Proxyjacking – Crystal Morin and Michael Clark, Sysdig
Sysdig’s Threat Research Team (Sysdig TRT) detected a new attack, dubbed proxyjacking, that leveraged the Log4j vulnerability for initial access. The attackers then sell the victim’s IP addresses to proxyware services for profit. While Log4j attacks are common, the payload used in this case was uncommon. Instead of the typical cryptojacking or backdoor payload, Sysdig TRT witnessed the attacker installing an agent which turned the compromised account into a proxy server, allowing the attacker to sell the IP to a proxyware service and collect the profit.
Transcript
This is texturing TV. Hey everyone, welcome back here to Tech strong TV. Next up today.
I have two folks from our friends over at cystic. They recently put out a I guess a blog post or an alert about some new research. They've done over at their Cloud threat research team speaking of their Cloud threat research team though.
Let me introduce you to two folks here from systic. First of all returning to our show. He's been on here before with us is Michael Clarke Michael's the director of threat research.
It says dig and joining Michael today is our first time first and on text on TV and we're happy to have her Crystal Morin Morin and Crystal is a research engineer on the threat research team with Michael. Text drug TV. Thanks for having us.
Okay. Thank you. So.
You know what Michael being that you're the veteran I'm gonna make you go first. If you wouldn't mind share people share with people a little bit of your story. Or as mentioned I run the threat research team here at systic been here for about a year and a half prior to that.
I was a Analyst at gardener on security operations. And prior to that I worked in instant responsive rapid 7 and about the 15 years of other random experience. So it's been a great time here to see learning all about cloud kubernetes and all those other very interesting Technologies.
That's great Michael. And and actually you've been doing a great job. We've been following along since you're on crystal.
How about a little bit about you? Yeah, sure. So I've been with cystic for about seven or eight months.
Now as a threat research engineer previously come from defense contractor Booz Allen Hamilton before that. I was in the Air Force and so my background is mostly on counter threat financing counterterrorism, and then I've made my way into tracking cyber actors. Very cool.
So look, I think most of our audience is pretty familiar with cystic. We do a ton of activity here with this dig around touch stronger cause our various Publications and stuff but for those who are watching maybe who aren't up on cystic. Michael how would you describe cystic to them?
There's so just think of a cloud security vendor we Cover up most of the areas of cnapped which is a acronym that has a pretty much all the cloud security technology in it. But, you know, we specialize in vulnerability management runtime security for a containers Cloud security alerts and a whole bunch more. It's really tough to describe it all in a minute, but We also stand from Falco.
The open source project is very popular. and yeah, so that's pretty much what's the status pretty cool and you know for us it kind of it rings all the bells here A texture because it's security it's devsecops. It's Cloud native security, you know it all of the above.
So it that's right. We I think run into cystic so much in our coverage and so forth. But you know, what a lot of companies today have threat research teams, and they're a lot of people doing threat research is part of threat analysis and everything else.
You know Michael we've been coming to you. Let's throw one out here at Crystal so. You know, what is the threat research team at cystic, you know day to day month to month.
What what's the mission there? and so our team has a very large breadth of they hang on we focus on a lot of different things everybody specializes in something in particular. We've got some folks that work on creating detection analytics for our customers.
And then we also have a Honey Nut that we use to capture malicious activity and we're looking for these three actors known or unknown who are using misconfigurations either to make money or to capture proprietary data. So that's kind of what we do in the day-to-day. Beautiful.
All right, I think we've got you know, what one more question for you Michael and then we're gonna jump into this latest report or not report. But this latest research for people who want to get up on sistig and the specifically the threat research team stay abreast of that. Is there a particular place on the cystic website they should go to or maybe it's not a website somewhere else online.
Where would you send them? Yeah. We have a section on our website.
So stay calm slash that research and you can find all of our content that we put out there. Perfect, all right, we've got that all out of the way guys. Let's dive in here to this latest bulletin or whatever we want to call.
That you got information you guys have published. I don't know Michael. It's your team.
But it's Crystal the lead on researcher on this or how do you want to it's okay? yeah, so we just found is what we decided to call proxy jacking and we found this malicious actor that used a log for J vulnerability for initial access into a network what they ended up doing was downloading a proxyware service onto the network to be able to meet the end goal of making money. So proxy were service allows a user to sell their IP address and their bandwidth can be used by anyone strangers who pay for an obscure IP outside of the region that they live in could be just for surfing, you know, like YouTube videos that they can't get in the region that they live in websites that might be blocked.
So they'll use a proxy where service so they can use an IP from another region. and if you live in a country where they filter the internet that's a pretty valuable resource, but there's probably more nefarious uses for for that as well right where there would be Bitcoin mining or you know, something impersonating someone else spoofing. Etc.
Yep, so that's what we found and so this malicious actor ended up. Selling the IP that they stole to a proxyware service and then they are then collecting the money from the proxyware service for their own benefit. So this is kind of like a cousin to crypto mining crypto jacking.
There's a similar end goal, right the attacker wants to make money. They do it in a similar manner. They're downloading scripts and Using defensive Asian techniques so they can maintain persistence on the victim account, but they're getting the money and unknown to the victim.
Sure. Now, I'm sure there are some people in our audience out here saying oh they're exploiting a log4j vulnerability. That's old news.
Everyone's patch that already wrong, right not everyone's patched and fix that already. Do we have any idea of How many vulnerable well if they're using an old log4j, they're all vulnerable. But how many?
You know. Instances or users are still using these old block 4J they haven't updated them. Yeah, so we found a stat from census.
I believe it was from earlier this year. They said that they were still 23,000 hosts live on the internet that were vulnerable to log for Jay. And again this proxy jacking campaign that we found was an initial access via log for Jay vulnerability.
That doesn't mean that that's the only way that an attacker could get into your system. I mean, it could be a plethora of vulnerabilities. Yeah.
Yeah, in this case, there's still 23,000 hosts that haven't patched dog for Jay yet. Crazy, isn't it crazy shocking mother? Hey Michael, um fruit, you know, I think again most of our audience understands what we mean by you're calling a proxy jacking, right?
But for those maybe who maybe on the developer side not security related don't. Don't get it. What exact you know when we say proxy jacking can you explain it to them?
Or it's basically taking over a system in order to run it as a proxy server against the the owners knowledge, of course and as Crystal kind of mentioned, you know. Bypassing restrictions is one kind of area but these Services sell but they sell the services to bypass protections more so bot protections scraping protections retail protections. So if they limit you to walk by and when I one item for IP address people use these services to buy multiple so they can buy buy at the stock.
So it's I think it's use much more for this retail evasion or web scraping and and other things get by people's protection. And you know, that's Crystal also said it's like crypto mining. However crypto mining is CPU this you'll end up seeing a lot of bandwidth being used so gigabytes.
It could be upwards of all 10 20 30 gigabytes a day of bandwidth being used which is cheaper. But you know, it could still add up especially if You know, the log4j could be a lot more than 23,000. That's just expose the internet that they know of so there's all these live for J instances behind.
It aren't directly exposed to the internet that could be affected. Yeah. All right.
Let's talk a little bit about remediation here now. I mean obviously patch your log for vulnerable log for Jay instances, right? That's that's number one, but how does one?
you know find out that you you've been a victim of this that it's been used against you and how do you I mean patching your log for J after they've already installed the proxy where it doesn't do you much good right? You know, how do you find out if you've been a victim of this and what do you got to do to stop it? You need visibility in several ways.
So, you know it visibility into what your your Cloud instance they're doing. Like are they using too much bandwidth? Are they using more than normal?
Do you have proper alerting set up in your cloud service provider to even know? If this happens the second is visibility into the instance. That's running it.
So that's are there any programs making network connections out there to suspicious hosts. Are they doing any other suspicious activity like running from a temp directory or trying to hide themselves with defensive Asian techniques. So just, you know cloud service provider visibility and runtime visibility.
Yes, like Mike said to with the CPU used crypto mining you can detect. Via CPU spikes, right? This isn't necessarily the case.
So yeah those good strong detection analytics for the threat actors kill chain is what's going to help you here. You're not going to be able to catch it just by looking at CPUs bikes or network traffic varies throughout the day. So that's not necessarily helpful either.
Yeah, would it? Is there a dial is there some sort of script or something or a test? Someone can?
Publish for these people is that let me ask you this. Michael is the director of The Reef threat research team. Is that something you guys think about?
Hey, let's put out an easy tool for people to diagnose this. He thought about it but it difficulty is they can rename it to whatever they want. So doing by names tough.
Yeah, the IP addresses they connect to while there are every service has their own. So we have to count you have to keep constantly looking at the threat intelligence IP indicators too to do that. They need a whole system to keep that all updated and and checking your system Sports and doing it just by Script is difficult.
Got it. Hey guys, excellent work on this. Look forward to seeing more.
We've got about a minute or minute and a half. Maybe left Michael. I know you're speaking later this month at RSA.
Conference and I we didn't you this on rehears science, you know surprising you but give us give us a preview. What are you talking about there? Cheers, so one of the things I've always been curious about is where are all they containers and kubernetes breaches.
So we hear about ransomware constantly on Windows networks and other incidents like that, but we barely hear about major compromises of kubernetes networks or container networks. So my talk will be going in new. You know why you don't hear much about it and what they look like because they let they're happening but they they haven't differently than we expect from our traditional knowledge of you know, how Windows networks are attacked.
So more supply chain more more other vectors, so that's what we talked about. Excellent looking forward to it. You have a time of the date and it's Tuesday.
I think nine the nine o'clock session or something like that. It's called where all the date where are all the container breaches. Excellent Man congratulations on that we'll be looking forward to it Crystal and Michael.
com/threat research and find out more information on this and the rest of the threat research teams work. And you know, we as I said, we've had Michael on before they're research team over. It's this thing does a good job you should Become a regular follower of that Michael Crystal.
Hopefully we'll see you both at RSA maybe and thanks for joining us today on Tech strong TV. Thank you much for having us. All right.
Hey, we're gonna take a break context strong, and we'll be back in a minute with some more news content and information, bye-bye.