all things cyber episode

3

Cyber horror stories from the edge of the internet

A fish-tank thermostat leading to a database, an inventory ghost, and the AI attacks keeping practitioners up.

Stephane Konarkowski

Welcome to the new episode of All Things Cyber, Halloween edition. Today we're going to be talking about some horror stories, so kids, be careful. Tim, first story, come on.

Tim Grieveson

I've got so many of them, Steph. So, as you know, I've worked in the industry a long time. About ten years ago I was contacted by a client in the casino market in the US. I'm going to protect their name, for obvious reasons, but they were a high-end casino, so they had all of the security you'd expect: good firewalls, good network detection, all the latest technology. They contacted me because they had something strange going on in the network. It transpired it wasn't what they thought it was — it ended up being the fish tank. So I'm going to call this story “the casino and the fish tank.”

What had actually occurred is a new supplier had delivered a very large fish tank into the foyer of the casino, and after that date they'd started seeing unusual activity on the network. So they checked all the usual things: the firewall, all the capabilities, and they really couldn't find out what it was. So they called me and a team in to do some forensic analysis.

Stephane Konarkowski

Because of a fish tank?

Tim Grieveson

Well, they didn't know it was a fish tank at the time, they didn't know what it was. They said they were expecting some sort of laptop, or some sort of phishing attempt. So we spent a couple of weeks tracking this down, and eventually what we found was a thermostat attached to the fish tank that regulated the temperature. Because it was this low-priority, non-network-connected device, they hadn't really understood it. But when we tracked it down, what we actually found is the hacker had found a vulnerability in the thermostat system.

Stephane Konarkowski

Wow.

Tim Grieveson

They'd used that to move laterally across the network in the casino, undetected, because it was low importance in terms of network traffic.

Stephane Konarkowski

A phish.

Tim Grieveson

Yeah, you could say it was a phishing attack. But what actually happened is the attacker used that to move laterally and reach the high-rollers database. So the real prize for the hacker was to gain access to that database: financial records, private and sensitive information, which they then used to draw the data back through the thermostat. The thermostat was connected to the cloud because they were using it to update the fish tank and monitor the water temperature, order the chemicals for the water, and so on. They used that to exfiltrate the database, push it up into the cloud, and ultimately get out of the internal network.

By the way, they did catch the hacker in the end. And although they had actually accessed the data, all the clientele data was safe, because the federal services got involved quite quickly. But it was really interesting to think that they'd had all that investment, they'd spent all the money on the things you'd expect: firewalls, IDSs and IPSs, security guards, physical CCTV, and it went silently undetected within their business. The moral for me was: understand the supply chain, and understand the vendor. It was a new vendor, and they hadn't really done what they needed to.

Excuse me, my telephone's ringing. It's actually my wife. Sorry about that, Steph. So, going back to the fish tank: never trust a fish.

Stephane Konarkowski

Never trust a fish. And always think about phishing.

Tim Grieveson

What about you, Steph? Have you got any similar horror stories?

Stephane Konarkowski

Horror stories, yes. But mine come from our side of things, from when we're looking at different networks and so on. So maybe not quite as fishy as yours. Here's what I've seen: I was called in to help with something strange happening on a website. The company was receiving phone calls from their customers about strange activity whenever they accessed the site, so I was called in to have a look and try to figure out what was happening.

I got access to the admin side of things to look at the logs, that was the first thing I looked at. I checked roughly a couple of days of activity, looking for anything unusual, anything that might be of interest. And I saw that there were some plugins that had been installed recently. I thought, okay, that's interesting.

I looked at the plugins, and what I saw is that the original plugin and the plugin that was installed were completely different. Well, maybe not completely; let's say the end of it was different. The reason I looked into this is that the file size was a bit strange compared to the original, because they'd installed that plugin before but the size was different. It could have been a new version or something like that, but it caught my attention. So I went inside the code, into the plugin, and there was a piece of code that had been added. What that code was doing was basically redirecting users to another application.

So I had a look at that application, first at the domain, and what I saw is that the domain had been registered about a month ago. So, again, very suspicious. Of course, I wasn't going to go and click on anything like that; you need to protect yourself. So I looked at the piece of code and thought, okay, this got installed by someone who had the rights to install the plugin. I had admin rights, the same way I had admin rights to look at all this, so someone had gained access to an account with admin rights, was able to install a plugin, and within the plugin put a piece of code to redirect to another website. That other website, after I investigated it, was installing malware on the computer of anyone who tried to log in to that page.

So what we did is we cleaned it up. We removed the plugin — that was one thing — and then we also removed a piece of code in the page that was calling the plugin back. They'd really put in an effort so that even if you removed something, it would reinstall itself automatically. So we removed the old piece of code, then monitored for a couple of days, and that was it.

So you can go to any website today, and what you need to watch for is anything suspicious. If you get redirected to another website, don't click on anything.

Tim Grieveson

Yeah, particularly tiny URLs and things like that.

Stephane Konarkowski

Yeah. It's like when you get an email from your bank saying, “Hey, can you click here to get access to your account.” Never do that. So that was one little finding, in terms of a plugin installed on a CMS platform, interesting because they changed it. The other thing we found is that the IPs connecting to it were coming from different places, different locations, so you already knew they were using some kind of VPN or whatever, always coming from the east side of things. That was the concentration of IPs being used.

So, again, another suspicious type of activity. We were able to solve the issue, but for the customer it was super scary getting calls all the time from their customers saying, “Hey, I'm getting redirected to a web page, what's going on, can I trust you?” and so on. So yeah, that's one of mine.  

What about you? Another one.

Tim Grieveson

Well, as it's Halloween, I'm going to call this one “the case of the digital ghost.” I was asked to attend a company that was an online commerce business with high-value products. They called us in to do some forensic analysis because they had a problem with their inventory system where it never seemed to be consistent. They'd have products in stock that they hadn't sold, and then all of a sudden they were out of stock. Products disappeared, and then came back online after a few days. Really strange.

What we actually found is the threat actor had embedded a piece of code into their inventory system, a very low-level piece of code. And what it was doing: it wasn't stealing any data, it wasn't exfiltrating anything at all, and it wasn't doing any lateral movement. All that code was doing was looking at certain products, changing the name of the product and changing the value to zero at certain periods of the month, and then reverting back.

So we thought this was quite strange. What actually transpired is that the threat actor was a gamer, and they were looking to get one of these exclusive consoles. Every time they tried to buy it, it was out of stock, because obviously everybody was interested in purchasing it. So what they did is they amended the code on those particular consoles, made it look like they were out of stock while they went in and bought the products at a very low value, and then shipped them back out. Because it wasn't on the system or in the inventory, the company didn't actually know they'd lost the stock.

So looking at and understanding the code within the application and the platform was clearly the thing they needed to go and look at. But it was something that puzzled us for months, because we couldn't really understand it. They're not stealing anything, they're not exfiltrating anything, there's no external access to the system. It was merely this small piece of code that they'd managed to get into the codebase.

What we did discover is that it was an insider who'd actually helped plant that code in there. So a couple of things came out of it. One: vetting the insider, who happened to work for a third party. Two: making sure you're doing proper vulnerability assessments of your code. And three: doing the assurance of that, and making sure you're doing it on a regular basis.

Stephane Konarkowski

Yeah, that change is basically what caused the interest there. Interesting, that's a good one, I like that.

Tim Grieveson

Steph, any more?

Stephane Konarkowski

I have one, yeah, that's an interesting one. This is one I came across while doing research, again for a bank. We discovered an application, the application that customers were using to connect to their bank accounts. But there was something strange. You know that feeling when you look at your screen and you know that something is not right? So what we did is we compared the two sets of code. Again, we're talking about code. We compared the code we had for that application, which looked just like the bank login, with another one we had, the original one. We thought, okay, maybe they have two different applications, maybe for redundancy, whatever.

Looking inside, we found that there was a connection being made somewhere else, to a completely different set of IPs than the original one. So that struck us again; we said, okay, that's a bit weird. What we did is we tried to understand where it was going. So I tried a few things, and I got the application to crash. I got my 500 error message. Some piece of code started appearing, like the Matrix, and I'm like, “Whoa, what's that?” So I stopped that and looked at what I had on my screen, and I saw a couple of URLs.

Of course, everything I was doing, I was doing on a system that was completely segregated, so it wasn't like I was going to get infected or something. And I saw some URLs, and I thought, okay, I'm going to have a look. Again, being curious. I went to that URL. First of all, I checked where it was coming from: a new domain, registered five months ago with a Gmail account. Something strange. And I had a look, and what did I see? The holy grail of the hacker. This time, the hacker forgot to secure the database he was using to collect all the usernames and passwords from the people logging on to that fake web page. He didn't secure it, so I had access to a whole database with the usernames and passwords of all the users of the bank.

So, funnily enough, what happened is that by trying something and getting the application to crash, that exposed a set of URLs, which I was then able to use to track down the database where everything was stored.

Tim Grieveson

I'm assuming the bank then gave you a nice fee for finding their vulnerability and fixing it for them.

Stephane Konarkowski

Well, at least they were made aware of something happening that was a bit out of their control — because someone can always spin up something on the side. But being able to get that data quite quickly, you can prevent people from trying.

Stephane Konarkowski

For the normal user, it's all about checking that you're in the right place. It's like emails: you get an email that says, “Oh, go here”. Like I said before, you click on the link because you think you're going to the bank. I never do that.

Tim Grieveson

Yeah. And if someone calls you now, even now, with AI... I was reading about this this morning on my way here: they can completely impersonate someone. The person talking on the other side could be, well, not a real person, but something basically impersonating a real person.

This happened to me recently, actually. I had a phone call masquerading as the bank, and it was AI-generated. It transpired because I did phone the bank and explain to them, and they said they'd never asked for details. This person said there'd been a compromise of my account and they were looking to access it, and they were asking me for password details. Clearly, as a security person, you'd never give them that. But it was an AI-generated voice, and it sounded really real: very polite, sounded great.

For me, it's like: you get an email, don't answer it, don't click on anything in the email. If you get a phone call, always call back. And call the number that you have, the correct number, not the number that phoned you, because they spoof that often.

Stephane Konarkowski

Exactly. So, like I said, be vigilant, there are ghosts everywhere. In terms of the moral of the story, you obviously need to monitor that kind of thing, but there's not much you can do, because anyone can spin up something like that. You just don't know that there's something happening. And while I was doing that exercise, there wasn't only one website. After that, I discovered five other websites doing exactly the same thing.

Tim Grieveson

Wow. So it's pretty haunting, then, isn't it? Look, Stephane, I've enjoyed chatting today. We'd love you all to share your stories with us. So if you have an interesting story about something that happened, either in your current workplace or in the past, and you don't need to share where you're working, we'd love to hear from you, and we'd love you to share those stories with the rest of the community. Thank you very much.

Stephane Konarkowski

Maybe it'll be a Christmas story next time. Or even a Valentine's story. Cheers, thanks very much. Bye-bye.

Thank you! You are now susbribed to The Recon Log
Oops! Something went wrong while submitting the form.