{"id":3175,"date":"2013-08-13T10:00:25","date_gmt":"2013-08-13T14:00:25","guid":{"rendered":"http:\/\/blog.nccomputertech.com\/?p=3175"},"modified":"2013-08-13T10:00:25","modified_gmt":"2013-08-13T14:00:25","slug":"security-team-pries-open-secrets-of-chinese-hacker-gang","status":"publish","type":"post","link":"https:\/\/nccomputertech.com\/techtalk\/2013\/08\/13\/security-team-pries-open-secrets-of-chinese-hacker-gang\/","title":{"rendered":"Security team pries open secrets of Chinese hacker gang"},"content":{"rendered":"<section class=\"page\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignnone\" alt=\"\" src=\"https:\/\/i0.wp.com\/zapt5.staticworld.net\/images\/article\/2013\/04\/hacker_internet_web_attack-100033459-large.jpg?resize=580%2C461\" width=\"580\" height=\"461\" \/><br \/>\nA Chinese hacker gang whose malware <a href=\"http:\/\/www.pcworld.com\/article\/230119\/article.html?tk=rel_news\">targeted RSA<\/a> in 2011 infiltrated more than 100 companies and organizations, and was so eager to steal data that it probed a major teleconference developer to find new ways to spy on corporations, according to researchers.<br \/>\nThe <a href=\"http:\/\/www.pcworld.com\/article\/2014632\/xtreme-rat-malware-targets-us-uk-other-governments.html?tk=rel_news\">remote-access Trojan,<\/a> or RAT, tagged as &#8220;Comfoo&#8221; is largely inactive, said a pair of veteran researchers from Dell SecureWorks, who presented their findings at the recent Black Hat security conference.<br \/>\nBut their discoveries showed just how pervasively a <a href=\"http:\/\/www.pcworld.com\/article\/2039262\/chinese-hackers-resume-attacks-on-u-s-targets.html?tk=rel_news\">dedicated group of attackers<\/a> can infiltrate networks and walk away with secrets.<br \/>\n&#8220;We&#8217;re not seeing it used to the extent it was before,&#8221; said Joe Stewart, director of malware research at SecureWorks, in explaining why he and his college, Don Jackson, revealed their undercover campaign.<\/p>\n<h2>Digital stakeout<\/h2>\n<p>For more than 18 months, Stewart and Jackson, director of SecureWorks&#8217; Counter Threat Unit (CTU), secretly monitored some of the workings of Comfoo, which they believe was the work of a hacker crew they&#8217;ve named the Beijing Group. The gang is one of China&#8217;s top-two hacker organizations.<\/p>\n<figure class=\"right medium\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/i0.wp.com\/images.techhive.com\/images\/article\/2013\/02\/identity_theft_hacker-100026919-medium.jpg?resize=300%2C200\" width=\"300\" height=\"200\" \/><figcaption><\/figcaption><\/figure>\n<p>To start, Stewart captured a sample of the malware used in <a href=\"http:\/\/www.pcworld.com\/article\/222522\/article.html?tk=rel_news\">the RSA attack,<\/a> which at the time was <a href=\"http:\/\/www.computerworld.com\/s\/article\/9218857\/Researcher_follows_RSA_hacking_trail_to_China\">attributed to Chinese hackers<\/a>, then reverse-engineered the encryption that the malware used to mask instructions to and from the gang&#8217;s command-and-control (C&amp;C) servers.<br \/>\nEventually, Stewart was able to spy on the hackers as they logged onto those C&amp;C servers. As they did, Stewart snatched the victims&#8217; MAC addresses\u2014unique identifiers for network hardware\u2014their IP, or &#8220;Internet protocol&#8221; addresses, and finally, a tag the hackers used to label each data-stealing campaign.<br \/>\nSecureWorks was not able to see what data the attackers were stealing, but their passive monitoring reaped dividends.<br \/>\n&#8220;We&#8217;ve done similar ops like this before,&#8221; said Stewart, &#8220;but with the custom stuff, you rarely get this kind of insight or this level of detail of the attacks and victims.&#8221;<\/p>\n<h2>Victims notified<\/h2>\n<p>SecureWorks said its stealthy stakeout\u2014which was intermittent to ensure that the hackers weren&#8217;t aware they were watching\u2014uncovered over 100 victims, more than 64 different campaigns and 200-plus Comfoo variants. The Atlanta-based security firm notified some of the victims directly, and others through CERTs, the computer emergency response teams that governments maintain.<br \/>\n&#8220;This was just a snapshot of the [total] victims,&#8221; Stewart cautioned.<br \/>\nThe hackers targeted a wide range of government agencies and ministries, private companies and trade organizations in fields as diverse as energy, media, semiconductors and telecommunications. They seemed eager to grab information from almost anywhere and anyone, although the victims were concentrated in Japan, India, South Korea, and the U.S.