+ All Categories
Home > Technology > APT Targeting Indian Police Agencies.

APT Targeting Indian Police Agencies.

Date post: 25-May-2015
Category:
Upload: rahul-sasi
View: 1,952 times
Download: 3 times
Share this document with a friend
Description:
My Cocon Presentation this was presented at the Non-technical tracks .So slides does not contain any technical details of the malware. If you need the samples mentioned in the slides, please do emails me.
Popular Tags:
21
Sandy APT: Advance Persistence Threat http://exploit- analysis.com/ Static AND DYnamic analysis Garage4Hackers
Transcript
Page 1: APT Targeting Indian Police Agencies.

Garage4Hackers

Sandy

APT: Advance Persistence Threat

http://exploit-analysis.com/

Static AND DYnamicanalysis

Page 2: APT Targeting Indian Police Agencies.

Garage4Hackers

About Me

[Rahul Sasi ]

I work as a Researcher.

One of the admins of www.Garage4Hackers.com.

https://twitter.com/fb1h2s

I spend my free time researching on new attack vectors.

Page 3: APT Targeting Indian Police Agencies.

Garage4Hackers

Presented my research papers at

Page 4: APT Targeting Indian Police Agencies.

Garage4Hackers

APT - Attacks

Advance Persistent threats: Any exploit | malware that particularly targets a specific organization, country in order to steal confidential information.

Page 5: APT Targeting Indian Police Agencies.

Garage4Hackers

About this Talk

With the rise in number of targeted attacks against government and private companies, there is a certain requirement for an intelligent method for determining these attacks.

This talk would be on an un-detected APT attack targeting Indian police organizations which we identified a week back.

Sandy is a free tool we have build that is capable of doing exploit analysis on Doc, RTF, XLS,PPT, Jar, Urls.

We also will explain the implications and policy guidelines for the prevention of these attacks.

Page 6: APT Targeting Indian Police Agencies.

Garage4Hackers

APT: Who should be concerned.

You need ask yourself what have u got that other people would want .

Commercially sensitive information, Intellectual property that has designs.

What I have seen is mostly, government, manufactures, financial services.

Page 7: APT Targeting Indian Police Agencies.

Garage4Hackers

My organization is small!

Many attacks I have seen were attacking small companies.

And most of the times its the start-up that have the innovative technology that can be used.

Or could be small organization working for the government.

We have seen smaller organizations targeted as much as the larger organizations.

Page 8: APT Targeting Indian Police Agencies.

Garage4Hackers

Recent APT Incident in news.FBI released a notice on targeted attack on US aviation Industry.

Many professionals from the aviation industry was targeted and there computers were infected or an attempt to infect was made.

Steal blueprints, new airspace technology and lots of stuffs .

Page 9: APT Targeting Indian Police Agencies.

Garage4Hackers

APT Steps

Page 10: APT Targeting Indian Police Agencies.

Garage4Hackers

Step 1: Establishing the backdoor.

Use of various Exploits .

Uses malicious attachments via email to infect victims.

These contained exploits targeting various applications like Adobe Reader and Microsoft Office.

Browser based exploits where you visit a particular a web page crafted with an exploits

Page 11: APT Targeting Indian Police Agencies.

Garage4Hackers

Document Exploits.Uses an exploit.

File comes in the form of .doc .rtf file that has the exploit embedded.

Once you open these doc files you would be infected.

These exploits affect OS with office | pdf installed.

Page 12: APT Targeting Indian Police Agencies.

Garage4Hackers

What is Sandy

A tool built under Indian Honeynet project.

Sandy is an online tool (sandbox) capable of doing both static and dynamic analysis of Malicious Office, PDF, Jar, Flash, HTML.

The input would be the above mentioned file formats and output would be extracted malwares, controllers, Urls.

In the talk I will share information on a particular sample targeting Indian police department that we received via sandy .

Page 13: APT Targeting Indian Police Agencies.

Sandy Submission Interface

www.exploit-analysis.com

Page 14: APT Targeting Indian Police Agencies.

Garage4Hackers

Sandy Submission:On 2013-09-03 we received a .doc file on sandy.

The exploit email was sent to the company’s top executives of an IT security company.

At the time of analysis only 2/34 Anti Virus was detecting it as malicious.

The document when opened on windows based machines dropped a backdoor on the users computer.

Page 15: APT Targeting Indian Police Agencies.

Garage4Hackers

Research on the Attackers

We managed to collect 30 other exploits that were used by the same group over a period of 1 year and analyzed them.

We tried to understand the attackers tools and techniques, Modus operandi and targets.

Out of the 30 exploits none of them was made on a Saturday or Sunday .

Page 16: APT Targeting Indian Police Agencies.

Garage4Hackers

Based on our research on the Malware infrastructure .

We were able to identify that the same group of attackers were targeting Indian police agencies .

We were able to locate a new persistence malware with no AV detection, which is digitally signed and is used by this team.

Except 1 Chinese AV no other AV company was detecting the threat.

The attacks were part of a Cyber spying [ campaign].

Page 17: APT Targeting Indian Police Agencies.

Garage4Hackers

Modus operandi &

Tools and TechniquesThe attacker were mainly using phishing based attacks via email to infect there targets.

The attackers were manually verifying the infected machines and were adding the new persistence malware to it.

So if they found the infected machine of high importance then they added a secondary advance monitoring tool to there systems.

Page 18: APT Targeting Indian Police Agencies.

Garage4Hackers

Targets

Targets were mainly government organizations.

Small private companies and contractors to the government.

Most of the infected computers were that of the secretaries .

Page 19: APT Targeting Indian Police Agencies.

Garage4Hackers

A map of the infections.

Page 20: APT Targeting Indian Police Agencies.

Garage4Hackers

Lessons Learned and Policy Implications.

Knowing what you need to protect is the most important task.

Active Government and community partnership is necessary.

Security awareness among employees: the human firewall.

No single layer of fraud prevention or authentication is enough to stop determined attackers.


Recommended