HomeRapidalertFacebook's announcement about Lecpetex a while ago.

Facebook's announcement about Lecpetex a while ago.

Lecpetex

Read Facebook's announcement (in English) regarding Lecpetex a while ago! Facebook has been trying to stop Lecpetex for about 7 (!) months without success!

You can read Facebook's full announcement/analysis [here]

The Threat Infrastructure team at Facebook analyzes threat information from all over the web to help keep people on Facebook safe and secure. We build platforms like ThreatData and work closely with our abuse-fighting teams to stay a step ahead of people who try to use Facebook's popularity and reach for bad intentions. Over the last seven months we battled and ultimately helped bring down a little known malware family known as "Lecpetex" that attackers were attempting to spread using Facebook and other online services. We coordinated with several industry partners in disrupting the botnet and proactively escalated the case to law enforcement officials. This post covers the interesting technical elements of the malware and describes our role in taking down the botnet.

facebook-changes-newsfeed-algorithm-640x400

Outline

  1. History and overview
  2. Mechanics of the Lecpetex botnet
  3. Facebook helps take down the botnet
  4. Malware technical detailsDelivery techniques (JAR + VBS + Dropbox)

a. Malware technical details Delivery techniques (JAR + VBS + Dropbox)
b. Malware string payload obfuscation (AES128 + SHA1)
c. C2 methodologies (dedicated C2, Pastebin, disposable email accounts)

History and overview

Late last year, our abuse-fighting teams started to see a distinct new botnet. The attack was given the name "Lecpetex" by our peers at the Microsoft Malware Protection Center. Based on statistics released by the Greek Police, the botnet may have infected as many as 250,000 computers. Those infections enabled those directing the botnet to hijack those computers and use them to promote social spam, which impacted close to 50,000 accounts at its peak. As we describe below, there were several technical features of the malware that made it more resilient to technical analysis and disruption efforts. In addition, the Lecpetex authors appeared to have a good understanding of anti-virus evasion because they made continuous changes to their malware to avoid detection. In total, the botnet operators launched more than 20 distinct waves of spam between December 2013 and June 2014.

Lecpetex worked almost exclusively by using relatively simple social engineering techniques to trick victims into running malicious Java applications and scripts that infected their computers. (For more on the success of social engineering being used to induce people to run malicious code, see our recent post about self-XSS).
Facebook_1_0
On April 30, 2014, we escalated the Lecpetex case to the Cybercrime Subdivision of the Greek Police, and the agency immediately showed strong interest in the case. On July 3 the Greek Police reported that the investigation had progressed to the final stage and that two suspects were placed in custody. According to the Greek Police, the authors were in the process of establishing a Bitcoin "mixing" service to help launder stolen Bitcoins at the time of their arrest. More details about their findings are available here.

The heat map below shows the distribution of Lecpetex victims as of June 10, 2014, with the highest concentration of victims found in the vicinity of Greece. Because Lecpetex spread through friend and contact networks, the distribution of victims tended to concentrate in specific geographies. From our analysis, the most frequently affected countries were Greece, Poland, Norway, India, Portugal, and the United States.

The Greek Police developed the following image to illustrate the botnet's operations as part of a presentation on Lecpetex.

Mechanics of the Lecpetex botnet

To better understand the botnet, here is a bit of additional detail about its capabilities and how the operators used it in an attempt to profit.

facebook-icon

Fundamentally, the Lecpetex botnet is a collection of modules installed on a Windows computer that can steal a person's online credentials and use that access to spread through private messages. Along the way, it self-installs updates to try to evade anti-virus products and installs arbitrary executables. Our analysis revealed two distinct malware payloads delivered to infected machines: the DarkComet RAT, and several variations of Litecoin mining software. Ultimately the botnet operators focused on Litecoin mining to monetize their pool of infected systems. We saw reports that the botnet was also seeded using malicious torrent downloads, but did not observe this tactic in our research.

More [here]

According to Facebook, the actions it took to investigate Lecpetex were:

  • December 2013: First detection of messages from Greece
  • April 10-17, 2014: Malware containment
  • April 30: Report to Greek authorities
  • May 2014: Malware authors leave messages (?) on malware management pages. Authors use self-deleting emails (disposable emails) and public pastebin websites for verification
  • May – June 2014: Facebook adds targeted security measures to prevent the spread of Lecpetex
  • June 2014: The creators add email distribution to the software due to Facebook's restrictions.
  • July 3, 2014: The Hellenic Police announces the arrest of two young men as the main creators of the software.

Some points of the announcement deserve special attention:

  • First of all, at the end of the announcement, Facebook executives mention that the collaboration can help identify new techniques to help users of the Facebook platform. Perhaps they should collaborate with the young creators of Lecpetex to increase the security of the social networking platform.
  • At no point in the announcement are they directed against the creators of Lecpetex, nor are they referred to criminal behavior or malicious actions that financially harmed either Facebook or any of its users.
  • The identification and analysis of the software was carried out, as they report, in collaboration with their partners at Microsoft as well as government organizations & American law enforcement authorities.
  • The announcement clearly states that the software had exceptional capabilities such as bypassing antivirus and elements that prevented its analysis by experts, a sign of the high level of knowledge of its creators. Furthermore, they emphasize the management of the software using self-destructing e-mails and through pastebin, which had not been encountered in other malware in the past.
  • At no point do you mention that any financial benefit was achieved from using the software.
  • There is complete identification of the announcements of the D.DIE and the announcement of Facebook. It is in fact the first time that the giant company of social networks PUBLICLY rewards the Greek service for its work and its cooperation!!!

The person responsible for analyzing and detecting the Lecpetex software is a member of the Facebook Security team, specifically Mat Henley and Matt Richard, security engineers. Mat Henley states in the announcement [here] that “Lecpetex did not affect Facebook’s infrastructure but rather users’ terminals.”

The Facebook announcement fully confirms the announcements of the Hellenic Police as published in the relevant press release a few days ago by Brigadier General M. Sfakianakis.

The conclusions are yours!

Note: Of particular interest are the comments of Greek Facebook users regarding the Lecpetex announcement. You can read them [here] and participate in the discussion that has already been opened.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS