CrowdStrike and Federal Authorities Dismantle Russian Malware That Secretly Stole Crypto for 8 Years

A campaign of malware operated by Russian cybercriminals for eight years was dismantled by federal authorities in conjunction with the cybersecurity firm CrowdStrike on Thursday. The malware, identified by the security firm as “EggJagger” or as Sality malware, preyed upon thousands of users of virtual currency by engaging in “clipboard hijacking.” The most common method that users of virtual currencies such as Bitcoin and Ethereum employ in order to send currency is to copy a virtual currency address from a web page to a computer’s clipboard and then later to paste the virtual currency address into the corresponding field of a wallet application. The malware sat idle on a user’s computer and then, before the user had a chance to discover the substitution, would change the virtual currency address that had been placed in the user’s clipboard to an address controlled by the cybercriminals, reported CoinDesk.

Once the compromised address was pasted into the user’s wallet software, and the resulting transaction had been confirmed, the cryptocurrency was transferred irretrievably to the attacker. While there was no particular attack functionality that triggered any alerts, the single defense against such an attack was for the user to manually verify the address that they had pasted into the sending field. Typically the first and last characters of a wallet address would be verified against what was expected, but in this case all would need to be checked. The reason for this type of attack to have persisted for some eight years is that it is an easy one to implement, and places the onus of security on the end user to perform correctly in these situations.

Analysis by CrowdStrike has uncovered the malfeit cryptocurrency operators amassed 12.1 million rubles ($150,000) in the years the malware was active and operating, however most of the stolen cryptocurrency had been deposited into online wallets, remained untouched by the cybercriminals. However with the recent and ongoing surge in value of many of the world’s most popular cryptocurrencies the hacker’s abandoned stash has appreciated significantly to an estimated $1.35m. The returns on such a relatively simple attack vector to extract cryptocurrency from individuals is significant and in this instance highlights that such malware, whilst still active after eight years, continues to reap significant returns on little more than foraging for victims, capitalizing on default settings and exploiting human nature of individuals utilizing online cryptocurrency services.

A major weakness of the botnet infrastructure behind EggJagger was the minimal security controls in place around the network of infected computers. As long as a compromised computer was responding to commands appropriately, it could be included in the botnet of other compromised systems. In a live demonstration of the vulnerability on Monday at CrowdStrike’s Day Zero summit in Las Vegas, the security team of researchers used the same hole to subvert EggJagger and replace the legitimate peer addresses embedded in the malware with the IP addresses of their own servers. Suddenly, more than 15,000 computers infected with EggJagger around the world lost connection to their command-and-control servers in an instant, bringing the whole operation crashing down.

The high-profile takedown of the long-running Russian malware operation highlighted the persistent cyber threats to financial infrastructure emanating from Russia, as well as the growing role of the private cybersecurity sector working in conjunction with law enforcement to counter threats to the financial system. Despite having developed sophisticated operational security measures over an eight-year period, Sality ultimately relied on a relatively simple vector to steal cryptocurrency from thousands of individuals and businesses – that of exploiting routine human practices. The botnet’s vulnerability to having its peer connections severed by not authenticating the connections was identified by law enforcement and subsequently exploited to dismantle the operation in a single action, bringing an end to a threat that had affected thousands of individuals and businesses across South Florida and the country.

Keep reading

Unknown's avatar

Author: HP McLovincraft

Seeker of rabbit holes. Pessimist. Libertine. Contrarian. Your huckleberry. Possibly true tales of sanity-blasting horror also known as abject reality. Prepare yourself. Veteran of a thousand psychic wars. I have seen the fnords. Deplatformed on Tumblr and Twitter.

Leave a comment