Insecure Internal Storage in Android

Today, Palo Alto Networks researcher Claud Xiao is delivering a presentation titled “Insecure Internal Storage in Android” at the Hacks in Taiwan Conference (HITCON).

Claud is discussing techniques for accessing private data in Android’s internal storage system using the Android Debug Bridge (ADB) backup/restore functionality. While over 85% of active Android devices are vulnerable to this attack, Android includes multiple levels of protection to prevent unauthorized data access. In today’s presentation, Claud will have demonstrated how an attacker could bypass all of those protections to gain access to usernames, passwords and a treasure trove of other data.

To understand this attack, it’s critical to understand how applications use Android internal storage and why unauthorized access to this data is so problematic.

Continue reading "Insecure Internal Storage in Android"

Palo Alto Networks Discovers 3 Critical Internet Explorer Vulnerabilities

Palo Alto Networks researchers discovered 3 new critical Internet Explorer (IE) vulnerabilities covering IE versions 8, 9, 10 and 11.

Each of these discoveries allows full remote code execution using a memory corruption vulnerability in IE. They have been documented in Microsoft Security Bulletin MS14-051and part of the August 2014 Security Bulletin. Palo Alto Networks researcher Bo Qu is credited with all 3 vulnerabilities.

Palo Alto Networks customers are protected from these vulnerabilities through our regular Vulnerability Protection updates, and we recommend Internet Explorer users upgrade to the latest patch from Microsoft.

Continue reading "Palo Alto Networks Discovers 3 Critical Internet Explorer Vulnerabilities"

Attacks on East Asia using Google Code for Command and Control

Recently, FireEye published a blog titled “Operation Poisoned Hurricane” which detailed the use of PlugX malware variants signed with legitimate certificates that used Google Code project pages for command and control (C2). We were able to uncover multiple additional samples exploiting the same technique as well as an additional Google Code account with multiple projects containing encoded commands.

The attacks against Palo Alto Networks customers, which took place between early June to early July, also targeted users in East Asia; in this case an international law firm’s regional office and a major university. All of the attacks were detected by our WildFire platform.

Of note, three of the Google Code projects associated with the newly uncovered account were added during the past few days, indicating it is still in active use.

Continue reading "Attacks on East Asia using Google Code for Command and Control"

Hunting the Mutex

Summary

Mutex analysis is an often overlooked and useful tool for malware author fingerprinting, family classification, and even discovery. Far from the hypothesized "huge amount of variability" in mutex names, likely hypothesized due to the seemingly random appearance of them, practical mutex usage is embarrassingly consistent. In fact, over 15% of all collected worms share a single mutex [2gvwnqjz].

This blog was sourced from the data generated by the WildFire Analytics cloud, which processes thousands of samples a day and provides insights into various characteristics and behaviors of malware worldwide. But before we get into the details, here is a quick overview of mutexes and why they exist in the first place.

Mutex Overview Continue reading "Hunting the Mutex"

Check Out Scenes from Palo Alto Networks at Black Hat 2014

From a well-attended session on our advanced endpoint protection, to the buzz at the booth for Unit 42, our threat intelligence team, and a full slate of demonstrations and visualizations, there was plenty to take in at a very busy Black Hat USA.

Here's a look back at Palo Alto Networks at Black Hat: Continue reading "Check Out Scenes from Palo Alto Networks at Black Hat 2014"

Black Hat 2014: Threat Intelligence With an Emphasis On Context

A few weeks ago we formally introduced Unit 42, the new threat intelligence team at Palo Alto Networks. Following the release Unit 42's inaugural research paper, 419 Evolution, many of the team leads are on the scene here at Black Hat 2014 in Las Vegas.

blog-title-unit42

It's a chance for the security community at large to get to know Unit 42 and our intelligence gathering process, which endeavors not only to provide technical research and detailed analysis of threats, but also to provide context into an attacker's motivations and methods using data collected from the Palo Alto Networks security platform. The approach is intended to help security practitioners and business leaders make sense of trends and thus make better-informed decisions about their security posture.

Ryan Olson, Unit 42 Intelligence Director, joined us from the show floor at Black Hat today to talk about Unit 42, 419 Evolution and what's to come from this exciting new Palo Alto Networks team. Watch below: Continue reading "Black Hat 2014: Threat Intelligence With an Emphasis On Context"

Where To Find Palo Alto Networks At Black Hat 2014

Black Hat USA 2014 is taking place all this week in Las Vegas, and as the exhibit halls and many of the briefings open on Wednesday, we invite you to visit with Palo Alto Networks throughout the show.

Black Hat

Join us at Booth #227 on Wednesday and Thursday to: Continue reading "Where To Find Palo Alto Networks At Black Hat 2014"

Palo Alto Networks Provides a New Breed of Intelligence to Detect and Prevent

Back in June, Microsoft patched 59 Internet Explorer vulnerabilities and Palo Alto Networks discovered 21 of them, all rated critical. Then in July, we released findings about evolved Nigerian 419 scammers from Unit 42, the new Palo Alto Networks threat intelligence team.

