Loading summary
N2K CyberWire
You're listening to the Cyberwire network, powered by N2K.
Dave Bittner
Hey everybody, Dave here. I've talked about Deleteme before and I'm still using it because it still works. It's been a few months now and I'm just as impressed today as I was when I signed up. Deleteme keeps finding and removing my personal information from data broker sites and they keep me updated with detailed reports so I know exactly what's been taken down. I'm genuinely relieved. Knowing my privacy isn't something I have to worry about every day. The Delete Me team handles everything. It's the set it and forget it peace of mind. And it's not just for individuals. DeleteMe also offers solutions for businesses, helping companies protect their employees personal information and reduce exposure to social engineering and phishing threats. And right now our listeners get a special 20% off your delete me plan. Just go to JoinDeleteMe.com N2K and use promo code N2K at checkout. That's JoinDeleteMe.com N2k code N2K.
N2K CyberWire
Foreign.
Dave Bittner
Hello everyone and welcome to the Cyberwires Research Saturday. I'm Dave Bittner and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in our rapidly evolving cyberspace. Thanks for joining us.
Michael Gorlick
So this is how we discovered basically the execution of the Infostiller, the not lab pile infosteeller was executing actually on one of our medium sized customers. And then we are starting to basically investigate and look back, which actually discovered, brought to the discovery of a full chain of AI frameworks compromised which I'm sure we will be discussing right now.
Dave Bittner
That's Michael Gorlick, Chief Technology Officer at morphisec. The research we're discussing today is titled New Noodle File Stealer distributes via fake AI video generation platforms. Well, let's dig into it together here. What exactly is Noodle File Stealer and what are its primary functions?
Michael Gorlick
Yeah, so this is very similar in a way to some of the other infrastructures, though it's delivery techniques is quite advanced and relatively rare, in which it was delivered through Python in memory with base 85 encoding, which is kind of very different from base 64. The steel itself, I guess the history of the browsers it can hijack, then intercept wallet credentials and more. But it's relatively minimal in a way to possibly avoid a significant footprint on the endpoint.
Dave Bittner
And how would someone find themselves with this on their system? How does it Infiltrate someone.
Michael Gorlick
Yeah. So in this case the delivery technique is quite advanced and we are talking about the delivery and in our blog post we discovered just a delivery of an archive that was basically downloaded by the different victims and this archive and we'll get to the, you know, the AI framework, but starting from the download portion, if you download this archive, this archive basically included different files like Document PDF and others with additional hidden directory if you download it actually today you will see that there are quite a lot of still those AI framework sites that also deliver archives. But this time you'll find invoices and other type of documents that can resonate very nice nicely in the way of social engineering. But those files, the document PDF or the invoice PDF or any of the other content files are not really invoices or not really documents. They basically are an advanced archive files with a bunch of different executables like we described in the blog itself, and with the modified headers to avoid basically simple scanning of those files and bypass existing solutions so that eventually the first loader operation is the one to fix those headers back and eventually decrypt or unarchive some of the files by, you know, changing their names back from the PDF to RAR or zip or whatever and then using a specific password, opening them and get to execute the next stage operation, which are the Python compiled executables, which is also an interesting stage by itself. But really we are talking about a significant archive with executables that are blown up of proportions of 150, 160, 170 megabytes with many, let's say, advanced techniques. Until you get to those archive, you still have a couple of very advanced techniques that will execute for example Net code within a native executable, et cetera. It's quite advanced techniques to bypass simple interpretation, scanning, interpreted PowerShell and interpret net sorry commands scanning.
Dave Bittner
So my understanding is that these folks are using fake AI video generation platforms to be a vector for the malware.
