Researchers Find Mysterious Russia-Linked Malware That Hijacks Anti-Theft Software Lojack
Summary
Security researchers are warning that malware with suspected links to Russian cyber-espionage group and alleged Democratic National Committee hackers Fancy Bear is turning up in installations of Lojack, an anti-computer theft program used by many corporations to guard their assets. On Tuesday, researchers with Arbor Networks’ ASERT lab said in a new report that they had discovered “LoJack agents containing command and control (C2) domains likely associated with Fancy Bear operations.” Due to the way Lojack was designed, it is apparently easy to make the software interact with malicious servers instead of legitimate ones, ASERT wrote: The researchers added that many antivirus software packages don’t detect the malicious executable sneaked into Lojack installations as a problem at all, and when they do, many flag it as not a virus or a “Risk Tool.” With the executable hiding in plain sight on the user’s computer, the rest of the work is easy: ASERT’s manager of threat research, Richard Hummel, told Dark Reading that the malware would allow attackers to seize control of the infected machine—which would be bad news if they were “on a critical system or the user is someone with high privileges .... with the permissions that LoJack requires, [the attackers] have permission to install whatever they want on the victims’ machines,” Hummel said. ]com, was “only recently spotted in the wild.” However, these clues only led ASERT to claim “moderate confidence” that the designers of the malware were, in fact, Fancy Bear, and detailed knowledge of the vulnerability has been floating around since 2014. Two of the domains, associated with a flyer for a NATO security conference that had been modified to include a malicious macro involving a tool allegedly often used by Fancy Bear, were only veiled late last year. As Bloomberg View’s Leonid Bershidsky has pointed out, the idea that so much nefarious digital activity is specifically tied to a handful of high-profile Russian groups tends to be overblown, and it’s hard to make a case based on known vulnerabilities or domains that could be fronts.