The way we perform cybersecurity research is opening the door to a new breed of intelligence that I predict will reshape how organizations gather and share cyber intelligence while converting it to actionable indicators.

The reason is evasive applications. Continue reading "Palo Alto Networks Provides a New Breed of Intelligence to Detect and Prevent"

Backoff and Citadel Abuse Remote Access Tools

Recent events continue to highlight the abuse of remote access applications in the enterprise. Last Tuesday, Trusteer reported that a new variant of Citadel, which has long relied on VNC to give attackers remote control over systems, began adding new credentials to systems it infects and enabling the standard Windows remote desktop application (RDP). This allows the attacker to maintain control over the system even after the Citadel infection is removed. As the report indicates, using RDP this way also allows the attackers to “fly under the radar” as RDP is commonly used by administrators and often not treated as a threat. Continue reading "Backoff and Citadel Abuse Remote Access Tools"

New Release: Decrypting NetWire C2 Traffic

On July 22, Palo Alto Networks threat intelligence team, Unit 42, released our first report on the evolution of “Silver Spaniel” 419 scammers.  Of particular note is how these actors use a Remote Administration Tool (RAT) named NetWire (part of the NetWiredRC malware family). This RAT gives a remote attacker complete control over a Windows, Mac OS X, or Linux system through a simple graphical user interface.

To better understand this RAT, our team reverse engineered the communication protocol that NetWire uses. Today we have released a tool that decrypts NetWire traffic and outputs any commands issued by the attacker.

NetWire Encrytion Protocol

NetWire uses a custom, TCP-based protocol. The producer of the NetWire WorldWiredLabs, states that the tool uses 256-bit AES encryption, which we found to be accurate. The tool generates two encryption keys using a static password that the attacker chooses when creating the NetWire binary. Each packet has the following structure:

< 4 Byte Little-Endian length > < 1 Byte Command > < Data >

The shortest possible packet is the “HeartBeat” command, which NetWire generates every 10 seconds.

pic 1
Continue reading "New Release: Decrypting NetWire C2 Traffic"

Meet the Unit 42 Team at Black Hat 2014

Black Hat USA 2014 kicks off next week, and along with our product and solution experts, you'll meet team leads from Unit 42, the Palo Alto Networks threat intelligence team.

Last week we celebrated the official launch of Unit 42, along with the release of 419 Evolution, a new report examining the evolution of Nigerian actors that had previously been active launching 419 scams and are now targeting businesses with more sophisticated techniques.

Download a copy of the report to understand the tools and infrastructure used in their attacks, as well as how to protect your critical assets.

419 evolution Continue reading "Meet the Unit 42 Team at Black Hat 2014"

Palo Alto Networks News of the Week – July 25

Here’s a roundup of this week’s top Palo Alto Networks news.

 

 

We are happy to officially introduce our new threat intelligence team, Unit 42, and the release of its first research paper, 419 Evolution.

419 evolution

Check out some of the great global coverage from this announcement: Continue reading "Palo Alto Networks News of the Week – July 25"

Unit 42: A New Era In Threat Intelligence

Today we would like to officially introduce our new threat intelligence team, Unit 42, and announce the release of our first research paper, 419 Evolution.

Unit 42 uses data collected from the Palo Alto Networks security platform to provide context into an attacker’s motivations and methods. Using our Critical Intelligence Requirements developed by our leadership, we determine what data is necessary to answer questions about threats to Palo Alto Networks and our customers. Continue reading "Unit 42: A New Era In Threat Intelligence"

Why Havex Is a Game-Changing Threat to Industrial Control Systems – Part 2

In part 1 of this 2-part blog series, we discussed why the Havex Trojan is a significant and concerning industry milestone. Here, in part 2, we look at how you can mitigate your exposure through the combination of good practices and next-generation firewall technology.

In my initial engagements with control systems operators interested in our technology, two security objectives, both linked with the objective of keeping uptime high, frequently come up.

First, the operations manager, or person responsible for security in the operational technology (OT) environment, is concerned over whether only the approved users are using the right applications and resources in the specific usage model intended for SCADA. This person, at the very basic level, would want to be able to validate that the system is used only in a way that aligns with the business objectives, ultimately with the goal of implementing role-based access control.  In this person’s mind, an internal user accidentally causing system downtime is as much a cyberthreat as an incident malicious in nature.  Continue reading "Why Havex Is a Game-Changing Threat to Industrial Control Systems – Part 2"

Black Hat 2014 Is Right Around the Corner…

Cybersecurity is moving away from legacy "defense-in-depth" and alert-focused solutions and toward a new toolkit that can detect and prevent the most sophisticated threats. Only Palo Alto Networks can deliver on the promise of a true next-generation security platform across network and endpoint, and we invite you to join us at Black Hat USA 2014 to learn about our intelligence-based approach to preventing advanced attacks before they cause harm.

logo

If you're headed for this year's Black Hat conference in Las Vegas (August 2-7), we want to see you! Here's how... Continue reading "Black Hat 2014 Is Right Around the Corner…"