Winnti-Stolen Digital Certificates Re-Used in Current Watering Hole Attacks on Tibetan and Uyghur Groups
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | footer.swf | he Tibetan Homes Foundation, i.e.: hxxp://maarip.org/uyghur/footer(.)swf So, what we have is an active watering hole campaign impl |
| md5 | 12181311e049eb9f1b909eabfdb55427 | E199C3DAB16CF8C9134E06FE12 215CEC7261D70A5913E79CD11EBC9ECC 12181311E049EB9F1B909EABFDB55427 Latest Webinars Reports Kaspersky researchers have discover |
| md5 | 215cec7261d70a5913e79cd11ebc9ecc | d publishers. Related md5: BD9FD3E199C3DAB16CF8C9134E06FE12 215CEC7261D70A5913E79CD11EBC9ECC 12181311E049EB9F1B909EABFDB55427 Latest Webinars Reports Ka |
| md5 | bd9fd3e199c3dab16cf8c9134e06fe12 | k campaigns on game developers and publishers. Related md5: BD9FD3E199C3DAB16CF8C9134E06FE12 215CEC7261D70A5913E79CD11EBC9ECC 12181311E049EB9F1B909EABFD |
| url | http://maarip.org/uyghur/footer( | “LadyBoyle” swf path as the Tibetan Homes Foundation, i.e.: hxxp://maarip.org/uyghur/footer(.)swf So, what we have is an active watering hole campaign i |
Full article475 words · extracted from securelist.com · click to collapse
A new-ish Flash exploit has been on the loose for attacks around the web. This time, the attackers have compromised a caregiver site providing support for Tibetan refugee children and are spreading backdoors signed with Winnti stolen certificates delivered with Flash exploits – the compromised web site is the NGO “Tibetan Homes Foundation”. Previously, FireEye identified similar “Lady Boyle” related malicious swf exploiting CVE-2013-0634. A notification has been sent to the contacts of the web site, but apparently the malicious footer.swf file is still hosted at the Foundation’s web site, so please do not visit it just yet. Also, be sure to update your Flash player to the latest version.

This site certainly appears to be a classic example of a “watering hole” attack. F-Secure pointed out another Lady Boyle watering hole set up against a related Uyghur group, which has been targeted in tandem following the early March World Uyghur Congress. The delivered backdoors are shown to be signed with Winnti-stolen digital certificates in the F-Secure post, including the stolen MGAME certificate.
Here is an example of those same stolen certs reused for the backdoors in the Tibetan Homes Foundation incident. We see both the MGAME cert and the ShenZehn certs signing the backdoors, here are screenshots of the latter:

Our products detect the Flash exploit+payload as Exploit.SWF.CVE-2013-0634.a. Here is a heatmap of our worldwide detections. Note that not all of these detections are Lady Boyle related, I estimate that at least a third of them are:

Other sites hosting the Lady Boyle swf exploit over the past couple of months have included “tibetangeeks.com”, who recently cleaned up their site and posted a cooperative plea to their attackers, and “vot.org” or the “Voice of Tibet” which is also cleaned up. Currently cleaned up but previously serving “Exploit.SWF.CVE-2013-0634.a” were Uyghur related sites “istiqlaltv.com” and “maarip.org”, with the same “LadyBoyle” swf path as the Tibetan Homes Foundation, i.e.:
hxxp://maarip.org/uyghur/footer(.)swf

So, what we have is an active watering hole campaign implementing a fairly new Flash exploit and abusing digital certificates that were stolen as a part of the ongoing Winnti targeted attack campaigns on game developers and publishers.
Related md5:
BD9FD3E199C3DAB16CF8C9134E06FE12
215CEC7261D70A5913E79CD11EBC9ECC
12181311E049EB9F1B909EABFDB55427
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/winnti-stolen-digital-certificates-re-used-in-current-watering-hole-attacks-on-tibetan-and-uyghur-groups-3/35692/