ShadowPad: espionage backdoor uncovered in admin tools for Unix and Linux servers
Summary
In 2017 Kaspersky discovered the “ShadowPad” backdoor, which for 17 days was hidden in admin tools such as Xshell, Xmanager and Xftp from the Korean vendor NetSarang. The trojanised DLL was signed with valid NetSarang certificates and distributed via the regular update channel to banks, pharmaceutical and energy companies. The malicious code consisted of encrypted modules that only became active after a signal from the command server.
Ideas
- Attackers compromised the vendor in order to reach its customers via legitimate updates.
- A valid signature only proves that something came from the vendor, not that it is harmless.
- Encrypted modules that are only decrypted when needed make detection harder.
- Suspicious DNS requests in a bank’s network led to the discovery.
Insights
- Admin tools are particularly rewarding targets because they have access to many servers.
- Network monitoring often detects supply chain attacks earlier than virus scanners.
Facts
- The manipulated file was called nssock2.dll.
- Shortly before, in June 2017, NotPetya had been spread via the update mechanism of a Ukrainian accounting software.
- The trojanised versions, such as Xshell 5.0 Build 1322, were distributed from 17 July to 4 August 2017.
References
Critique
- The report names affected builds but no network indicators such as domains that could be used to detect an active infection.
Remarks
- A few weeks later a similar supply chain attack hit CCleaner; in 2020 SolarWinds followed with a far greater impact.
Recommendations
- Monitor outgoing DNS requests from admin workstations for unusual destinations.
- Restrict tools with server access to dedicated, hardened admin computers.
Links to the original source and the Web Archive open in a new tab.