Jump to content

FireEye Malware

Intelligence Lab

Threat research, analysis, and mitigation

« September 2012 | Main | November 2012 »

5 posts from October 2012

Looking Forward to Windows 8: A Look Back at Windows Security

With the release of Windows 8 scheduled for October 26, Windows security is on our mind. Windows is one of the most widely used operating systems in the world, making it a lucrative target for exploit developers and malware authors. In previous versions of Windows, many security features were introduced, including ASLR, DEP and pointer encodings. Microsoft utilized software development lifecycle and threat modeling to ensure it was delivering a secure operating system to its users; however, many of previous Windows security exploits were the result of developers overlooking the proper implementation of protocol standards. Supplementing the detailed analysis made available by Microsoft, in this blog post, we share additional analysis of one of these exploits and highlight a short list of additional exploits that were the result of poor security validation.

Microsoft implemented many initiatives focused on developing code that was secure from exploitation of vulnerabilities, but unfortunately, many zero-day vulnerabilities were reported in Windows 2008 and Windows 7.

Let’s dive into the analysis of one zero-day CVE-2011-0654 which was reported on February 14, 2011, for Windows 7 and 2008 servers to understand the factor that seems to have been missed to ensure the safety of Windows.  

Continue reading "Looking Forward to Windows 8: A Look Back at Windows Security" »

Defining Advanced Malware is as Difficult as Preventing It (Part 1 of 2)

Advanced targeted attacks—or the ubiquitous advanced persistent threat (APT), if you prefer—have captured the attention of the security industry because of their clandestine and sinister nature. Unfortunately, it is almost as challenging to get the security industry to agree on what constitutes an APT as it is to protect against one, but we can identify and agree upon a few common themes.

Before I begin, I do want to make reference to testimony before congress from Richard Bejtlich, currently CSO at Mandiant, and formerly USAF. Rather than summarize, I'll quote from the hearing on "Developments in China's Cyber and Nuclear Capabilities:"

"...I use the strict definition of APT as created by the Air Force in 2006, namely as an unclassified reference to intrusions sets ultimately traced back to actors in China."

This is a very fair and accurate definition. However, at the core, it requires the big "A"—attribution. Private companies (excluding government contractors) rarely have the ability to accurately identify a specific attacker, hence, making the distinction among a PLA unit, university training program, or contracted hacker, difficult. Because of that missing link, and the fact that many have misused the term, many attacks are miscategorized as APT simply due to being "advanced."

Having said that, whether an attack is APT (or more accurately, if the attacker is the APT), or whether the attack is from another well-financed adversary, the TTPs have significant overlap. A typical scenario combines sophisticated exploits and social engineering to breach networks, execute malware instances, and establish communication with command and control (C&C) servers. As a result, technologies that examine executable files, monitor outbound communication, or analyze suspicious patterns in the network have become very popular; however, the effectiveness of some such solutions is questionable at best since advanced malware is constantly evolving to stay a step ahead of detection.

In this post, I will delineate the key characteristics of an advanced persistent threat and discuss some of the common approaches to mitigation. In a follow-up post, I will deconstruct why these common approaches are little more than a Band-Aid on a gaping wound.

Continue reading "Defining Advanced Malware is as Difficult as Preventing It (Part 1 of 2)" »

Spear Phishing In Action

Recently, while monitoring an infected system we uncovered activity that showed a good example of attackers selectively emailing malware to a specific group (in this case a country).

After conducting analysis of the threat, network traffic, and hosts involved, we believe that the attackers were directly targeting companies located in the Middle East—Saudi Arabia, to be exact.

In the following examples we can see the sequence of events leading up to the spear phishing as well as the tactics used to seek out targets for the attack (aka the “reconnaissance”).

Continue reading "Spear Phishing In Action" »

More About Attacks on Financial Industries…

On Sept. 17, the FBI issued a warning about the possibility of cyber attacks on the financial industry. Recently, we observed another kind of an attack (not Distributed Denial of Service or Denial of Service attack) across at least two major financial institutions. The attack, if successful, will result in the establishment of a malicious communication channel on the victim’s computer. The purpose of this blog is to share the finer technical details about the level of obfuscation which was done to hide the malicious executable in the attack.

Continue reading "More About Attacks on Financial Industries… " »

Christmas Comes Early For Hackers: Email Attack Trends From 3Q2012

In our first half (1H) of 2012 Advanced Threat Report, we looked at various factors related to email-based attack trends, including exploit vector type (e.g., link/attachment), domain frequency, and attachment polymorphism. With the holiday season starting back up, we’ll refocus our attention on all the corresponding threat data collected quarter-to-date for 2012. To be clear, these statistics reflect the number of malicious attachments seen after initial SPAM and anti-virus filtering across our customer deployments, who share intelligence back to us.

Continue reading "Christmas Comes Early For Hackers: Email Attack Trends From 3Q2012" »