<br \/>\nBut one victim caught their attention.<br \/>\nWhile Stewart and Jackson declined to name any of the victims, they said one campaign had been aimed at a major videoconferencing software developer.<br \/>\nThey speculated that the attackers were sniffing through that company&#8217;s network for information on vulnerabilities in the software, which they could then exploit at other targets to put eyes and ears on confidential industry and government meetings. &#8220;They might be trying to leverage that access to spy on third parties,&#8221; said Stewart.<\/p>\n<h2>Unusual spy targets<\/h2>\n<figure class=\" large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" alt=\"comfoo\" src=\"https:\/\/i0.wp.com\/images.techhive.com\/images\/article\/2013\/08\/comfoo-infections-100049688-large.jpg?resize=580%2C300\" width=\"580\" height=\"300\" \/><small class=\"credit\">SecureWorks<\/small><figcaption>SecureWorks&#8217; virtual stakeout pinpointed the physical location of many of the Comfoo C&amp;C servers. China was the hotspot.<\/figcaption><\/figure>\n<p>In a report SecureWorks published last week on Comfoo, the company said that targeting audio and videoconferencing products was &#8220;unusual.&#8221;<br \/>\nOther attacks may have had the same goal: Acquire inside information on everything from specialized security software to digital certificates for use in future campaigns.<br \/>\nSecureWorks&#8217; surveillance will also let security researchers better track the hacker gang, even though the cyber criminals have changed their malware tools since using Comfoo, and will undoubtedly do so again, said Jackson.<br \/>\n&#8220;It&#8217;s safe to assume that they&#8217;ll change their toolkits,&#8221; Jackson said. &#8220;But as long as the key features match, we should be able to match them [in the future] with campaigns.&#8221;<br \/>\nHacker gangs, Jackson added, have personalities and quirks, and can be &#8220;fingerprinted&#8221; by closely analyzing not only the malware they use, but also how they organize the C&amp;C infrastructure. &#8220;They all have patterns,&#8221; Jackson said.<br \/>\nAlthough he wouldn&#8217;t go into specifics, Jackson said that SecureWorks had already used the patterns found in the Comfoo campaigns to identify newer malware and attacks that the company believes is the work of the Beijing Group.<br \/>\n&#8220;As long as it&#8217;s evolutionary rather than revolutionary, we should be able to spot them,&#8221; Jackson said.<br \/>\nvia <a href=\"http:\/\/www.pcworld.com\/article\/2046356\/security-team-pries-open-secrets-of-chinese-hacker-gang.html\">PCWorld<\/a><br \/>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>A Chinese hacker gang whose malware targeted RSA in 2011 infiltrated more than 100 companies and organizations, and was so [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[6,7],"tags":[342,453,655],"class_list":["post-3175","post","type-post","status-publish","format-standard","hentry","category-networking","category-security","tag-exploits","tag-hackers","tag-malware"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/papNkV-Pd","jetpack-related-posts":[{"id":6294,"url":"https:\/\/nccomputertech.com\/techtalk\/2014\/08\/27\/research-team-creates-undetectable-malware-bound-to-legitimate-software-downloads\/","url_meta":{"origin":3175,"position":0},"title":"Research team creates undetectable malware bound to legitimate software downloads","author":"NCCT","date":"August 27, 2014","format":false,"excerpt":"Most cyber attacks from your typical home hacker, come by way of techniques used 10 years ago or more like phishing scams, poor password management, and things of that nature. But now it seems as though a research team from Germany has developed on all new strain of malware. The\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/nccomputertech.com\/techtalk\/category\/security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":3156,"url":"https:\/\/nccomputertech.com\/techtalk\/2013\/08\/09\/hand-of-thief-banking-trojan-doesnt-do-windows-but-it-does-linux\/","url_meta":{"origin":3175,"position":1},"title":"\u201cHand of Thief\u201d banking trojan doesn\u2019t do Windows\u2014but it does Linux","author":"NCCT","date":"August 9, 2013","format":false,"excerpt":"Signaling criminals' growing interest in attacking non-Windows computers, researchers have discovered banking fraud malware that targets people using the open-source Linux operating system. Hand of Thief, which was recently discovered by researchers from security firm RSA, sells for about $2,000 in underground Internet forums and boasts its own support and\u2026","rel":"","context":"In &quot;Linux&quot;","block_context":{"text":"Linux","link":"https:\/\/nccomputertech.com\/techtalk\/category\/linux\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/nccomputertech.com\/techtalk\/wp-content\/uploads\/2013\/08\/hand-of-thief-640x294.jpg?