The fake browser update scam gets a makeover
krebsonsecurity.com
krebsonsecurity.com
And the reason for this two-step architecture is to make it convenient to change the real payload.
And the problem is where to host the real payload. The first idea was Cloudflare, but Cloudflare keeps taking that sort of thing down. So now they host it "on the blockchain" which means it "can’t be blocked".
What I don't understand is who is actually serving the HTTP call that effectively proxies the data from the blockchain. It seems like they (like Cloudflare, or a regular hosting service) are opening themselves up to all sorts of risks by serving arbitrary content.
This diagram show the full flow of the attack: https://miro.medium.com/v2/resize:fit:1400/format:webp/1*by4...
Because reads from blockchain are "free" (meaning, there is no cryptocurrency payment required to read data from the smart contracts on BSC), this is effectively free storage/hosting for the attacker.
The malicious code is served by BSC web API. According to the Krebs article, BSC "is aware of the malware abusing its blockchain, and is actively addressing the issue." I am not clear if they are taking this situation Very Seriously(TM), but I assume they are.
But combined with the insane browser expectation of being able run unsigned JS and such from anywhere, you could probably host an entire simple text forum on whatever public chain as long as no one cares about it being fast.
Direct API is nice but any block chain explorer service would work in a pinch.
> In response to questions from KrebsOnSecurity, the BNB Smart Chain (BSC) said its team is aware of the malware abusing its blockchain, and is actively addressing the issue. The company said all addresses associated with the spread of the malware have been blacklisted, and that its technicians had developed a model to detect future smart contracts that use similar methods to host malicious scripts.
Earlier in the article it said
> Due to the publicly accessible and unchangeable nature of the blockchain, code can be hosted ‘on-chain’ without the ability for a takedown... “So you get a free, untracked, and robust way to get your data (the malicious payload) without leaving traces,” Tal said.
Make up your mind...
It's not robust since you have to use an API (i.e. Binance API) to access the blockchain from a compromised website, then Binance can effectively "take it down" by blocking access via the API.
Now if they made the compromised website talk directly to the node on the blockchain network that would be different. Except, why not just host the malware on the website in the first place...
Every public blockchain works this way afaik. I've even made a site for hosting webpages on Optimism: https://newgeocities.com
The real discussion imo is that blockchain node operators should be pressured to respond to concerns about unwanted content. There's no reason they can't coordinate on filters in the same way Ethereum validators use Flashbots to ignore Tornado Cash transactions. Although I hope they can find a better solution than blocking entire contracts because it's really nice to write a simple contract for data storage. Remember: a contract is a protocol, not a program. The validators follow the instructions but it's more like a database schema to which people submit conforming messages. As the contract creator, you're just publishing your code on chain. Each user takes responsibility for their own data.
I see it as a massive bet on storage prices continuing to decrease.
many devs will always post their applications on blockchains, and simply do system design conducive to that environment, because web 2.0 cloud models do not compete in pricing especially if you have a burst of activity
many devs bring their whole audience over, and the audience is willing to pay to update the state of the application with no overhead cost to the dev, which is also impossible to implement in web 2.0 cloud offerings, aside from just searching and hoping for free tiers
who cares if none of those applications match your use case, just call it the entertainment sector then and you still have value and utility to someone, that self perpetuates
Of course in reality most blockchain folk are grifters who will happily compromise their principles as soon as you credibly threaten their pocketbook - see the Ethereum DAO for the clearest example. Still, it's funny to force them to admit it.
I believe there's other requirements for BSC validators too, like staking a bunch of BNB.
even binance operated nodes
the only thing Binance did was do the exact same thing that Cloudflare did, both on their HTTP routes. Binance just had one for convenience and to attract use of their blockchain, which … worked?
its actually lazy and amateurish that the hackers are using HTTP to access this code on the blockchain, they dont have to
This free endpoint has many abuse protection mechanisms, as free services need (see: Cloudflare). However until today no one was hosting any malicious web payloads.
It's just matter to add a new abuse rule by BNB Smart Chain team to take this down.
That's pretty much any website that accepts user input or integrates with an external service. I could post a base64-encoded malware to HN too, it would just get caught a lot faster (wasn't this a real thing on reddit?). I think the trick here is that it doesn't look out of place on a blockchain explorer/gateway because most of that data is opaque binary content to begin with.
So long as there is uncensorable data anywhere, this will always remain possible.
If I recall too, the intermediate domains appeared to all be subdomains from (possibly) compromised godaddy accounts.
https://arstechnica.com/information-technology/2021/06/moner...
Onion services provide authentication and NAT traversal while maintaining security and anonymity. Just because you aren't using that functionality doesn't mean it doesn't have a use.
How do you intend to have a clearnet application that can stand up to the same threat model that SecureDrop does?
Get this, I've never used either of these services before. And the even crazier part is that if I did, they wouldn't know what I'm giving my friends money for anyways. And lastly, just use cash if your decision making is being opressed by the surveillance capitalism. Monero serves no purpose that hasn't already been fullfilled by a non-dubious measure
> How do you intend to have a clearnet application that can stand up to the same threat model that SecureDrop does?
I don't know, ask Stripe maybe how they haven't gotten any customer data stolen yet with their massive threat profile while not using Tor in any capacity
Stripe's threat modeling is nothing like SecureDrop's. Stripe has plenty of identifying information that they would be forced to surrender upon subpoena that SecureDrop simply wouldn't be able to furnish because it never has that information to begin with. How is this not apparent? Comparing the two reeks of bad faith.
This is morally equivalent to:
- "just send a letter through the post if you don't like EU's chat control"
- "just read the newspaper if you don't like Google's Federated Learning of Cohorts"
I'd like to believe we can get the benefits of 21st century tech without giving up our privacy to get it. Thanks to Monero that belief is a reality. You're welcome to stick with cash and the pony express if you like, but it's not a great look painting everyone who disagrees with your values as a criminal.
So was Encrochat
I haven't bought much with Monero, but I always offer it because I adore the premise. I personally think its great, one of the few truly valuable cryptocurrencies.
"You could say exactly the same thing about any form of encryption..."
That seems very untrue. I like my credit card details to be encrypted when I send them for the exact opposite of assisting cybercrime.
> You could say exactly the same thing about any form of encryption.
Maybe YOU could, and maybe you'd even be telling the truth, if you're going to this site over http and and not https.
But lets hope for our sake, we never get there.
Literally does not understand crypto.
Well, that's the point.
Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course.
The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations have decided you can't do because they're morally questionable or financially risky.
Stripe has an excellent list of examples (https://stripe.com/legal/restricted-businesses). Here is a selection:
* Pornography and other mature audience content (including literature, imagery and other media) depicting nudity or explicit sexual acts
* Online dating services
* Bankruptcy attorneys and bail bonds
* Sports forecasting or odds making with a monetary or material prize
* Charity sweepstakes and raffles for the explicit purpose of fundraising
* Unauthorized sale of brand name or designer products or services
And so on. All these are legal, but in a cashless society without decentralized currency, they might as well be illegal because no centralized payment processor will allow them.
But hey, Bitcoin can also be used for CSAM, unlike VPNs, Tor, or cash, which is why the HN cognoscenti condemns it.
You could be careful to not leak your wallet address of course, but if we'd truly be a cashless society without decentralized currency you'd want to buy your groceries with it too, or order computer parts. What prevents these shops you buy from from having a security issue and leaking your wallet address? You could have a separate wallet per shop, but you need to get money into it somehow which can be traced as well(because it's the blockchain).
Note: I'm not an expert on blockchain/crypto, there might be ways to mitigate this, I'm just legit curious as to how this would be solved in a world like this.
Answer #1: relax, they already know everything about you. With every interaction in society, you leave some combination of name, email, address, purchase history, security-camera footage, license-plate footage, IP address, cell-tower history, credit-card number, Venmo likes, etc. The history of a unit of digital currency certainly helps fill in gaps. But whoever "they" are to you, they already know.
Answer #2: No single tool is a one-size-fits-all answer to privacy. TCP/IP needs TLS for transport-layer privacy, DNSSEC and TLS certs for authenticity, VPNs and Tor for protection against traffic analysis, throwaway accounts to segregate one's personal workstreams, and so on. The privacy of the internet results from an ever-evolving collection of tools.
Bitcoin is TCP/IP for money. It's a pipe that allows transfer of value from one place to another -- that's it. It doesn't provide anonymity, but unlike centralized payment-processing systems, it allows the creation of tools on top of it that could provide a practical level of anonymity. A Bitcoin mixer, for example, is comparable to a VPN.
Note that if VPNs or TLS were invented today, rather than decades ago, the Hive Mind would be demonizing them as tools for criminals and/or the kind of person none of us admits to being (purchasers of porn, etc.). We take a lot of internet privacy tools for granted, mostly because we're accustomed to them, but also because they were grandfathered before September 2001.
Straw man much?
AFAIK there’s nothing competitive with sending an international payment of any amount in half a second for a tiny fraction of a cent in fees.
For example, Visa recently expanded their pilot of USDC settlement to include Solana, citing its speed and low fees: https://usa.visa.com/about-visa/newsroom/press-releases.rele...
They refer to it as “modernizing cross-border money movement” and I think that summarises the potential pretty well!
[0] https://news.rublex.io/gridless-uses-mining/ [1] https://africancrypto.com/gridless-enables-cheap-renewable-e...
Never going to happen, because that's breaking YouTube.
I'm going to tell them that they should no longer use it for any sort of financial work. No banks, no shares, nothing. Ever, for any reason.
This stuff is too good now. Most of us -- and I include the tech-literate, because we all slip eventually -- are basically helpless at this point.
Solution? iOS apps, or, I'm sorry, use a Mac. I know it's not immune to malware but for all practical purposes it might as well be.
/s
This attack can still be pulled off without JS though: using plain old CSS & HTML. It seems these attacks are targeted to the non tech savvy, but even I (tech savvy) get duped by persuasive messages in my browser. This is why I advocate for a Phishing/Malware 101 course which is mandatory for all types of tech-related courses and learning.
I am a web dev, and I agree that JS on the web is bad for pages that should be just documents like a news webpage or wiki page. JS makes sense for applications like a video game, video/audio/level/text editor, or some internal app that your company trust, but for random untrusted document pages JavaScript is a detriment, even if we only consider UX.
You haven't in your career, stumbled across web (sites/apps) that sit somewhere on the spectrum between the extremes of "document" vs "app"?
It strikes me that there's a fairly even distribution between those two points - even if we discount all the misguided "could have been a static site but someone decided it had to be an app" decisions.
I actually agree with you on reigning in javascript but I think much of the web is poorer without it. We had an answer for this years back and it was called "progressive enhancement".
Why isn't this still the norm?
The HN population consists for a large part of computer power users and developers who are fully aware of the capabilities of browsers and the dangers of remote code execution. I'll never understand why the default stance on HN still mostly seems to be javascript good, if not for the convenience factor.
Native apps and programmable documents (PDFs and spreadsheets for example) are the real security nightmare.
The danger on the web lies squarely with easily fooled idiots visiting shady sites.
In fact, we don't have to imagine that world: it was the world of the late 90s.
Hence why exploits like these are always about getting software installed onto the host rather than being 100% JS.
And before anyone says “but package managers solve this problem”, no they don’t. There have been numerous cases of compromised software leaking into office repositories. It happened with a Ubuntu package were an attacker hacked the upstream repository. It’s happened with npm. Browser extensions from Google and Firefox repos are frequently a source for Trojans. Android and iOS have lots of apps that appear to be free torches or other such utilities but are actually just harvesting all your data. Just because a software package is published to an official repository, it doesn’t make that package safe.
