{"id":31422,"date":"2018-03-20T16:01:35","date_gmt":"2018-03-20T08:01:35","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=31422"},"modified":"2018-03-20T16:01:35","modified_gmt":"2018-03-20T08:01:35","slug":"how-olympicdestroyer-malware-was-designed-to-confuse-cybersecurity-community","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/03\/20\/how-olympicdestroyer-malware-was-designed-to-confuse-cybersecurity-community\/","title":{"rendered":"How OlympicDestroyer malware was designed to confuse cybersecurity community"},"content":{"rendered":"<p dir=\"ltr\"><strong>Kaspersky Lab\u2019s Global Research and Analysis Team published the results of its own research into attacks by the OlympicDestroyer malware, providing technical evidence of a very sophisticated false flag placed inside the worm by the malware creator in order to knock threat hunters off the trail to its real origin.<\/strong><\/p>\n<p dir=\"ltr\">The OlympicDestroyer worm made some headlines during the Winter Olympic Games. The Pyeongchang Olympics experienced a cyberattack that temporarily paralyzed IT systems ahead of the official opening ceremony, shutting down display monitors, killing Wi-Fi, and taking down the Olympics website so that visitors were unable to print tickets.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/apis.mail.yahoo.com\/ws\/v3\/mailboxes\/@.id==VjN-aCbUujP9WRIFkzC-HPKo0PwYPu4jD5cOi_sjbMnujizFHppaB98KCecoWGnkGzTGwSeqnpH3u8fKhDbfMcoHqg\/messages\/@.id==AJTPxAoAAAPKWq9_dweVaGX_FQk\/content\/parts\/@.id==1.2\/thumbnail?appId=YMailNorrin&amp;downloadWhenThumbnailFails=true&amp;pid=1.2\" alt=\"\" width=\"620\" height=\"384\" \/><\/div>\n<p dir=\"ltr\">Kaspersky Lab has also found that several ski resort facilities in South Korea suffered from this worm, which disabled the operation of ski gates and ski lifts at the resorts. Although the actual impact of attacks with this malware was limited, it clearly contained the capability to be devastating, which luckily didn\u2019t happen.<\/p>\n<p dir=\"ltr\">Nevertheless, the real interest of the cybersecurity industry lay not in the potential or even actual damage caused by the Destroyer\u2019s attacks, but in the origin of the malware. Perhaps no other sophisticated malware has had so many attribution hypotheses put forward as the OlympicDestroyer.<\/p>\n<p dir=\"ltr\">Within days of its discovery, research teams from all over the world had between them managed to attribute this malware to Russia, China and North Korea, based on a number of features previously attributed to cyber-espionage and sabotage actors allegedly based in these countries or working for these countries\u2019 governments.<\/p>\n<p dir=\"ltr\">Kaspersky Lab researchers were also trying to understand which hacking group was behind this malware. At some point during their research, they came across something that looked like 100% evidence connecting the malware to Lazarus \u2013 an infamous nation state backed group linked to North Korea.<\/p>\n<p dir=\"ltr\">This conclusion was based on a unique trace left by the attackers. A combination of certain features of the code development environment stored in the files can be used as a \u2018fingerprint\u2019, in some cases identifying the malware authors and their projects.<\/p>\n<p dir=\"ltr\">In the sample analyzed by Kaspersky Lab, this fingerprint gave a 100% match with previously known Lazarus malware components and zero overlap with any other clean or malicious file known to date to Kaspersky Lab. Combined with other similarities in tactics, techniques and procedures (TTPs), it drew researchers to the preliminary conclusion that OlympicDestroyer was yet another Lazarus operation.<\/p>\n<p dir=\"ltr\">However, the motives and other inconsistencies with Lazarus TTPs uncovered during the investigation by Kaspersky Lab onsite at the compromised facility in South Korea made researchers revisit the rare artefact.<\/p>\n<p dir=\"ltr\">Following another careful look at the evidence and manual verification of each feature, researchers discovered that the set of features didn\u2019t match the code \u2013 it had been forged to perfectly match the fingerprint used by Lazarus.<\/p>\n<p dir=\"ltr\">As a result, the researchers concluded that the features\u2019 \u2018fingerprint\u2019 is a very sophisticated false flag, intentionally placed inside the malware in order to give threat hunters the impression that they had found \u2018smoking gun\u2019 evidence, knocking them of the trail to more accurate attribution.<\/p>\n<p dir=\"ltr\">\u201cTo our knowledge, the evidence we were able to find was not previously used for attribution. Yet the attackers decided to use it, predicting that someone would find it. They counted on the fact that forgery of this artefact is very hard to prove. It\u2019s as if a criminal had stolen someone else\u2019 DNA and left it at a crime scene instead of their own. We discovered and proved that the DNA found on the crime scene was dropped there on purpose. All this demonstrates how much effort attackers are ready to spend in order to stay unidentified for as long as possible. We\u2019ve always said that attribution in cyberspace is very hard as lots of things can be faked, and OlympicDestroyer is a pretty precise illustration of this,\u201d said Vitaly Kamluk, head of APAC Research Team, Kaspersky Lab.<\/p>\n<p dir=\"ltr\">\u201cAnother takeaway from this story for us is that attribution is has to be taken extremely seriously. Given how politicized cyberspace has recently become, the wrong attribution could lead to severe consequences and actors may start trying to manipulate the opinion of the security community in order to influence the geopolitical agenda,\u201d he added.<\/p>\n<p dir=\"ltr\">The accurate attribution of OlympicDestroyer is still an open question \u2013 simply because it is a unique example of the implementation of very sophisticated false flags. However, Kaspersky Lab researchers found that the attackers used privacy-protecting service NordVPN and a hosting provider called MonoVM, which both accept Bitcoins. These and some other discovered TTPs were previously seen to be used by Sofacy \u2013 the Russian-speaking actor.<\/p>\n<p dir=\"ltr\">Kaspersky Lab products detect and block the OlympicDestroyer malware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab\u2019s Global Research and Analysis Team published the results of its own research into attacks by the OlympicDestroyer malware, providing technical evidence of a very sophisticated false flag placed inside the worm by the malware creator in order to knock threat hunters off the trail to its real origin.<\/p>\n","protected":false},"author":6,"featured_media":31423,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[117,103,5898,54],"class_list":["post-31422","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-kaspersky-lab","tag-malware","tag-olympicdestroyer","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/31422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=31422"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/31422\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/31423"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=31422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=31422"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=31422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}