New SysJoker Backdoor Targets Windows, Linux, and macOS
intezer.com
intezer.com
I regularly run tools like Autoruns to disable unwanted new entries in places like this. These days it's more of a problem for me with regular software than it is malware.
Unfortunately locking down the registry key can break legitimate installers.
Does anyone know of a decent utility that monitors for changes in the background and notifies you via an unintrusive little icon in the system tray (no balloons) which you can click when convenient to review the offenders?
Have also contemplated a process "whitelist" that allows you to whitelist regular programs (maybe it has a mode you can run for a time where it learns automatically) and let's you easily view stuff running that you don't recognize.
Aside from being able to manage some persistent login items under Settings > Users > Login Items, there is a free tool available from Patrick Wardle that helps manage the hidden launch items (like updaters) on MacOS called Knock Knock.
Its all very well checking _your__own_ HKCU keys, but what if the persistent entry was setup in another window user account??? That point isnt made obvious on that website link!
On Win10 how many people can easily see the Administrator (500), DefaultAccount (503), Guest(501) & WDAGutilityAccount (504) and checked their metrics???
Who checks their services are all genuine?
There are loads of place to run apps at system startup besides the registry. This link shows you where you can autorun apps buts it was written in 2016 and I think there are now a few more places where you can autorun at startup. https://www.ghacks.net/2016/06/04/windows-automatic-startup-...
You could also piggy back off another common utility if you know how to delta patch an app, or even use a driver if you can get in that deep without arousing any suspicion!
The next problem is trying to avoid getting picked up by the AV/malware running, unless your group policy doesnt allow anything to run other than what is allowed in the group policy.
Havent tried this on home in win10 but it might/should work https://www.howtogeek.com/howto/8739/restrict-users-to-run-o... Basically in Pro and above you can use group policy to restrict windows so it only runs allowed programs, then you are in the same situation as Linux users.
- MJ Registry Watcher
- RegShot
- Or monitor yourself with some WMI query
Nowadays you don't even need root to install something that runs a every login: There is the user instance of systemd. Of course without root those services are limited in what they can do.
How do we know that isn't an attack?
In past weeks wasn't it revealed that even major AV vendors have been begun auto-installing shady crypto miners on end-user machines?
Running all mounts as RO isn't feasible in every case. Maybe docker and VMs can help insulate and protect to a degree. Yet even still, once an attacker makes it into your private network it's pretty likely that the state converges to Game Over.
This stonks to high heaven.
EDIT: Here is the Norton anti virus crypto miner story https://news.ycombinator.com/item?id=29795910
Modern antiviruses do more than just scanning files. They also have system hooks as well, for behavioral analysis and real time scanning. It's unclear how that would be implemented with the scheme you just described, without a massive API being added to the kernel.
Scanning the system from within the system feels bound to fail, when a lot of my stuff has to run as root. Even if I'm not root, there is this: https://xkcd.com/1200/
But if you want jails and read-only FS, you can try to construct it from something like Docker. With LVM you can make point-in-time FS snapshots and scan those. Docker probably has known escapes, but if your scanner is FOSS you could layer it inside a wasm runtime too.
Defense-in-depth doctrine says that something is better than nothing, but I feel like expecting a broken system to report that it's broken and fix itself is a bit doomed. Having a physically separate audit server behind a data diode is also an approach I've considered. That way malware is less able to hide logs once it's in. The trouble is, all these ideas require lots of new code that nobody has a reason to trust or maintain or use.
You don't mean this should be included in _every_ operating system, right?
I'd say the overhead would be too high for that little protection benefit, at least for a portion of computers.
This seems impossible to achieve if you are locked up in jail.
The whole concept of anti-virus software being trusted is just wrong, both in theory and practice.
I’ve also noticed I don’t really find much malware in the wild, at least nothing targeting you’re typical PC user. Maybe I’ll find some boring, barely obfuscated adware, but of it seems to target larger, enterprise organization, which I suppose also makes sense. There was a write up a few days ago about an exploit targeting MS Word that was at least mildly more interesting than most of the stuff I hear about now.
Maybe the attack is already completely done, and they're just leaving the C&C servers and the rest of the botnet up to avoid leaking "The C&C servers went offline at X time" as a piece of information.
Does anybody know what came of this?
https://www.intezer.com/blog/malware-analysis/hiddenwasp-mal...
Did the threat materialize or was it a dud?
- so far the only people i see flogging this are some company called Intezer.
- MITRE related security sites all show a blurb on it saying NPM packages "might" be a vector.
- NOWHERE is it listed the vector or method of attack employed for linux systems, but sure, add linux because SEO reasons.
can anyone give a tech source for the linux side of the house?
Are there other methods in use for masquerading, or do people simply hard-code a group of C2 IPs or DNS entries?