Hell, we even tried applets!
not every app is on the windows or Mac App store, not every app is on the Linux package managers. even so there is no sandboxing so you're just waiting until one of them gets compromised and hope nothing bad happens
sandboxing hostile apps is the only true way to protect yourself, and even that isn't perfect
Lenovo sells all-in-one PCs that run Android, and in a world without Javascript, you can imagine such a thing having become much more common that it actually has become so far in our world (e.g., with more enhancements done to Android to work well with a mouse) and of course Android has very solid sandboxing of apps.
Well, here's your actual problem. That's a vastly different threat model!
Modern browsers are very well sandboxed.
But the real story is "WordPress websites still hacked in masses".
WordPress, somehow, cannot manage to turn themselves into a secure and tough system. It remains a prime target, it's installations get hacked by the thousands and it's causing real harm at that.
(Yeah, yeah, I know the users, admins, plugins, themes and hosted are to blame. And I know it's possible to truly harden a WP- I've built a WP hosting company that did exactly this. But it's saddening how poor the wider community handles it's security)
I have to host a few dozen WordPress sites for customers and the ones that got hacked were all backtracked to: enumerating usernames, and some had their password equal that. You could blame WordPress for not being more strict rejecting those per default.
I am convinced this responsibility isn't taken up by the community or by organisations behind it, seriously enough. Simply because the current status continues to be abysmal. I have many practical ideas how many issues could be solved, most are put forward and put down almost monthly in the community.
The current status is resignment: "well, we are big and this is how things are". No! Things could be better, more secure etc. But for that, things do have to change.
Until developers are widely taught how to develop secure software, the problem will just keep moving around. We can't make software development environments where it's impossible to create a vulnerability, and we will never convince users to stop wanting new capabilities. Making things secure in the first place needs to be part of the solution.
Being a player that powers a vast part of all websites, gives a responsibility. Taking up that responsibility includes making unpopular decisions. While "getting rid of the entire plugin system" is probably a bridge too far (it would kill WP instantly) the system needs overhaul (same for hosting, same for themes), badly. There is an intermediate solution, I am sure¹.
But the starting point must be "our community cannot handle the power we give it, so let's find a solution for that".
¹ I refrain from concrete examples here, bc HN tends to spiral into discussions on why random potential solution X will never work. I want to keep this on a higher level.
And/Or a setup where a plugin's runtime is isolated from main WP and other plugins and it can only communicate with WP over a tiny and very much hardened API.
so many possibilities. This problem has been solved mostly. Just not for PHP (that I know) and certainly not for WP.
Cryptocurrency would have been good, as a technology, if its infrastructure didn't purposely embrace grifters and skepticism.
In general it is going to be impossible to block content. We need to charge for bytes or something like that. But that produces other problems which could be worse
I read that 25 year ago as a suggested solution to email spam, and it's many times less feasible today than it was back then.
It contained IPFS url with a login form sending data to some hacked site so this is already a standard practice.
It is also a bit amusing when you host your own mailserver for years.
There will be occasional false positives and some people would complain, but most IPFS gateway operators would just choose the top blocklist for simplicity.
How does this work? Can a single entity really just blacklist certain addresses? How is this decentralized?
I am kinda surprised you haven't heard about this already. This has been used in the past to take down NFTs [0] and to make Bitcoins unspendable [1]
It's the famous "on chain only" caveat: all the decentralized systems are only decentralized in the ideal world, if nothing except the chain exists. Once practical reality comes in, there are plenty of levers for centralized control.
An in practice, there was no hard fork, and yet Moxie's NFT was "removed" from opensea and from the metamask wallet. Sure, someone with a full client can still see the NFT and _techinically_ all the data is there.. and yet the data is value-less. Would you pay any amount of money for NFT you cannot show off to anyone nor use with any online service?
