ложкин from ap ts to criminals cut

29
COPYCATS: FROM APTS TO CRIMINALS Sergey Lozhkin Senior Security Researcher Kaspersky Lab

Post on 16-Apr-2017

336 views

Category:

Internet


1 download

TRANSCRIPT

Page 1: ложкин From ap ts to criminals cut

COPYCATS: FROM APTS TO CRIMINALS

Sergey LozhkinSenior Security Researcher Kaspersky Lab

Page 2: ложкин From ap ts to criminals cut

AGENDA

SkimerCarbanakMETEL

GCMANAPTs??????

Page 3: ложкин From ap ts to criminals cut

GCMAN

Page 4: ложкин From ap ts to criminals cut

200 USD PER MINUTE

Page 5: ложкин From ap ts to criminals cut

BE PERSISTENT

• 2 months of tries on Sat

— What was your pw?— Sonic17

Page 6: ложкин From ap ts to criminals cut

TROUBLE IN THOUGHT

Page 7: ложкин From ap ts to criminals cut

INFO−.ASP

Page 8: ложкин From ap ts to criminals cut

Ads Web

server

GCMAN ATTACK

Corporate online

banking webserver

Online banking

DBAdmin’s

WorkstationsProcessing Connection

server

Page 9: ложкин From ap ts to criminals cut

GCMAN SUMMARY

1. Knocking to front door2. Avoid whitelisting

techs3. >1 year persistence

Page 10: ложкин From ap ts to criminals cut

CARBANAK

Page 11: ложкин From ap ts to criminals cut
Page 12: ложкин From ap ts to criminals cut

CARBANAK SUMMARY

1. Global criminals’ ATP2. Spear-phishing is

everything 3. It is all about MONEY

Page 13: ложкин From ap ts to criminals cut

METEL

Page 14: ложкин From ap ts to criminals cut

Source http://ageofgeeks.com/wp-content/uploads/2015/04/furious-7-paul-walker.jpg

Page 15: ложкин From ap ts to criminals cut
Page 16: ложкин From ap ts to criminals cut

METEL – TRANSACTIONS ROLLBACK

Page 17: ложкин From ap ts to criminals cut

CHALLENGE

WIPE PATERN

RAND 4096 ALWAYS

Page 18: ложкин From ap ts to criminals cut

METEL SUMMARY

1. IOCs’ horror 2. Spear-phishing is

everything 3. It is all about MONEY

Page 19: ложкин From ap ts to criminals cut

SKIMER

Page 20: ложкин From ap ts to criminals cut

SKIMER

Page 21: ложкин From ap ts to criminals cut

SKIMER–XFS SERVICE PATCH

Page 22: ложкин From ap ts to criminals cut

SKIMER–SERVICE PATCHED

Page 23: ложкин From ap ts to criminals cut

ATM INFECTOR –MAGIC CARD

CARD 1 – INTERFACE COMMANDSCARD 2 – TRACK 2 HARDCODED

Page 24: ложкин From ap ts to criminals cut

SKIMER SUMMARY

1. Silent2. Attack on ATM users3. Attack on banks

Page 25: ложкин From ap ts to criminals cut

LAZARUS

Page 26: ложкин From ap ts to criminals cut
Page 27: ложкин From ap ts to criminals cut
Page 28: ложкин From ap ts to criminals cut

LAZARUS SUMMARY

1. Active from 20092. Attacks on everything3. New group that made

1bln USD after Carba

Page 29: ложкин From ap ts to criminals cut

7H@NK Y0U1

Sergey LozhkinPrincipal Security Researcher Kaspersky Lab