![News 2025-03-17 - Malicious Browser Plugins will Destroy us ALL!!!!! — Talkin' Bout [Infosec] News cover](https://assets.blubrry.com/coverart/orig/577207-646458.jpg)
Loading summary
John
Oh, what the heck?
Corey
What?
John
Oh, no, just, I just had Steam big, Big screen mode turn on and I didn't press anything and I can't see anything.
Corey
Get on your big screen mode.
John
Pants exit big picture mode. Okay, I'm good, I'm good. I'm here. I sent the link in the private chat, but it's called Islanders.
Corey
Very. Thank you.
John
Very good.
Corey
There we go. Awesome.
John
You can add or, or we can allude to a news article. You go out and play Pokemon Go.
Corey
I, I, I've tried playing that. I, I don't know. I missed the whole Pokemon thing quite a bit. Like, not even the card game. I've just barely missed Magic the Gathering. No.
Joff
Yeah, no, Yeah, I was in that, that same gap with like, Magic the Gathering to the Pokemon Go. Like, I, I miss the Pokemon stuff, but magic still brings me in. They're doing, they're doing Final Fantasy and magic meshed together and I'm like, well, there goes my wallet.
Corey
Yeah, I, I, I, I missed me back in 1977 generation where there were some people that got into magic at the beginning. And I remember hanging out and trying to play it and really wishing and trying really hard to like that game.
Joff
And no, I ran into people that still remember my technique. Like, a year ago, I ran into somebody that I played with in high school and they're like, I remember you. Like, you would come up with like these, these fun jank decks that would have some whole, you would, you would manipulate some broken thing to where you would just like, clone. You're that creatures with enchant and you would just do this. And nobody could figure out how to beat it because I wasn't playing the matter. And I'm like, I'm still like that. I don't play the matter. I play like some weird thing. And you're like, my, my deck didn't plan for this. Like, what is going on?
Corey
There's a future in computer security for you.
Ralph
Exactly.
Corey
Exactly.
Joff
I would like.
John
I've been in the same boat, John, though. I've been looking for a new hobby that'll at least get me out of the house. And this weekend, I'm going paintballing for the first time.
Corey
There you go. That'll be fun. May I recommend our Lord and savior? Mountain biking and rock climbing, though. Those are, those are two. Like, I don't know about you, Corey, but, like, biking season can't get here fast enough.
Mary
Like, I'm actually, I'm already there. John, come to the pnw, my friend.
Corey
Grinding or are you able?
Mary
Like, oh, I can. I rode. I rode Bellingham last weekend. It's in. So it was a little snowy at the top, but it was good. I also ride gravel and road, though. If it. If it's bike stuff, I'm into it. I just like forest bathing. I just go out there and I'm like, look at that fern. It's so pretty. And then I just. Happier.
John
I miss trees.
Corey
I like, my problem is, like, not that, like, once, you know, I can go out, I can rock climb. I can do all that stuff. That's fine. My problem is, like, I'm an empty nester pretty much now, so I just don't have kids to, like, yell at at the house or, like, walk around, and I'm. There's no kids to yell at. That mess is mine. That messes Erica.
Mary
Who left these dishes.
Ralph
Dang it.
Mary
It was me.
Corey
And Erica's, like, madly working and learning Monday.com or Jira and stuff. And I'm like, well. Well, I can't go downstairs and play rock and roll because that's gonna. That. That will definitely disturb her. And I can't. I can't watch movies. I can't handle them anymore. I don't know what happened. It just broke in my head. I'm like that old guy. It's like, all these movies are derivative crap. Yeah. Just like, just try. I tried to do the video game thing, and I'm still trying. I will, I will. I will try. But we'll see.
Mary
I remember when I first got hired, it said you were playing Mech Warrior for, like, at least two months, dude.
John
Yeah, Warrior was legit.
Corey
That's my. That's my. That's my. Like, that game comes out and that's. I can play that game because that was like, the first graphical video game that I had was MechWarrior1. And. And I started playing that. If you can look at the graphics on it. I don't know if Ryan can bring up a picture, but I can still sit down in that game and I can beat it probably within like 45 minutes, fairly quickly. And when you need a different game.
Mary
That'S way too fast.
Corey
Yeah, and I. And I. Yeah, it's way too fast. And the new ones I like, play it for a little while, and then I'm just done. I've just had it after a while, so.
John
John, have you heard of a game called Dark Souls?
Corey
There, that one. Scroll down.
John
No, don't play Dark Souls. That is the opposite of a good time.
Corey
There we go.
Joff
I remember Mac 2? The. The what? Ghost Bear playing?
Corey
Yeah. So that was the MechWarrior one. Graphics and. Yep. Played Mech Warrior two. I played all of the MechWarrior games all the way through, but that was the. That's. That's the straight crack for me.
Joff
Did you play five?
Corey
Yep. Yep.
Joff
Okay.
Corey
Yep. And the new one, Clans and Mercenaries, was awesome. Mercenaries. And it's not that great until you get into the mods and the mods just kick out.
Joff
Oh, yeah. Yep. That's how it's always been, how it always will be.
Corey
And I'm just Community. Nope. Done. So. All right, we got a group here. Are we ready to do this?
Mary
Yeah.
Corey
Yeah. Dark Souls. Ready for calming, relaxing games like, F you. What. What is wrong with these people? It's.
John
It's cyber security in a video game. You just get tortured over and over and over again until you get it.
Corey
Right once and you're like, okay, all right, let's. Let's bring out the. Let's bring out the crooked finger and let's get this thing going. Hello and welcome to Black Hills Infosec. Talking about news, and this week we have a whole bunch of awesome stories. We have polymorphic extensions. Not polyphia extensions. Polymorphic extensions. Hackers take credit for the X Cyber attack because of course they do. Lazarus Strikes, NPM again. Saudi Arabia buys Pokemon. Go. Can't get away from video games. I just. Let's get back into hacking. That's the way to go. Hackers use advanced MFA bypassing techniques, which are not for people that have been doing this for the while. We've been seeing this, like, again and again and again. And then China's Volt Typhoon. Not a trendy alternative rock band, but a group of hackers from China. They dwell in the United States electronic grid for an extended period of time, get bored, and apparently go away because those networks suck. Well, we are joined by an amazing cast of characters today, so I want to say thank you all for joining. I kind of want to do the polymorphic plugin thing, like browser plugins, a little bit later, unless we have people that have to skedaddle. Jeff, are you okay hanging around because I wanted you to. You and I have been talking about. Screw it, let's do it. Let's do it, Joff. Let's go right into it. And Jeff's microphone does not work. There's nothing coming from his microphone at all. So what I'm going to do is I'm going to pantomime jaw while he makes mouth Movements.
Mary
You see, John, browser I turned my.
Corey
Brain into years and these things are freaking amazing. And we'll be doing that.
Mary
John, thanks for approving my request for an RTX 5090.
Jeff
It's really, it's, it's really something when you're Restream. Restream, as I call it, decides Restream that your microphone is a Pro Tools virtual device.
Corey
How do you tell me, tell me you do like professional quality music, Jeff, without telling me that you do professional quality music. Damn.
Jeff
I think the captain out of the.
Corey
Bag it is, it is the keyboard in the back. So I'm going to set this up, but I want you guys to talk about it. But in all seriousness, we have been talking about how the browser is the new endpoint for a long, long, long time at anti siphon security training classes. Anytime we talk about it from bhis and I, I kind of started, I think publicly talking about this more and more and more where you look at plugins like Grammarly. Grammarly is a keylogger, right? And I tweeted this out a number of years ago and Grammarly actually responded and said no, no, no, we're totally not a keylogger. Anything that is marked secret. We don't actually log or do anything with him. Like that makes me feel better. It's not the passwords, it's literally just all the stuff the passwords are protecting. And when you look at the power of some of these plugins, it is ridiculous. And they can hook into a number of different tabs, they can basically grab all of your keystrokes, basically all of the security relevant things that you can think of. And that's. And Jaff headed up some programs at BHIS to create malicious browser plugins which he will talk about here in a little bit. But let's do that, Jeff. Let's talk about like the state of the plugins and the research that you did and Jack's done at BHIS for our continuous pen testing stuff and for, you know, standard pen testing over the years. Where have we been with that malicious browser plugin game? And then I want to segue into why the polymorphic plugin stuff is so cool. So go ahead.
Jeff
So look, obviously depends on the browser architecture. So, so we can just say right now that that Chromium is absolutely the dominant browser architecture, right? It's, it's behind Edge, it's behind Chrome, it is more than likely the architecture almost everybody uses. Right? So you know, having said that quite a while ago, I started digging really heavily into the architecture of the browser, trying to say, trying to work out, you know, how exactly are they putting this thing together and where are the barriers between the various components of the browser. And I ended up being very impressed. First of all, I do think that the Google crowd with the Chromium project have done a very, very good job in breaking the browser up into a process and multi threaded architecture that attempts to silo and protect different components of how the browser operates, which is awesome. There are some things that are awfully hard to solve though, and JavaScript is one of these really strange animals that I truly think people are trying to move away from, honestly. Right. There is a web code virtual engine that kind of runs and executes a lot of this JavaScript and a lot of the plugins that WebAssembly now fits into. And there's this considerable concern that we are adding, just like anything in our industry, we're adding additional functionality. And as we add additional functionality to any architecture, naturally, at least initially, we are going to expand the attck surface, right? And that's the kind of things we have to deal with. But you know, if you were to sit on your desktop right now and do a process listing of Chrome, you'll find something really interesting. Chrome, when it launches, launches multiple different types of processes and, and there are many of them, but in particular there's things called renderers versus network processes versus, I'm trying to remember the different categories now versus other processes. And so early on in the piece I started digging into the browser and saying, well, can I get in between the renderer process and the process that does all the network traffic? Because if I can get in between that in terms of inter process communication, then I get to listen to everything, regardless of whether it's TLS or not. There used to be old ways of doing that that have gone by the wayside. One of the old ways that was in existence was to hook specific functions in open TLS, right? Because sorry, OpenSSL, same thing, OpenSSL under the hood, right? Had very good, well documented functions. And if you hook into the encrypt decrypt side of it, right. You can obviously try to intercept traffic. So, okay, that's a little bit of a background. The renderer process is going to have some vulnerability to plugins. Where we get interesting problems that are difficult to solve is plugins are a spoken architecture thing right now they are siloed from these other processes. But you, when you're in a plugin scenario, you can affect the renderer process because what it renders is, you know, what it's being told to render.
Corey
Right.
Jeff
Ultimately, anyway, I'll stop there.
Joff
Let's.
Jeff
What else are we going to talk about?
Corey
I want to talk about, I want to set up the stage because I think it goes into like continuous pen testing and Corey and Ralph and open it up to other people. But I want to walk through the actual article now, kind of taking what Jaff was talking about. And if you spend some time looking at, like I mentioned Grammarly, you got one password that gets access to all of your different tabs, right? Salesforce was one that they actually utilized for demonstration purposes. Once again, whenever they talk about this article, it wasn't a vulnerability in something like Salesforce or there's plugins that'll show you different coupons. Like you go to a website that's selling you stuff, it'll be like, well, here's coupons available. So you have these plugins that are legitimate, quote unquote plugins that are harvesting information about what tabs and what you're doing on those websites. And just like Jeff was talking about, you're kind of hitting this intersection between making the Internet more functional and usable for people. And then you get into security issues. Now what Square X came up and Square X Labs is it isn't just an issue of creating a malicious plugin. All right. And Jav, correct me if I'm wrong, one of the more difficult things you run into if you're trying to create a malicious plugin is getting it published in a store. And that in and of itself may be is not that difficult, even though they do have security checks. Go ahead. Yeah.
Ralph
Oh no, I was just going to say I posted another article internally about just those two things. So first is about how the Chrome Web Store is a mess, right. And this article that was in there, he goes in deep detail about how much of a mess the Chrome Web Store is and this ties into making malicious extensions. But essentially he goes through and finding out that making a featured plugin is super easy, right? And it's not that hard. You would think that a feature would mean someone reviewed it, but that's not the case. Reporting it is like a very like non effective mechanism for these. And then I'll add to one other thing you just mentioned, which was the plugins to give you discount coupon codes. What was the honey was found that they were actually making up coupon codes. There's a whole other thing about this. So that's like, you know, on top of them being able to see what sites you are. And then making coupon codes and then not making them so they make more money. It's a whole other thing. But anyways, yes, it's bad, it's bad, it's bad all the way across like from the Chrome web store to the kind of applications that are being made as plugins to people abusing. The whole process is, it's, it's out there, right?
Corey
So yeah, and I want to circle back to that because I think that gets into whenever you have Google, you have Microsoft, you have Apple becoming the actual gateway guardians for applications and your plugins and absolutely everything. You know, they'll always say things like, well, you need someone to validate and make sure it's secure. But their number one goal is not security. Their goal is to try to get as much in the store because the more that you have these plugins, the more people buy stuff, the more they make a percentage of that revenue. So whenever we're looking at the stuff that came from Square X, an attacker can take and publish this polymorphic extension in Chrome. And it took us a while we were able to find it. I think Jack found it last week and he was able to pull it down and look at the code and it was pretty cool, but through a social engineering tactics. And this is one of those areas and one of the reasons why a lot of pen testing firms aren't doing this is once it's published in the store, it means anybody can download it, right? So you run into this idea of scope creep, not in a good way or even a marginally, kind of, maybe slightly bad way, but horrific way, where you might actually end up exploiting completely innocent bystanders. And there's ways around trying to deal with that. But that becomes a real problem once it's just in the store. But you use social engineering to trick a victim to install this malicious plugin. During the process, it'll go through and say, hey, you need to pin it. Then it'll take a look at what other plugins exist and it'll impersonate and kind of overlay that plugin. And one of the coolest things about this is it can actually disable that plugin and work as kind of an abstraction layer for that plugin and backdoor its functions. A kind of horrible example of this that I, you know, because I'm old and I'm always trying to relate things to what I've done in the past is looking at stuxnet. Stuxnet was an old school virus that basically took over Siemens PLC Dynamic Link libraries and wrapped. I think that There was originally 11 functions in the dynamic link library that it wrapped, but it basically renamed the original one. And then it had a handful of malicious functions, but it would forward all of the legit functions to the legitimate dynamic link library. So now we're seeing that same type of approach, but now it's being used to impersonate target extensions. So this is literally impersonating an extension that somebody is running on their computer system. They probably installed it for legitimate reasons. Like we said, 1Password or Salesforce or any of those different ones that are, that you can see UBlock origin and what is it, Ghostry or AdBlock plus or any of those different things. And it can wrap that. And with the, with the Salesforce or the 1Password extension mentioned, they were able to intercept the authentication for that plugin. And then I think they had a quote in here. They have the keys to the kingdom at that particular point. And if you get to the bottom, Ryan, if you can scroll all the way down, all the way down, where it talks about how do we protect against this? They really kind of get to what Ralph was talking about. Like on the Chrome Store, we're kind of screwed. The Chrome Store is very much the Wild west. There is not a lot of protections. Yeah, it seemed like a good IDE idea if we buy all of our stuff, but really it doesn't look like Google is doing as much security checking as they should for users and enterprises. They're like, be careful what you install, which is always horrible advice. Right. And then on the Enterprise side you can actually query through Active Directory and Azure type things what plugins are installed, but only on browsers that are controlled by your organization. It's kind of rough. And of course squarex much credit to them. They basically, basically were like, you can do all of this or you can just buy our product, which specializes in defending against this type of type of attack, which I thought was kind of fun.
Ralph
I heard you have a problem, we have product.
Corey
Yeah, if you have a problem, we have a product. If you have an ambulance, we'll chase it.
Jeff
One of the interesting things I found with the Chromium project was, and a lot of people probably aware of this and if you're not, you're about to be. There is this enormous list of command line flags that you can add to Chromium based browser. It doesn't matter if it's Edge or Chrome, whatever, to change its behavior from a security protection perspective. And so one of the strategies that I had gone down And I've seen done before as well, is try to write something that can crash the browser. If you crash the browser, just restart it immediately, pretend to the user like, hey, everything's cool, but at the same time weaken the protections when you restart it. And, you know, some strategies like that. So I could see there's going to be some, you know, sort of further attempts to go even more polymorphic, if you like, where we have sort of combo attempts to, to perhaps have something that crashes the browser, restarts it, maybe drops a little side load of a DLL on the restart and weakens the protections enough that it'll actually load that dll, which per my earlier comment, you know, hats off, by the way to the Google Chrome team on this one. When they actually have the architecture, the different processes running the Chromium project, they tightened down in particular on Microsoft Windows, the process protection flags really, really well. I mean, they really did a good job on that.
Corey
But I remember correctly, when you were working on this for bhis, it was difficult to break out of what the browser was doing. When we're on the browser, we're doing really, really, really good.
Jeff
Right, exactly.
Corey
And I can't remember what the hell did we name our malicious browser plugin?
Jeff
I don't remember it right now, but my head.
Corey
But, but when we're looking at that, it's really locked down. But if you stay within the context of the browser, like being able to pull session identifiers, being able to pull credentials, being able to do keystroke logging, all of that was relatively. I mean, there were still definitely protections in place, but it was easier to get around those protections than trying to break out of the browser itself and do stuff to the operating system.
Jeff
Yeah, that's right. If you stay within that tab context, basically you can do things. And that's just the, the fact that Google wants people to write these fancy plugins and stuff. Right. And they also bolted the webassembly engine on top of that, and so they expanded the capability as well. You know, that's where things started to get really, really interesting. Our attention turned away a little bit, but maybe it's time to turn our attention back.
Corey
Maybe it is.
Jeff
Maybe.
Mary
I feel like we varied the lead a little bit on this. To be clear, what someone did is they made a browser extension that was in the Google Chrome Web store, and that browser extension is polymorphic, which doesn't actually mean anything. What it means is it can impersonate other applications, other extensions. So as far as detecting that it's not really malware, it's just another password manager. From the perspective of like the Google AI app scanner thing.
Jeff
It's a feature, right?
Mary
Yeah, yeah, it's a feature. It can. It's a password manager. It's also.
Corey
It is a separate plugin though, too, Corey. I think that that's a really important thing from a detection perspective. It's not inserting itself as a Trojan into the existing plugin. Correct.
Mary
It does nothing on the endpoint. It doesn't do anything with DLLs, it doesn't do anything with webassembly. It's a legitimate extension that just impersonates other extensions. So it's basically a watering hole attack.
Corey
Yeah, exactly.
Jeff
Yeah.
Corey
Yep. Yeah. So I think showing how difficult and I think it's continuing to show, once again, that the browser is really where malware development is moving. And, you know, I just see this as a great. Because everything's in the cloud. I can't remember, I think Bron, when you said something, it's like, sure, it's not the operating system. It's just literally everything that the business does is in the browser.
Jeff
Right?
Corey
That's right.
Mary
Yeah, exactly. I mean, it's like, why go after the endpoint? The endpoint can be valuable. Sure. But if the user is like 90% of users, they probably just do email in the browser, do their team stuff in the browser, access sensitive web apps in the browser, do whatever their business function is in the browser, other than those things.
Jeff
One of my initial focuses, though, was go after the endpoint. Make the endpoint attack its own browser. Right?
Corey
Yeah, that was the reboot trick that you did.
Mary
Sure. But you can also just say, this is a great password manager that's free and just get 30,000 people to install it.
Jeff
Yeah. And frankly, that that's the easier path.
Mary
Right.
Corey
But also, taking this another level, Corey, like, if we're talking about like social engineering, the idea of like, you know, a watering hole attack is kind of maybe a dynamic watering hole attack. Somebody's trying to go to, let's say, Dropbox, or they're trying to go to box.com or they're trying to go to Doc Hub or DocuSign or any of those things, dynamically generating those plugins to match that specific website. You know, I think there's a lot more that can be done with this. And it's sad. You know, this is one of those in like malicious computer security research where it's like, well, then why are attackers not doing that? Because literally all the other they're doing still works just fine. They haven't, they haven't had to progress to this yet. It's just more greenfield space for them to get into. And, and I, I don't know, I think that's.
Mary
I, I mean, I think it's a, it's like a great angle for exploitation. It's like an easy initial access vector that doesn't require you to detonate a payload or do something that CrowdStrike's going to be super excited about. It just requires you to convince a user to install a browser plugin, which isn't like, I think most people. Also, how much security training is covering malicious browser plugins?
John
How many organizations are you seeing that don't have managed browsers?
Mary
All the past.
John
Okay, so I've worked at great places.
Corey
Wait, I want to clarify. You'll see them using Edge for Microsoft, but they're still running like standard Chrome. They're running Firefox.
Mary
Well, they don't lock down the browser.
Ralph
Is there a product that does that though?
Corey
A lot of your EDRs are not looking in your browser at all. They look at the browser as one monolithic process that they stay the f away from. Yeah, they just don't go there.
Mary
Yeah.
John
The thing is that you could track the file. You can track Chrome add ons being installed via files. Right.
Corey
Malicious.
Joff
I've seen that. But the problem is like the, again, what we've called out before, like the special snowflakes that they go, okay, you don't allow me to install things in Chrome because you have an allow listed list of browsers. I'm going to use Firefox. And because I am such a special snowflake in your organization, you are not going to come down on me for using Firefox because I am like this special whatever in your environment and you cannot tell me what to do on my machine are getting compromised and getting targeted.
Corey
And Alex, how many times do we see. You know this app works best with Firefox. Oh yeah, yeah.
Mary
Literally never. It's always Chrome.
Corey
It's always Chrome.
Ralph
I literally never told you.
Mary
No one says this works best for Firefox.
Corey
I want to get Mary and Shecky in.
Jeff
It's a rehash. The local administrator argument is what, what Alex just said.
Corey
We're right back.
Joff
Yeah, yeah, yep.
Corey
Go ahead, Mary. Shecky, your thoughts on this too because of spread the love a little bit.
Joff
Go ahead, Mary.
Erica
Yeah, I actually, I use Mary Ellen. You know, I think in a large, really, really large organization with like 60 to 80,000 endpoints. I mean, it's these, these. It's inevitable that you're going to have, they're just going to creep in and I haven't found a process like automated. You know, I, you know, back in the day, you know, a couple of years ago when I was at a large company, I would run queries maybe weekly. It's, it's a real issue. This is a really.
Corey
So when you were doing those queries could. A little bit of context on that. What was the parameters, if there was even policy process, procedure around it? And then were there any situations where you found things and you're like, no, no, no, absolutely not. With, with the, like the browser plugin stuff.
Erica
Yeah, I mean we would, our, the policy was pretty much we would recommend that every, every, you know, even like, you know, people using, you know, the coupon, you know, extensions and things like that. There were a lot of those and you know, you hated to be that person. But it's just, you know, they're, they're also, the traffic is not just going there, it's, it's going to a lot of places and you just, and it just creates a lot of noise and a lot of extra traffic as well that you don't need on the network.
Corey
So, you know, it's one of those things we always talked about disable ads if you can like block them at the network level. But that's, that's neat, but it's not really realistic because a lot of times if you do that, it actually shuts down legitimate sites from functioning properly at all because they get mad that their ads aren't rendering.
Jeff
So.
Bronwyn
Yeah, well, and even ad blockers, they will, they will break legitimate websites because so many websites are doing so much more in the client with JavaScript and various libraries instead of having it on the server. And I understand that from a load balancing perspective, but you're damned if you do, you're damned if you don't.
Ralph
Yeah, whenever I enable ad blocking in my house, my wife just gets upset because the targeted ads don't work anymore.
Mary
First Google link doesn't work, Instagram doesn't work. I'm out. That's all I want to use. She's like, I have to turn off.
Ralph
The WI fi or I can't click the ads.
Jeff
I'm like, that's, I'm old school on this. I still have a manual list of domains that I'm fetching and I'm blocking it in my own DNS infrastructure. And I'm also blocking DNS over HTTPs because on principle that's Is that considered.
Mary
Is that a job hole? What is that.
Corey
20 bucks in the switch?
Jeff
Okay. Because that's, that's an absolute protocol abomination. Don't get me started. Where's Paul Vixie when I need it? And you know, all of that said, when my family comes and complains, I tell them to stop complaining. I'm. I, I've got a hard border on that one.
Mary
Your family is now using purely cellular data at your house. Exactly.
Jeff
What's going on, Bron?
Corey
When you add something, I saw your hand go up like you were going to say something.
Bronwyn
One of the things that no one has touched on yet is when plugins go stale and they're no longer being maintained and then they get taken over. So now you've got, in addition to all of the other stuff, now you have a legitimate plugin that has been taken over by a malicious actor. And isn't that a whole lot of fun?
Corey
And I think we should use that as an opportunity to transition into Lazarus. Attacking NPM packages again. I just. Absolutely. So North Korea, once again, props to them getting out.
Mary
Would you say they brought this technique back from the dead?
Corey
They brought this technique back from the dead.
Ralph
It never died.
Corey
I, I love this. You know, what is it? Socket security? Giving some credit. Great research. They uncovered beaver tail malware. Love the names. I love the names.
Mary
That's just a Canadian delicacy. That's just a treat.
Corey
I just think it's like the BUC EE's of InfoSec. You know, it's like beavertail, seemingly benignly named packages. Which always cracks me up when people are like, is buffer validator, event handle, package array empty validator. Like my God, those names are not malicious. What did they expect? Do they expect who's downloading package? Like, you know, it's. Maybe that would be more effective.
Mary
If you think NPM developers know what they're downloading. You are whoever tried to install one.
Ralph
Package on npm or p npm or npx or the other 500 other package managers.
Corey
Why do we need so many of them?
Ralph
Listen, you click, you type in one thing that you would like to install and then all the dependencies come along and it is like a train, just.
Joff
A train dependencies for like, you know, loading up the like is number even, is number odd. Like why are you downloading a package that tells you if a number is even or if an array is. It's empty.
Mary
There was that time like years ago where the package for like left aligned text. It was like a three line package. A three line of code package got removed and it broke like 30,000 programs because everyone was using it.
Corey
And I think that they do that because coding is hard, apparently.
Mary
I mean, reinventing the wheel is bad, but this is taking it to the extreme.
Corey
Come on, it's not Fortran or Effing Assembly.
Ralph
We just talked about this, right? We said the browser is the new operating system, right? This is the window to everything.
Mary
So.
Ralph
But that interface is built on JavaScript and that comes from Node Package Manager, the whole thing. All the websites that you go visit, they're all in JavaScript, they're all using some kind of node framework, whether that's a server side or just client side. It could just be a client side application. Doesn't have to be all of. Of Node as we think of it normally. Right. Well, every modern application is used and.
Corey
RALPH to kind of, kind of roll with it a little bit more. Obfuscation is incredibly normal in the JavaScript space. Right?
Mary
That's called.
Ralph
Yes, absolutely. Yeah.
Corey
And they use it all the time to protect intellectual property. They use it for a variety of different reasons. Like, so you can't just be like, well, this is obfuscated JavaScript, therefore it's evil. Because I would argue that most JavaScript is obfuscated. Right, Bronwyn?
Bronwyn
Well, it's also bandwidth. You got to remember ISPs charge by bandwidth. If all of a sudden you get a spike in traffic by minifying any type of file, whether it's JavaScript, HTML or CSS, I can cut my cost as a developer significantly due to the bandwidth demands on a website. So it's not. Yes, obfuscation is often a reason for minifying, but the developers, they may or may not care about obfuscation so much as their bosses care about the cost every time a website gets hit.
Mary
Yeah, well, don't worry. This attack will have no impact because as we know, every software that's developed has a secure software bill of materials that is validated.
Corey
Every. Yeah, and let's also remember, Corey, that's.
Mary
Why.
Corey
No one should ever use open source software, because it's not as secure as commercial software which never uses.
Ralph
I've never seen. Well, I think there is commercial NPM packages, but almost all of them are open source.
Corey
I'm just gonna throw that out there. I was being sarcastic.
Mary
I know. I know you are.
Corey
I'm just letting the Internet know because there's people that are listening to this and they'll flame me on email. They'll be like, your software is actually more secure And I can't believe sarcasm folks.
Bronwyn
They obviously don't know that sarcasm is one of the many services.
Corey
It is one of the services. It's one of. It's the hacker. It's the we can hacker. Sarcasm is just one of the services we offer at bhis.
Jeff
You're not supposed to inhale, Corey. Don't inhale. On the day of the green.
Mary
I listen in my state, I can inhale all I want it.
Corey
Yeah, I. Okay, so I want to get to some more stories, get a little bit diversity. One of them. I don't want to talk about Twitter right now. God. I don't want to talk about.
Mary
We can talk about Typhoon. Let's talk about the Typhoon.
Corey
Yes, go ahead, Corey, take it away.
Mary
So basically this is a kind of. It's a. Again, like most cyber security blogs, it's a thinly veiled ad because that's the world we live in. Everything's an ad. Sorry. But basically it's a cool little case study of why people like some power grid in Massachusetts should have. Network monitoring is essentially the use case. It's specifically by the firm Dragos, who we've worked with on our OT Backdoors and breaches deck. Big fans of them. They do really good work and have an awesome product. But basically the story goes, there's a power grid, it's a relatively small power grid called Littleton Electric light and water departments. Lil Lulled. That's how you pronounce that.
Corey
It's loose.
Mary
Basically they were in the process of implement implementing network monitoring with Dragos. And during the process they were like, hey, this is malicious. So they accelerated the project, I guess, which is pretty funny to imagine. Like, oh yeah, we definitely need this. We're already compromised. And essentially they did a full deep dive. The two techniques that are called out in the article are SMB traversal, which I was like, are we talking Internet bound SMB traversal? Like, how bad is this? Is this like, did they just link an SMB beacon to the public Internet? I don't know. I'm imagining it was probably that bad. And also RDP lateral movement. So basically like how I imagine this is some person's computer got compromised, they had direct access to IoT and so they are pivoting into the OT environment. Interestingly, I think the, the, the threat actor is this Volt Typhoon, which is a Chinese affiliated threat actor and they were just gathering data. So this is the P&APT, right? This is the persistence part. They were just kind of hanging out watching, see what was Going on. I don't know what their plan was, but it's always spooky.
Corey
Just hang.
Mary
300 days is a long time.
Jeff
Well, I, I thought you were about to say that the, the grid operator doxed themselves in the process.
Mary
No, I mean, this is a public, like, you know, this is something they published intentionally as like a little use case kind of thing. I mean, honestly, kudos to the utility. Kudos to them for following on the sword and saying, we messed this up, or, you know, we had this incursion. Here's what we learned, here's what you should do about it. Like, it does go a long way because these small utilities, they don't always feel like they're represented in the cybersecurity community. Right? Like, these are small entities with small budgets. They don't always feel like participants in the cybersecurity community. So it's cool to have something like this be public, but, yeah, scary.
Corey
So a couple of additional things that I think are really interesting, like the entire SCADA ICS ot like, industry, anytime anyone gets a breach, like, they freak out. They're probably one of the more reactionary groups in the infosec space, and that's fine. Right? Because people can die. So, you know, just. I understand that reactionary thing. I'm not ripping on it at all.
Mary
And they have pretty heavy regulatory requirements.
Corey
They do, they do. And. And so their risk tolerance is really, really, really low. So this particular breach, you will see presentations talking about this breach, the impact of this breach for a year, two years, maybe three after this thing breaks down. Because this is stuff that resonates with that specific group in a way that hardly any of the other groups resonate with attacks because they happen all the time. That's number one. Number two, the other problem I have with that. And that's okay, I understand that's okay, Is they tend to be very hyper focused on what ex happened here. We need to stop that from happening in our place. And they only focus on that technique that was discovered. And I've talked with Rob at Dragos, and I've talked to a number of people in this space over the years, and that is one of the problems that they run into is whenever you're trying to sell a comprehensive security architecture, something like Dragos, a lot of times the customers are like, well, I just need to stop what these people did over here, whether it's Florida or this particular breed. And we don't need all of that other stuff because you're just trying to sell us more than what we actually need, because their budgets are definitely problematic in those spaces as well. So if you're in. If you're in this space, don't fall into that trap of, we just need to fix this. Because the attackers will take advantage of anything they can to gain access to your environment. That's why a comprehensive security strategy is so important. Someone was saying something. Sorry.
Mary
Oh, I was. So I was going to a couple things. Number one, the argument here is really for visibility. It's not necessarily can you be attacked? It's are you already compromised? Right. Which seems like a good first step. If you're a power grid, wouldn't the first step be are we already compromised by Volt Typhoon and can we do anything about it? If we are. Right. That's like an important call out. The other thing I wanted to call out is this particular one was funded partially through the. A government grant to help acquire these types of security products called Appa Appa, which I don't really know what that is, but they do call that out. On the second page of the study, they say this. Their ability to purchase this product was a government grant, which I fully support personally. Like these smaller districts, they either have to raise prices or they have to get a federal grant. They're not going to go out and buy. I mean, it's not Dragos's fault. These products are expensive because they're really advanced in combination, complex to make and develop and deploy. So, you know, it's just kind of a cool, unique thing.
Corey
And since we're talking advertisements, I'm just going to throw this out. Corey. Like, we just so happen to have a product called AC Hunter that is dedicated to doing network level beacon detection. Check it out. You can run the Community Edition.
Mary
We also have an open source version.
Corey
We do, yeah. Community Edition costs you nothing. Like, you can just set up Rita and AC Hunter, feed it a PCAP file and see if you have beaconing in your environment. So. So you might want to. Might want to track that. Somebody said Appa, not abba. No dancing, not abba.
Jeff
Yeah, we're not going to Stockholm. We're not going to go to the ABBA Museum.
Corey
I'm going to try my best not to sing. I'm not going to sing that. We're not. We're not going to do abba.
Jeff
I. Fernando came to mind immediately. Anyway, you know, it makes me think though, that there's an opportunity in this too. And. And maybe I'm. This is probably a bit of a stretch, but I wonder if there's enough of the smaller utility companies that are of a cookie cutter nature that I reference security architecture could be developed and shopped around to them. I'm sure there's other people that afford that.
Corey
The problem with those security architecture docs in this space. And once again, this is from me talking to Rob, Leslie, Justin Searle, Ed and Guardians talking to people about this is the idea of a reference architecture, as good of an idea as that sound, doesn't fly because the architectures are very diverse and they tend to look at themselves as a whole bunch of precious snowflakes, which they kind of are.
Jeff
Yeah.
Corey
And it's.
Mary
Well, it's just inertia with what equipment they already have.
Corey
It is. It is.
Mary
It's like the badge readers thing. Oh, you have hid. Okay, what are you going to do? Buy a new building? Like, it's exactly. Okay. We can't Deploy. We have 72,000 substation switches or whatever. If we were to purchase and replace every single one, it would cost, you know, $2 million or whatever.
Corey
Like, and to be fair, right. There's a lot of vendors in the space that are like, you know, why don't you just spend millions and millions and millions of dollars with us? Right. That comes up all the time. And I think that that's part of the reason. God, this is turning into a freaking commercial for Dragos. You're welcome. Rob, I was about to say if you.
Mary
We'll take our payment on the back end.
Corey
That is one of the reasons why Dragos works really well is yes, they do cost money. Absolutely. But they actually were designed from the ground up to try to hook into kind of the existing logging architectures so that they can ingest those logs to do that detection analysis without a huge kind of like change of the entire infrastructure.
Mary
Yeah, get visibility. That's the key. Get visibility. Decide what. What's what to do once you have visibility. Without that, you wouldn't even know you were compromised, which is way scarier than actually being compromised.
Corey
It is, Absolutely.
Mary
So who plays Pokemon?
Corey
Let's do Pokemon. Let's do that. So this, this one's easy. Saudi Arabia by Pokemon Go. And a lot of your location.
Mary
That's the whole article wrong.
Jeff
What does that mean?
Mary
Savvy games.
John
All right.
Mary
Which is totally not what.
John
What people don't realize in Pokemon.
Jeff
Go it for the game. Right, Right.
Corey
They actually give you mbs is like, I gotta win, damn it. I could just totally kill someone right now. They're like, yes, sir, we're buying the game right now. So no One laughed at that.
Mary
Or tell us about.
Corey
Okay. God.
John
So the thing that they're buying is in Pokemon Go they actually have you scan things, right. And you get rewarded for scanning stuff. And they're building a 3D environment with these scannings. And that's the interesting part that actually Niantech, who owns Poke, who owned Pokemon Go beforehand, is still grasping onto that. Anything that's scanned is still going to go to Niantics now. New spatial 3D augmented geographical company that who knows what they're going to do with.
Ralph
Now there's a lot of buzzwords.
John
Yeah, well, that's literally like what I. I have all this. Huh.
Mary
How do I. Is it. Is this camera only or is it actually using like the iPhone Lidar so it.
Corey
I.
John
Who knows what it's using in the back? I don't have. I use an Android, but it actually has you go up, you have to circle around the object and it tells you how long and then it uploads it. And it actually takes a while to do all this. I actually don't do this.
Mary
Is it like do your house key? What is the first option?
John
No, it's. So it does.
Corey
Wait, it's better than that, right? There's research in 6G in this space. I was talking with one of my friends in Finland last week and like 6G, the way 6G is going to work is it's ultra high frequency, ultra high bandwidth, but you won't be able to go to like traditional cell phone towers at distance. So people will be setting up these little 6G routers which are really, really, really super small. Trust me, there's a point to all of this where you can set up these little tiny routers so you can offload. So you aren't going to massive of centralized towers, but multiple little 6G routers. So when you start buying routers for your home, they're going to have 6G enabled so your new 6G phones can connect to it. All right, so why is 6G scary as hell? And why is this technology like crazy cool? 6G can scan the room like the equivalent of Batman, if you remember the first Batman movie with Christopher Nolan's where you can scan the room and it can actually tell you where things are, the position of things, identify things, who's an adult in the room, who's a child. It can take temperatures. It is flipping crazy. Banjo Crashland said it sounds like a story from the future is. Yes, it is. Something from the future is. So whenever you're talking about this ability to scan and model. And from a three dimensional perspective, it's no longer an issue of using like the lidar. It's no longer an issue of like using the camera itself. But they're going to be able to get that type of telemetry building layouts where people are positioning even with your phone in your pocket, man.
Jeff
Yep.
Corey
All right.
Jeff
I don't have funds to build my own skiff right now, but I'm thinking that's a really good idea.
Ralph
The other thing they're saying with 6G is it's going to be a mesh network as opposed to the HubSpot architecture.
Corey
That's what I mean by lots and lots of little tiny routers that all correlate and connect and drop.
Ralph
The benefit obviously of the mesh is that there's no one route out. So it just finds the best route.
Jeff
And so.
Mary
So for cellular 6G, we've just replaced it with WI Fi. That's what I'm doing. But it's like it's different than the.
Jeff
Other mesh WI fi.
Mary
We replaced cellular service with WI Fi.
Corey
Yes. So most phones that are. That whenever we start moving to 6G are going to have the 5G chip and the 6G chip. So it'll basically. It's just like you have multiple radios in your phone right now.
Mary
If I have to be close to it, it. I'm just going to go on WI fi.
Corey
Yeah, I know, I know.
Ralph
How many bands are your phone's going to support at that point? I mean, we're already 2.5.
Mary
I mean, I already have you two on my phone. How many more bands?
Ralph
There's like 17. There's like 17 bands of 5G. Like, and by the way, it's all the different frequencies.
Mary
I don't.
Ralph
Is there cancer? It's just. Is that what's going to.
Corey
I don't know.
Mary
Listen, John, you know how many conspiracy theories you just spawned on this podcast? You got to dial hope.
Corey
I hope everybody is diving to the 6G standard right now. People behind it are like, what the hell just happened?
Mary
Finally been viewed.
Ralph
You brought back 6G.
Jeff
4 minute.
Corey
That's a sweet spot. Not 3.5. 4 minute abs.
Mary
So, okay, there's a funny one. There's a funny breach. So it's in the big Wells breaching section. It's a Daily Mail article. I know. Daily Mail is basically the National Enquirer. So this is a trash article. Article. But it's a funny story. So bank of America published a data breach notification. The best part about this is it's not A, It's a physical data breach. So what did they do? Their data destruction vendor left documents sitting outside. That's the breach.
Corey
Awesome.
Ralph
In a trash can outside or like, I think, yes.
Mary
It was literally just in a trash can outside. Outside. So again, I'm not, it's not actually that big of a breach. It's just kind of funny that it's not a data breach. That's a freaking SQL injection.
Bronwyn
At least two customers, two were impact.
Joff
I know, I know.
Mary
That's the other best part is it affects two customers.
Ralph
They drove to their house to apologize, though.
Mary
How did this count? I know. It's so funny because it's so silly that they had to publish a data breach notification because someone left a box of documents outside with 400 people's info in it. It's just sill and it's stupid. And I just thought it was a funny.
Jeff
Probably Iron Mountain dumpster diving for the win. That's what I say.
Ralph
I think someone just was like, hey, are these supposed to be out here? And they were like, oh, look, pii.
Mary
Yeah. All of you physical security people, Ralph, I see you this point to this news article. This is your, this is your new North Star for the next five years. You use this article as justification for why you need a physical pen to test.
Corey
Right.
Mary
Look at this.
Ralph
They leaving documents outside unsecure.
Mary
Yep. That's a finding. That's a pen test finding.
Corey
It is. It is.
Mary
So, yeah, I just thought that was funny.
Joff
Yes.
Corey
Oh, wow.
Mary
There's no chicken wing article, but it'll be.
Ralph
Oh, chicken wing.
Corey
Do we want to talk about X and the DOS attack?
Mary
Yeah, I mean, it's, it's a nothing burger. This is an article. Yeah, yeah. People claimed, People claim the ex. Attack. Attack. Cool. Moving on.
Joff
Cool.
Corey
I, I, I think. You know what? So if anybody is trying to track this story. There was a DDoS attack against X. Some of the traffic came from Ukraine, a small percentage of it. And there was like, oh, it was a launch. An attack from Ukraine. No, it's just, just some packets came from there. So I, I honestly, I don't, I don't care. I don't think anybody would have cared if it wouldn't. It wasn't amplified and it was political.
Mary
So I like how the, the details that provided by Elon Musk just define what a DDoS is. It just says, here's what we know. This was a large attack. Either a large coordinated group or a country is involved.
Corey
Thank you.
Mary
Thank you for that. That makes per. Yes. You just defined DDoS. Congratulations.
Corey
You did well. Congratulations.
Bronwyn
And of course, Packet origins can't be spoofed ever, can they?
Corey
No, well, no, no, they can't actually.
Jeff
No, they can't.
Mary
The OSI model will save us all.
Corey
That's some of that trademark Black Hills Information Security sarcasm. Yeah, way to go.
Jeff
Look, I actually do take exception to this. If ISPs actually implemented reverse path forward checks on all of their interfaces on their BGP routes, packet spoofing with it stopped.
Ralph
Well, how would that make them more money?
Mary
Wouldn't matter, because there's another factor at play here, which is one company or country can compromise computers in another country.
Corey
Yeah, then you're using real computers. And we saw that. I can't remember, it was a couple of weeks ago. We saw routers like the Mirai 2 botnet, where it's just compromise a bunch of things and go, yeah, botnets are.
Mary
Alive and well and DDoS is big business.
Ralph
Yeah, exactly. I mean, most of the big botnets are compromised devices anyways. They're not just like going around with a credit card like, hey, get as many computers as we can.
Mary
Your Synology nas is sending 10 trillion packets a second. It's not because you're backing up your data to the cloud. It's because you left that management interface.
Corey
I'll just go ahead downloading all the.
Ralph
Stuff I like to download.
Jeff
I'll just go ahead and contradict myself.
Corey
I think it gets into a larger question of attribution, right? And I keep telling people, go read the vault documents from the CIA breach and there's a document in there about like creating attributional artifacts to attribute it to somebody else. And it's like Bronwyn's said, whether or not they're spoofing the packets, whether or not they're compromising systems in those locations and launching that attack. Attribution is really hard. So just always take it with a grain of salt anytime you're reading anything about attribution.
Jeff
But John, they make it look so easy in the movies.
Ralph
Have you seen Swordfish?
Corey
I mean, they were what they really.
Mary
Should do for this. And like, if you read this article deeply, it's basically what they're doing is just spinning the magic magical wheel of attribution. And what do you know, it's Russia.
Corey
Or not Russia, because we can't say it's Russia anymore, folks. It's got to be. All right, I want to get into the multi factor bypass article.
Mary
This is also kind of a nothing burger.
Corey
It is. I think it's Important. I, I would. I was really happy that Ralph was here and Corey, you guys are almost always here. But I think a lot of people, like I've been traveling for the past month a lot, and there's a lot of people that are under the assumption that if they're running mfa, they're completely secure against any type of spear phishing attack. Can you guys kind of walk through whenever we're doing continuous pen testing, coming up with techniques that we use in the standard pen testing practice. What are some techniques that we use to kind of walk and get around MFA in organizations and Stop. All of you that are texting in the chat, chat about the OSI model. You're gonna trigger me.
Mary
Stop.
Corey
All right.
Mary
What he meant was keep going loudly.
Bronwyn
So you realize you just challenge accepted, right?
Mary
I know, I know this article. Yeah. So the article is pretty cool for any I rec. I still recommend reading the article. I know I said it was nothing burger, but the reason why is because the article is basically just a collection of all the cool fishing techniques that exist in the world right now. The there's adversary in the middle. There's browser in the middle. There's browser in the browser. There's probably browser in the browser. In the browser, you know, just keeps going.
Ralph
That's three layers deep, man.
Mary
But basically what John's talking about is if you're mfa, you're secure. That's only true if you're only authenticating with passwords. Now, turns out that browsers and other tools like to authenticate with more than just passwords, because if you don't have anything but a password, you have to type your password for every request, which doesn't sound like a good idea. So there's these things called session tokens. Session tokens function as authentication information and they can be stolen. And session tokens are issued after MFA is completed. So most of these attacks browser in the middle, adversary in the middle, browser in the browser, all of them rely on essentially granting authentication tokens to a untrusted third party party. The only kind of MFA that's resistant to this is what they specifically call phishing resistant mfa, which is basically universal second factor, AKA Yubikeys. All other functions and forms of mfa, whether it's SMS or push notification or phone code, they are all vulnerable to this adversary in the middle, browser in the middle. Nonsense.
Corey
Well, even with the Yubikey stuff, if we can intercept like browser in the middle, and then we basically tell the site that we're a phone or an iPad, that on some of Those sites, it disables any Yubikey authentication as well.
Ralph
It depends on the configuration.
Mary
I mean, yeah, yeah, you'd get it. You'd be, you're getting into like how the site's configured, but then you get.
Corey
Into how many people are using Yubikey. For a hundred thousand people in their company, not many.
Mary
And even now we don't recommend it to our clients. We only recommend it for high privilege accounts. It's. It should not be every single user. Having a Yubikey is really over and overkill.
Corey
It's totally practicable.
Ralph
Yeah. The other solution too and is universal two factor with passkey.
Jeff
Right.
Ralph
So those are built into something like 1Password. Those are also, what do you call it, man in the middle resistant. Just the same way the Yubikey is. It's just not a physical device, but it does still require that essentially authentication of the other side and that nothing's in the middle.
Mary
So yeah, security people hate passwords. Passwords, we've, we hate them. We are sick of them. Let's switch to password lists. Let's get over. I mean as an attacker, I love passwords, but as a defender, passwords are garbage. Like if you don't know your password, you can't compromise yourself, especially not if it's a passkey that's cryptographically tied to one site. So yeah, it's just a cool collection of phishing techniques. If you aren't familiar with modern phishing techniques, I mean we have many webcasts where we talk about it, right?
Corey
We just had one.
Mary
Check out Rhino. Check out Rhino's webcast later this week.
Ralph
Week.
Mary
But yeah, I mean this is basically a pen tester menu right now if your pen test firm isn't using most of these techniques, they're not a very good firm. There's evil jinx. There's evil no vnc. Yeah, I mean it's. And Cuttlefish is a cool one too. I've heard a lot of people in the pen test biz talking about Cuttlefish. It's, it's cool. I mean these techniques are terrifying. Yeah. Browser in the middle and browser in the browser. They're really cool.
Corey
Browser in the browser. Yeah. Okay, I like this. I like. Somebody just said screw passwords. Bring ntlm.
Ralph
I think he was trying to get you, John.
Corey
I know, I know. I, I keep trying to explain to everybody, like if you're ever in a compliance standard and someone says no clear text authentication, you have to shut down all NTLM, NTLMB1, NTLMB2. And landman authentication because Microsoft treats the password hash as if it is the password itself and it sent barely just little bit of obfuscation it sent clear text but that's a whole nother but.
Jeff
Wait I thought it was salted and crypto.
Corey
No no salt at Microsoft low sodium.
Ralph
Diets no salt with your traditional not netlm hashes there is no salt and they're never going to change it They've.
Jeff
Already acknowledged day they say yeah so.
Corey
All right well that's a good show. Let's wrap it. Thank you very much everybody for attending and I will see you guys all next week or at another webcast. There's all kinds of free stuff. Check it out once again if you need to get hacked, afraid to get hacked think you're hacked trying to prevent yourself from getting hacked or learning about hacking or learning how to defend yourself against hack Black Hills information security is there for all of your hacking needs. Also check out anti siphon security training and with that that we're out of here. Everybody bring out the finger Ryan, bring it.
Podcast Summary: Talkin' About [Infosec] News, Powered by Black Hills Information Security
Episode: News 2025-03-17 - Malicious Browser Plugins will Destroy us ALL!!!!!
Release Date: March 19, 2025
Host/Authors: Black Hills Information Security Team (John, Corey, Joff, Mary, Ralph, Jeff, Bronwyn, Erica)
The episode kicks off with a casual conversation among the hosts, briefly touching on personal hobbies and transitioning smoothly into the primary focus: the escalating threat posed by malicious browser plugins. The discussion sets the stage for an in-depth exploration of browser security vulnerabilities and the sophisticated methods attackers employ to exploit them.
