Operation ShadowHammer: New Supply Chain Attack Threatens Users Worldwide

Kaspersky Lab research uncovers a new advanced persistent threat (APT) campaign that affects a large number of users through what is known as a supply chain attack. 

A supply chain attack is one of the most dangerous and effective infection vectors, increasingly exploited in advanced operations over the last few years – as we have seen with ShadowPad or CCleaner. It targets specific weaknesses in the interconnected systems of human, organizational, material, and intellectual resources involved in the product life cycle: from initial development stage through to the end user. While a vendor’s infrastructure can be secure, there could be vulnerabilities in its providers’ facilities that would sabotage the supply chain, leading to a devastating and unexpected data breach.

The actors behind ShadowHammer targeted the ASUS Live Update Utility as the initial source of infection. This is a pre-installed utility in most new ASUS computers, for automatic BIOS, UEFI, drivers and applications updates. Using stolen digital certificates used by ASUS to sign legitimate binaries, the attackers have tampered older versions of ASUS software, injecting their own malicious code. Trojanised versions of the utility were signed with legitimate certificates and were hosted on and distributed from official ASUS update servers – which made them mostly invisible to the vast majority of protection solutions.

This means that potentially every user of the affected software could have become a victim, actors behind ShadowHammer were focused on gaining access to several hundreds of users, which they had prior knowledge about.

As Kaspersky Lab’s researchers discovers, each backdoor code contains a table of hardcoded MAC addresses – the unique identifier of network adapters used to connect a computer to a network. Once running on a victim’s device, the backdoor verified its MAC address against this table. If the MAC address matches one of the entries, the malware downloads the next stage of malicious code. Otherwise, the infiltrated updater does not show any network activity, which is why it remains undiscovered for such a long time. In total, security experts are able to identify more than 600 MAC addresses. These are targeted by over 230 unique backdoored samples with different shellcodes.

The modular approach and extra precautions taken when executing code, to prevent accidental code or data leakage indicates that it is very important for the actors behind this sophisticated attack to remain undetected, while hitting some very specific targets with surgical precision. Deep technical analysis shows that the arsenal of the attackers is very advanced and reflects a very high level of development within the group.

The search for similar malware reveals software from three other vendors in Asia, all backdoored with very similar methods and techniques. Kaspersky Lab has reported the issue to Asus and other vendors.

The selected vendors are extremely attractive targets for APT groups that might want to take advantage of their vast customer base. It is not yet very clear what the ultimate goal of the attackers was and we are still researching who was behind the attack. However, techniques used to achieve unauthorised code execution, as well as other discovered artefacts suggest that ShadowHammer is probably related to the BARIUM APT, which was previously linked to the ShadowPad and CCleaner incidents, among others. This new campaign is yet another example of how sophisticated and dangerous a smart supply chain attack can be nowadays,” said Vitaly Kamluk, Director of Global Research and Analysis Team, APAC, at Kaspersky Lab.

All Kaspersky Lab products successfully detect and block the malware used in Operation ShadowHammer.

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky Lab researchers recommend implementing the following measures:

  • In addition to adopting must-have endpoint protection, implement a corporate grade security solution which detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform;
  • For endpoint level detection, investigation and timely remediation of incidents, we recommend implementing EDR solutions such as Kaspersky Endpoint Detection and Response or contacting a professional incident response team;
  • Integrate Threat Intelligence feeds into your SIEM and other security controls in order to get access to the most relevant and up-to-date threat data and prepare for future attacks.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest News

Penang Government advocates talents to explore various high-quality job opportunities in the State

Penang’s strong talent pool has long been a key driver in the state’s success in attracting strategic investments, especially in selected niche...

Bursa Malaysia named ‘Best Stock Exchange for Islamic Listings’ at 14th Annual IFN Services Providers Poll

Bursa Malaysia Berhad (“Bursa Malaysia” or the “Exchange”) has been named by Islamic Finance News (“IFN”) at the recent 14th Annual IFN...

Petronas Dagangan Berhad becomes first LNG solution provider for off-grid customers in Peninsular Malaysia

Following the launch of the Virtual Pipeline System (VPS) solution via the Regasification Terminal (RGT) in Pengerang, Johor, Petronas Dagangan Berhad (PDB)...

Huawei Malaysia signs MoU with Serba Dinamik to establish Smart Campuses in Malaysia

Huawei Technologies (Malaysia) Sdn. Bhd. (Huawei) and Serba Dinamik Group Berhad (Serba Dinamik) have teamed up to explore and develop innovative digital...

Shopee finds demand for premium and branded segment multiplied by over 300 times since 2015

E-commerce platform, Shopee has seen growing confidence and comfort in purchasing premium and branded items priced RM3,000 and above in addition to...

Must read

Affordable rent-to-own scheme for the youth of B40

By Sofea Azahar, In addressing the issue of housing affordability and ownership within the youth in low-income group...

The pandemic push to pivot: The reality of a renewable energy leader

By Ko Chuan Zhen, Chief Executive Officer & Co Founder of Plus Solar, The pandemic was an acid test...

Empowering Malaysians to become informed investors one app at a time

With a goal to build 500 applications that focuses on enabling action, Reactive Labs, co-founded by George and Riza, aims to go...

Bigo Live: A growing sensation in an industry with a big appetite

The live-streaming industry has seen a massive growth in years. From the likes of Vimeo to Facebook Live, the industry has grown...