Kaspersky Lab has uncovered a new advanced persistent threat (APT) campaign that has affected a large number of users through what is known as a supply chain attack. Its research found that threat actors behind Operation ShadowHammer have targeted users of the ASUS Live Update Utility, by injecting a backdoor into it at least between June and November 2018. Kaspersky Lab experts estimate that the attack may have affected more than a million users worldwide.
A supply chain attack is one of the most dangerous and effective infection vectors, increasinglyexploited in advanced operations over the last few years – as we have seen with ShadowPad or CCleaner. It targets specific weaknesses in the interconnected systems of human, organisational, material, and intellectual resources involved in the product life cycle: from initial development stage through to the end user. While a vendor’s infrastructure can be secure, there could be vulnerabilities in its providers’ facilities that would sabotage the supply chain, leading to a devastating and unexpected data breach.
The actors behind ShadowHammer targeted the ASUS Live Update Utility as the initial source of infection. This is a pre-installed utility in most new ASUS computers, for automatic BIOS, UEFI, drivers and applications updates. Using stolen digital certificates used by ASUS to sign legitimate binaries, the attackers have tampered older versions of ASUS software, injecting their own malicious code. Trojanized versions of the utility were signed with legitimate certificates and were hosted on and distributed from official ASUS update servers – which made them mostly invisible to the vast majority of protection solutions.
While this means that potentially every user of the affected software could have become a victim, actors behind ShadowHammer were focused on gaining access to several hundreds of users, which they had prior knowledge about. As Kaspersky Lab’s researchers discovered, each backdoor code contained a table of hardcoded MAC addresses – the unique identifier of network adapters used to connect a computer to a network.
Once running on a victim’s device, the backdoor verified its MAC address against this table. If the MAC address matched one of the entries, the malware downloaded the next stage of malicious code. Otherwise, the infiltrated updater did not show any network activity, which is why it remained undiscovered for such a long time. In total, security experts were able to identify more than 600 MAC addresses. These were targeted by over 230 unique backdoored samples with different shellcodes.
The modular approach and extra precautions taken when executing code, to prevent accidental code or data leakage indicates that it was very important for the actors behind this sophisticated attack to remain undetected, while hitting some very specific targets with surgical precision. Deep technical analysis shows that the arsenal of the attackers is very advanced and reflects a very high level of development within the group.
The search for similar malware has revealed software from three other vendors in Asia, all backdoored with very similar methods and techniques. Kaspersky Lab has reported the issue to Asus and other vendors.
“The selected vendors are extremely attractive targets for APT groups that might want to take advantage of their vast customer base,” said Vitaly Kamluk, Director of Global Research and Analysis Team, APAC, at Kaspersky Lab. “It is not yet very clear what the ultimate goal of the attackers was and we are still researching who was behind the attack. However, techniques used to achieve unauthorised code execution, as well as other discovered artefacts suggest that ShadowHammer is probably related to the BARIUM APT, which was previously linked to the ShadowPad and CCleaner incidents, among others. This new campaign is yet another example of how sophisticated and dangerous a smart supply chain attack can be nowadays.”
In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky Lab researchers recommend implementing the following measures:
- In addition to adopting must-have endpoint protection, implement a corporate grade security solution which detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform;
- For endpoint level detection, investigation and timely remediation of incidents, we recommend implementing EDR solutions such as Kaspersky Endpoint Detection and Response or contacting a professional incident response team;
- Integrate Threat Intelligence feeds into your SIEM and other security controls in order to get access to the most relevant and up-to-date threat data and prepare for future attacks.
Kaspersky Lab will present full findings on Operation ShadowHammer at the Security Analyst Summit 2019 in Singapore, running from 9 to 11 April.
Click here to read Asus’ response.
Hearables are the new wearables
Earworn devices were among the fastest growing categories of wearable in the last quarter, capturing almost half of the market
Global wearable device shipments grew 85.2% in the second quarter of 2019 (2Q19) as shipments totaled 67.7 million units according to new data from the International Data Corporation (IDC) Worldwide Quarterly Wearable Device Tracker. Earworn devices (hearables) were among the fastest growing categories, capturing 46.9% of the overall wearables market during the quarter, up from 24.8% a year ago. Driving that growth was a slew of new products and consumers who purchased their second wearable, a hearable, to use in parallel with existing watches or wrist bands.
“The growing popularity of the hearables segment is forcing existing brands to reconsider past designs when launching new products, as evident in Samsung’s popular Galaxy Buds, while also attracting new brands to market,” said Jitesh Ubrani research manager for IDC Mobile Device Trackers. “And though it’s still early days, the market is showing signs of emerging subsegments such as hearables dedicated to sports from the likes of Jabra, premium hearables from companies such as Bose, and ones dedicated to hearing loss such as those from Nuheara.”
“What has been driving the hearables market is the experience,” says Ramon T. Llamas, research director, Wearables. “Quality audio is still the hallmark of hearables, but additional features – ranging from adjusting audio to smart assistants and health and fitness – increase their value and utility. As prices come down and more features come on board, this next generation of hearables will become the new normal for earphones.”
Hearable Company Highlights
Apple led the market for hearables by capturing 50.2% share during the quarter. New products such as the refreshed AirPods and the latest from the Beats lineup helped the company grow 218.2% compared to last year. With the iPhone business facing challenges, Apple’s wearables business, particularly the popularity of the AirPods, is helping the company once again become the de facto standard though this time it’s for hearables.
Samsung, thanks to its self-branded devices and the JBL brand, captured the second position during the quarter. The highly publicized Galaxy Buds were one of the company’s most popular pair of hearables as the pair was bundled with the purchase of Samsung’s latest smartphone. Additionally, the JBL Tune 500BT managed to capture a large share as the low price and wide availability helped move a lot of volume.
