HomeSecurityInfo-stealing Python malware uses Unicode to evade detection

Info-stealing Python malware uses Unicode to evade detection

A Python library on PyPI uses Unicode to evade detection, stealing and removing developer account data and other confidential information from compromised devices.

In order to avoid detection by automated scans and defenses based on string matching, the malicious “onyxproxy” package uses a mix of various Unicode fonts in its source code.

The discovery of onyxproxy comes from cybersecurity experts at Phylum, who published a report explaining the technique.

Since its release on PyPI two weeks ago, the malicious package had amassed 183 downloads before being removed from the platform yesterday.

See also: What malware distribution techniques does the ScarCruft hacking group use?

Python Unicode

Unicode is a groundbreaking character encoding standard that unifies over 100,000 characters from numerous scripts and languages ​​into one massive system. With this innovative technology, users can access various sets/shapes with ease, while maintaining data accuracy across platforms .

Unicode was developed to ensure interoperability and standardized text representation across languages, platforms, and devices, and was created to prevent encoding problems that could otherwise lead to data corruption.

The “onyxproxy” package hides a “setup.py” that contains thousands of suspicious code strings combining Unicode characters.

A simple glance at these strings wouldn't necessarily reveal significant differences between them, however the change in font style has a huge impact on Python interpreters who are able to recognize and interpret the characters as distinctly different.

See also: Play ransomware group published Royal Dirkzwager data

For example, Unicode provides five different variations of the letter “n” and 19 versions of the letter “s,” each of which corresponds to different languages, mathematical formulas, and more. Even something as simple as a word like “self” can be represented 122,740 ways with Unicode (19x19x20x17).

Developers can take advantage of Python's Unicode support for identifiers, such as code variables, functions, classes, modules, and other objects. This feature allows them to create unique identifiers that look the same but refer to different functions.

Info-stealing Python malware uses Unicode to evade detection

The creators of Onyxproxy implemented the identifiers “__import__”, “subprocess”, and “CryptUnprotectData”, which are larger and more varied, thus allowing it to effectively fool string matching defenses.

Python's Unicode support can easily be abused to hide malicious string mappings, making code appear harmless while still performing malicious behavior. In this case, stealing sensitive data and authentication tokens from developers.

While this obfuscation method is not particularly sophisticated, it is concerning to see it being used and may be indicative of a broader misuse of Unicode for Python obfuscation.

See also: Rio Tinto: Staff personal data may have been leaked

The Python developer community has long since begun a substantive discussion about the potential dangers of Unicode in Python.

In summary, these threats have been verified and security professionals need to deploy more effective detection systems to combat them.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS