quinta-feira, 15 de janeiro de 2015

New "Skeleton Key" Malware, Allows Bypassing of Passwords

Remember When we Disscused How Passwords were Dead ? If you Needed More Proof that, this is True, the Bad Guys Have you Covered with a New Piece of Malware that Turned Up in the Wild. SecureWorks, the Security Arm of Dell, has Discovered the New Piece of Malware Dubbed, "Skeleton Key". The Attack Consists of Installing Rogue Software within Active Directory and the Malware then Allows Attackers to Login as Any User on the Domain, without the Need for Further Authentication. It's Important to Note that, the Installation Requires Administrator Access or a Flaw on the Server that Grants such Access. Interestingly, "Skeleton Key" Doesn't actually Install itself on the Filesystem. Instead, it's an In-Memory Patch of Active Directory which Makes Detection Even More Difficult.


Even Worse, this Access is Not Logged and is Completely Silent and, as a Result, Extremely Undetectable. Identifying the Malware Using Traditional Network Monitoring also Doesn't Work Due to the Fact that, "Skeleton Key" Doesn't Generate any Network Traffic. It's Not All Doom and Gloom though. The Good News is that, in its Current Form, the Malware Doesn't Survive a System Reboot. Also, the Fact that, it Requires Administrator Rights to Install Limits the Attack Surface, Making a Disgruntled Sysadmin One of the Largest Threat Vectors. In Addition, according to the Researchers, the Malware is Rendered Useless if an Organization Requires 2-Factor Authentication to Connect to Servers, VPN, Email and the Like. If this Isn't a Wake-Up Call to Stop Relying on Passwords as your Main Means of Security, I Don't Know What is.




Info Sources:

http://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis

http://www.zdnet.com/article/skeleton-key-malware-bypasses-authentication-on-corporate-networks



0 comentários:

Enviar um comentário