How Cybercriminals Can Abuse Chat Platform APIs as C&C Infrastructures [pdf]
documents.trendmicro.com
documents.trendmicro.com
My favorite idea so far is to look for the existence of a specific username across several services for commands. Only the usernames are (in part) generated via a TOTP style rolling code. So to see if something should activate, it will look for the existence of a username of "imnotabot349556" on reddit, HN, and twitter. if it sees any of them, it can read a small command from any number of places on those sites that the user can post some kind of comment/profile/text.
This is super easy to control securely (could be done from anywhere, using any machine, over TOR or other networks), is hard to shut down (the rolling codes mean they would need to either have access to the "secret" and ban all future codes, or just ban "imnotabot*" which wouldn't be sustainable if multiple botnets started using this method, not to mention you could just switch to a hash of everything as the username), and is fairly fullproof (no reliance on any one network or channel). And with some forethought, an update mechanism can be built into it as well, so when someone gets close to your scheme, you could have all your bots update at a moment's notice to a new one.
At the end of the day, trying to stop a C&C server of a botnet is a futile exercise. Once the botnet is out there, there's no stopping it by shutting down a C&C server. There are just SO many ways to pass information, and when the information is on the size of hundreds of bytes in some cases, there's just no hope.
It means "spending" to send a command, but you only lose the fee.
They will have access to the secret, because they have access to the programs that run the TOTP algorithm.
And any fix that they introduce, can be trivially updated to change around by any of the other services. They'd have to coordinate across all services that are used to update at the same time in order to stop it.
Anyone that does this can register the reddit/twitter handles or domain names as soon as they figure this out, if they aren't pre-registered. And if you're the provider, you are then given a list of accounts to kill. Now you're in a game of cat and mouse with the botnet operator, and each move you take kills off some of the operators bots, perhaps all of them if you get ahead of them by enough.
In this setting, if there's a central point, it can be cut. It's different if there is no central point (i.e. conficker P2P).
Laptop users who want broad Internet access (and will complain loudly if reddit/HN/Twitter is "down") aren't the same thing as the app server that only talks to a short whitelisted set of RFC1918 IPs, on specific ports only, and doesn't have Internet access - not even DNS. (WannaCry demonstrated why not.)
Reddit and the like needs to accept they are hosting botnet C&C servers due to hosting loads of user-generated content (I'd do an invite-only subreddit with a tracking pixel in the CSS), but that doesn't make it pointless for the rest of us to do something where possible.
So that you could nuke it if a not-you IP accessed the subreddit? That's nice and could be very easily automated.
Problem is that this stops application level automated updating. Firewalls are all fine but unfortunately they operate at IP level, not DNS - which means good luck if the vendor's auto-update server uses stuff like Cloudflare, ELB or anything other that (more or less rapidly) changes IP addresses.
Also stupid if you actually do that since the chat API provider can simply cut you off and you don't have a C2 anymore and lost access to all the systems you infected.
Your fallback should be a peer2peer network in DHT style, scanning the entire IP address space on a well known port to find nodes to connect to.
When a node is found, addresses of other nodes are requested, and a cache of a few thousand infected nodes kept to use as seeds for future connections.
Imagine you have 1 million infected machines, then most new nodes will find and connect to the network within 4000 packets sent across the network. For good measure, build in a list of a few thousand addresses into the malware as bootstrap nodes.
In other news, water is wet, the sky is blue, etc. etc.
Legitimate History as a Service?
Are they going to waste the next year on how Twitter, Facebook, etc. can be used by criminals?
New Update http://somefile,com/command.json
Subscribe to @newJunkAccount and @AnotherJunkAccount
@newJunkAccount has CLOSED his account