HomeSecurityData exfiltration attack based on video steganography

Data exfiltration attack based on video steganography

data exfiltration

 

Security experts have detected an attack against a large company that used a data exfiltration techniquebasedon videosteganography.

Attackers achieve data exfiltration with a technique based on videos uploaded to cloud services . The attackers used this technique to extract data from the target without being detected by conventional security solutions, such as Intrusion Prevention Systems/Intrusion Detection Systems. To further improve the tactic, malicious users use steganography to “hide” the encrypted data in videos that are uploaded to a video sharing service

Why only videos and not images?

Security experts know that there are many tools available that can detect the use of steganography in images, and that such software is able to detect the signatures of steganography tools and techniques. The situation is quite different for videos , and attackers who use this technique know this.

Attackers can use one of the many available tools or open source software (i.e. OpenPuff) to apply steganography to the exfiltrated data. As revealed by Tripwire in a blog post, one of the Fortune 500 was recently hit by hackers who used the above technique for exfiltration .

 

dataexfiltrationvideos2

The data exfiltration was not detected until the company noticed that many duplicate video files had been uploaded from their network to a video sharing website.

The problem is that the available tools that can detect the presence of steganography are generally designed to detect images and not videos. The hacker that use this technique are well aware of this and therefore this is the reason why they use video files instead of images which would be an easier data transfer mechanism.

As a mitigation strategy, network administrators are advised to monitor the installation and binary of applications or custom binaries used by attackers to encode data into a video or image. Administrators should also monitor outbound connections to external services.

Another mitigation strategy to identify software that could be used in the data exfiltration technique is to scan host systems for video files specifically for critical systems.

As explained by Tripwire , in the Fortune 500 case , the attackers used the same video files to send different chunks of data from the targeted network.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS