HomeSecurityMicrosoft: warning about tampered software updaters

Microsoft: warning about tampered software updaters

Microsoft has warned software companies to better protect their updater processes after discovering a "well-planned and orchestrated" attack that took down the update service of an unnamed software product.

As Microsoft's threat intelligence team explains, the attackers used the update mechanism of a popular application to gain access to several high-profile technology and financial organizations. According to Microsoft, the software developer itself was also under attack.Microsoft

The espionage campaign, dubbed WilySupply by Microsoft, is likely financially motivated and targets updaters to primarily reach finance and payment companies.

In this case, they used the updater to install an “unsigned low-prevalence executable” to scan the victim’s network by establishing remote access.

Such an attack on the update process of a trusted software is a clever side door for attackers, as users use the mechanism to receive valid updates.

Microsoft notes that the same technique has been used in various attacks, such as the breaches that occurred at South Korean companies in 2013 via a malicious version of a SimDisk installer.

The attackers are reportedly using free, open-source tools, such as Evil Grade, which helps exploit flawed update applications to introduce fake updates. As Microsoft notes, WilySupply did just that, while protecting the attackers' identities.

The other tool used by the attackers was Meterpreter, the memory component of the Metaplsoit framework.

“The executable turned out to be a malicious binary that runs PowerShell scripts with the Meterpreter reverse shell, which silently grants remote control to the attacker. The binary was identified by Microsoft as “Rivit.”

“Using the timeline and process tree views in the Windows Defender ATP console, we were able to identify the process responsible for the malicious activities and pinpoint their occurrence. We traced these activities to a software updater,” Microsoft says.

“Forensic examination of the Temp folder on the infected machine showed us a legitimate third-party updater running as a service.”

The updater downloaded an unsigned, low-prevalence executable file before the malicious activity was observed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS