Actionable Intelligence for Malware Defense.

Blog » The Shiqiang Gang
Blog
The Shiqiang Gang
2012.05.15 | By John Dennis | 0 comments

In a series of blog posts our colleagues at Trend and AlienVault have detailed recent attacks on NGO’s, and how trojanized RTF files have been used as vehicles to plant various remote access trojans on unsuspecting users using the CVE-2012-0158 vulnerability.

In addition, they both mention that apparently stolen digital certificates have been used to sign the trojan files. The certificates mentioned were both revoked April 20th:

Shenzhen Xuri Weiye Technology Co., Ltd.
VeriSign Class 3 Code Signing 2010 CA
‎serial no. 3893f13dd39fe088fdf54ee008ae38e1
Valid from 8. December 2011 to 8. December 2012
Revocation Date: Apr 20 18:02:03 2012 GMT

Quanzhou Xiegao Microwave Electronic Co., Ltd
Thawte Code Signing CA – G2
‎serial no. 382d08b7caf01c6b6434c35fe0445b83
Valid from 31. March 2012 to 1. April 2013
Revocation Date: Apr 20 08:57:47 2012 GMT

Enter the Shiqiang Gang

The Quanzhou Xiegao certificate contains a peculiarity, one that links that attack with many others, and has prompted us to dub the people responsible The Shiqiang Gang.

Digital code signing certificates are often complex. They contain a lot more information that most people think of, and some which is not very visible up front. Some of this information is found in the SignerInfo structure, which contains important information like issuing Certificate Authority, the certificate’s serial number, and various hashes. It also contains the optional fields programName and moreInfo, where the latter is intended for storing a website link to more information about the signer. However, in this case there is no URL. Instead it says:

“identifierBegin:shiqiang:identifierEnd“.

According to Google, “shiqiang” means something like “Top Ten”. (I hope it does not mean anything nasty).

There’s no particular reason for that string to be there. It is probably an unintended result of reusing a build setup without fully sanitizing it. However, it is interesting to see what shows up once we start querying our malware databases for certificates containing this string:


These entries are all signed with stolen certificates. And they are all (except in one case) Etchfro trojans, of the type detailed by AlienVault and Trend. The exception is a modified Gh0st Rat.

The exact certificates used are shown below. Most of them – 8/12 – still validate, but not for long, as a revokation request is underway to the various CA’s.


Not all samples signed with these certificates contain the “shiqiang” string, but many do, and they just seem to keep on coming. We’ve seen this phenomenon for over a year, some very recently. Also, quite a few samples with other stolen certificates may be connected, but we have not seen them signed with the “shiqiang” string yet. This applies to, for example, the Shenzhen Xuri Weiye certificate mentioned above.

The companies that have lost certificates obviously have a security problem. In the case of Jiangxi You Ma Chuang Da Software Technology, the Shiqiang Gang literally seems to have moved in with their family and pets and set up tent in their code signing servers. Note how the company has been shopping certificates from different CA’s. The certificate they use at the time of writing is issued by GlobalSign. I think it’s not stolen yet. I think.

A couple of document examples show us what kind of targets the Shiqiang gang are aiming at.

1. MD5 2da2ee8e17ed4582723f8a96c49d80a2. Shows what seems to be a grant request from National Endowment for Democracy (www.ned.org). Uses the Quanzhou Xiegao Microwave Electronic certificate.

2. MD5 0b99e0f0a7f7e59e9098e4c88c6b4ce4. Shows a price survey conducted by Hong Kong Catholic Commission for Labour Affairs, as an effort to increase minimum wage. Dropped executable uses the Xiamen Xingjinqiang Trading Co certificate.


This is interesting, and ties in with other incidents. For example, some of these Etchfro files belong to a particular type – the “Woodin” variety – which Frankie Li documented as being used against Hong Kong local politicians.

MD5 3d8a39631b00bb53389b211bc7e60b7b – an signed Etchfro/Woodin variation

Much has been written about the way Chinese malware is used to spy on NGO’s, and that is not without reason. Out of the CVE-2012-0158 I have been looking at recently, the vast majority is of this nature – aimed at Tibetans, Uighurs, and human rights activists home and abroad. In lesser numbers we see attacks directed at foreign industrial or military targets.

The domestic political espionage seen from the Shiqiang Gang fits an emerging picture of targeted malware producers acting highly predatory at home, where mass-theft of Chinese companies’ code signing certificates is only one aspect. I’ll come back to cover some other aspects, like money theft and straight up fraud, in a later post.

References:

http://labs.alienvault.com/labs/index.php/2012/cve-2012-0158-tibet-targeted-attacks-and-so-on/

http://blog.trendmicro.com/cve-2012-0158-now-being-used-in-more-tibetan-themed-targeted-attack-campaigns

Click to access Final_Paper_v3.1.pdf

Microsoft Corp.: Windows Authenticode Portable Executable Signature Format

“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”