Tuesday, June 6, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

undetected since 2021 and resists firmware update

Researcher by Researcher
March 20, 2023
in Cybersecurity
0
undetected since 2021 and resists firmware update
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


A possible Chinese attack campaign on compromised unpatched SonicWall SMA edge devices stayed undetected since 2021 and could persist even through firmware updates.

A model representing edge computing security with connected devices.
Image: ArtemisDiana/Adobe Stock

As reported by a new Mandiant research document, a new malware is made of several bash scripts and a single Executable and Linkable Format (ELF) binary file identified as a TinyShell backdoor variant. Tinyshell is a publicly available tool used by several threat actors (Figure A).

Figure A

Related articles

Sentra Raises $30 Million for DSPM Technology

Dozens of Malicious Extensions Found in Chrome Web Store

June 6, 2023
Learn how to protect your company from cyberattacks for just $46

Learn how to protect your company from cyberattacks for just $46

June 5, 2023
List of malware files used in the attack.
Image: Mandiant. List of malware files used in the attack.

The main malware process is a file called “firewalld,” which executes the TinyShell backdoor with parameters that allow it to provide a reverse shell to the threat actor. The reverse shell calls a C2 server at a time and day provided by the script. If no IP address is provided when calling the TinyShell binary, it embeds a hardcoded IP address to reach.

Must-read security coverage

A copy of the “firewalld” file called “iptabled” was altered to ensure continuity of the primary malware in case of a crash or termination. The two scripts were set up to activate one another in case the other  wasn’tt already running, which created a backup instance of the primary malware process and thereby enhanced its resilience.

The “firewalld” process is launched at boot time by a startup script named “rc.local” intended to facilitate an attacker’s prolonged access.

A file named “ifconfig6” is also used to increase stability. The main “firewalld” process adds a small patch to a legitimate SonicWall binary named “firebased,” which replaces a shutdown string with a call to the “ipconfig6” script. Mandiant researchers suspect that attackers encountered issues when the “firebased” script was shutting down the instance and decided to create a small script to patch it.

Once everything is set, the final goal of the malware is to routinely execute a SQL command to grab the hashed credentials of all logged in users. The attacker could then retrieve those hashes to crack them offline.

Firmware updates modified

A bash script named “geoBotnetd” found on an infected device checks every 10 seconds for a firmware upgrade to appear in /cf/FIRMWARE/NEW/INITRD.GZ. If that’s  the case, the script will backup the file, unzip it, mount it, and then copy over the whole package of malware files. It also adds a backdoored root user named “acme” to the system. The malware then rezips it all and puts it back in place.

This technique, although not very sophisticated, shows how motivated the attackers are to keep their access long-term, because a solid knowledge of the firmware upgrade process is necessary to create and deploy such a technique.

Mandiant researchers indicate that this technique is consistent with another attack campaign they have analyzed that supported key Chinese government priorities.

A long running campaign for cyber espionage purposes

While the primary vector of infection stays unknown in this attack campaign, Mandiant researchers indicate that the malware or a predecessor of it was likely deployed in 2021 and that the threat actor probably retained access, even through multiple firmware updates.

Because the sole purpose of the malware is to steal user credentials, it is strongly suspected that the attack campaign follows cyber espionage goals.

Mandiant insists on the fact that developing malware for a managed appliance is no trivial task, as vendors do not generally offer direct access to the operating system or even to the filesystem of such devices. This makes it harder to develop exploits and malware for those devices.

How to protect from this threat

For this particular attack, SonicWall urges SMA100 customers to upgrade to version 10.2.1.7 or higher. The upgrade includes hardening enhancements such as File Integrity Monitoring (FIM) and anomalous process identification.

On a larger scale, protecting edge devices from compromise requires a multi layered approach that includes both physical and software security measures.

In addition,  educate employees on cybersecurity best practices, such as identifying phishing emails and avoiding suspicious websites or downloads. While the initial infection vector isn’t known, it’s highly possible that it might have been phishing emails.

Disclosure: I work for Trend Micro, but the views expressed in this article are mine.



Source link

Tags: FirmwareresistsUndetectedupdate
Share76Tweet47

Related Posts

Sentra Raises $30 Million for DSPM Technology

Dozens of Malicious Extensions Found in Chrome Web Store

June 6, 2023
0

Security researchers recently identified more than 30 malicious extensions that had made their way into the Chrome web store, potentially...

Learn how to protect your company from cyberattacks for just $46

Learn how to protect your company from cyberattacks for just $46

June 5, 2023
0

Cloud computing brings many business benefits, but it’s essential to know how to protect your data and operations. Image: StackCommerce...

Decipher Podcast: Hazel Burton | Decipher

Decipher Podcast: Hazel Burton | Decipher

June 5, 2023
0

Podcast Ransomware Task Force Ransomware Decipher Podcast: Megan Stifel Returns Megan Stifel, chief strategy officer for the Institute for Security...

Sentra Raises $30 Million for DSPM Technology

Galvanick Banks $10 Million for Industrial XDR Technology

June 5, 2023
0

Galvanick, an early-stage startup working on an Extended Detection & Response (XDR) platform for industrial infrastructure, has scored $10 million...

How to know what personal information Microsoft Edge knows about you

How to know what personal information Microsoft Edge knows about you

June 5, 2023
0

Users should be aware of what personal data is being collected and stored by Microsoft Edge and be prepared to...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Sentra Raises $30 Million for DSPM Technology

Dozens of Malicious Extensions Found in Chrome Web Store

June 6, 2023
Pepper Advantage Obtains Fintech Licence in Indonesia

Pepper Advantage Obtains Fintech Licence in Indonesia

June 6, 2023
Learn how to protect your company from cyberattacks for just $46

Learn how to protect your company from cyberattacks for just $46

June 5, 2023
Decipher Podcast: Hazel Burton | Decipher

Decipher Podcast: Hazel Burton | Decipher

June 5, 2023

Recent Posts

Sentra Raises $30 Million for DSPM Technology

Dozens of Malicious Extensions Found in Chrome Web Store

June 6, 2023
Pepper Advantage Obtains Fintech Licence in Indonesia

Pepper Advantage Obtains Fintech Licence in Indonesia

June 6, 2023
Learn how to protect your company from cyberattacks for just $46

Learn how to protect your company from cyberattacks for just $46

June 5, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved