{"id":33096,"date":"2018-09-12T13:21:07","date_gmt":"2018-09-12T05:21:07","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=33096"},"modified":"2018-09-12T13:21:08","modified_gmt":"2018-09-12T05:21:08","slug":"luckymouse-malware-returns-with-a-legitimate-digital-certificate","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/09\/12\/luckymouse-malware-returns-with-a-legitimate-digital-certificate\/","title":{"rendered":"LuckyMouse malware returns with a legitimate digital certificate"},"content":{"rendered":"<p>The Kaspersky Lab Global Research and Analysis Team (GReAT) has discovered several infections from a previously unknown Trojan, which is most likely related to the infamous Chinese-speaking threat actor \u2013 LuckyMouse.<\/p>\n<p>The most peculiar trait of this malware is its hand-picked driver, signed with a legitimate digital certificate, which has been issued by a company developing information security-related software.<\/p>\n<p>The LuckyMouse group is known for highly targeted cyberattacks on large entities around the world. The group\u2019s activity is posing a danger to whole regions, including South-Eastern and Central Asia, as their attacks seem to have a political agenda.<\/p>\n<p>Judging by victim profiles and the group\u2019s previous attack vectors, Kaspersky Lab researchers think that the Trojan they\u2019ve detected might have been used for nation-state backed cyber-espionage.<\/p>\n<p>The Trojan discovered by Kaspersky Lab experts infected a target computer via a driver built by the threat actors. This allowed the attackers to execute all common tasks such as command execution, downloading and uploading files, and to intercept network traffic.<\/p>\n<p>The driver turned out to be the most interesting part of this campaign. To make it trustworthy, the group apparently stole a digital certificate, which belongs to an information security-related software developer and used this to sign malware samples. This was done in an attempt to avoid being detected by security solutions, as a legitimate signature makes the malware look like legal software.<\/p>\n<p>Another noteworthy feature of the driver is that despite Luckymouse\u2019s ability to create its own malicious software, the software used in the attack appeared to be a combination of publicly available code samples from the public repositories and custom malware.<\/p>\n<p>Such simple adoption of a ready-to-use third-party code, instead of writing original code, saves developers time and makes attribution more difficult.<\/p>\n<p>\u201cWhen a new LuckyMouse campaign appears, it\u2019s almost always around the same time as the leadup to a high-profile political event, and the timing of an attack usually precedes world leader summits. The actor isn\u2019t too worried about attribution \u2013 because they are now implementing third-party code samples into their programs, it\u2019s not time-consuming for them to add another layer to their droppers, or to develop a modification for the malware and still remain untraced,\u201d notes Denis Legezo, security researcher at Kaspersky Lab.<\/p>\n<p>Kaspersky Lab has previously <a href=\"https:\/\/securelist.com\/luckymouse-hits-national-data-center\/86083\/\"><u>reported<\/u><\/a> on the LuckyMouse actor attacking a national data center to organize a country-level waterholing campaign.<\/p>\n<p>How to protect yourself:<\/p>\n<p>\u2022\tDo not automatically trust the code running on your systems.\u00a0 Digital certificates do not guarantee the absence of backdoors.<\/p>\n<p>\u2022\tUse a robust security solution, equipped with malicious-behavior detection technologies that enable even previously unknown threats to be caught.<\/p>\n<p>\u2022\tSubscribe your organization\u2019s security team to a high quality threat intelligence reporting service in order to get early access to information on the most recent developments in the tactics, techniques and procedures of sophisticated threat actors.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Kaspersky Lab Global Research and Analysis Team (GReAT) has discovered several infections from a previously unknown Trojan, which is most likely related to the infamous Chinese-speaking threat actor \u2013 LuckyMouse. The most peculiar trait of this malware is its hand-picked driver, signed with a legitimate digital certificate, which has been issued by a company [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":33095,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[117],"class_list":["post-33096","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-kaspersky-lab"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/33096","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=33096"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/33096\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/33095"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=33096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=33096"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=33096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}