Reductor malware hijacks HTTPS traffic

1 October 2019 Editor's Choice, Information Security, News & Events

Kaspersky researchers have discovered new malware that hijacks victims’ interaction with HTTPS web pages via patching the pseudo random number generator used in the process of establishing encrypted communication between the user and the website. Along with the installation of rogue digital certificates it gives the actors the ability to spy on users’ browser activity.

While the “S” in HTTPS stands for “Secure” and infers that information exchanged between a browser and a website is not accessible to third parties, there still are many ways for a skilled high-profile hacking group to interfere in this process. Reductor is a tool developed for such intrusion and was used for cyber-espionage on diplomatic entities in CIS countries, primarily by monitoring their employees' internet traffic. What’s more, the found modules had RAT (remote administration tool) functions and the capabilities of this malware were almost unlimited.

Reductor distributors had two main attack vectors, one of which consisted of having modules downloaded through COMPfun malware, previously attributed to the Turla Russian-speaking threat actor. Another vector seemed to be trickier: apparently the attacker had the opportunity to patch clean software on the fly while it is being downloaded from legitimate websites to users’ computers. The software installers were downloaded from the warez websites which offer free downloads of pirated software. While the original installers available on those websites were not infected, they would end up on the victims’ PCs carrying malware. Kaspersky researchers concluded that replacement happens on the fly and that Reductor’s operators have some control over the target’s network channel.

Once Reductor found its way to the victim’s device, it would manipulate installed digital certificates, patching browsers’ pseudo random number generators used to encrypt the traffic coming from the user to HTTPS websites. To identify victims, whose traffic is hijacked, the criminals would add unique hardware- and software-based identifiers for each of them and mark them with certain numbers in a not-so-random-anymore numbers generator. Once the browser on the infected device is patched, the threat actor receives all information and actions performed with this browser, while the victim remains unsuspecting of anything untoward.

“We haven’t seen malware developers interacting with browser encryption in this way before” comments Kurt Baumgartner, security researcher at Kaspersky’s Global Research and Analysis Team. “It is elegant in a way and allowed attackers to stay well under the radar for a long time. The level of sophistication of the attack method suggests that the creators of Reductor malware are highly professional – which is quite common among nation-state backed actors. However we weren’t able to find solid technical clues which would attach this malware to any known threat actor. We urge all organisations dealing with sensitive data to stay alert and have regular, thorough security checks.”

To avoid being affected by malware, such as Reductor, Kaspersky recommends:

• Performing regular security audit of an organisation’s IT infrastructure.

• Adopting proven security solutions equipped with web threat protection that identifies and blocks threats that attempt to use encrypted channels to penetrate the system undetected like Kaspersky Endpoint Security for Business.

• In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as Kaspersky Anti Targeted Attack Platform.

• Providing your SOC team with access to the latest threat intelligence, to keep up to date with the new and emerging tools, techniques and tactics used by threat actors and cybercriminals.

• Implementing security awareness training sessions for staff so that they will know the risk associated with pirated software and how to distinguish it.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Deepfakes and digital trust
Editor's Choice
By securing the video right from the specific camera that captured it, there is no need to prove the chain of custody for the video, you can verify the authenticity at every step.

Read more...
A new generational framework
Editor's Choice Training & Education
Beyond Generation X, and Millennials, Dr Chris Blair discusses the seven decades of technological evolution and the generations they defined, from the 1960’s Mainframe Cohort, to the 2020’s AI Navigators.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
Key design considerations for a control room
Leaderware Editor's Choice Surveillance Training & Education
If you are designing or upgrading a control room, or even reviewing or auditing an existing control room, there are a number of design factors that one would need to consider.

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
CCTV control room operator job description
Leaderware Editor's Choice Surveillance Training & Education
Control room operators are still critical components of security operations and will remain so for the foreseeable future, despite the advances of AI, which serves as a vital enhancement to the human operator.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Amendments to the Private Security Industry Regulations
Technews Publishing Agriculture (Industry) News & Events Associations
SANSEA, SASA, National Security Forum, CEO, TAPSOSA, and LASA oppose recently published Amendments to the Private Security Industry Regulations regarding firearms.

Read more...