What Lurks in the Shadows: Advanced Cyber Attacks that Hide in SSL Traffic
Last Update: Monday, November 16, 2015 : 10:34 (+4GMT)
From Target to Sony, and Anthem to Ashley Madison, no company is immune to the risk of cyber-attacks and the resulting loss of customer information. Network security solutions can reduce the risk of attack, but these solutions face an unexpected adversary: SSL encryption.
While SSL encryption improves privacy and integrity, it also creates a blind spot in corporate defenses. Today, roughly half of all Internet traffic is encrypted, and this figure is expected to reach 67% by 2016.
Attackers can exploit the SSL blind spot to sneak past security controls. Almost every network attack can be encrypted in HTTPS, FTPS, SMTPS and other SSL-enabled protocols. Therefore, cataloguing every attack that can hide in encrypted traffic would result in a very long and boring blog.
Instead, we will look at how malware developers use encryption to evade detection and how their evasion techniques have become stealthier over time.
SSL for Command and Control Communications
The Zeus banking Trojan is one of many types of malware that incorporate encryption. Zeus is not new—it was first identified in 2007—but it continues to be the most prevalent and dangerous Trojans around, having compromised roughly 4 million PCs as of December 2014[1].
Zeus has outlived other types of financial malware because it is difficult to detect and remove. Plus, the widespread availability of the Zeus attack toolkit has enabled countless criminal groups to develop variants that are even more sophisticated and sneaky.
As a case in point, the Gameover Zeus Trojan leverages encryption for both malware distribution and command and control (C&C) communications. For example, the Upatre downloader utility, which is often used to install Gameover, downloads the Gameover software over an SSL connection from a compromised web server. Once the Gameover software is installed, it uses peer-to-peer networks to communicate to C&C servers.
Because Gameover used 2048-bit encryption and continually changed domain names, law enforcement agencies struggled to contain the Gameover botnet, although they eventually shut it down in June 2014 as part of Operation Tovar.
Command & Control Gets Social
In an effort to avoid detection, new malware strains use social networks and web-based email for C&C communications. Security researchers have discovered malware that receives C&C commands from malicious Twitter accounts and comments on Pinterest[2]. Like most social networks, Twitter and Pinterest encrypt all communications. Therefore, organizations should inspect SSL traffic to detect botnet activity. Otherwise, IT security analysts might observe client machines accessing Twitter or Pinterest sites and assume the traffic is harmless.
Malware Steals a Page from the General Petraeus Playbook
Demonstrating how social malware has become, security researchers in Germany discovered a remote access Trojan (RAT) that receives C&C commands through online email accounts like Yahoo and Gmail[3]. However, in an interesting twist, consultants at Shape Security discovered that at least one Icoscript strain receives C&C updates from Gmail draft messages. Much like disgraced General David Petraeus—who communicated with his mistress Paula Broadwell through Gmail draft messages—the malware attempted to evade detection by not quite sending emails.
Like most online email programs, Gmail and Yahoo Mail encrypt traffic. Malware developers use this encryption to their advantage to evade detection. To detect malicious activity, organizations should decrypt and inspect traffic to email sites. Otherwise, malware could be passing them by.
In conclusion, privacy concerns fueled by the Snowden effect have triggered a massive spike in SSL traffic over the past three years. Today, cybercriminals are hiding their attacks using SSL traffic to circumvent existing security controls. It is imperative that CIOs and IT managers in the Middle East familiarize themselves with solutions that uncover hidden threats in encrypted traffic.
[1] The State of Financial Trojans 2014, Symantec
[2] Banking Trojan Targets South Korean Banks; Uses Pinterest as C&C Channel, Trend Micro
[3] Stealth malware: botnet control via webmail, G Data
By: Glen Ogden, Regional Sales Director, Middle East at A10 Networks
- From a Pair of Shoes to a New Dubai Property: British Expat Wins Through ‘Win ... [2883-Views]
- Five ways Emirates is helping customers travel with greater confidence... [2159-Views]
- Sheikh Zayed Falcon Release Programme releases 2,400+ falcons in the wild sinc... [1691-Views]
- DSS FINAL SALE BRINGS UP TO 90% OFF ACROSS MORE THAN 500 BRANDS FOR THE FINAL ... [1366-Views]
- e& UAE launches Business Pro AI bundled with Microsoft Copilot at no additiona... [1295-Views]
- e& UAE leads industry transition to 5G-native IoT with successful testing of R... [1168-Views]
- How to Choose the Right Medical Insurance in Dubai Based On Your Lifestyle?... [1109-Views]
- Held under the patronage of His Highness Sheikh Hamdan bin Zayed Al Nahyan Ab... [1070-Views]
- Beautyworld Dubai's 30th Edition Brings Global BeautyIcons Together This Octob... [1046-Views]
- Tadej Pogacar Chases Tour de France–Vuelta a Espana Double... [1011-Views]
- To enhance quality of sports services Ministry of Sports organises the first ... [927-Views]
- LG EMPOWERS DESIGNERS AND VIDEOGRAPHERS WITH NEW ULTRAFINE EVO 6K MONITOR... [845-Views]
- Best Recruitment Agencies in Dubai and Executive Search Firms in the UAE in 20... [800-Views]
- RTA Hosts Microsoft Copilot Day to Enhance Employee Efficiency and Accelerate ... [766-Views]
- ORA Land Launches BluBay with Suryakumar Yadav as Brand Ambassador, Reinforcin... [748-Views]
- ‘A Dubai Invite’ programme concludes following more than 90,000 applications ... [699-Views]
- Your Guide to Winning Big This Summer Through Dubai Summer Surprises... [695-Views]
- Isaac del Toro lands overall title at the Lidl Deutschland Tour... [691-Views]
- EDGE Debuts Multi-Domain Defence Capabilities at DALO Industry Days 2026... [681-Views]
- Stellar Wine Cellar: Emirates to serve exceptional Champagnes and fine wines o... [661-Views]





