Attacks/Breaches

8/11/2017
01:58 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

APT28 Uses EternalBlue to Spy on Hotel Wifi Networks

Hacker group APT28 is using the EternalBlue hacking tool to spread throughout hotel networks and collect guests' information.

If you're not yet skeptical of hotel wifi networks, APT28 is giving you a good reason to think twice before logging on. The Russian hacker group, otherwise known as Fancy Bear, is reportedly gaining control of those networks and using its access to spy on guests.

FireEye, which has been watching the group, saw signs indicating APT28 is trying to compromise government and business travelers through access to hotels' guest wifi networks. The security firm attributes this campaign to APT28 "with moderate confidence."

APT28 is using a few notable techniques in these attacks against the hospitality sector, including sniffing passwords from wifi traffic and poisoning the NetBIOS Name Service. This time it's also using the EternalBlue exploit, an alleged NSA hacking tool leaked by ShadowBrokers and recently used to spread WannaCry and NotPetya malware campaigns.

It's a new move for the group, says Ben Read, FireEye's manager for cyberespionage analysis. This is the first time APT28 has used EternalBlue, which "makes it easy to move to vulnerable systems," he explains.

Attackers use spearphishing to enter hotel networks. FireEye uncovered a malicious document targeting hospitality businesses, including hotels in seven European countries and one in the Middle East. The document, called Hotel_Reservation_Form.doc, is likely opened by someone at the reservation desk. If successfully executed, the macro installs APT28's Gamefish malware.

Once inside, attackers move laterally to detect machines that control both guest and internal wifi networks. When they find them, they deploy Responder, which simplifies credential theft.

"Responder is deployed manually," says Read. "The reason you deploy Responder is to steal passwords from people who are connected to the network."

Responder is an open-source tool that enables NetBIOS Name Service poisoning, which looks for computers attempting to connect to network resources. When it detects a victim trying to connect to a printer or shared file, for example, it pretends to be that resource and causes the victim machine to send its username and hashed passwords.

APT28 used Responder to steal credentials, which allowed them to escalate privileges within the victim network. It leveraged EternalBlue to spread laterally throughout the network and find target machines. Victims' credentials could be stolen remotely or by using a machine in physical proximity to, and on the same network as, the target device.

"Once they have credentials, what they can get into depends on how the network is set up," says Read. Under the right circumstances, attackers could remotely log into a victim's computer and deploy malware, or log into a target Outlook account. This would be possible using single-factor authentication and no interaction with the victim.

However, it may be impossible to use credentials for accessing these accounts if the victim is using a VPN or has enabled two-factor authentication.

Cyberattacks on the hospitality industry can be used to collect information on target hotels but usually aim to steal data from guests. Read believes this is the case with APT28's recent activity, though researchers have not determined the ultimate purpose of the targeting in this campaign.

"The hotels targeted were middle-to-upper market in European capitals," he explains. "This was likely targeting the type of people staying there, like diplomats or business leaders."

It's a warning for travelers, especially business or government personnel, to buckle down on security. "You run a risk any time you connect to a wifi network not controlled by your company," Read warns. He advises travelers to avoid opening suspicious documents or enabling macros, and to travel with a hotspot rather than rely on hotel wifi.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
The Fundamental Flaw in Security Awareness Programs
Ira Winkler, CISSP, President, Secure Mentem,  7/19/2018
Number of Retailers Impacted by Breaches Doubles
Ericka Chickowski, Contributing Writer, Dark Reading,  7/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19990
PUBLISHED: 2018-07-23
October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that can result in an Authenticated user with media module permission creating arbitrary folder name with XSS content. This attack appear to be exploitable v...
CVE-2018-19990
PUBLISHED: 2018-07-23
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend pat...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fix...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears to be exploitable via specially crafted ASF file that has to be provide...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources like CPU and RAM. This attack appear to be exploitable via specially c...