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/nccomputertech.com\/techtalk\/wp-content\/uploads\/2013\/08\/hand-of-thief-640x294.jpg?resize=350%2C200 1x, https:\/\/i0.wp.com\/nccomputertech.com\/techtalk\/wp-content\/uploads\/2013\/08\/hand-of-thief-640x294.jpg?resize=525%2C300 1.5x"},"classes":[]},{"id":8714,"url":"https:\/\/nccomputertech.com\/techtalk\/2015\/11\/05\/newly-discovered-adware-digs-its-claws-deep-into-android-is-nearly-impossible-to-remove\/","url_meta":{"origin":3175,"position":2},"title":"Newly discovered adware digs its claws deep into Android, is nearly impossible to remove","author":"NCCT","date":"November 5, 2015","format":false,"excerpt":"Security researchers found over 20,000 adware samples hiding in apps that masquerade as Facebook, Twitter, Snapchat, and other popular services. Derek Walter | @derekwalter | PCWorld Security researchers have uncovered a new style of Android malware that hides inside of apps that act and look like they\u2019re legitimate services. Lookout\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/nccomputertech.com\/techtalk\/category\/security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":3213,"url":"https:\/\/nccomputertech.com\/techtalk\/2013\/08\/20\/researchers-manage-to-get-malware-published-in-apples-ios-app-store\/","url_meta":{"origin":3175,"position":3},"title":"Researchers manage to get malware published in Apple&#039;s iOS App Store","author":"NCCT","date":"August 20, 2013","format":false,"excerpt":"While the posting of malware remains a rare occurrence on Apple's iOS App Store, a team of security researchers figured out a way to get a malicious piece of software past Apple's certification team. The team from Georgia Tech said that the app was approved and published by Apple in\u2026","rel":"","context":"In &quot;Apple&quot;","block_context":{"text":"Apple","link":"https:\/\/nccomputertech.com\/techtalk\/category\/apple\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":7586,"url":"https:\/\/nccomputertech.com\/techtalk\/2015\/02\/06\/sneaky-linux-malware-comes-with-sophisticated-custom-built-rootkit\/","url_meta":{"origin":3175,"position":4},"title":"Sneaky Linux malware comes with sophisticated custom-built rootkit","author":"NCCT","date":"February 6, 2015","format":false,"excerpt":"A malware program designed for Linux systems, including embedded devices with ARM architecture, uses a sophisticated kernel rootkit that\u2019s custom built for each infection. The malware, known as XOR.DDoS, was first spotted in September by security research outfit Malware Must Die. However, it has since evolved and new versions were\u2026","rel":"","context":"In &quot;Linux&quot;","block_context":{"text":"Linux","link":"https:\/\/nccomputertech.com\/techtalk\/category\/linux\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":8923,"url":"https:\/\/nccomputertech.com\/techtalk\/2016\/05\/17\/this-botnet-has-infected-nearly-a-million-devices-since-2014\/","url_meta":{"origin":3175,"position":5},"title":"This botnet has infected nearly a million devices since 2014","author":"NCCT","date":"May 17, 2016","format":false,"excerpt":"By Shawn Knight | TechSpot One of the many ways that cybercriminals earn income is through affiliate advertising programs like Google\u2019s AdSense. Rather than generate traffic through content creation, hackers figure out ways to trick advertising platforms into thinking a partner is sending them legitimate traffic. Not knowing they're being\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/nccomputertech.com\/techtalk\/category\/security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/posts\/3175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/comments?post=3175"}],"version-history":[{"count":0,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/posts\/3175\/revisions"}],"wp:attachment":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/media?parent=3175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/categories?post=3175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/tags?post=3175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}