Xiaomi’s AirDots (amongst other models) helped the company capture the third position. Though the company primarily sells its hearables in China, Xiaomi has already started to make inroads in other markets such as Europe and the Middle East with its smartphones and wrist bands. IDC expects Xiaomi to follow suit with its hearables.
Bose, a company with a long history of headphones and other audio products, ranked fourth in this market. The company’s long lineage in audio and premium offering has helped set the company apart from the remainder of the pack. The QC35ii and the SoundSport Free were two of its most popular products during the quarter. The latest Headphones 700 and upcoming Earbuds 500 should help the company maintain momentum in the upcoming quarters.
ReSound, the parent company of Jabra, rounded out the top 5 with 5.1% share and 132.9% growth. Jabra’s Elite Active 65t have been extremely popular as an alternative to Apple’s AirPods and have also been promoted heavily on Amazon’s store, allowing the company to pitch itself as a strong consumer brand in addition to its preexisting headset business that is targeted at office workers. At IFA 2019, Jabra announced the next version of the Elite Active series, which helps modernize the hearables and should provide healthy competition for others on the list.
Top 5 Wearable Companies, Hearable Devices only, by Shipment Volume, Market Share, and Year-Over-Year Growth, Q2 2019 (shipments in millions)
|2Q19 Market |
|2Q18 Market |
|Source: IDC Worldwide Quarterly Wearables Tracker, September 9, 2019|
Note: IDC defines Earwear/Hearables as the wearables that hang on or plug into the ear. The device must operate wirelessly and provide stereo sound while also including at least one of the following features:
- Track health/fitness (e.g., Samsung Gear IconX).
- Modify audio, and not just noise reduction (e.g., Nuheara IQbuds).
- Provide language translation on the device (e.g., Waverly Labs).
- Enable smart assistants at the touch of a button or through hotword detection even if the assistant is running on another device such as a smartphone (e.g., Apple’s AirPods and Google’s Pixel Buds).
Phishing attacks hook into iOS
The number of phishing attacks targeting users of Mac computers, iOS-based mobile devices, and the associated web services ecosystem to lure them into fraudulent schemes has reached 1.6 million in the first half of 2019 (H1-19) – proving that the growing number of users of popular digital devices is clearly attracting more and more cybercriminals!
While the volume of malicious software threatening users of macOS and the iOS mobile platform is much lower than those threating users of Windows and Android platforms, when it comes to phishing – a platform agnostic cyberthreat – things are quite different.
Phishing attacks rely on social engineering, which means most have nothing to do with software. In fact, Kaspersky’s recent Threats to Mac Users research highlighted that the number of cases where users faced fraudulent web pages utilising the Apple brand, as a decoy, has increased significantly in the first six-months of the year, reaching 1.6 million. This figure is around 9% greater than attacks experienced during the whole of 2018, when Kaspersky security solutions prevented more than 1.49 million attempts to access Apple-themed phishing pages.
What’s more, some regions had more macOS users hit by phishing than others, for instance, Brazil leads this list with 30.9% of users attacked, followed by India with 22.1% – and while not as prominent as other regions (and in proportion to the number of Apple device users), South Africa still sits at 17.5%.
The research is based on threat statistics voluntarily shared by users of Kaspersky Security Network – a global cloud infrastructure designed for immediate response to emerging cyberthreats.
Among the most frequent fraud schemes are those designed to resemble the iCloud service interface, aimed at stealing credentials to Apple ID accounts. Links to such services usually come from spam emails posed as emails from technical support. They often threaten to block user accounts should they not click the link.
Another widespread scheme is the use of scaremongering pages that try to convince the user that their computer is under serious security threat and it will only take a couple of clicks and a few dollars to solve those issues.
“While technically these fraud schemes are nothing new, we believe they pose an even greater danger to Apple users than similar schemes against users of other platforms – such as Windows or Android. This is because the ecosystem around Macs and other Apple devices is generally considered a far safer environment. Therefore, users might be less cautious when they encounter fake websites. Meanwhile the successful theft of iCloud account credentials could lead to serious consequences – an iPhone or iPad could be remotely blocked or wiped by a malicious user, for example. We urge users of Apple devices to pay more attention to any emails they receive, especially those claiming to be from technical support and requesting the user’s details or asking the user to visit a link,” said Tatyana Sidorina, security researcher at Kaspersky.
In addition to a rise in phishing, thereport also revealed other types of threats to users of macOS-based devices. The results have demonstrated some relatively positive tendencies: the most common threats for Mac users proved not to be critically dangerous malware, like banking Trojans, but instead AdWare threats, which are not-necessarily fatal and defined as ‘potentially unwanted programs’. Most are threatening users by overloading their devices with unrequested advertisements, yet some of these programs might, in fact, turn out to be a disguise for more serious threats.
Other findings of the report include:
- The total number of phishing attacks detected in the first half of 2019 (H1-19) on Mac computers protected by Kaspersky solutions was almost 6 million. The whole of 2018 saw 7.3 million hits.
- 39.95% of the detected attacks were aimed at stealing users’ financial data. That is 10%more than in the first half of 2018 (H1-18).
- Some regions had more macOS users hit by phishing than others: Brazil leads this list with 30.9% of users attacked, followed by India with 22.1% and South Africa with 17.5%.
- The most active malware to hit macOS users were variations of the Shlayer family, that succeeded in distribution by disguising itself as Adobe Flash Player updates.
To keep your devices safe, Kaspersky recommends:
- Keeping macOS and all your apps and programs up to date
- Using only legitimate software, downloaded from official webpages or installed from the Mac App Store
- Starting to use a reliable security solution like Kaspersky Internet Security that delivers advanced protection on Mac, as well as on PC and mobile devices.