Kaspersky Lab detects new mobile malware for Android and iOS and maps HackingTeam's Command and Control servers
Athens, June 24, 2014
According to new research conducted by Kaspersky Lab, in collaboration with Citizen Lab, the list of victims includes activists and human rights advocates, as well as journalists and politicians.
RCS Infrastructure
Kaspersky Lab leveraged various security approaches to identify Galileo Command & Control (C&C) servers around the world. For the identification process, Kaspersky Lab experts relied on special indicators and connectivity data obtained from existing reverse engineering samples.
During the investigation, Kaspersky Lab researchers identified over 320 RCS C&C servers in more than 40 countries. The majority of the servers were located in the US, Kazakhstan, Ecuador, the UK, and Canada.
Commenting on the latest findings, Sergey Golovanov, Principal Security Researcher at Kaspersky Lab, said: “The presence of these servers in a particular country does not imply that they are used by law enforcement agencies in that country. However, it makes sense for RCS users to deploy C&C servers in the regions they control, where the risks of cross-border legal issues or potential server seizures are lower.”.
RCS Mobile Implants
Although HackingTeam’s mobile Trojans for iOS and Android had previously been known to exist, no one had actually identified them – or had noticed them being used in attacks. Kaspersky Lab experts have been investigating RCS malware for the past two years. Earlier this year, they were able to identify specific samples of mobile modules that matched the settings of other RCS malware they had already collected. During the latest investigation, they collected new sample variants from victims via Kaspersky Security Network, Kaspersky Lab’s cloud-based network. In addition, the company’s experts worked closely with Morgan Marquis-Boire from Citizen Lab, who has extensively researched the malware developed by HackingTeam.
"Infection" carriers
The operators behind RCS Galileo develop a specific malicious implant for each specific target. Once the sample is prepared, the attacker transfers it to the victim’s mobile device. Known methods of “infection” include spearphishing through social engineering. Often, this is combined with the use of exploits, such as zero-day exploits, as well as local “infections” via USB cables during the synchronization process of mobile devices.
One of Kaspersky Lab’s most important discoveries concerns the exact way a Galileo mobile Trojan infects an iPhone. This is done by jailbreaking the device. However, even unjailbroken iPhones can become vulnerable. Specifically, an attacker can run a jailbreaking tool, such as “Evasi0n”, via an already infected computer to remotely jailbreak and “infect” the device. To avoid the risk of “infection”, Kaspersky Lab experts recommend that users not jailbreak their iPhones in the first place. Secondly, users should constantly update their iOS to the latest version.
Custom Spying
RCS mobile modules have been developed with particular care to operate in a discreet manner. For example, they pay special attention to the battery life of mobile devices. This is achieved through carefully tailored spying capabilities or through special activation functions. For example, the recording process can only start when the victim connects to a specific Wi-Fi network (such as a media house network) or when the SIM card is changed or while the device is charging.
In general, RCS mobile Trojans can perform many different types of surveillance, such as reporting the target's location, taking photos, copying calendar notes, recording new SIM cards inserted into the infected device, and intercepting phone calls and messages. In addition to classic SMS, interception also occurs on messages sent by specific applications, such as Viber, WhatsApp, and Skype.
Localization
Kaspersky Lab products detect RCS/DaVinci/Galileo spyware tools, which have been registered under the names: Backdoor.Win32.Korablin, Backdoor.Win64.Korablin, Backdoor.Multi.Korablin, Rootkit.Win32.Korablin, Rootkit.Win64.Korablin, Rootkit.OSX.Morcut, Trojan.OSX.Morcut, Trojan.Multi.Korablin, Trojan.Win32.Agent, Trojan-Dropper.Win32.Korablin, Trojan-PSW.Win32.Agent, Trojan-Spy.AndroidOS.Mekir and Backdoor.AndroidOS.Criag.
About Kaspersky Lab
KasperskyLab is the world's largest privately held computer security company. The company is among the top four security providers in the world*. Throughout its 16-year history, KasperskyLab has been pioneering security innovations, providing cost-effective solutions to protect consumers, small and medium-sized businesses and large enterprises. Today, KasperskyLab's operations span 200 countries and regions around the world, with the company providing online security to over 300 million users. For more information, visit: www.kaspersky.com.