Chromium Architecture and Process Separation
Jeff delves into the intricacies of Chromium-based browsers, highlighting their multi-process architecture designed to silo and protect different browser components. Despite these protections, the addition of functionalities like JavaScript and WebAssembly has inadvertently expanded the attack surface. Jeff notes, "[...] there is this web code virtual engine that kind of runs and executes a lot of this JavaScript [...] as we add additional functionality, naturally, we are going to expand the attack surface" (09:04).
Polymorphic Extensions and Plugin Impersonation
Corey and the team discuss the emergence of polymorphic browser extensions capable of impersonating legitimate plugins. Mary explains, "They can basically impersonate other extensions... it's a watering hole attack" (23:29). These malicious extensions can disable legitimate plugins and create backdoors, analogous to the Stuxnet virus's method of wrapping and forwarding legitimate functions while introducing malicious ones.
Social Engineering Tactics for Plugin Installation
The hosts emphasize the role of social engineering in deploying malicious plugins. Corey remarks, "You can just say, this is a great password manager that's free and just get 30,000 people to install it" (24:44). The ease of publishing extensions on platforms like the Chrome Web Store, coupled with ineffective reporting mechanisms, allows attackers to distribute malicious plugins widely before detection.
Comparison to Stuxnet
Jeff draws a parallel between modern browser plugin attacks and the Stuxnet virus, stating, "It's like the Stuxnet virus... they took over Siemens PLC Dynamic Link libraries" (13:12). This comparison underscores the sophistication of current browser-based attacks, which can infiltrate and manipulate trusted systems seamlessly.
Challenges in Detection and Prevention
Ralph and Mary discuss the difficulties in detecting malicious plugins within enterprise environments. Ralph points out, "A lot of your EDRs are not looking in your browser at all" (26:24), highlighting the gaps in current security solutions that treat browsers as monolithic processes, thereby missing nuanced plugin behaviors.
Critique of Chrome Web Store Security
The team criticizes the Chrome Web Store's lax security measures. Ralph states, "The Chrome Web Store is a mess... making malicious extensions is super easy" (14:37). The absence of rigorous reviews and the inefficacy of reporting mechanisms allow malicious extensions to proliferate unchecked.
Problems with Reporting Mechanisms
Corey elaborates on the ineffectiveness of existing reporting systems: "Reporting it is like a very non-effective mechanism for these" (14:37). This inefficacy enables attackers to evade detection and maintain persistence within users' browsers.
Watering Hole Attacks
Mary highlights the strategic advantage of watering hole attacks through malicious plugins: "It's a legitimate extension that just impersonates other extensions... it's a watering hole attack" (23:29). Such attacks exploit trusted channels to infiltrate broader networks without immediate suspicion.
Enterprise Management of Plugins
The discussion touches on the challenges enterprises face in managing browser plugins. Mary and Ralph note that many organizations do not enforce strict browser management policies, leading to vulnerabilities: "Most people aren't using managed browsers" (25:57).
Phishing Resistant MFA vs. Traditional MFA
The hosts examine the limitations of traditional Multi-Factor Authentication (MFA) methods in the face of advanced phishing techniques. Mary articulates, "All of these attacks rely on granting authentication tokens to an untrusted third party" (55:51). They advocate for phishing-resistant MFA solutions like Yubikeys and passkeys, which offer enhanced protection by mitigating session token theft.
Session Tokens and Their Vulnerabilities
Corey explains how session tokens, issued after MFA completion, can be exploited by attackers: "Session tokens function as authentication information and they can be stolen" (55:51). This vulnerability underscores the necessity for more robust authentication mechanisms.
Discussion on Yubikeys and Passkeys
Ralph and Mary discuss the practicality and implementation challenges of deploying Yubikeys and passkeys across organizations. They acknowledge that while effective for high-privilege accounts, widespread adoption remains limited: "We only recommend it for high privilege accounts... having a Yubikey is really overkill" (57:36).
Background on Volt Typhoon’s Attack
Mary presents a case study involving Volt Typhoon, a Chinese-affiliated threat actor targeting the Littleton Electric Light and Water Departments in Massachusetts. The attackers employed techniques like SMB traversal and RDP lateral movement to infiltrate the power grid: "They were just gathering data... this is the persistence part" (37:04).
Techniques Used: SMB Traversal and RDP Lateral Movement
The breach involved exploiting SMB traversal vulnerabilities and leveraging Remote Desktop Protocol (RDP) for lateral movement within the network. Mary speculates, "Are we talking Internet bound SMB traversal?... I imagine it was probably that bad" (37:04).
Importance of Network Monitoring and Solutions like Dragos
Corey and Mary emphasize the critical role of network monitoring in detecting such intrusions. Mary commends the utility for seeking Dragos' solutions through a government grant, stating, "These products are expensive because they're really advanced... it's just a cool, unique thing" (41:56). They advocate for comprehensive security architectures to prevent and mitigate such sophisticated attacks.
6G Technology and Privacy/Security Implications
The hosts briefly discuss the impending rollout of 6G technology, highlighting its potential for advanced room scanning and telemetry. Corey warns, "6G can scan the room like the equivalent of Batman... building layouts where people are positioning even with your phone in your pocket" (46:04). They express concerns over the privacy and security ramifications of such pervasive scanning capabilities.
Bank of America's Physical Data Breach
Mary humorously recounts Bank of America's minor data breach, where sensitive documents were left in a trash can outside: "It was literally just in a trash can outside... affects two customers" (50:00). This anecdote underscores that not all breaches are high-tech; simple oversights can also compromise data security.
DDoS Attacks Against X (Formerly Twitter)
The conversation touches on a Distributed Denial of Service (DDoS) attack against X, critiquing the oversimplified attribution often presented in media reports. Corey notes, "Attribution is really hard... always take it with a grain of salt" (53:04), emphasizing the complexities in accurately identifying the perpetrators behind such attacks.
In wrapping up, the hosts reiterate the importance of comprehensive security strategies that extend beyond traditional measures. They advocate for enhanced visibility, robust authentication mechanisms, and proactive monitoring to safeguard against evolving threats. Corey concludes with a call to action: "If you need to get hacked, afraid to get hacked... Black Hills Information Security is there for all of your hacking needs" (55:23), highlighting their commitment to providing advanced security solutions.
Notable Quotes:
Jeff (09:04): "There is this web code virtual engine that kind of runs and executes a lot of this JavaScript... as we add additional functionality, naturally, we are going to expand the attack surface."
Mary (23:29): "It's a legitimate extension that just impersonates other extensions... it's a watering hole attack."
Ralph (14:37): "The Chrome Web Store is a mess... making malicious extensions is super easy."
Corey (23:29): "Basically a watering hole attack."
Corey (55:19): "What are some techniques that we use to kind of walk and get around MFA in organizations."
Mary (55:51): "Session tokens function as authentication information and they can be stolen."
Conclusion
This episode of Talkin' About [Infosec] News provides a comprehensive examination of the rising threat of malicious browser plugins, the vulnerabilities within browser architectures, and the sophisticated techniques attackers use to exploit these weaknesses. Through detailed discussions and real-world case studies, the Black Hills Information Security team underscores the necessity for robust, multifaceted security strategies in an increasingly complex digital landscape.