Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Angler EK Uses Diffie-Hellman Protocol to Prevent Detection

The notorious Angler exploit kit has started leveraging the Diffie-Hellman cryptographic algorithm to make it more difficult to detect exploits and prevent researchers from analyzing them. Kaspersky Lab has managed to successfully attack the implementation used by cybercriminals.

The notorious Angler exploit kit has started leveraging the Diffie-Hellman cryptographic algorithm to make it more difficult to detect exploits and prevent researchers from analyzing them. Kaspersky Lab has managed to successfully attack the implementation used by cybercriminals.

According to researchers at Kaspersky Lab, this is the first time the Diffie-Hellman protocol has been used by an exploit kit. By utilizing an implementation of the popular crypto algorithm, attackers ensure that firewalls are unable to decipher shellcodes and exploits by analyzing intercepted traffic. Furthermore, analysts are prevented from obtaining the exploit code.

“To make matters worse for analysts, JavaScript code and ActionScript code multiple obfuscation and a user IP ban upon sending the encrypted structure with a shellcode to the user were used in addition to the Diffie-Hellman protocol,” Kaspersky Lab researchers wrote in a blog post on Tuesday. “After getting the structure with the shellcode by that means (encrypted with a one-time key by using the Diffie-Hellman protocol), the exploit kit sample becomes unusable after one processing: the analyst is unable to understand what a specific file does, reproduce the attack, and, quite often, identify the exploit and vulnerability at all.”

The use of the Diffie-Hellman protocol by Angler was revealed by FireEye on August 10 after support for a recently patched Internet Explorer vulnerability identified as CVE-2015-2419 was added to the exploit kit.

The Angler EK attacks observed by Kaspersky leveraged the Diffie-Hellman protocol to secure the delivery of not just the Internet Explorer exploit, but also an Adobe Flash Player (CVE-2015-5560) exploit.

Kaspersky says it has found a way to crack the Diffie-Hellman implementation used by the attackers and decipher the shellcode. The attack was carried out using a modified version of the Pohlig-Hellman algorithm. The technical details are available on Kaspersky’s SecureList blog.

Experts have tested the effectiveness of their attack using traffic dumps provided by the French researcher known as Kafeine on his “Malware don’t need Coffee” blog.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Malware & Threats

Unpatched and unprotected VMware ESXi servers worldwide have been targeted in a ransomware attack exploiting a vulnerability patched in 2021.

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.