Saturday, May 28, 2022
  • Zero Day Initiative’s Pwn2Own Miami 2022 – ‘Axel ‘0vercl0k’ Souchet Vs. Iconics Genesis64′
  • How to Prevent API Abuse
  • 4 Reasons MSPs Should Monitor Their GitHub Footprint
  • Securing applications in the multi-cloud: Where should organizations start?
  • XKCD ‘Voyager Wires’

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Bloggers Network
    • Latest Posts
    • Contributors
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Events
    • Upcoming Events
    • Upcoming Webinars
    • On-Demand Events
    • On-Demand Webinars
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
  • Library
  • Related Sites
    • Techstrong Group
    • Container Journal
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
    • Digital Anarchist
  • Media Kit
  • About Us

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Data Security SBN News Security Bloggers Network 

Home » Cybersecurity » Data Security » Bad Actors Using MitM Attacks against ASUS to Distribute Plead Backdoor

SBN

Bad Actors Using MitM Attacks against ASUS to Distribute Plead Backdoor

by David Bisson on May 14, 2019

Researchers believe bad actors are using man-in-the-middle (MitM) attacks against ASUS software to distribute the Plead backdoor.

Cybersecurity Live - Boston

Near the end of April 2019, researchers at ESET observed several attack attempts that both created and executed the Plead backdoor using “AsusWSPanel.exe,” a legitimate process which belongs to the Windows client for the cloud-based storage service ASUS WebStorage developed by the ASUS Corporation. In fact, all Plead samples observed by ESET had the name “Asus Webstorage Upate.exe”

In their analysis of these attack attempts, the Slovakian security firm said it believes that one of two things might have happened. It proposed that ASUS might have suffered a supply chain attack. But ESET discounted this possibility based on three observations: the same update mechanism delivered legitimate ASUS WebStorage binaries, there’s no evidence of the ASUS WebStorage binaries having acted as C&C servers or delivered malicious binaries and the attack attempts themselves delivered standalone malicious files not hidden in legitimate software.

The more likely situation in the minds of ESET’s researchers is that bad actors used MitM attacks and vulnerable routers to deliver the malware. Anton Cherepanov, malware researcher at ESET Slovakia, articulated this viewpoint in a blog post:

Our investigation uncovered that most of the affected organizations have routers made by the same producer; moreover, the admin panels of these routers are accessible from the internet. Thus, we believe that a MitM attack at the router level is the most probable scenario.

As the ASUS WebStorage software requests an update using HTTP, ESET reasons that the attackers might have replaced the “guid” and “link” elements included in the “update.asuswebstorage.com” server’s XML request with their own data. The security firm actually observed this happen in the wild. In that instance, they inserted a new URL that pointed to (Read more...)

*** This is a Security Bloggers Network syndicated blog from The State of Security authored by David Bisson. Read the original post at: https://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/

May 14, 2019May 14, 2019 David Bisson backdoor, IT Security and Data Protection, Latest Security News, mitm, Plead
  • ← Shared Responsibility in the Cloud (and how to mess it up)
  • 3 Ways Cloud Adoption is Changing the Role of the CISO →

TechStrong TV – Live

Click full-screen to enable volume control
Watch latest episodes and shows

Subscribe to our Newsletters

Get breaking news, free eBooks and upcoming events delivered to your inbox.
  • View Security Boulevard Privacy Policy
  • This field is for validation purposes and should be left unchanged.

Most Read on the Boulevard

Cars in the Crosshairs: Automakers, Regulators Take on Cybersecurity
CISA Announces Joint Ransomware Task Force
DoJ Decision Gives Good Faith Hackers Relief From CFAA
Oracle Adds Services to Strengthen Cloud Security
CISA Issues Alert on Weak Security Control Exploits
MY TAKE: ‘Digital trust’ has a huge role to play mitigating cybersecurity threats, going forward
Strava-cide? Top California Cyclist Allegedly Murdered by Jealous Texan
I joined Balbix to Fuel Explosive Growth Through a Partner Ecosystem
Why Data-centric Security Holds the Key to Successful AI Deployments
Lara Logan Switched from News Reporter to Extreme Right Propagandist

Upcoming Webinars

Tue 31

Leveraging a Cloud Data Platform to Respond to Cybersecurity Events

May 31 @ 11:00 am - 12:00 pm
Jun 01

The 2022 Guide to API Security

June 1 @ 11:00 am - 12:00 pm
Jun 01

Security From Code to Cloud and Back to Code

June 1 @ 1:00 pm - 2:00 pm
Jun 08

Beyond Unification: How CNAP Should Reduce Cloud Security Risk

June 8 @ 11:00 am - 12:00 pm
Jun 08

When Less Is More: Full Life Cycle Serverless Security

June 8 @ 1:00 pm - 2:00 pm
Jun 15

Top 5 Reasons Why Effective SDLC Security Controls Are So Difficult

June 15 @ 1:00 pm - 2:00 pm
Jun 21

Why Cloud-Native Applications and APIs Are at Risk

June 21 @ 1:00 pm - 2:00 pm
Jun 28

CISO Talk Master Class Episode: Catch Lightning in a Bottle – The Essentials: Bringing It All Together

June 28 @ 1:00 pm - 2:00 pm

More Webinars

Download Free eBook

7 Must-Read eBooks for Security Professionals

Industry Spotlight

Cars in the Crosshairs: Automakers, Regulators Take on Cybersecurity
Cybersecurity Governance, Risk & Compliance Industry Spotlight IoT & ICS Security Security Awareness Security Boulevard (Original) Threat Intelligence 

Cars in the Crosshairs: Automakers, Regulators Take on Cybersecurity

May 23, 2022 Mike Hodge | 4 days ago 0
Establishing a Root of Trust in Embedded Linux and IoT
Cybersecurity Endpoint Industry Spotlight IoT & ICS Security Security Boulevard (Original) Vulnerabilities 

Establishing a Root of Trust in Embedded Linux and IoT

April 18, 2022 Anita Buehrle | Apr 18 Comments Off on Establishing a Root of Trust in Embedded Linux and IoT
Attorney-Client Privilege and Email Privacy
Cybersecurity Data Security Identity & Access Industry Spotlight Network Security Security Boulevard (Original) 

Attorney-Client Privilege and Email Privacy

April 7, 2022 Mark Rasch | Apr 07 Comments Off on Attorney-Client Privilege and Email Privacy

Top Stories

Digital Driver’s License Fails Spectacularly — ‘Laughably Easy’ to Forge
Analytics & Intelligence Application Security Cloud Security Cyberlaw Cybersecurity Data Security DevOps Endpoint Featured Governance, Risk & Compliance Identity & Access Incident Response Malware Mobile Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social Engineering Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

Digital Driver’s License Fails Spectacularly — ‘Laughably Easy’ to Forge

May 26, 2022 Richi Jennings | 1 day ago 0
Zola Wedding App ‘Hacked’ — Victims Lose BIG Money
Analytics & Intelligence Application Security Cloud Security Cybersecurity Data Security Featured Governance, Risk & Compliance Identity & Access Incident Response Mobile Security Most Read This Week Network Security News Popular Post Security Boulevard (Original) Social Engineering Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

Zola Wedding App ‘Hacked’ — Victims Lose BIG Money

May 24, 2022 Richi Jennings | 3 days ago 0
Oracle Adds Services to Strengthen Cloud Security
Application Security Cloud Security Cybersecurity Featured Network Security News Security Boulevard (Original) Spotlight 

Oracle Adds Services to Strengthen Cloud Security

May 24, 2022 Michael Vizard | 3 days ago 0

Security Humor

XKCD ‘Voyager Wires’

XKCD ‘Voyager Wires’

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Bloggers Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsors Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Container Journal
  • DevOps.com
  • Techstrong Research
  • Techstrong TV
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
  • Digital Anarchist
Powered by Techstrong Group
Copyright © 2022 Techstrong Group Inc. All rights reserved.

API Poll

Step 1 of 5

20%
Do you have an API security project in 2022?
Who is responsible for API Security?
What is your API security maturity?
What is your top 3 concerns regarding API security? (select 3)
Which API Security practices do you follow most? (select all that apply)
This field is for validation purposes and should be left unchanged.