manu quintans & frank ruiz – 50 shades of crimeware [rooted con 2014]

65
1 Rooted CON 2014 6-7-8 Marzo // 6-7-8 March 50 Shades of Crimeware Manu Quintans – Frank Ruiz

Upload: rootedcon

Post on 12-Jan-2015

846 views

Category:

Technology


0 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

1Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

50 Shades of Crimeware

Manu Quintans – Frank Ruiz

Page 2: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

2Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

WHO WE ARE?

Manu Quintans - Threat Intelligence Manager at Buguroo / Deloitte

Frank Ruiz - Intelligence Analyst at Fox IT

And…yes!, we hunt malware like a sir.

Page 3: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

3Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

INDEXWhat we know about Cyber-Crime ?

It’s Time Back to reality.

Understand Cyber-Crime activities.

Previously on … 2013

Reality bites

Cyber-Crime Evolutions – 2013-2014

New trends at Cyber-Crime

Examples (We have a Target… )

Infrastructure

Demo Time (Yeah! We have a demo, please release your smartphone and enjoy…)

Page 4: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

4Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

What we know about Cyber-Crime ?

Page 5: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

5Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

What we know about Cyber-Crime ?

Page 6: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

6Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

What we know about Cyber-Crime ?

Page 7: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

7Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

What we know about Cyber-Crime ?

Page 8: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

8Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

What we know about Cyber-Crime ?

Page 9: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

9Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

What we know about Cyber-Crime ?

Brian Krebs Post Life Cycle

WE NEED DIAGRAM.

Page 10: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

10Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

It’s Time Back to reality.

Page 11: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

11Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

It’s Time Back to reality.

Page 12: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

12Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

It’s Time Back to reality.

Page 13: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

13Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

It’s Time Back to reality.

Page 14: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

14Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

Page 15: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

15Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

The UndercoatJust for Kiddies

HackForums

Exploit.IN Antichat.RU

Damagelabs

DarkCode

Indetectables

LAYE

R #1

Page 16: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

16Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.THE UNDERCOAT

Page 17: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

17Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.THE UNDERCOAT

Page 18: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

18Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.THE UNDERCOAT

Page 19: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

19Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.THE UNDERCOAT

Page 20: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

20Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

The LimboPSEUDO-PRO

CPRO.SU

Pustota

Verified.msx

x

Infraud.su

LAYE

R #2

Page 21: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

21Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

Page 22: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

22Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

Page 23: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

23Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

LAYE

R #3

Heaven’s doorGang’stah!-PRO

TopSe

curit

yMaza (M

azafucka

)Korovka

Comm

uizm

Page 24: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

24Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

Page 25: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

25Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

Page 26: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

26Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

LAYE

R #4

Private

семьяZeusP2P

CryptoLocker

Sinowallx

Gozi

Page 27: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

27Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

VIDEO HISTORY

Page 28: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

28Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Understand Cyber-Crime activities.

The UndercoatJust for Kiddies

HackForums

Exploit.IN Antichat.RU

Damagelabs

DarkCode

Indetectables

The LimboPSEUDO-PRO

CPRO.SU

Pustota

Verified.msx

Infraud.su

x

Heaven’s doorGang’stah!-PRO

TopSe

curit

y

Maza

(Mazaf

ucka) Korovka

Comm

uizm

Private

семьяZeusP2P

CryptoLocker

Sinowall

x

Gozi

Page 29: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

29Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Previously on … 2013

Page 30: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

30Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Previously on … 2013

First year, without new Banking Trojans. (Except’s KINS aka Kasper)

Symlink Arrested (January)

Paunch Arrested (BlackHole Exploit Kit) (OCTOBER)

FBI shut down SilkRoad and they arrest Ross Willian Ulbrich. (OCTOBER)

Target Breach. :-) – (NOVEMBER/DECEMBER)

FBI With Spanish Police Cooperation take’s down Liberty Reserver and arrest CEO.– (MAY 2013)

Page 31: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

31Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Previously on … 2013 / 2014

Has been a special year in the evolution of the industry of cybercrime:

The feeling of impunity begins to disappear.

Groups midlevel begin to close and professionalize their assets.

Ironically, the vetted gang’s start to show some gaps.

Page 32: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

32Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Previously on … 2013 / 2014

These changes are due to:

Detentions.

Proliferation of bloggers / twitters 'investigating' cybercrime scene. (Pr0n stars)

Insider Researchers.

Leaks (Pasties, services…)

Page 33: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

33Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Previously on … 2013 / 2014

Conclusions:

The “industry” of Cyber-Crime, now are more than closed than ever.

Page 34: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

34Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime

Page 35: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

35Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime

We found new trends at Cyber-Crime Industry, like… :POS MALWARE (POINT OF SALES) SYSEM

NEW MOBILE MALWARE (EG: TOR BASED)

CRYPTOCURRENCIES

Page 36: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

36Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime

POS (POINT OF SALE), but why?

The lack of a Banking Trojan for sale and the large increase in demand for cards has moved many players in this business.Citadel users move there business to this new system.

Grows offer POS malware sales.

Page 37: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

37Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime

POS (POINT OF SALE), What We found on underground Market?

Alina Malware

The beauty, the Bad and the Ugly

Dexter Malware

BlackPos Malware

Page 38: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

38Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-CrimePOS (POINT OF SALE), and services? Of course!

JackPos

Page 39: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

39Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime Mobile Malware

Increase of injections with support for mobile malware.

Mobile malware for sale:

iBanking (as Service).

Perkele

Uses new resources like TOR.

Page 40: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

40Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime Mobile Malware

IBanking

Page 41: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

41Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime Mobile Malware

Perkele

Page 42: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

42Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime CryptoCurrencies

Page 43: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

43Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime CryptoCurrencies

Page 44: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

44Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime CryptoCurrencies

Page 45: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

45Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

New trends at Cyber-Crime CryptoCurrencies

TOTAL HASH RATE

24H HASH RATE

Page 46: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

46Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Let’s see some real examples about new trends.

Page 47: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

47Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Example

Page 48: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

48Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

ExampleTimeline:

Brian Krebs18/Dec/2013: Sources: Target Investigating Data Breach20/Dec/2013: Cards Stolen in Target Breach Flood Underground Markets22/Dec/2013: Non-US Cards Used At Target Fetch Premium24/Dec/2013: Who’s Selling Credit Cards from Target?10/Jan/2014: Target: Names, Emails, Phone Numbers on Up To 70 Million Customers Stolen15/Jan/2014: A First Look at the Target Intrusion, Malware16/Jan/2014: A Closer Look at the Target Malware, Part II29/Jan/2014: New Clues in the Target Breach04/Feb/2014: These Guys Battled BlackPOS at a Retailer05/Feb/2014: Target Hackers Broke in Via HVAC Company12/Feb/2014: Email Attack on Vendor Set Up Breach at Target19/Feb/2014: Fire Sale on Cards Stolen in Target Breach25/Feb/2014: Card Backlog Extends Pain from Target Breach

Page 49: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

49Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Example

Page 50: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

50Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Example

Page 51: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

51Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Intelligence

Page 52: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

52Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Intelligence

Page 53: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

53Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Intelligence

Page 54: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

54Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Cyber-Criminals Infrastructure

Page 55: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

55Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Infrastructure

BOTNETINTERNET

Simple

Page 56: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

56Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureProxy

BOTNETINTERNET

VICTIMS

PROXY

Page 57: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

57Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureDuble Proxy

BOTNETINTERNET

VICTIMS

PROXY - 1

PROXY - 2

Page 58: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

58Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureFastflux + C&C

FAST FLUXBOTNETFASTFLUX

VICTIM

HTTP GET

RESPONSECONTENT

GET REDIRECT

RESPONSECONTENT

Page 59: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

59Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureFastflux + PROXY + C&C

FAST FLUXBOTNETFASTFLUX

VICTIM

HTTP GET

RESPONSECONTENT

GET REDIRECT

RESPONSECONTENT

Page 60: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

60Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureBP HOSTERS

BP HOSTERINTERNET

VICTIMS

Backend Server

Page 61: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

61Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureOWN Infrastructures

INTERNET

IPIP Tunel

OpenVPN Server

VPN Client

Backend Server

Backend Server

Backend Server

Backend Server

Backend Server

VICTIMS

Page 62: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

62Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureP2P

INTERNET

P2P Network

Web Panel

Backup Server

VICTIMS

Page 63: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

63Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

InfrastructureTOR

INTERNET

Web Panel

TOR NetworkVICTIMS

Page 64: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

64Rooted CON 2014 6-7-8 Marzo // 6-7-8 March

Page 65: Manu Quintans & Frank Ruiz – 50 shades of crimeware [Rooted CON 2014]

65Rooted CON 2014 6-7-8 Marzo // 6-7-8 March