How the FBI proved a remote admin tool was actually malware

On Thursday, the US government announced it had seized a website used to sell malware designed to spy on computers and mobile phones.

The malware is called NetWire, and over the years several cybersecurity companies and at least one government agency have produced reports detailing how hackers use the malware. . NetWire was also reportedly promoted on hacking forums, but the malware owner promoted it on his website making it look like a legitimate remote administration tool.

“NetWire is specifically designed to help companies complete a variety of tasks related to maintaining their computer infrastructure. It maintains a list of all remote computers and provides their status and inventory , and can connect to any of them for maintenance purposes.

In a press release announcing the seizure of the website hosted at worldwiredlabs.com, the US Attorney’s Office for the Central District of California said the FBI began investigating the site in 2020. commit international money laundering, fraud, and computer crime;

A spokesperson for the Federal Attorney’s Office provided TechCrunch with a copy of the warrant used to seize the website. The warrant details how the FBI determined that NetWire was in fact Remote Access Trojan (RAT) malware and not a legitimate app to control. remote computer.

The warrant includes an affidavit written by an unnamed FBI task force officer, acknowledging that an FBI investigative team member or agent purchased a NetWire license, downloaded malware, and analyzed the FBI in October. – explains that he gave it to a computer scientist in LA. 5th, 2020 and 12th January, 2021.

Image credit: net wire

To test the functionality of the malware, a computer scientist used NetWire’s builder tool on a test computer to build a “customized instance of the NetWire RAT” installed in a Windows virtual machine controlled by an agent. . During this process, the NetWire website stated that “the FBI never required the FBI to verify that it owned, operated, or possessed the machine under test that it attacked during the test (the attack was for any lawful or authorized purpose)”

In other words, based on this experiment, the FBI concluded that NetWire’s owners never bothered to ensure that their customers were using NetWire for legitimate purposes on computers they owned or controlled. .

FBI computer scientists can use the virtual machines they set up to remotely access files, open and kill apps like Windows Notepad, extract saved passwords, record keystrokes, prompts or shells. command execution via , and screenshots.

“FBI-LA [computer scientist] We emphasized that in all the functions tested above, the infected computer displayed no notification or warning that these actions were taking place. This is contrary to legitimate remote access tools that normally require user consent to do so,” the task force officer wrote in the affidavit.

Officers also cited a complaint the FBI received from a U.S.-based NetWire victim in August 2021, except that the victim hired a third party to confirm the identity of the victim and the incident. Many details of were not included. A cybersecurity firm concluded that the victim received a malicious email installing her NetWire.

Ciaran McEvoy, a spokesperson for the U.S. Attorney’s Office for the Central District of California, told TechCrunch that other than the warrant and the accompanying affidavit, no other public documents were known about the case. Information used to sell NetWire, including the identity of the owner, is currently restricted.

In a press release, the DOJ said Croatian authorities had arrested a local citizen allegedly running the website, but did not name the suspect.

Following this announcement, cybersecurity journalist Brian Krebs revealed that publicly accessible DNS records, WHOIS website registration data, information provided by services that index data published in public database leaks, as well as Google+ profiles I used to write an article linking worldwiredlabs.com. A website for someone named Mario Zanko.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *