{"id":9862,"date":"2015-08-12T12:27:40","date_gmt":"2015-08-12T04:27:40","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=9862"},"modified":"2015-08-12T12:33:14","modified_gmt":"2015-08-12T04:33:14","slug":"darkhotel-cyberespionage-group-returns-using-exploit-leaked-from-hacking-team","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2015\/08\/12\/darkhotel-cyberespionage-group-returns-using-exploit-leaked-from-hacking-team\/","title":{"rendered":"Cyberespionage group that spies on execs in hotels now use Hacking Team&#8217;s exploit tools"},"content":{"rendered":"<p>Following the public leak of files belonging to Hacking Team \u2013 the company known for selling \u201clegal spyware\u201d to some governments and law enforcement agencies \u2013 a number of cyberespionage groups have started using for their own malicious purposes, the tools Hacking Team provided to its customers to carry out attacks.<\/p>\n<p>This includes several exploits targeting Adobe Flash Player and Windows OS. At least one of these has been re-purposed by the powerful cyberespionage actor, \u201cDarkhotel\u201d.<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/08\/KL_Darkhotel-2015.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-9863 size-large\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/08\/KL_Darkhotel-2015-1024x576.jpg\" alt=\"KL_Darkhotel 2015\" width=\"640\" height=\"360\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/08\/KL_Darkhotel-2015-1024x576.jpg 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/08\/KL_Darkhotel-2015-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/08\/KL_Darkhotel-2015-195x110.jpg 195w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/08\/KL_Darkhotel-2015.jpg 1563w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><br \/>\nKaspersky Lab has discovered that the \u201cDarkhotel\u201d, an elite spying crew uncovered by its experts in 2014 and famous for infiltrating Wi-Fi networks in luxury hotels to compromise selected corporate executives, has been using a zero-day vulnerability from Hacking Team\u2019s collection since the beginning of July, straight after the notorious leak of Hacking Team files on July, 5th.<\/p>\n<p>Not known to have been a client of Hacking Team, the Darkhotel group appears to have grabbed the files once they became publicly available.<\/p>\n<p>This is not the group\u2019s only zero-day, Kaspersky Lab estimates that over the past few years it may have gone through half a dozen or more zero-days targeting Adobe Flash Player, apparently investing significant money in supplementing its arsenal.<\/p>\n<p>In 2015, the Darkhotel group extended its geographical reach around the world while continuing to spearphish targets in North and South Korea, Russia, Japan, Bangladesh, Thailand, India, Mozambique and Germany.<\/p>\n<p><strong>Collateral assistance from Hacking Team<\/strong><\/p>\n<p>Kaspersky Lab\u2019s security researchers have registered new techniques and activities from Darkhotel, a known advanced persistent threat (APT) actor that has been active for almost eight years.<\/p>\n<p>In attacks dated 2014 and earlier, the group misused stolen code-signing certificates and employed unusual methods like compromising hotel Wi-Fi to place spying tools on targets\u2019 systems.<\/p>\n<p>In 2015, many of these techniques and activities have been maintained, but Kaspersky Lab has also uncovered new variants of malicious executable files, the ongoing use of stolen certificates, relentless spoofing social-engineering techniques and the deployment of Hacking Team\u2019s zero-day vulnerability:<\/p>\n<p><strong>Ongoing use of stolen certificates.<\/strong> The Darkhotel group appears to maintain a stockpile of stolen certificates and deploys their downloaders and the backdoors signed with them to cheat the targeted system.<\/p>\n<p>Some of the more recent revoked certificates include Xuchang Hongguang Technology Co. Ltd. \u2013 the company whose certificates were used in previous attacks performed by the threat actor.<\/p>\n<p><strong>Relentless spearphishing.<\/strong> The Darkhotel APT is indeed persistent: it tries to spearphish a target, and if it doesn\u2019t succeed returns several months later for another try with much the same social-engineering schemes.<\/p>\n<p><strong>Deployment of Hacking Team\u2019s zero-day exploit.<\/strong> The compromised website, tisone360.com, contains a set of backdoors and exploits. The most interesting of these is the Hacking Team Flash zero-day vulnerability.<\/p>\n<p>\u201cDarkhotel has returned with yet another Adobe Flash Player exploit hosted on a compromised website, and this time it appears to have been driven by the Hacking Team leak. The group has previously delivered a different Flash exploit on the same website, which we reported as a zero-day to Adobe in January 2014,\u201d said Kurt Baumgartner, Principal Security Researcher at Kaspersky Lab.<\/p>\n<p>\u201cDarkhotel seems to have burned through a pile of Flash zero-day and half-day exploits over the past few years, and it may have stockpiled more to perform precise attacks on high-level individuals globally. From previous attacks we know that Darkhotel spies on CEOs, senior vice presidents, sales and marketing directors and top R&amp;D staff,\u201d Baumgartner added.<\/p>\n<p>Since last year, the group has worked hard to enhance its defensive techniques, for example by expanding its anti-detection technology list. The 2015 version of the Darkhotel downloader is designed to identify anti-virus technologies from 27 vendors, with the intention of bypassing them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following the public leak of files belonging to Hacking Team \u2013 the company known for selling \u201clegal spyware\u201d to some governments and law enforcement agencies \u2013 a number of cyberespionage groups have started using for their own malicious purposes, the tools Hacking Team provided to its customers to carry out attacks. This includes several exploits [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":9863,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[2846,3334,3333,117],"class_list":["post-9862","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cyberespionage","tag-darkhotel","tag-hacking-team","tag-kaspersky-lab"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/9862","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=9862"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/9862\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/9863"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=9862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=9862"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=9862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}