Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

7/11/2014
02:38 PM
50%
50%

Attack Campaign Targets Facebook, Dropbox User Credentials

The goal of the attackers is not fully clear but the credential theft could set up sophisticated targeted attackers.

Researchers at security firm Cyphort have uncovered a five-year-old attack campaign that has quietly gone about the business of stealing user credentials for Dropbox, Facebook, and other applications unnoticed until now.

At this point, it does not appear the attackers are targeting specific organizations or industries, since their tentacles seem to have reached organizations ranging from energy companies to charities. According to Cyphort's McEnroe Navaraj, the intent of the data collection is unknown, but there is no shortage of ways for the credentials to be turned to the attackers' advantage.

The so-called NightHunter attack uses SMTP email for exfiltrating data rather than "more common CnC (command and control) mechanisms that use web protocols," Navaraj said in a blog post:

This could be to simply "hide (and steal data) in the plain sight" as organizations beef up web anomaly detection for dealing with advanced attacks.

It involves several different malware keyloggers, including Predator Pain, Limitless, and Spyrex. The unifying feature is that they all use SMTP (email) for data exfiltration. Email to social networking is like snail-mail is to email … it is outdated and often overlooked, so it can be a more stealthy way of data theft. So we called it NightHunter.

According to Cyphort, the company received a sample through a phishing email. The sample is a .net binary that steals users' credentials and sends them to a remote email server when executed. When researchers examined the sample, they also uncovered other similar samples in the wild as well. Navaraj said in the post:

These samples are delivered mostly through phishing emails. These emails are sent with DOC/ZIP/RAR attachments. You can get infected by opening a malicious document with scripting enabled. Most of the phishing emails are targeted towards personnel in finance/sales/HR departments. Sometimes actors may act as goods resale agents. We have seen cases where it was bundled with fake IDM/7zip installers. Most of these samples used keylogger tools to sniff data from the victim.

Cyphort co-founder Fengmin Gong notes that some of the servers used by the attackers are either private or have access protections that prevented the firm from looking into the upload account, so the actual number of infected machines is higher than the 1,800 compromised machines the company is aware of.

"This attack is ongoing and we continue to monitor it," Gong tells Dark Reading. "The attackers are very aggressive in their data-collection methodology, as well as the intervals of data exfiltration. Given the systematic nature of the actors behind this campaign, we are speculating that they are still in a 'reconnaissance stage' targeting credentials of high-level executives, but at this point it is impossible to speculate on their endgame with any degree of certainty."

Still, he says he believes the attackers may be using big-data techniques to mine the stolen credentials, which would give them the ability to leverage the credentials for targeted attacks. The situation also underscores just how effective phishing still is at hooking victims, he says. The attackers used messages disguised as emails about a variety of topics, with subject lines such as "Purchase Order" and "Inquiry." In addition to the applications mentioned above, the attackers are also targeting credentials for Skype, Amazon, LinkedIn, Google, Yahoo, Hotmail, Rediff, and banks.

Navaraj blogged:

NightHunter is one the more unique campaigns we have researched at Cyphort due to the footprint and complex data collection models it exhibits, furthermore the use of low-signal evasion it is leveraging such as webmail for data exfiltration points to much larger end-goal.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/14/2014 | 10:00:46 AM
Re: next phase
I agree Robert
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/14/2014 | 9:50:29 AM
Re: next phase
Based on the longevity and the fact this campaign has avoided detection until now I wouldn't be surprised if the data collected has already been used in surgical breaches.
Denise J. Wasson
0%
100%
Denise J. Wasson,
User Rank: Apprentice
7/13/2014 | 12:29:25 PM
Re: next phase
There are many rumors about attack Campaign towrds Facebook, Dropbox users credentials, although there is no evidence of stolen data and the other vital signs of accessing od a theif into that platform. The job resume may help to learn more abouth the good and professional resume makimg. 
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/13/2014 | 4:46:21 AM
next phase
Despite there is no evidence of targeted attacks using the stolen data, the most worrying aspect of such operation is the possibility that collected information will be managed with big data techniques to conduct surgical offensives with serious consequences.

Another concerning aspect of the specific campaign is that it goes undetected since 2009 ... and this is just the tip of the iceberg.

Regards

Pierluigi 
Microsoft Patches Wormable RCE Vulns in Remote Desktop Services
Kelly Sheridan, Staff Editor, Dark Reading,  8/13/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
GitHub Named in Capital One Breach Lawsuit
Dark Reading Staff 8/14/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15132
PUBLISHED: 2019-08-17
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocki...
CVE-2019-15133
PUBLISHED: 2019-08-17
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
CVE-2019-15134
PUBLISHED: 2019-08-17
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network threads from working. This is related to _receive in sys/net/gnrc/transport_layer/tcp/gnrc_tcp_eventloo...
CVE-2019-14937
PUBLISHED: 2019-08-17
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
CVE-2019-13069
PUBLISHED: 2019-08-17
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an additional user account, and then use SSH and port forwarding to reach a 127.0.0.1 service.