Hello, anyone know anything about this, specifically other than changing passwords, how to protect yourself?
Apparently it's a "datastealer" thing (I've no idea) so are these covered in the standard Winows Security scans?
What about Linux - does that need anti-virus scans and whatnot? (Hoping The Natural Philosopher responds to that bit)
Thanks all.
Didn't find your answer? Ask the community — no account required.
J
John Rumm
You are better protected if you:
Use unique randomly generated passwords for every site / account / login etc.;
Never reuse credentials;
Enable 2FA where it is available;
Delete accounts on services where they are no longer needed;
Take great care to not get phished, and not allow session stealing[1] malware onto your platforms and possibly also force segregation between malware vectors and computers that are logged into sensitive or particularly valuable online resources[2].
[1] Normally when you login to a site, that site will jump through whatever security process is required to confirm you have access, and then set cookies in the web browser to cache the results of that authentication. That saves you having to re-authenticated with every single click on the site - it "remembers" that you are authenticated. So session stealing malware will attempt to grab those cookies and exfiltrate them. It allows an attacker to make it look like not only are they you, but also that "you" have already passed authentication and are logged in - on *their* computer.
[2] A risk is that in addition to being logged into the "valuable" web site, the user will use the same computer for other work - say for example handling email. That can be dangerous, since it is a vector for malware delivery (either directly, or by social engineering). So by keeping those activities running in their own separate VMs (or on separate physical machines) you can lower the risk.
A data stealer can be the actual malware that lifts info from an individual end user's computer, but could also be something that lifts large bocks of data from databases or other online storage "bins" that have been left unprotected. Sadly something that is all too common. Someone develops a web site that depends on a back end database for storing user data, login credentials etc, and hosts that on a cloud platform like AWS. They *should* setup robust security to control who has access to it, but frequently don't because they have implemented their "security" in the web application, forgetting that bad actors might choose to just ignore their web app, and try taking directly to the database sever itself, or perhaps even the file system that hosts its database file.
Needless to say a compromised database can yield millions or billions of login credentials (or at least partial ones) in one hit.
Stolen lists also get placed on popular hacker forums etc (known as "pastes"), and those will often get aggregated into other collections and made available to those looking for some mischief.
Many hacked web resources are running on linux platforms; so the platform itself is not invulnerable to poor security practice.
On the desktop it is a less popular target, due to lack market share, but there are sill risks.
(plus most Mac and Linix users are in denial!)
The biggest risk is that there will be a web site out there that you signed up for, that has been hacked since. There will also be data aggregators that held information about you that have been hacked and your personal data lifted. Alas there is nothing you can do directly to stop that loss, all you can do it make what is lost less "re-useable".
It can be quite informative to slap an email address into:
formatting link
and it will tell you which known data breaches include that address. You can also check how often particular passwords turn up:
"Oh no — pwned!
This password has been seen 21,690,062 times before in data breaches! "
Can you guess the password I entered?
(and yes the site is legit, but don't take my word for it!)
Loads more info on breaches etc here:
formatting link
P
Paul
It's a weapons test.
You don't put that many passwords in a file, unless you're sending a message.
The Dark Web would choose to sell these passwords in smaller sets, to extract more value from them.
It could be a series of store exploits. Apple Store, Google Play Store, Microsoft Store, Linux supply chain exploit. That's a lot of activity, to not be detected.
It could be a TLS exploit (unmasking of all trunked traffic).
It could be a DOH exploit (something involving a novel setting on a web browser). Maybe the odd bit of traffic is directed to a thru-node.
A systematic exploit is a more reasonable assumption than an attack on four supply lines for programs without being detected.
Air gapping your machine, should make it safe (for some value of <snicker> ).
Until they tell us "how", we can't buy our way out of this.
We've known for decades, that DNS is broken. That's bad enough.
The Internet is not a very trustworthy place, because it was never designed for this. The facilities we have, are bandaids. A lot of "trust" was involved in the haphazard design of the Internet.
we'll know how to protect ourselves, when a followup news article appears.
Is it a quantum attack ? Unlikely. (crypto factoring via quantum computers)
Paul
J
Jeff Layman
When I ran Windows (NT, XP, 7) I used antivirus programs. Never found anything.
I've been running Linux (Ubuntu for a couple of years, Mint for 8+). I don't use an antivirus program. This thread is three years old, but is worth a read:
formatting link
T
The Natural Philosopher
Obviously its technically possible to design a virus for linux, but each distro is different enough to make it hard, and there are not that many Linux desktops out there to make it that worth while.
I've never used a virus scanner on any linux and as far as I know not caught any malware.
As far as passwords go I have a two tier approach. Passwords that it would be inconvenient to have hacked but not in any way disastrous are stored in browser.
Very sensitive passwords (to do with money) are kept *only* in my master password application, that requires a password to decrypt it.
P
Paul
Never used an AV on WinXP, then one day got tipped over while using a browser. It was a redirection attack, where a commercial site had something planted at top level, to send you off to another site, and somewhere in the 200 windows that opened, was an exploit that worked against the OS.
On the third boot of a Kaspersky trialware, the pest was gone. I got a subscription for one year to Kaspersky, but it was annoying enough from a behavior perspective, to not renew. Generally speaking, I think the Kaspersky was pretty good, but some cosmetic issues (a lot of dialogs opening all the time), meant I would not keep using it.
W8/W10/W11 had the Microsoft product. W7 had an antispyware from Microsoft, and that's not the same thing as the later AV.
The Windows AV can slow the PC down. If you run hashdeep over your C: drive, to generate "checksums", it runs at 1/8th the normal speed when the Windows Defender is running.
The notion of an "infostealer", I don't know if any of the OSes have a specific protection for that. First we start with Wikipedia
formatting link
"it is spread to target victim machines using various social engineering techniques. Phishing, including spear phishing campaigns that target specific victims, is commonly employed. Infostealers are commonly embedded in email attachments or malicious links that link to websites that perform drive-by downloads.[2][4] Additionally, they are often bundled with compromised or malicious browser extensions, infected game cheating packages, and pirated or otherwise compromised software."
But that can't be what happened this time, because 16 billion passwords are involved. Spear phishing only works on a limited set of people who have a "profile".
As an example, a USENETter used to have his own website. He was a small business man, selling a particular electronics device that could withstand high temperatures. To have a web site, he purchased a domain from GoDaddy. He did not stealth his personal details when filling out the domain info. For example, one option is to not show your personal email address. His email address was showing.
A Black Hat, sent him a fake email with what looked like a PDF attachment. You know, one of these tricks. The email, naturally, says "GoDaddy Domain Renewal".
bill.pdf.exe
As soon as the USENETter saw the attachment, he double clicked. The entire room of computers, was wiped out by ransomware. (It meant there was a worm in the ransomware, that worked on the old/unpatched OSes he was running.)
That's an example of phishing. Nobody is immune to phishing, if the "bait" is of good quality and design. But you can see that, even when victims are available in bulk (just scan the GoDaddy database and reel the suckers in), it still takes a lot of human resources to do these sorts of things. Onesy-twosy attacks yield $20 lots of passwords. This is 16 billion passwords, and implies another vector, with a much wider distribution, was used.
This is one of the reasons, for a time, sending ransomware to the "little people" stopped. Because it was costing too much, to offer email service to the people stuck with the ransomware. The red rectangle could give you a contact on the screen, and you could write to the person and try to barter down the ransom.
The infostealer in this case, must be "something that works everywhere", in order that 30 lots of passwords is the result.
But until they tell us the actual vector, there's no point in getting worked into a lather. Just your general OPSEC, says more about you than anything else. I've dealt with people who cannot resist clicking blue AdChoice boxes. You can tell them not to do that all you want, but they'll keep doing it. Some people know their limitations in respect of this, and they use an unelevated account, plus installing a raft of AVs and such, as a compensation for all the evil stuff they will be clicking on :-) Which is a pretty unique response to a bad habit.
Paul
T
The Natural Philosopher
Which wouldn't run on linux... and who is actually stupid enough to click on a .exe file?
A
alan_m
All the people who run windows and hide the file extension :)
D
David Wade
some e-mail programs hide the ".exe" .....
Dave
J
Joe
A fair number of domestic Windows users, I'd have thought, and they will all be running with Administrator rights because that's how the first Windows user is configured. Business computers are generally secured against running random .exe files and users don't have many privileges. Note that by default Windows does not show the user the file extension, so many users won't even know it's an .exe file.
There's not actually any problem about writing Linux viruses and worms, but few Linux users (before Ubuntu and friends) run with root privileges, and there aren't really enough Linux desktop users to allow malware to spread. Certainly there are few Linux desktops in business use, where the rewards are.
M
Max Demian
I would hope that people likely to be affected would be warned by the suppliers of the relevant software to change their passwords.
I don't suppose they will, though.
T
The Natural Philosopher
M$soft 'our users are too stupid to understand s*it, so lets make it easier to hack them'
N
No mail
I would love to check some of my passwords but don't have sufficient trust that this wouldn't lead to a problem (despite what they say). It would be useful to be able check partial passwords (or use wildcards) because then the user could decide on their balance of risk vs the time to search through possible hits.
J
Jeff Layman
Even if the .exe isn't hidden, a good way of "hiding" it is to name the file something like "interesting.pdf .exe". with a number of spaces in front of the .exe, so that the true extension becomes invisible.
P
Paul
The Windows OS default setting, is to hide extensions
bill # These files have different icons, but bill.pdf is not shown bill # Whereas this one could be a white rectangle of an icon and is bill.exe
Email tools will have their own policies.
The idea was just to show, that if reasonably crafted ("looks like a bill, smells like a bill"), a person could be in a rush to see what the bill is this year. And when you work for the bomb squad, you just can't be in a rush. Attachments present ? Slow down. Don't be in a rush.
But in order to "align" a few billion people with some "bait", that is a lot of work, and is unlikely to be the mechanism for all this material. But we know that the various "Stores", have had class attacks, where say twenty Apps will all contain the same exploit and didn't get caught and curated away. Usually the download count for items like that is "a few million".
Whatever is going on, it has to be something more systematic than this.
*******
Computer users should know, that PDF has Javascript.
The Javascript should be turned off in the Acrobat settings, as that is a vector for mischief.
The Javascript can even be obfuscated -- examination with a hex editor or a text editor, will not show it. The document opens, "unpacks itself", and then the Javascript can be run. It is unknown to me, whether an AV uses a sandbox and actually opens a PDF, to watch heuristically for abnormal behavior.
PDF as a format, did not start off life "armed to the teeth". But via extending the format, today it's more dangerous than it was in the past.
Turn off the Acrobat Javascript, until you actually need it enabled.
Paul
J
Joe
I'd be interested to know which idiots still store their users' credentials in plaintext form, or else what kind of hashing they use which is of insufficient strength. Even with the computer power being assembled today for AI, cracking 16 billion decently strong hashes must be an end-of-the-universe job, or at least it should be.
J
John Rumm
Well a password on its own is not much use, even if they were doing something underhand.
J
John Rumm
With the default settings you would not see the file extension...
J
John Rumm
Many passwords are of insufficient complexity, and also consist largely of dictionary words, so can be relatively easy match to their hashes using rainbow tables.
Best practice would also "salt" the passwords before hashing (i.e. adding random extra text to the plaintext password, then storing that salt with the password) to nullify the efficiency gains from the use of pre-computed rainbow tables, but it only takes poor security practice one one web compromised web site to allow a set of credentials to be decoded. In itself not a problem unless poor security practice by the user results in that same set being used more than once.
Also keep in mind that not all attacks will require cracking passwords. Phishing attacks, key loggers, "Man in the Middle" attacks etc will capture plain text passwords in the first place.
T
The Natural Philosopher
No. PDF does not have javascript
-- Renewable energy: Expensive solutions that don't work to a problem that doesn't exist instituted by self legalising protection rackets that don't protect, masquerading as public servants who don't serve the public.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.