BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Least Privilege and South Korea

Posted March 26, 2013    BeyondTrust Research Team

No, this isn’t some editorial piece about the interrelationships of varying social strata in South Korean society and Gangnam Style. Despite how interesting that may be, we are instead taking a quick look at the latest “wiper” malware to strike fear in the hearts of CTOs and IT admins alike – DarkSeoul (or Jokra or KillMBR, depending on who you ask). If you haven’t heard of DarkSeoul, here’s what you need to know:

– Trojan that wipes out harddrives
– Targeted banks and media organizations in South Korea
– No Command and Control functionality (fire and forget)
– Wiping set to commence on March 20th
– Cross-platform (Windows, UNIX, and Linux)

Well, that was short… what’s all the ruckus about then? Just as with Batchwiper, running in a Least Privilege environment would have significantly reduced the effectiveness of DarkSeoul, if not completely disabled it. In the case of this malware, the Trojan siphons credentials from mRemote and SecureCRT installations on Windows systems, looking for root credentials to UNIX and Linux boxes. In a Least Privilege environment, and in an environment managed by tools such as PowerBroker Servers for Linux & Unix (PBUL), IT can make smarter, granular decisions about what certain accounts can do. This is especially critical on infrastructural systems, which often run Linux and UNIX, responsible for production roles and other critical functionality in the enterprise environment. PBUL lets you restrict access to certain functions and system calls, which can be leveraged to potentially prevent any user from deleting critical directories, such as home and kernel. Not to mention, running in a Least Privilege environment within Windows, with the use of PowerBroker for Windows, would have hamstrung DarkSeoul even further. Running as a non-administrator within Windows severely limits malware’s capabilities, including deleting system-critical directories.

TL;DR? An ounce of prevention is worth a pound of cure… or in this case, an ounce of prevention prevents all your files from getting deleted and breaking your ATMs.

Tags:
, , , ,

Leave a Reply

Additional articles

flash-logo

Adobe Patches Zero-Day Flaw Being Exploited in the Wild

Posted January 22, 2015    BeyondTrust Research Team

Earlier this week, French malware researcher Kafeine reported on a new Adobe Flash zero-day vulnerability that was being exploited in the wild using the latest versions of the Angler Exploit Toolkit. “Any version of Internet Explorer or Firefox with any version of Windows will get owned if Flash up to 16.0.0.287 (included) is installed and enabled”…

Tags:
, , , , ,

Your Data Security Strategy Starts with Deploying a Least Privilege Model (part 2 of 2)

Posted January 22, 2015    Scott Lang

In last week’s blog, we talked about how controls and accountability must be put into place so that only the right folks can access data and the systems on which that data resides, and that employing a least privilege model helps to achieve that and more. We’re using conclusions and data from a recent report…

Tags:
, , , ,
Larry-Brock-CISO

Basic Blocking and Tackling for Defending Against Advanced Targeted Attacks

Posted January 22, 2015    Larry Brock

With football season at its pinnacle at both the college and professional levels, the best teams continually focus on the fundamentals that make them successful. In security, we need to do the same.  It is okay for us to have a few key plays, especially in certain industries where we have to focus on unique…

Tags:
, , , , ,