HomeSecurityBPFDoor malware: Exploits Solaris vulnerability to gain root privileges

BPFDoor malware: Exploits Solaris vulnerability to gain root privileges

New research into the inner workings of the BPFdoor malware for Linux and Solaris reveals that the threat actor behind it used an old vulnerability to achieve persistence on targeted systems.

BPFDoor is a custom backdoor that has been used for at least five years in attacks against telecommunications, government, education, and logistics organizations.

The malware was only recently discovered and first reported by researchers from PricewaterhouseCoopers (PwC), who based threat actor China- referred to as Red Menshen.

BPFDoor malware: Exploits Solaris vulnerability to gain root privileges

See also: Mozilla: Fixes zero-days exploited in Pwn2Own

PwC found BPFDoor during an incident response engagement in 2021. Looking more closely at the malware, researchers noticed that it was receiving commands from Virtual Private Servers (VPS) controlled via compromised routers in Taiwan.

Subsequent, comprehensive research by Craig Rowland, the founder of Sandfly Security, and Kevin Beaumont demonstrated the extremely insidious nature of the malware, which can effectively bypass most detection systems.

BPFDoor cannot be stopped by firewalls, can operate without opening any ports, and does not need a command and control server, as it can receive commands from any IP address on the Web.

Using a public exploit

Cybersecurity firm CrowdStrike observed a threat actor primarily focused on targeting Linux and Solaris systems using the custom BPFDoor implant on telecommunications providers to steal personal user information (e.g. call detail records, data on specific phone numbers).

CrowdStrike is tracking the backdoor called JustForFun and attributes it to an adversary referred to as DecisiveArchitect. Researchers have analyzed the activity of this adversary multiple times since 2019.

In a report today, researchers provide details on how defenders can detect the BPFDoor implant and highlight the techniques used across Solaris systems.

See also: Zoom fixes some security holes – Update to version 5.10.0

They note that once DecisiveArchitect gains access to a Solaris system, it achieves root-level privileges by exploiting CVE-2019-3010 – a vulnerability in the XScreenSaver component of the Solaris operating system (version 11.x).

The exploit code for the vulnerability has been publicly available for three years, and it appears that DecisiveArchitect has made no attempt to modify it.

BPFDoor malware: Exploits Solaris vulnerability to gain root privileges

The threat actor begins exploiting the flaw typically “within minutes of deploying the JustForFun implant,” according to the researchers’ observations.

CrowdStrike researchers note that on Solaris systems the threat actor uses the LD_PRELOAD environment variable to achieve functionality similar to the command-line spoofing seen on Linux hosts.

However, as of April 2022, DecisiveArchitect updated its tactics, techniques, and procedures and began using the LD_PRELOAD environment variable on Linux machines as well to load the BPFDoor/JustForFun implant into the legitimate /sbin/agetty process.

Manual detection

Researchers emphasize that detecting BPFDoor/JustForFun implants on a Linux system can prove to be a daunting task because the threat agent modifies existing SysVinit scripts on the host to achieve persistence.

Therefore, simply reviewing the lines of code in SysVinit scripts is unlikely to reveal the reference to the implant and all file references should be analyzed.

See also: DuckDuckGo: Allows Microsoft trackers due to agreement

To make detection even more difficult, the file names and paths for the implant and related persistence-related scripts are different from one system to another.

CrowdStrike provides a set of commands that could help defenders investigate whether BPFDoor is present on their network by identifying processes running with a raw socket open:

BPFDoor solaris

The lsof command in Linux will report the spoofed command line and can help analysts list open files associated with a process ID.

The commands for Solaris systems will loop through each process looking for strings indicating a process running a packet filter and looking for processes that loaded the libpcap library.

While these commands alone cannot necessarily reveal the implant, they are useful in determining whether further investigation of suspicious activity is warranted.

Today's CrowdStrike report includes a list of indicators of compromise for both Linux and Solaris systems, as well as two Windows scripts whose purpose remains unknown.

Researchers say that the threat actor behind BFPDoor interacts with Windows machines during the early stages of the attack, but they did not detect any custom implants for this operating system.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS