HomeSecurityHackers exploit Dropbox to hide C&C Servers

Hackers are using Dropbox to hide C&C servers

Dropbox

Dropbox is being exploited by state-sponsored hackers as a means to carry out hacking attacks.

 

A dangerous malware targeting organizations and SMEs in Hong Kong was recently discovered by security researchers from FireEye. The software is actually a backdoor that hides servers inside Dropbox accounts.

According to researchers, the attacks that have occurred so far appear to be part of a state-sponsored campaign, which is being carried out by a hacking group also known as admin@338.

In the past, this group has targeted international organizations in the financial, economic, and commercial sectors, utilizing spear phishing campaigns to distribute dangerous Remote Access Trojans (Rats), such as Poison Ivy.

In their most recent campaign, the hackers used the same phishing techniques, targeting only a small number of Hong Kong media organizations. The targets included newspapers, radio and television stations.

 

How hackers act

As the researchers point out, the hacking group uses emails containing decoy Word documents, which exploit current events related to anti-government actions, tricking potential victims into opening a malicious attachment.

The Word file contains the Microsoft Office vulnerability CVE-2012-0158, allowing attackers to install the Lowball malware on the victim's computer.

Lowball is a powerful backdoor, capable of stealing data and uploading it to a remote server. The malware also has the ability to download new files and execute shell commands.

 

Lowball uses Dropbox as a C&C server

What makes the malware stand out is the fact that the C&C server is not hosted on a web server somewhere on the internet, but is located inside a Dropbox account.

The backdoor sends data via encrypted HTTPS requests on port 443, to a designated Dropbox account, using Dropbox's official API.

On the server, a corresponding BAT file is created for each infected computer, which attackers can update with various shell commands.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS