SiliVaccine: A Special Report Into North Korea’s Anti-Virus

Revealed: In an exclusive piece of research, Check Point Researchers have carried out a revealing investigation into North Korea’s home-grown anti-virus software, SiliVaccine.          One of several interesting factors is that a key component of SiliVaccine’s code is a 10-year-old copy of one of Trend Micro’s, a Japanese company, software components.

 

A Suspicious Email

This investigation began when our research team received a very rare sample of North Korea’s ‘SiliVaccine’ anti-virus software from Martyn Williams, a freelance journalist with a focus on North Korean technology. Mr. Williams had himself received the software as a link in a suspicious email sent to him on July 8th 2014, by someone going by the name of ‘Kang Yong Hak’. This sender’s mailbox has since been rendered unreachable.

 

The strange email sent by ‘Kang Yong Hak’, supposedly a Japanese engineer, contained a link to a Dropbox-hosted zip file that held a copy of the SiliVaccine software, a Korean language readme file instructing how to use the software and a suspicious looking file posing as an update patch for SiliVaccine.

 

Trend Micro’s AV Scan Engine

 

After detailed forensic analysis of SiliVaccine’s engine files (the software component that provides the core file scanning capability of the anti-virus), our research team discovered exact matches of SiliVaccine and large chunks of 10+-year-old anti-virus engine code belonging to Trend Micro, a completely separate Japan-based provider of cybersecurity solutions. For this to happen, the developers who built SiliVaccine could have had access to a compiled library from any of Trend Micro’s commercially released products, or, theoretically, source code access.

 

Of course, the purpose of an anti-virus is to block all known malware signatures. However, a deeper investigation into SiliVaccine found that it was designed to overlook one particular signature, which ordinarily it would be expected to block, and which is blocked by the Trend Micro detection engine. While it is unclear what this signature actually is, what is clear is that the North Korean regime does not want to alert its users to it.

 

Bundled Malware

 

As for the supposed patch update file, this was found to be the JAKU malware. This was not necessarily part of the anti-virus but could have been included in the zip file as a way to target journalists such as Mr. Williams.

 

In brief, JAKU is a highly resilient botnet forming malware that has infected around 19,000 victims, primarily by malicious BitTorrent file shares. It has however been seen to target and track more specific individual victims in both South Korea and Japan, including members of International Non-Governmental Organizations (NGOs), engineering companies, academics, scientists and government employees.

 

Our investigation found though that the JAKU file was signed with a certificate issued to a certain ‘Ningbo Gaoxinqu zhidian Electric Power Technology Co., Ltd’, the same company that was used to sign files by another well-known APT group, ‘Dark Hotel’. Both JAKU and Dark Hotel are thought to be attributed to North Korean threat actors.

 

The Japanese Connection

 

Japan and North Korea do not enjoy friendly political or diplomatic relations, which makes is strange that the initial email containing the copy of SiliVaccine appeared to have been sent by a

 

Japanese national.  However the unlikely connection does not end there, as other connections with Japan were also found by our researchers.

 

During our investigation, we discovered the names of the companies that are thought to have authored SiliVaccine, PGI (Pyonyang Gwangmyong Information Technology) and STS Tech-Service.

 

STS Tech-Service is known to have worked with other companies, including ‘Silver Star’ and ‘Magnolia’, both of which are based in Japan and have had previous cooperation with the KCC (Korea Computer Center), a North Korean government entity.

 

Trend Micro’s Response

 

Our team reached out to notify Trend Micro of their detection engine being used in SiliVaccine, who responded promptly and were highly cooperative. Their response was as follows:

 

“Trend Micro is aware of the research by Check Point on the “SiliVaccine” North Korean anti-virus product, and Check Point has provided us with a copy of the software for verification. While we are unable to confirm the source or authenticity of that copy, it apparently incorporates a module based on a 10+ year-old version of the widely distributed Trend Micro scan engine used by a variety of our products. Trend Micro has never done business in or with North Korea. We are confident that any such usage of the module is entirely unlicensed and illegal, and we have seen no evidence that source code was involved. The scan engine version at issue is quite old and has been widely incorporated in commercial products from Trend Micro and third party security products through various OEM deals over the years, so the specific means by which it may have been obtained by the creators of SiliVaccine is unknown. Trend Micro takes a strong stance against software piracy, however legal recourse in this case would not be productive. We do not believe that the infringing use at issue poses any material risk to our customers.”

 

Trend Micro’s indication that a widely licensed library was misappropriated may be behind SiliVaccine’s use of a 10+ year-old version of their scan engine is backed up by an additional analysis our team made of an older version of SiliVaccine, too. This suggests that this is not a one-time occurrence.

 

Summary

 

This revealing exploration into SiliVaccine may well raise suspicions of authenticity and motives of the IT security products and operations of this hermit kingdom.

 

While attribution is always a difficult task in cyber security, there are many questions raised by our findings. What is clear, however, are the shady practices and questionable goals of SiliVaccine’s creators. Our investigations point to yet another example of state-sponsored technologies being used in the fifth generation of the cyber threat landscape.

 

For a more technical look inside SiliVaccine, please check out Check Point Research’s findings.

The post SiliVaccine: A Special Report Into North Korea’s Anti-Virus appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/2HErHwV

Facebook to allow users to clear browsing history with new feature

(Reuters) - Facebook Inc Chief Executive Officer Mark Zuckerberg said on Tuesday the social network is building a new privacy control called "clear history" to allow users to delete browsing history.


from Reuters: Technology News https://ift.tt/2w2WePQ

Facebook to allow users to clear browsing history

(Reuters) - Facebook Inc Chief Executive Officer Mark Zuckerberg on Tuesday said the social network is building a new privacy control called "clear history" to allow users to delete browsing history, and he plans to discuss the feature at Facebook's annual F8 conference.


from Reuters: Technology News https://ift.tt/2rbUD4z

SiliVaccine: A Special Report Into North Korea’s Anti-Virus

Revealed: In an exclusive piece of research, Check Point Researchers have carried out a revealing investigation into North Korea’s home-grown anti-virus software, SiliVaccine.          One of several interesting factors is that a key component of SiliVaccine’s code is a 10-year-old copy of one of Trend Micro’s, a Japanese company, software components.

 

A Suspicious Email

This investigation began when our research team received a very rare sample of North Korea’s ‘SiliVaccine’ anti-virus software from Martyn Williams, a freelance journalist with a focus on North Korean technology. Mr. Williams had himself received the software as a link in a suspicious email sent to him on July 8th 2014, by someone going by the name of ‘Kang Yong Hak’. This sender’s mailbox has since been rendered unreachable.

 

The strange email sent by ‘Kang Yong Hak’, supposedly a Japanese engineer, contained a link to a Dropbox-hosted zip file that held a copy of the SiliVaccine software, a Korean language readme file instructing how to use the software and a suspicious looking file posing as an update patch for SiliVaccine.

 

Trend Micro’s AV Scan Engine

 

After detailed forensic analysis of SiliVaccine’s engine files (the software component that provides the core file scanning capability of the anti-virus), our research team discovered exact matches of SiliVaccine and large chunks of 10+-year-old anti-virus engine code belonging to Trend Micro, a completely separate Japan-based provider of cybersecurity solutions. For this to happen, the developers who built SiliVaccine could have had access to a compiled library from any of Trend Micro’s commercially released products, or, theoretically, source code access.

 

Of course, the purpose of an anti-virus is to block all known malware signatures. However, a deeper investigation into SiliVaccine found that it was designed to overlook one particular signature, which ordinarily it would be expected to block, and which is blocked by the Trend Micro detection engine. While it is unclear what this signature actually is, what is clear is that the North Korean regime does not want to alert its users to it.

 

Bundled Malware

 

As for the supposed patch update file, this was found to be the JAKU malware. This was not necessarily part of the anti-virus but could have been included in the zip file as a way to target journalists such as Mr. Williams.

 

In brief, JAKU is a highly resilient botnet forming malware that has infected around 19,000 victims, primarily by malicious BitTorrent file shares. It has however been seen to target and track more specific individual victims in both South Korea and Japan, including members of International Non-Governmental Organizations (NGOs), engineering companies, academics, scientists and government employees.

 

Our investigation found though that the JAKU file was signed with a certificate issued to a certain ‘Ningbo Gaoxinqu zhidian Electric Power Technology Co., Ltd’, the same company that was used to sign files by another well-known APT group, ‘Dark Hotel’. Both JAKU and Dark Hotel are thought to be attributed to North Korean threat actors.

 

The Japanese Connection

 

Japan and North Korea do not enjoy friendly political or diplomatic relations, which makes is strange that the initial email containing the copy of SiliVaccine appeared to have been sent by a

 

Japanese national.  However the unlikely connection does not end there, as other connections with Japan were also found by our researchers.

 

During our investigation, we discovered the names of the companies that are thought to have authored SiliVaccine, PGI (Pyonyang Gwangmyong Information Technology) and STS Tech-Service.

 

STS Tech-Service is known to have worked with other companies, including ‘Silver Star’ and ‘Magnolia’, both of which are based in Japan and have had previous cooperation with the KCC (Korea Computer Center), a North Korean government entity.

 

Trend Micro’s Response

 

Our team reached out to notify Trend Micro of their detection engine being used in SiliVaccine, who responded promptly and were highly cooperative. Their response was as follows:

 

“Trend Micro is aware of the research by Check Point on the “SiliVaccine” North Korean anti-virus product, and Check Point has provided us with a copy of the software for verification. While we are unable to confirm the source or authenticity of that copy, it apparently incorporates a module based on a 10+ year-old version of the widely distributed Trend Micro scan engine used by a variety of our products. Trend Micro has never done business in or with North Korea. We are confident that any such usage of the module is entirely unlicensed and illegal, and we have seen no evidence that source code was involved. The scan engine version at issue is quite old and has been widely incorporated in commercial products from Trend Micro and third party security products through various OEM deals over the years, so the specific means by which it may have been obtained by the creators of SiliVaccine is unknown. Trend Micro takes a strong stance against software piracy, however legal recourse in this case would not be productive. We do not believe that the infringing use at issue poses any material risk to our customers.”

 

Trend Micro’s indication that a widely licensed library was misappropriated may be behind SiliVaccine’s use of a 10+ year-old version of their scan engine is backed up by an additional analysis our team made of an older version of SiliVaccine, too. This suggests that this is not a one-time occurrence.

 

Summary

 

This revealing exploration into SiliVaccine may well raise suspicions of authenticity and motives of the IT security products and operations of this hermit kingdom.

 

While attribution is always a difficult task in cyber security, there are many questions raised by our findings. What is clear, however, are the shady practices and questionable goals of SiliVaccine’s creators. Our investigations point to yet another example of state-sponsored technologies being used in the fifth generation of the cyber threat landscape.

 

For a more technical look inside SiliVaccine, please check out Check Point Research’s findings.

The post SiliVaccine: A Special Report Into North Korea’s Anti-Virus appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/2HErHwV

Robert Mueller Likely Knows How This Investigation Ends

Nearly a year since his appointment as special counsel, Robert Mueller has accelerated the pace of his investigation.

from Security Latest https://ift.tt/2I8ewnt

A New Cryptocurrency Mining Virus is Spreading Through Facebook

If you receive a link for a video, even if it looks exciting, sent by someone (or your friend) on Facebook messenger—just don't click on it without taking a second thought. Cybersecurity researchers from Trend Micro are warning users of a malicious Chrome extension which is spreading through Facebook Messenger and targeting users of cryptocurrency trading platforms to steal their accounts’


from The Hacker News https://ift.tt/2KqSL0s

Uber loses its license in southern UK coastal city of Brighton

LONDON (Reuters) - Uber's [UBER.UL] license in the southern English coastal city of Brighton will not be renewed, the local council said on Tuesday, adding the taxi app is not "fit and proper" and citing concerns over a data breach and the use of drivers from outside the area.


from Reuters: Technology News https://ift.tt/2I0S3Zs

Uber loses its license in UK coastal city of Brighton

LONDON (Reuters) - Uber's [UBER.UL] license in the southern English coastal city of Brighton will not be renewed as the council said the taxi app was not "fit and proper" to hold a license, citing concerns over a data breach and the use of drivers from outside the area.


from Reuters: Technology News https://ift.tt/2HEmq8N

U.S. agency to probe Nintendo systems after rival's complaint

WASHINGTON (Reuters) - The U.S. International Trade Commission said on Tuesday it will investigate certain gaming console systems from Nintendo Co Ltd after California-based Gamevice Inc filed a complaint alleging that their importation infringed on its patents.


from Reuters: Technology News https://ift.tt/2HGWycg

U.S. Commerce Secretary says 5G priority for Trump administration

WASHINGTON (Reuters) - U.S. Commerce Secretary Wilbur Ross on Tuesday said building a next generation 5G mobile network was a priority for the Trump administration, boosting the argument behind wireless carriers Sprint Corp and T-Mobile US Inc's proposed deal.


from Reuters: Technology News https://ift.tt/2rdrhCV

PROTECTING YOUR PRIVACY – Part 1: The Privacy Risks of Social Networks and Online Browsing

Most Americans today spend many of their waking hours online. In fact, we’re up to spending an average of five hours per day just on our mobiles. Much of this time is spent browsing the web or checking in, updating and sharing via our favorite social networks. There’s just one problem: unless you have your privacy controls locked down, the chances are you could be sharing way more personal data with third parties than you’re comfortable with.

 

That information could then be used to serve you up relevant ads; it could help government snoopers investigate cases; it could be used to screen you ahead of job interviews; to compile credit scores; and even to help political candidates influence your voting behavior. Most dangerous of all, it could be harvested by hackers to commit identity fraud.

It nothing else, the recent Facebook-Cambridge Analytica scandal has brought privacy right back into the spotlight as a major concern for American netizens. If data on 87 million Facebook users can be harvested by a third-party without their consent and used for political profiling, there are serious questions to be answered about how our information is being used by the online entities we interact with every day.

The good news is that there are things you can do right now to protect your privacy online, both by using the built-in features of many social networks and browsers and third-party tools like Trend Micro Security’s Privacy Scanner.

This two-part blog series will first examine how online privacy affects you — where the key problems are and the consequences of over-sharing data on the web. Then in part two we’ll take a look at concrete steps you can take to better protect your privacy online.

Why should I care?

Most of us take using the internet for granted today — we treat is as a utility like running water or electricity in our homes. But we might not stop to think about what we’re giving away in order to access this online world. There are various ways that our data can end up in the hands of third parties, whether it’s granted explicitly by us, hidden away in privacy policy small print, or stolen without our knowledge. Sharing our personal data like this can sometimes be beneficial: for example, resulting in better targeted ads. But at the other end of the spectrum it could lead to identity theft and cyber-attacks.

There are three main dimensions to consider:

  • The social network: Whether you’re on Facebook, Twitter, Instagram, LinkedIn or other social sites, the risks are broadly the same. You might over-share information in your public feed or sign up to a privacy agreement without realizing how intrusive the policy is.

 

Although many of us don’t read privacy agreements when we sign up for social networking sites, it would be a useful exercise to find out exactly what rights you have, how your info will be protected and when it won’t. Be warned though, policies can change significantly even overnight.

  • Third-party applications: These are programs that interact with the social network but are owned and run by separate developers. Many require deep access to your user profile without being held to the same levels of accounting over what they do with it. This is the problem that led to the Cambridge Analytica scandal, after a third-party developer harvested data on tens of millions of Facebook users who were merely ‘friends’ with users of his app.
  • Browser tracking: We often forget just how much information we can give away via simple internet searches. That makes our browsing data highly valuable to advertisers and malicious third parties looking for information to blackmail us. They could also target any online passwords we store in the browser.

Focus on privacy

Let’s take a closer look at three examples where your online privacy could be at risk:

Facebook: So much of our digital lives are lived on Facebook today that it’s arguably the most important site to keep a close eye on. Everything from your email address, birthday and phone number, to political views, sexual orientation and who you’re married or related to could be online there. That’s in addition to any public updates, links, photos and videos you might post.

If you overshare, this information could be used by prospective employers, credit agencies, or police and government agents. There’s also the risk of the info being used by online stalkers or trolls. Most concerning is if scammers come across your profile. They are particularly adept at piecing together bits of your identity data: either to commit ID fraud by opening new accounts in your name, or to launch highly convincing phishing emails designed to elicit more personal data such as bank details, or to spread malware.

Any linked apps you might have such as online games and quizzes could also demand access to sensitive private information. They might sell this on to third-party advertisers or others. Although Facebook has now changed its terms of service and clamped down on such activity, this is how the details of 87m users ended up being used for political targeting.

Twitter: It’s much easier to protect your privacy on this site, as you only share with the world what you tweet or put in your public profile. That said, there are concerns around geolocation. If this feature is on, then users may accidentally leak their location at the time of a post. In extreme circumstances, this could be used by robbers to burgle a user’s home, if they see the owner is away.

You could also be tagged in photos unless you request not to be, and third-party marketers might be able to access your account-linked email and phone number. Twitter will also serve you ads based on website visits or behavior on the site, unless you choose not to.

Online Browsing: We focus here on Chrome as the most popular browser, but these cautionary notes pertain to any browser you may use. Surfing the web via Chrome provides Google with a huge amount of data on your personal life, which it then sells to advertisers to personalize your search results. That’s why its ad revenue for 2017 was close to $100bn. The incognito browser offers some protection, but can also lull users into a false sense of security. Although using it will mean any data on the sites you search for and the pages you visit will not be stored in your browser’s history, cookie store, or search history, the ISPs and third parties that know your IP address will still be able to track its geolocation, as will the websites you visit, unless you use a VPN.

Chrome also asks if you want to store online passwords every time you enter them on a new site. Although this saves time, it can create additional security risks because they’re stored in the browser. If you’re hacked, an online attacker could steal these digital keys fairly easily, to unlock your accounts at will.

Stay tuned for part two, where we’ll explore what you can do to protect your privacy online.

The post PROTECTING YOUR PRIVACY – Part 1: The Privacy Risks of Social Networks and Online Browsing appeared first on .



from Trend Micro Simply Security https://ift.tt/2HLTHuv

UK lawmakers prepared to summon Facebook boss Zuckerberg over data scandal

LONDON (Reuters) - British parliamentarians said they were prepared to issue a formal summons for Facebook Chief Executive Mark Zuckerberg to appear before them and answer questions over a data scandal which has engulfed the technology giant.


from Reuters: Technology News https://ift.tt/2KnKSsN

Tomorrow's jobs require impressing a bot with quick thinking

NEW YORK (Reuters) - When Andrew Chamberlain started in his job four years ago in the research group at jobs website Glassdoor.com, he worked in a programming language called Stata. Then it was R. Then Python. Then PySpark.


from Reuters: Technology News https://ift.tt/2reaqQl

World of Warcraft goes offline to Czech forest

PRAGUE (Reuters) - Czech web developer Vojtech Ruzicka ditched his laptop and urban Prague lifestyle and decamped to the forest dressed as a blue-faced shaman for a "World of Warcraft" reenactment game.


from Reuters: Technology News https://ift.tt/2w2NWXZ

Man Who Hacked Jail Systems to Release His Friend Early Gets 7-Years in Prison

Remember a young hacker who hacked jail systems in an attempt to release his prison inmate early? Well, that hacker will now be joining his inmate behind bars. Konrads Voits of Ypsilanti, Michigan, has been sentenced to seven years and three months in prison for attempting to hack the Washtenaw County Jail computer system and modifying prison records to get his friend released early. <!--


from The Hacker News https://ift.tt/2I0BMnv

Singapore airport may use facial recognition systems to find late passengers

SINGAPORE (Reuters) - Ever been delayed on a flight because of straggling fellow passengers?


from Reuters: Technology News https://ift.tt/2JHKK6a

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...