BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Least Privilege and South Korea

Posted March 26, 2013    BeyondTrust Research Team

No, this isn’t some editorial piece about the interrelationships of varying social strata in South Korean society and Gangnam Style. Despite how interesting that may be, we are instead taking a quick look at the latest “wiper” malware to strike fear in the hearts of CTOs and IT admins alike – DarkSeoul (or Jokra or KillMBR, depending on who you ask). If you haven’t heard of DarkSeoul, here’s what you need to know:

– Trojan that wipes out harddrives
– Targeted banks and media organizations in South Korea
– No Command and Control functionality (fire and forget)
– Wiping set to commence on March 20th
– Cross-platform (Windows, UNIX, and Linux)

Well, that was short… what’s all the ruckus about then? Just as with Batchwiper, running in a Least Privilege environment would have significantly reduced the effectiveness of DarkSeoul, if not completely disabled it. In the case of this malware, the Trojan siphons credentials from mRemote and SecureCRT installations on Windows systems, looking for root credentials to UNIX and Linux boxes. In a Least Privilege environment, and in an environment managed by tools such as PowerBroker Servers for Linux & Unix (PBUL), IT can make smarter, granular decisions about what certain accounts can do. This is especially critical on infrastructural systems, which often run Linux and UNIX, responsible for production roles and other critical functionality in the enterprise environment. PBUL lets you restrict access to certain functions and system calls, which can be leveraged to potentially prevent any user from deleting critical directories, such as home and kernel. Not to mention, running in a Least Privilege environment within Windows, with the use of PowerBroker for Windows, would have hamstrung DarkSeoul even further. Running as a non-administrator within Windows severely limits malware’s capabilities, including deleting system-critical directories.

TL;DR? An ounce of prevention is worth a pound of cure… or in this case, an ounce of prevention prevents all your files from getting deleted and breaking your ATMs.

Tags:
, , , ,

Leave a Reply

Additional articles

powerbroker-for-mac-diagram-small

PowerBroker for Mac: A Least-Privileged Apple a Day…

Posted July 27, 2015    Jason Silva

BeyondTrust PowerBroker for Mac reduces the risk of privilege misuse by enabling standard users on Mac OS X to perform administrative tasks successfully without entering elevated credentials.

Tags:
, ,
PrivilegedAccountManagement

On Demand Webinar – Now is the time for Privileged Account Management

Posted July 24, 2015    BeyondTrust Software

In this webinar, SANS Instructor and Founder of Voodoo Security, Dave Shackleford, will revisit several hacking and breach scenarios that involved privileged accounts, and use these as examples while discussing tools and tactics to get this problem under control once and for all.

Tags:
, ,
dave-shackleford-headshot

Privileged Account Management: The Time is Now

Posted July 22, 2015    Dave Shackleford

There’s plenty of problems we don’t have great options for in InfoSec today. Malware is a pain point that keeps evolving rapidly. 0-day exploits are tough to prepare for. Privileged account management? We got this. We know the root causes, we know how it manifests, we know how to get it under control effectively, and there are great technology solutions that are enterprise-class.

Tags:
, ,