Michael Gorlick
Yes, exactly. At least we intercepted, I think this was the most interesting thing. We intercepted a bunch of websites. But when we were investigating those AI framework websites, Lumadream, Dream AI, we got to a very popular Facebook pages. There are bunch of those Facebook pages that are still very much active. They're websites with high reputation delivering this malware and all of them using a very similar template. And if you look on the websites, on the different websites, you'll see that their followers, their amount of followers is even higher than the regular, the original one, the original framework. So Take for example a legitimate framework called lumalabs AI video generator framework. You see that the amount of followers there, like it's about 2.7 thousand of followers and you have all kind of different screenshots there. In a way this platform is intended for you to upload your images and then see, see this platform generating video. Many of you probably saw those kind of advertisement of inputting or basically uploading your kid image and, and you as a result you have an output of a video that shows how the kid becomes older and all those very interesting advertisements. So you have the same advertisement there. And I have non real malicious platforms here with three point something thousand followers, with 1.8 thousand followers, totally legit with like my Facebook mark Blue v Mark validated, fully pushing those malicious platform. And if you get to those platform, the difference between those malicious platform to them legitimate platforms is the fact that those malicious platform just allow you to download those example of videos, let's call it like that, for free, without going through the old signing operation, while the legitimate one is actually requires you to sign up for that, that thing. But if you go look even deeper and try to compare, okay, so maybe the SSL certificate are not good enough, maybe there could be some issues. And you'll find that both the legitimate and non legitimate website are all using kind of very basic certificates like let's encrypt or something like that of that form, which is funny but not exactly because of the increase of those platforms. Every second person creates something very cool today with using those CI tools they go and sign their sites, websites with the most basic certificate they can get to. And there is no concept of high reputation, low reputation anymore. Right, because all of them are low reputation, legitimate or non legitimate. Since you get kind of to the point in which hey, I don't know if it's legitimate or not and I don't have anyone to trust.
Dave Bittner
We'll be right back. And now a word from our sponsor. Spy Cloud identity is the new battleground and attackers are exploiting stolen identities to infiltrate your organization. Traditional defenses can't keep up. Spy Cloud's holistic identity threat protection helps security teams uncover and automatically remediate hidden exposures across your users from breaches, malware and phishing to neutralize identity based threats like account takeover, fraud and ransomware. Don't let invisible threats compromise your business. Get your free corporate darknet exposure report@spycloud.com cyberwire and see what attackers already know. That's spycloud.com cyberwire.
N2K CyberWire
On WhatsApp no one can see or hear your personal messages. Whether it's a voice call message or sending a password to WhatsApp, it's all just this. So whether you're sharing the streaming password in the family chat, or trading those late night voice messages that could basically become a podcast, your personal messages stay between you, your friends and your family. No one else, not even us. WhatsApp message privately with everyone.
Dave Bittner
So what happens once I engage with this fake AI video generation platform? So I'm on Facebook, I'm scrolling through as you do, this catches my eye and I decide to play with it. What happens next in terms of it being able to take advantage of me and install the malware? How does it work?
Michael Gorlick
Yeah, so you get from one of those like Facebook advertisement in which you see some kind of a nice video, cool video. This leads you to a page with high reputation advertising, higher than the legitimate one. And at the, you know, core of the page, in the main part of the page, you have the link for the platform itself. Sometimes the link also comes from top buttons like Learn more automatically forwards your redirection to that platform as soon as you get to the platform. The platform in a way is very similar to the legitimate platforms. You can find other places. Very cool design, looks very professional and many times leads to the same result of downloading some kind of archive file. So whether you upload your images just trying to something for free, there are different control flows, let's call it like that, different flows that will lead to the same malicious files called Script JS, JavaScript file that eventually triggers the download of an archive. So you get to this download from different interactions with those malicious websites. It's always the same archive and different websites deliver different archives. It's always an archive though, and quite a heavy one. Right. And then from obviously downloading the archive, you want to open it. And this archive, when you just look at the zip or unarchive it, you will see only one file. But essentially this archive has a hidden directory which has all those malicious component. Now if you use for example 7 zip and just open that archive without decrypting it, you will see that hidden folder. Most of the users unfortunately are not so sophisticated. They just open the zip and miss out on this hidden folder which will be triggered by the executable.
Dave Bittner
What about detection here? I mean, what sort of challenges do security professionals face when trying to detect and mitigate something like noodle file?
Michael Gorlick
Yeah, well, if it wouldn't be an archive that you would download, the detection would be simpler. You could detect that on the perimeter level, many of the browsers and the defender for cloud and different very basic filtering capabilities to identify those advanced.net overblown executables or misconfigured like RAR files. But the fact that you download an archive, the archive, it's very easy to hide artifacts within those archives. So as soon as it gets to your disk, it's actually quite challenging to detect by existing controls. So you need more sophisticated controls and places like ours, for example. Or you can implement if you own a business and you can allow yourself to implement hardening capabilities like application controls and others, which basically do not allow you just to execute anything. And Even if your MP4 has some kind of line spaces that leads to an execution of executable, still will prevent that. So it's really dependent on the organization. For the regular users or innovators or those that are just interested to download something cool from those kind of platforms. I would really recommend not to download archives. And if they get archives, just delete those. If this platform kind of Downloads you an MP4, you will be able to to trust at least your basic security controls that will identify that this is not an executable, it's an MP4, it's a video file. Your browser will not let you download executable without using a smart screen, which is the core technology that provided by Microsoft. But smart screen can be bypassed again by using archives.
Dave Bittner
So are there any particular technical elements of this that are that are worth sharing? Anything that caught your attention inside the malware itself?
Michael Gorlick
I mean, the malware itself really is one of the things that we identified is the way they used decrypt the Python code itself. They use a combination of base 64 and base 85, which is quite rare. We saw those kind of techniques in some of the GitHubs that were correlated to Korean attacks. We did follow the OSINT and got to actors that are Taiwanese in this case, which is also a bit of unique. Don't see too many Taiwanese attack on this scale. So there were definitely, if we are looking on the Austin side, a couple of interesting points. But again, the base 85 decoding was for me, if we are looking on the infosteel, the most interesting the infrasteller also and many times delivered in parallel with a rock. In this case it was the X Worm also delivered a very similar way by basically taking a base 64 and decoded that with base 85. This is double decoding. And then everyone knows what the X worm rod obviously and it's extremely persistent and it's much beyond just stealing browser cookies, your history and wallets. It's a persistent, fully capable malware that can execute remote commands. And I would say in most of the cases of this nobihill delivery, we had that route delivered in parallel to the infosteeler. So definitely you would like to validate your network outbound communication. You would like to validate your persistency steps. You know the regular run keys, regular services, if no new services were generated, kind of the basic persistency validation, something that for sure I would validate.
Dave Bittner
What do you hope that people take away from this research that you've published? What are the take homes for you?
Michael Gorlick
Yeah, I mean we'll always have sophisticated malware. So this is our job, right? I'm doing it 25 years and every time the hackers, the adversaries are innovate in a crazy pace and with the AI they innovate even faster. You see new tactics, new techniques all the time. At this moment I'm kind of not concerned with regard to the super advanced malware. I'm more concerned of the delivery techniques, as probably was sound from my small lecture. This is the time right now in which it kind of reminds me the 2016 exploit kit times and the times when they Wanna cry appeared very non stable in a time where many new attack surfaces and new delivery techniques are possible. And it will take a year or two until security controls will adapt to this new delivery risk and we'll find a solution to try and identify what is a legitimate AI framework and what is not. Until then, I would recommend people not to hurry and download anything from those AI platforms. Be extremely careful and validate everything that is downloaded. And where do you upload stuff as well. Many of them are generated by a simple person using the same AI tools that are available to anyone else.
Dave Bittner
Our thanks to Michael Gorlick from Morphisec for joining us. The research is titled New Noodle File Stealer Distributes via Fake AI video Generation platforms. We'll have a link in the Show Notes. And that's Research Saturday brought to you by N2K CyberWire. We'd love to hear from you. We're conducting our annual audience survey to learn more about our listeners. We're collecting your insights until the end of August. There's a link in the Show Notes. We hope you'll check it out. This episode was produced by Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next time.
