A malicious exit server on the Tor has been found distributing a new type of malware that researchers have dubbed OnionDuke due to its connection to the group behind the MiniDuke cyber-espionage tool.
This type of attack is unusual and was discovered by Josh Pitts, a security consultant at Leviathan Security, who found that the malicious exit node modifies uncompressed binaries passing through it and adds a malicious executable. This method makes it easy for the attacker to bypass integrity checks associated with the original file.
F-Secure security researchers studied the distribution technique of the new malware and confirmed the information presented by Pitts, providing details on how the payload was executed, its communication with the (C&C) command and control server, and its embedded functionality.
Artturi Lehtiö analyzed the behavior of the dropper and noticed that it contained an encrypted DLL that appeared as a GIF image. After decrypting the DLL, the dropper saves it to disk and executes it.
The execution of malicious activities continues by decrypting the configuration file and attempting to connect to the C&C server which will send further instructions for the malware.
Various elements of OnionDuke have been identified during the analysis, revealing its capabilities. The theft of credentials is the intended purpose of the malware and in order to achieve its persistence on the affected system, the creator added routines to detect the presence of security systems (antivirus, firewall).
Researchers found the connection between OnionDuke and MiniDuke, which consisted of a C&C domain registered in 2011 under the alias John Kasai and used to register others two weeks later.
“This clearly suggests that, although OnionDuke and MiniDuke are two separate malware ‘families’, those behind them are connected by the use of shared infrastructure,” Artturi Lehtiö wrote in a blog post on Friday.
According to the researcher, there are indications that OnionDuke has been used in targeted attacks against European government organizations.
Downloading unencrypted executables through Tor is a risky act because the identity of the exit node is unknown. Lehtiö suggests using a VPN that will encrypt the connection end-to-end.

