Moose Malware Uses Linux Routers For Social Network Fraud

The newest distros the lastest Nvidia driver, gadgets .....

Moderators: b1o, jkerr82508

User avatar
Snorkasaurus
Berserk
Posts: 587
Joined: 30 Dec 2013, 19:19
Contact:

Moose Malware Uses Linux Routers For Social Network Fraud

Postby Snorkasaurus » 02 Jun 2015, 18:18

From this 15-05-27 article at DarkReading.com
the article wrote:There is no peer-to-peer protocol, [Moose] uses a hardcoded IP address instead of DNS for C&C, and even though the backdoor is listening on the Internet on port 10073 to offer its proxy service, only IP addresses in a whitelist are allowed to connect. Another reason for our lack of success is the lack of security tools ecosystems (like Anti-Virus) on embedded systems. Finally, the hosting providers where the C&C are located were relunctant to cooperate, which didn’t help.

This gives me the impression that the malicious traffic would be coming from a single IP address. Why she would state that and then not provide the IP address I don't know. Based on the description, simply blocking traffic to/from that IP address would defeat the malware.

S.

User avatar
viking60
Über-Berserk
Posts: 9351
Joined: 14 Mar 2010, 16:34

Re: Moose Malware Uses Linux Routers For Social Network Frau

Postby viking60 » 02 Jun 2015, 18:59

It looks like it.
This thing is clearly made to get more likes on Facebook and social media - being popular= money these days.

It seems to need Telnet to infect too so it will only infect people with an insecure infrastructure.
Manjaro 64bit on the main box -Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz and nVidia Corporation GT200b [GeForce GTX 275] (rev a1. + Centos on the server - Arch on the laptop.
"There are no stupid questions - Only stupid answers!"

User avatar
Snorkasaurus
Berserk
Posts: 587
Joined: 30 Dec 2013, 19:19
Contact:

Re: Moose Malware Uses Linux Routers For Social Network Frau

Postby Snorkasaurus » 02 Jun 2015, 20:12

viking60 wrote:It looks like it.
This thing is clearly made to get more likes on Facebook and social media - being popular= money these days.

It is really sad that marketing has become this sleazy. Fake Facebook accounts to shill popularity, native advertising to fool consumers in to believing a product is being backed by a trustworthy source, sponsored links that are intentionally hard to distinguish from actual content, service providers who track you so they can shove targeted advertising under your nose, and on and on. It is quite sad that corporations are sinking to new levels of sleaze every day, literally tricking people in to buying crap, and the bulk of the population doesn't know/care.
viking60 wrote:It seems to need Telnet to infect too so it will only infect people with an insecure infrastructure.

I tried to find any information on whether pfsense might be vulnerable to Moose but didn't see anything. I am currently using an iptables/masq'ing script for a router but have been considering dd-wrt so I can use a low-power embedded device... I am pretty sure that dd-wrt forces you to change the admin password before it will even let you configure your WAN connection. Not sure if pfSense also does that.

S.

User avatar
R_Head
Berserk
Posts: 2819
Joined: 17 Mar 2010, 15:40

Re: Moose Malware Uses Linux Routers For Social Network Frau

Postby R_Head » 03 Jun 2015, 16:56

I hate to sound like a Neo Amish but the root cause is social media. I am so happy that I do not participate. The only social thing for me is family and some forums and nobody knows your name.

User avatar
dedanna1029
Sound-Berserk
Posts: 8780
Joined: 14 Mar 2010, 20:29
Contact:

Re: Moose Malware Uses Linux Routers For Social Network Frau

Postby dedanna1029 » 13 Jul 2015, 07:02

Question, would just blocking port 10073 be of use in this? If they can't listen, then it would seem to me that it would screw their whole game?
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html

User avatar
dedanna1029
Sound-Berserk
Posts: 8780
Joined: 14 Mar 2010, 20:29
Contact:

Re: Moose Malware Uses Linux Routers For Social Network Frau

Postby dedanna1029 » 14 Jul 2015, 07:33

Snorkasaurus wrote:I tried to find any information on whether pfsense might be vulnerable to Moose but didn't see anything. I am currently using an iptables/masq'ing script for a router but have been considering dd-wrt so I can use a low-power embedded device... I am pretty sure that dd-wrt forces you to change the admin password before it will even let you configure your WAN connection. Not sure if pfSense also does that.


*nods.
Lookie here.
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html


Return to “Linux News”