Michael Gorlick
It.
Podcast Summary: CyberWire Daily – "A New Stealer Hiding Behind AI Hype" [Research Saturday]
Podcast Information:
Timestamp: [01:31]
Dave Bittner, the host of CyberWire's Research Saturday, welcomes listeners to the weekly deep dive into the latest cybersecurity threats, vulnerabilities, and protective measures. This episode focuses on a newly discovered malware strain dubbed the "Noodle File Stealer," which is leveraging the burgeoning AI video generation trend as a vector for its distribution.
Timestamp: [01:56]
Michael Gorlick, Chief Technology Officer at Morphisec, introduces the primary subject of discussion—the Noodle File Stealer. He explains how the team initially identified the malware during an investigation involving one of their medium-sized clients. This led to uncovering a comprehensive chain of compromised AI frameworks, highlighting a sophisticated attack methodology.
Timestamp: [02:24]
Michael elaborates on the characteristics and functionalities of the Noodle File Stealer, describing it as a highly advanced threat that employs uncommon delivery techniques:
"The delivery technique is quite advanced and relatively rare, in which it was delivered through Python in memory with base 85 encoding, which is kind of very different from base 64." ([02:51])
Key Functions:
Timestamp: [03:40]
Michael delves into how the malware infiltrates systems, emphasizing the sophisticated social engineering strategies employed:
"They distribute the malware via fake AI video generation platforms, presenting malicious actors as legitimate services." ([06:42])
Delivery Process:
Michael explains the complexity of this method:
"It's quite an advanced archive with executables that are blown up to proportions of 150, 160, 170 megabytes with many advanced techniques." ([03:47])
Timestamp: [16:58]
Michael provides an in-depth technical breakdown of the Noodle File Stealer:
"They use a combination of base 64 and base 85, which is quite rare. We saw those techniques in some GitHubs correlated to Korean attacks." ([16:58])
Technical Highlights:
Timestamp: [14:28]
The conversation shifts to the difficulties faced by security professionals in identifying and mitigating threats like the Noodle File Stealer:
"The archive makes it quite challenging to detect by existing controls. You need more sophisticated controls and places like ours." ([14:39])
Challenges:
Recommendations:
Timestamp: [19:22]
In concluding remarks, Michael shares his perspective on the broader implications of these findings:
"This reminds me of the 2016 exploit kit times... It will take a year or two until security controls adapt to this new delivery risk." ([19:22])
Key Points:
Timestamp: [19:22]
Mike emphasizes the constant cat-and-mouse game between cybersecurity professionals and malicious actors:
"Hackers are innovate at a crazy pace, and with AI, they innovate even faster. We'll always have sophisticated malware." ([19:22])
Takeaways:
Michael Gorlick on Delivery Techniques:
"This delivery technique is quite advanced and relatively rare, in which it was delivered through Python in memory with base 85 encoding, which is kind of very different from base 64." ([02:51])
On Detection Challenges:
"The archive makes it quite challenging to detect by existing controls. You need more sophisticated controls and places like ours." ([14:39])
Michael on Future Security Needs:
"This reminds me of the 2016 exploit kit times... It will take a year or two until security controls adapt to this new delivery risk." ([19:22])
Conclusion
This episode of CyberWire Daily's Research Saturday provides a comprehensive analysis of the newly identified Noodle File Stealer malware. By exploiting the popularity of AI video generation platforms, the malware employs sophisticated delivery and obfuscation techniques to infiltrate targeted systems. The discussion underscores the necessity for advanced security measures and heightened user awareness to combat such evolving cyber threats. As AI technologies continue to advance, so too do the strategies of malicious actors, making continuous vigilance and adaptation paramount in the field of cybersecurity.