Endpoint

1/5/2018
03:15 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

LockPoS Malware Sneaks onto Kernel via new Injection Technique

"Alarming evolution" of Flokibot bypasses antivirus software and was likely built by a group of advanced attackers, researchers say.

A sneaky new injection technique delivers LockPoS malware straight into the kernel, researchers report. This "silent" method bypasses traditional antivirus software.

LockPoS is a type of point-of-sale (PoS) malware designed to snatch credit card data from the memory of computers connected to PoS card scanners. It reads the memory of processes running on the system to look for data that looks like payment card info and sends it to the command and control servers.

There are multiple stages of unpacking and decryption in LockPoS, but Cyberbit researchers report its most interesting traits are the injection technique and routines for code injection. The team discovered a new way LockPoS is arriving on machines.

LockPoS comes from the same botnet used to send Flokibot PoS, a bot based on leaked Zeus code discovered by Malwarebytes in 2016. The LockPoS injection technique is similar to the one used by Flokibot but uses different API calls for injection, and is more advanced overall.

Meir Brown, Cyberbit's director of research for endpoint detection and response, says researchers detected the new technique when they discovered a LockPoS malware sample using remote access but couldn't identify the injection. Usually the technique is obvious.

"It was somehow injected without us being able to see the injection technique," Brown explains, noting that malware typically uses a Windows API to operate code injection and there are many different APIs that malware can use. "Here, there is no evidence of injection," he says. 

Cyberbit malware analyst Hod Gavriel ran the malware through a reversing lab to understand this. He discovered the injection was silent because it directly entered the kernel. All the routines used to inject the code are exported from a core dll file of the Windows OS, which serves as a "gate" from the user space to the kernel space, researchers report. The malware avoids antivirus systems by mapping this core file from the disk to its own virtual address space.

"Flokibot was not that impressive because the injection was still discoverable," says Gavriel. "Here, in LockPoS, it is totally silent. It can inject code without raising any flags. Somebody put a lot of effort into this malware … it's not simple code."

He calls this an "alarming evolution" of Flokibot that was likely built by a group of advanced attackers. "This is not something that can be done by five people in a lab. This is an operation."

Brown says this discovery is a sign PoS malware is evolving. Authors are investing more in generating attacks on vendors and creating more advanced threats to both stay hidden and evade security tools. While it has been used in the wild, he notes researchers have not seen any evidence of specific breaches that used this LockPoS injection technique.

"The whole point-of-sale, retail market should be aware they're being targeted," he says. "They need to raise the bar in security." This doesn't only mean investing in the right technology, but the right people. Businesses need someone to understand and respond to threats they detect.

Ed Cabrera, chief cybersecurity officer at Trend Micro, says researchers at the company are "seeing a lot of innovation going on" in PoS malware. While the bot delivery method has been around for a while, attackers are evolving their strategies around distributing malware.

"They're not improving the malware itself but they're improving the process for delivering, and becoming much more effective in their tactics," he explains. Attackers are refining their campaigns, using automation to launch attacks and exfiltrate information. Many are narrowing their focus on smaller businesses, which typically don't have strong security measures in place.

"One trend we're seeing is -- thanks to PoS malware bots that are conducting these types of attacks -- criminals can be much more effective in doing automated attacks, possibly reaching small and medium-sized businesses in a much more effective way," he explains.

Cabrera says retailers are becoming better at understanding the threats they face but usually don't ramp up their security strategies until after a breach, when their vulnerabilities are made much more obvious. Depending on the store, they start building security programs in response, he says.

Related Content:

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/9/2018 | 3:39:18 PM
Re: Which "Kernel"? PUT TARGET PLATFORM FRONT AND CENTER
Don't be too hard - after all most EVERYTHING is on a Windows platform to start with.  However nice and wonderful Ubuntu and Linux are ... percentage is always windows, the curse we have to live with. 
SchemaCzar
50%
50%
SchemaCzar,
User Rank: Strategist
1/8/2018 | 10:31:50 AM
Which "Kernel"? PUT TARGET PLATFORM FRONT AND CENTER
It's ridiculous that a Windows-only attack technique is barely identified as such until well through the article.
Researchers Offer a 'VirusTotal for ICS'
Kelly Jackson Higgins, Executive Editor at Dark Reading,  1/16/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2017
A look at the biggest news stories (so far) of 2017 that shaped the cybersecurity landscape -- from Russian hacking, ransomware's coming-out party, and voting machine vulnerabilities to the massive data breach of credit-monitoring firm Equifax.
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.