Wednesday, April 6, 2016

Security Researchers Uncover Stealthy New Threat


Image Credit: Beanuts, Flickr Creative Commons
Digital security researchers announced the discovery of a stealthy new form of targeted malware on Wednesday, March 23. Dubbed “USB Thief” because it's designed to be carried on a USB thumb drive, steal data from a target system and then erase all traces of its presence, the trojan could potentially be the latest in a series of sophisticated state-sponsored malware campaigns.

"USB Thief is, in many aspects different from the more common malware types that we're used to seeing flooding the internet," said Tomáš Gardoň, the ESET analyst who posted the announcement of the discovery. "This one uses only USB devices for propagation, and it does not leave any evidence on the compromised computer. Its creators also employ special mechanisms to protect the malware from being reproduced or copied, which makes it even harder to detect and analyze."

The trojan is capable of completely erasing any indicators of its presence once its mission is accomplished and has a unique built-in encryption scheme to prevent any attempt to reproduce the trojan or dissect it in a security lab. Each stage uses an encryption key derived from the device ID of the host flash drive, meaning that any given instance of the malware can only be run from that specific drive.


Furthermore, every file created by the trojan has a custom file name derived from both actual file content and the time the file is created, making each instance more unique and difficult to reproduce.

Illustration of the USB Thief execution process
At no point does any stage of the program leave any evidence on the targeted computer, meaning that it functions much like the USB drives of Hollywood hackers, untraceably copying all the data from any computer it's plugged into.



The malware bears similarities to previous state-funded malware programs such as Stuxnet, Flame and Gauss, which have also historically been spread by USB in order to target specific systems that are often not connected to the internet. In an email to Ars Technica, Gardoň revealed that the malware has been detected almost exclusively in African and Latin American organizations. 

If this is indeed a state-sponsored attack, it represents a refining of previous efforts. Stuxnet, the first known major state-sponsored malware project, was designed by the U.S. and Israeli governments to sabotage Iranian nuclear equipment, but quickly spread beyond its intended target, infecting computers the world over.



Flame, which followed Stuxnet, raised the bar for state-sponsored malware, deploying a complex suite of surveillance packages that extensively monitored any infected system, even recording audio through any microphone connected to an infected machine. Like Stuxnet, Flame specifically targeted Iranian systems. Its complexity and specificity suggest that, like Stuxnet, it was likely designed by the U.S. and Israel. Also like Stuxnet, Flame ultimately spread far wider than its initial targets, resulting in its detection.

Gauss, another sophisticated surveillance package targeting the Middle East, was capable of performing a similarly diverse repertoire of surveillance tasks, particularly focusing on monitoring data from certain Lebanese banks. While Gauss spread beyond its target, it introduced a new level of security in the form of an encrypted payload that only unravels in the presence of a specific, still unknown key.  The function of that payload is still a mystery, despite researchers having had nearly four years since its initial discovery in 2012 to attempt to decrypt it.

While all of these projects were large-scale, long term attacks intended to sit on a target computer and collect a continuous stream of data over time, USB Thief is designed to strike once and then vanish without a trace. This makes the trojan far harder to detect. Because the malware is limited to a single device, unintentional infection of an untargeted machine is almost impossible. And not only is it encrypted and limited to a single USB drive, but if USB Thief detects the presence of Kaspersky Antivirus, it won't run at all.  Kaspersky played a major role in the detection and deconstruction of other state-sponsored malware programs.

If USB Thief is indeed an espionage tool created by a nation-state, it is currently unclear who is responsible. Previous major projects like Stuxnet have had targets that suggested clear political motivations, which ultimately proved accurate. The identity of the trojan's author remains a mystery for now.

No comments:

Post a Comment