Reductor malware hijacks HTTPS traffic

1 October 2019 Editor's Choice, Information Security, News & Events

Kaspersky researchers have discovered new malware that hijacks victims’ interaction with HTTPS web pages via patching the pseudo random number generator used in the process of establishing encrypted communication between the user and the website. Along with the installation of rogue digital certificates it gives the actors the ability to spy on users’ browser activity.

While the “S” in HTTPS stands for “Secure” and infers that information exchanged between a browser and a website is not accessible to third parties, there still are many ways for a skilled high-profile hacking group to interfere in this process. Reductor is a tool developed for such intrusion and was used for cyber-espionage on diplomatic entities in CIS countries, primarily by monitoring their employees' internet traffic. What’s more, the found modules had RAT (remote administration tool) functions and the capabilities of this malware were almost unlimited.

Reductor distributors had two main attack vectors, one of which consisted of having modules downloaded through COMPfun malware, previously attributed to the Turla Russian-speaking threat actor. Another vector seemed to be trickier: apparently the attacker had the opportunity to patch clean software on the fly while it is being downloaded from legitimate websites to users’ computers. The software installers were downloaded from the warez websites which offer free downloads of pirated software. While the original installers available on those websites were not infected, they would end up on the victims’ PCs carrying malware. Kaspersky researchers concluded that replacement happens on the fly and that Reductor’s operators have some control over the target’s network channel.

Once Reductor found its way to the victim’s device, it would manipulate installed digital certificates, patching browsers’ pseudo random number generators used to encrypt the traffic coming from the user to HTTPS websites. To identify victims, whose traffic is hijacked, the criminals would add unique hardware- and software-based identifiers for each of them and mark them with certain numbers in a not-so-random-anymore numbers generator. Once the browser on the infected device is patched, the threat actor receives all information and actions performed with this browser, while the victim remains unsuspecting of anything untoward.

“We haven’t seen malware developers interacting with browser encryption in this way before” comments Kurt Baumgartner, security researcher at Kaspersky’s Global Research and Analysis Team. “It is elegant in a way and allowed attackers to stay well under the radar for a long time. The level of sophistication of the attack method suggests that the creators of Reductor malware are highly professional – which is quite common among nation-state backed actors. However we weren’t able to find solid technical clues which would attach this malware to any known threat actor. We urge all organisations dealing with sensitive data to stay alert and have regular, thorough security checks.”

To avoid being affected by malware, such as Reductor, Kaspersky recommends:

• Performing regular security audit of an organisation’s IT infrastructure.

• Adopting proven security solutions equipped with web threat protection that identifies and blocks threats that attempt to use encrypted channels to penetrate the system undetected like Kaspersky Endpoint Security for Business.

• In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform.

• Providing your SOC team with access to the latest threat intelligence, to keep up to date with the new and emerging tools, techniques and tactics used by threat actors and cybercriminals.

• Implementing security awareness training sessions for staff so that they will know the risk associated with pirated software and how to distinguish it.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Protect the integrity of critical video evidence
Surveillance News & Events
SWEAR has announced the Community Video Integrity Project, a new initiative designed to help cities and public agencies proactively protect the integrity of critical video and establish a verifiable record of authenticity from the moment it is captured.

Read more...
ONVIF strengthens authenticity of video surveillance footage
Surveillance News & Events
Amid a rising tide of manipulated and AI-generated footage, the add-on will equip the surveillance industry with a shared, standards-based way to establish where video came from and whether it has remained unaltered.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Detect procurement fraud before losses escalate
Security Services & Risk Management News & Events Financial (Industry) Editor's Choice
Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.