The same goes with bitcoin - sure, the chain will happily process your bitcoin transactions from the mixer and accept your gas fees. So if you are only looking on the chain, it is all fine and decentralized. But if you are actually trying to withdraw the money, then your accounts get blocked. So in practice, this may not be 100% useless, but this is still significantly less useful than "clean" bitcoin. And no hard fork or even community consensus required.
in this context it does matter. cloudlfare and any other "web 2" (for lack of a better encompassing term) is censorable. they can use any other HTTP API (or host their own although that could be blocked by a VPS eventually).
i agree with the rest of what you're saying. the reality is that it's a decentralized world that inherently requires centralized bridging. the KYC push was the turning point for controlling all the on/off ramps. it's still possible to exchange entirely on chain but the recipient would have to acknowledge that if the sender is black listed then their received holdings are subject to the same control.
as long as there is "border control" back to tradfi then there will always be a centralized constraint on the concept. in theory we may see a future where people have enough markets for remaining purely on chain but anything related to government fiat (housing, taxes etc) will by definition remain centralized.
forget about mixers. just launch an NFT or ordinals collection, buy it first with your clean KYC’d coin, pump it with your dirty coin, and sell your clean coin to whoever is buying - the audience or your dirty coin address
now you just have more clean coin, if you even want govbucks then you can get that on an exchange with no issue now
a decentralized blockchain cannot block an address from sending or receiving transactions (without a hard fork - like ethereum did some years ago).
however, centralized services (like binancd) run nodes which read and publish on-chain data (transactions and data, like malware, associated with them) through regular HTTP APIs.
anyone running an API can choose to not allow access to data associated with certain addresses. it's their API and they can do what they want with it. the same way the youtube (insert platform) API could decide to block queries for certain channels or topics.
I thought web3 was supposed to be uncensored so we could serve and download all the malware we wanted?
Therefore, the fact that "every time [you] read about" it, it involves some dramatic exceptional circumstance, is somewhat par-for-the-course.
By the same standard, the only things that I - as a non-enthusiast - ever read about the art world, is the extreme valuations, the thefts, the rude vandalisms. The only things I ever read about banks are the record profits, the manipulations of finance, the robberies. The only thing I ever read about the Middle East, is war.
The fact that it's mostly filled with decent ordinary people just trying to live their lives, is the boring, the unremarked yet dominant landscape, which somehow gets lost in the loud buzz of persistent drama.
No, I will not "update" my browser nor enable JavaScript just to read your text and images.
Everyone seems to have discovered that "security" is a great excuse to coerce people into doing things.
"The only thing we have to fear, is fear itself."
Too bad it was malware.
“In response to questions from KrebsOnSecurity, the BNB Smart Chain (BSC) said its team is aware of the malware abusing its blockchain, and is actively addressing the issue. The company said all addresses associated with the spread of the malware have been blacklisted, and that its technicians had developed a model to detect future smart contracts that use similar methods to host malicious scripts.”
I thought one of the big drivers for people using blockchain is the decentralised nature- resistance to censorship etc. Seems like this one isn’t a great long-term choice for malware as it’s not censorship resistant (as evidenced by the blacklist).
The malware guys can probably still find another 3rd party block viewer . But it is hassle for them.
If the majority of nodes in the network comply with the blacklist, then it works. But at any point, someone who runs a node (or nodes) can choose to ignore the blacklist.
It's only centralized if the majority of people running BNB Smart Chain decide to trust Binance.
Another reason to use ublock origin for private use and also deploy it in company use with GPO, Intune or other RMM.
Since the attack is likely JavaScript based, provided one configures Ublock Origin to by default deny all JavaScript (this is not Ublock's default mode, you have to turn on "I am an advanced user" mode and then block all JS by default using the advanced user UI controls) then the answer is very likely: yes, it will. Because if it is JS based - if no JS runs, no exploit happens.
Finally a practical use for web3
Still a very good practice today.
1) the simplest methods can stick around the longest. His skimmer page is 13 years old and it's still relevant, for example. Similarly, we will not be rid of fake download buttons or compromised wordpress sites in our lifetimes.
2) If you write about the simple stuff, your articles will be evergreen. You don't have to time the market when your product never falls out of demand.
Tl;dr, there are multiple ransomware groups that are using this method to find new infostealer victims.
https://krebsonsecurity.com/2023/09/snatch-ransom-group-expo...