Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Angler EK Uses Diffie-Hellman Protocol to Prevent Detection

The notorious Angler exploit kit has started leveraging the Diffie-Hellman cryptographic algorithm to make it more difficult to detect exploits and prevent researchers from analyzing them. Kaspersky Lab has managed to successfully attack the implementation used by cybercriminals.

The notorious Angler exploit kit has started leveraging the Diffie-Hellman cryptographic algorithm to make it more difficult to detect exploits and prevent researchers from analyzing them. Kaspersky Lab has managed to successfully attack the implementation used by cybercriminals.

According to researchers at Kaspersky Lab, this is the first time the Diffie-Hellman protocol has been used by an exploit kit. By utilizing an implementation of the popular crypto algorithm, attackers ensure that firewalls are unable to decipher shellcodes and exploits by analyzing intercepted traffic. Furthermore, analysts are prevented from obtaining the exploit code.

“To make matters worse for analysts, JavaScript code and ActionScript code multiple obfuscation and a user IP ban upon sending the encrypted structure with a shellcode to the user were used in addition to the Diffie-Hellman protocol,” Kaspersky Lab researchers wrote in a blog post on Tuesday. “After getting the structure with the shellcode by that means (encrypted with a one-time key by using the Diffie-Hellman protocol), the exploit kit sample becomes unusable after one processing: the analyst is unable to understand what a specific file does, reproduce the attack, and, quite often, identify the exploit and vulnerability at all.”

The use of the Diffie-Hellman protocol by Angler was revealed by FireEye on August 10 after support for a recently patched Internet Explorer vulnerability identified as CVE-2015-2419 was added to the exploit kit.

The Angler EK attacks observed by Kaspersky leveraged the Diffie-Hellman protocol to secure the delivery of not just the Internet Explorer exploit, but also an Adobe Flash Player (CVE-2015-5560) exploit.

Kaspersky says it has found a way to crack the Diffie-Hellman implementation used by the attackers and decipher the shellcode. The attack was carried out using a modified version of the Pohlig-Hellman algorithm. The technical details are available on Kaspersky’s SecureList blog.

Advertisement. Scroll to continue reading.

Experts have tested the effectiveness of their attack using traffic dumps provided by the French researcher known as Kafeine on his “Malware don’t need Coffee” blog.

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.