APT Targeting Indian Police Agencies.
-
Upload
rahul-sasi -
Category
Technology
-
view
1.952 -
download
3
description
Transcript of APT Targeting Indian Police Agencies.
Garage4Hackers
Sandy
APT: Advance Persistence Threat
http://exploit-analysis.com/
Static AND DYnamicanalysis
Garage4Hackers
About Me
[Rahul Sasi ]
I work as a Researcher.
One of the admins of www.Garage4Hackers.com.
https://twitter.com/fb1h2s
I spend my free time researching on new attack vectors.
Garage4Hackers
Presented my research papers at
Garage4Hackers
APT - Attacks
Advance Persistent threats: Any exploit | malware that particularly targets a specific organization, country in order to steal confidential information.
Garage4Hackers
About this Talk
With the rise in number of targeted attacks against government and private companies, there is a certain requirement for an intelligent method for determining these attacks.
This talk would be on an un-detected APT attack targeting Indian police organizations which we identified a week back.
Sandy is a free tool we have build that is capable of doing exploit analysis on Doc, RTF, XLS,PPT, Jar, Urls.
We also will explain the implications and policy guidelines for the prevention of these attacks.
Garage4Hackers
APT: Who should be concerned.
You need ask yourself what have u got that other people would want .
Commercially sensitive information, Intellectual property that has designs.
What I have seen is mostly, government, manufactures, financial services.
Garage4Hackers
My organization is small!
Many attacks I have seen were attacking small companies.
And most of the times its the start-up that have the innovative technology that can be used.
Or could be small organization working for the government.
We have seen smaller organizations targeted as much as the larger organizations.
Garage4Hackers
Recent APT Incident in news.FBI released a notice on targeted attack on US aviation Industry.
Many professionals from the aviation industry was targeted and there computers were infected or an attempt to infect was made.
Steal blueprints, new airspace technology and lots of stuffs .
Garage4Hackers
APT Steps
Garage4Hackers
Step 1: Establishing the backdoor.
Use of various Exploits .
Uses malicious attachments via email to infect victims.
These contained exploits targeting various applications like Adobe Reader and Microsoft Office.
Browser based exploits where you visit a particular a web page crafted with an exploits
Garage4Hackers
Document Exploits.Uses an exploit.
File comes in the form of .doc .rtf file that has the exploit embedded.
Once you open these doc files you would be infected.
These exploits affect OS with office | pdf installed.
Garage4Hackers
What is Sandy
A tool built under Indian Honeynet project.
Sandy is an online tool (sandbox) capable of doing both static and dynamic analysis of Malicious Office, PDF, Jar, Flash, HTML.
The input would be the above mentioned file formats and output would be extracted malwares, controllers, Urls.
In the talk I will share information on a particular sample targeting Indian police department that we received via sandy .
Sandy Submission Interface
www.exploit-analysis.com
Garage4Hackers
Sandy Submission:On 2013-09-03 we received a .doc file on sandy.
The exploit email was sent to the company’s top executives of an IT security company.
At the time of analysis only 2/34 Anti Virus was detecting it as malicious.
The document when opened on windows based machines dropped a backdoor on the users computer.
Garage4Hackers
Research on the Attackers
We managed to collect 30 other exploits that were used by the same group over a period of 1 year and analyzed them.
We tried to understand the attackers tools and techniques, Modus operandi and targets.
Out of the 30 exploits none of them was made on a Saturday or Sunday .
Garage4Hackers
Based on our research on the Malware infrastructure .
We were able to identify that the same group of attackers were targeting Indian police agencies .
We were able to locate a new persistence malware with no AV detection, which is digitally signed and is used by this team.
Except 1 Chinese AV no other AV company was detecting the threat.
The attacks were part of a Cyber spying [ campaign].
Garage4Hackers
Modus operandi &
Tools and TechniquesThe attacker were mainly using phishing based attacks via email to infect there targets.
The attackers were manually verifying the infected machines and were adding the new persistence malware to it.
So if they found the infected machine of high importance then they added a secondary advance monitoring tool to there systems.
Garage4Hackers
Targets
Targets were mainly government organizations.
Small private companies and contractors to the government.
Most of the infected computers were that of the secretaries .
Garage4Hackers
A map of the infections.
Garage4Hackers
Lessons Learned and Policy Implications.
Knowing what you need to protect is the most important task.
Active Government and community partnership is necessary.
Security awareness among employees: the human firewall.
No single layer of fraud prevention or authentication is enough to stop determined attackers.
Garage4Hackers
Thank You
Contact me at if you need malware samples :
https://twitter.com/fb1h2s
https://www.facebook.com/loverahulsas