trying to grapple with the way in which Google and McAfee were characterizing the attacks as sophisticated while Damballa labeled them amateurish and connected them to some common cybercrime activities. Well, it turns out that it was a confusing for a reason. (And is still confusing, check out Damballa's reaction to "Aurora Lite")
Some of the domain names included as part of Aurora turned out to be not part of Aurora. McAfee explains:
While originally some of these domains and files had been reported to be associated with Operation Aurora, we have since come to believe that this malware is unrelated to Aurora and uses a different set of Command & Control servers.
Turns out that these domain names (google.homeunix.com tyuqwer.dyndns.org blogspot.blogsite.org voanews.ath.cx ymail.ath.cx), once included as part of Aurora - an attack traced to China -- were now traced Vietnam. It looks the domains were erroneously included as part of Aurora because they were discovered during the Aurora investigation:
We suspect the effort to create the botnet started in late 2009, coinciding by chance with the Operation Aurora attacks. While McAfee Labs identified the malware during our investigation into Operation Aurora, we believe the attacks are not related.
Neel Mehta of Google noted that there may be a political dimension to the attacks:
The malware infected the computers of potentially tens of thousands of users who downloaded Vietnamese keyboard language software and possibly other legitimate software that was altered to infect users. While the malware itself was not especially sophisticated, it has nonetheless been used for damaging purposes. These infected machines have been used both to spy on their owners as well as participate in distributed denial of service (DDoS) attacks against blogs containing messages of political dissent. Specifically, these attacks have tried to squelch opposition to bauxite mining efforts in Vietnam, an important and emotionally charged issue in the country.
In terms of the attack vector, McAfee's Kurtz stated:
We believe the attackers first compromised www.vps.org, the Web site of the Vietnamese Professionals Society (VPS), and replaced the legitimate keyboard driver with a Trojan horse. The attackers then sent an e-mail to targeted individuals which pointed them back to the VPS Web site, where they downloaded the Trojan instead.
To Summarize, from Google and McAfee, we have:
- Command and control servers are google.homeunix.com tyuqwer.dyndns.org blogspot.blogsite.org voanews.ath.cx ymail.ath.cx
- The botnet started in late 2009, coinciding with the Aurora attacks, which would make the date mid-December
- There were targeted attacks that encouraged the download of malicious software from www.vps.org which had already been compromise and was hosting the malware
- The malware, W32/VulcanBot, was disguised as a Vietnamese keyboard driver
- This botnet DDoSed sites that opposed a bauxite mine in Vietnam
The website that may have been DDoS'd in connection with the bauxite mine may have been bauxitevietnam.info.
The AP's Ben Stocking reports that:
Last fall, the government detained several bloggers who criticized the bauxite mine, and in December, a Web site called bauxitevietnam.info, which had drawn millions of visitors opposed to the mine, was hacked.
Stocking also reported:
Vietnam has hired a Chinese company to build the plant to process bauxite taken from the mines and hundreds of Chinese are reportedly working there.
Vietnam has some of the world's largest reserves of bauxite, the primary ingredient in aluminum. The government has argued that the mine would bring economic benefits to the impoverished Central Highlands.
Opponents say the project would cause major environmental problems and have raised the specter of Chinese workers flooding into the strategically sensitive region.
OK, so maybe there is a China connection. Or maybe not.
McAfee points out that:
The command and control servers were predominantly being accessed from IP addresses in Vietnam.
Ok, back to the Aurora mess. Damballa found a sample on 2009-08-19 which they classified as Fake AV / Scareware masquerading as Microsoft Antispyware Services. This malware used several of the same command and control servers as noted by McAfee (google.homeunix.com
voanews.ath.cx ymail.ath.cx) along with more yahoo.blogdns.net, ec2-79-125-21-42.eu-west-1.compute.amazonaws.com, and ip-173-201-21-161.ip.secureserver.net inekoncuba.inekon.co.cu.
8 April 2009 - bb2aa6bf91388242dcff552eb476c545
16 April 2009 - 4488dea2071f0818d3b6269a061c2df6
3 December 2009 - 69baf3c6d3a8d41b789526ba72c79c2d
20 January 2010 - 7ee6628b8caeef57607e5426261b8c0c
McAfee has the date for W32/Vulcanbot as 01/23/2010 nine months after a sample was submitted to a ThreatExpert with common command and control servers. Is this really a new botnet? What are the apparently politically motivated attacks doing with rogue AV and typical crimeware junk? Without detailed information about the Vietnamese case its very difficult to make an accurate assessment.
Subscribe to:
Posts (Atom)