BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Least Privilege and South Korea

Posted March 26, 2013    BeyondTrust Research Team

No, this isn’t some editorial piece about the interrelationships of varying social strata in South Korean society and Gangnam Style. Despite how interesting that may be, we are instead taking a quick look at the latest “wiper” malware to strike fear in the hearts of CTOs and IT admins alike – DarkSeoul (or Jokra or KillMBR, depending on who you ask). If you haven’t heard of DarkSeoul, here’s what you need to know:

– Trojan that wipes out harddrives
– Targeted banks and media organizations in South Korea
– No Command and Control functionality (fire and forget)
– Wiping set to commence on March 20th
– Cross-platform (Windows, UNIX, and Linux)

Well, that was short… what’s all the ruckus about then? Just as with Batchwiper, running in a Least Privilege environment would have significantly reduced the effectiveness of DarkSeoul, if not completely disabled it. In the case of this malware, the Trojan siphons credentials from mRemote and SecureCRT installations on Windows systems, looking for root credentials to UNIX and Linux boxes. In a Least Privilege environment, and in an environment managed by tools such as PowerBroker Servers for Linux & Unix (PBUL), IT can make smarter, granular decisions about what certain accounts can do. This is especially critical on infrastructural systems, which often run Linux and UNIX, responsible for production roles and other critical functionality in the enterprise environment. PBUL lets you restrict access to certain functions and system calls, which can be leveraged to potentially prevent any user from deleting critical directories, such as home and kernel. Not to mention, running in a Least Privilege environment within Windows, with the use of PowerBroker for Windows, would have hamstrung DarkSeoul even further. Running as a non-administrator within Windows severely limits malware’s capabilities, including deleting system-critical directories.

TL;DR? An ounce of prevention is worth a pound of cure… or in this case, an ounce of prevention prevents all your files from getting deleted and breaking your ATMs.

Tags:
, , , ,

Leave a Reply

Additional articles

dave-shackleford-headshot

Why You Still Suck at Patching…and How to Turn Your Life Around

Posted March 25, 2015    Dave Shackleford

Live webinar | March 26, 2015 | 10am PT/1pm ET | Dave Shackleford, SANS Instructor | Why You Still Suck at Patching…and How to Turn Your Life Around

Tags:
, ,
infographic

Privilege Gone Wild 2: Over 25% of Organizations Have No Privileged Access Controls

Posted March 24, 2015    Scott Lang

BeyondTrust recently conducted a survey, with over 700 respondents, to explore how organizations view the risk of misuse from privileged account misuse, as well as trends in addressing and mitigating those risks.

Tags:
,
webinar_ondemand

On Demand Webinar – A Security Expert’s Guide: The Windows Events You Should be Tracking and Why

Posted March 23, 2015    Lindsay Marsh

On-Demand Webinar – Windows Security Expert and MCSE, Russell Smith, discusses the Windows Events you should be tracking right now and why. He will also show you how to set up Event Log subscriptions so you have better monitoring across your Windows environments.

Tags:
, ,