Russian Malware 'Patches' Chrome and Firefox To Fingerprint TLS Traffic

Peter Reutemann <[email protected]> Mon, 7 Oct 2019 11:48:13 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12JMak6+X4VpxogUC49QdSTC7+AZ3V=jGmG-gyKxEcGuWw@mail.gmail.com>
'A Russian cyber-espionage hacker group has been spotted using a novel
technique that involves patching locally installed browsers like
Chrome and Firefox in order to modify the browsers' internal
components. The end goal of these modifications is to alter the way
the two browsers set up HTTPS connections, and add a per-victim
fingerprint for the TLS-encrypted web traffic that originates from the
infected computers...

According to a Kaspersky report published this week, hackers are
infecting victims with a remote access trojan named Reductor, through
which they are modifying the two browsers. This process involves two
steps. They first install their own digital certificates to each
infected host. This would allow hackers to intercept any TLS traffic
originating from the host. Second, they modify the Chrome and Firefox
installation to patch their pseudo-random number generation (PRNG)
functions. These functions are used when generating random numbers
needed for the process of negotiating and establishing new TLS
handshakes for HTTPS connections.

Turla hackers are using these tainted PRNG functions to add a small
fingerprint at the start of every new TLS connection.

The attack is being attributed to Turla, "a well-known hacker group
believed to operate under the protection of the Russian government,"
ZDNet reports. And though the remote-access trojan already grants full
control over a victim's device, one theory is the modified browsers
offer "a secondary surveillance mechanism" if that trojan was
discovered and removed. Researchers believe the malware is installed
during file transfers over HTTP connections, suggesting an ISP had
been compromised, according to the article.

"A January 2018 report from fellow cyber-security firm ESET revealed
that Turla had compromised at least four ISPs before, in Eastern
Europe and the former Soviet space, also with the purpose of tainting
downloads and adding malware to legitimate fil'

-- source: https://news.slashdot.org/story/19/10/06/2242221

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz