An interview with Euler Neto on ErrTraffic

Episode 385 –

This week, we sit down with Euler Neto, a cybersecurity analyst at WatchGuard, to discuss his research into the ErrTraffic Malware-as-a-Service loader found targeting Portuguese-speaking users in recent months.

View Transcript

Marc Laliberte  00:00
Hey everyone, welcome back to the 443 Security Simplified. I'm your host Mark Liberty, and joining me today is not Cory Nachreiner. Instead, I've got Euler Neto, a senior cybersecurity analyst here at WatchGuard on the endpoint security team. If you've been following Secplicity over the last half a year or so, you've probably seen quite a few really in-depth technical analysis of various malware campaigns that we've been seeing. Euler, I am super excited to have you on today to talk about one of your more recent posts.

Euler Neto  00:34
Hi, hi, Marc. It's really good to to be here. Thanks for having me.

Marc Laliberte  00:39
Awesome. And so today we're going to be diving into the world of air traffic, which is a malware campaign that Euler just wrote about a couple of weeks back. Now, I'll go through some of the technical details of it and what it means for cyber defenders. And with that, I guess let's go ahead and hack our way in. Bueller, just to get started, though, since this is the first time that we've had you on here, every time we have a guest on, we like to learn about what got them into cybersecurity. We say, "What is your hacker origin story? Like a like a superhero movie, so I guess to start with, do you want to give like maybe a bit of a background about why you chose to get into cybersecurity and specifically malware research, and then what got you to where you are right now?

Euler Neto  01:35
I have a degree in computer science, and during the course, I I have interest in cybersecurity, specifically in computer forensics. I I like the all this investigation process and how choose the the the computer theory to in an investigation to give a response. So after the I concluded the the course, the computer science course. I I did a a course to computer forensics, so I I saw about in network network forensics, operations such as forensics, wow, and more analysis. And when I did the specific closing, my eyes look, oh, this is what I really like them. All that I I studied in the university, the assembly language, all these things I I can use here. I really like it.

Marc Laliberte  02:51
Yeah, computer forensics is an area that I find super interesting. Like you just said, like I love the idea of like looking at artifacts to try and piece together exactly what happened, and malware analysis is one. Like personally, if I had another life, I probably would have gone down that path too, because it's also super fun or interesting trying to piece together like how one of these applications works. But like you are an expert, and it's taken a lot to to get to the point where you are now to understand like how to rip apart malware and understand exactly what it's doing in the backend. So I am envious of your career choice if that's not not obvious here. And you've written a lot of really interesting posts on cyclicity over the past couple of months or so. The one that I want to talk about today is I think your most recent one that you published a bit earlier this month on the concept of air traffic, which is a malware campaign that uses a few different techniques that we'll get into. But as I pull it up here on the screen, just for a couple of the other folks on here, like watching the call, if you aren't already subscribed to the Seclicity blog, you absolutely should. Euler and a few others on his team have been putting out a lot of really interesting technical write-ups. There was one in July on Timber Steeler. We had one on a grandeur. Oh boy, cannot pronounce that, but Grandorero Euler, is that is that Portuguese? Is that Spanish? What do you think it

Euler Neto  04:31
is? It's a Brazilian, not not not just Brazilian. It's members in Brazil, Spain. I don't know if Portugal.

Marc Laliberte  04:42
Okay,

Euler Neto  04:42
but there are the main targets. Got it. Three countries.

Marc Laliberte  04:48
Form book was another one you went over. I remember the Bienlan one as well too. So lots of really interesting posts where you do a great job. I love reading the the posts that you write by the way because you do. Great job of really diving into the the weeds of exactly how these campaigns are working, kind of the different pieces as they come together, and highlighting some of the techniques that attackers have been using against small and mid-sized businesses. So today we're going to start with or focus entirely on this air traffic campaign that you recently analyzed, and I guess to start with, like in your own words, what is air traffic, and what caught your attention with this campaign that made you decide to really start ripping it apart to understand how it works?

Euler Neto  05:38
Air traffic. It's a it's a platform which is so the underwater for us. So it's just one more of these platforms that help try the actors and our develops to to get access to all these computes to

Marc Laliberte  06:07
like a

Marc Laliberte  06:08
malware as a service offering. Then where

Euler Neto  06:11
yeah,

Marc Laliberte  06:11
like I don't know how to make malware. They host it all for me.

Euler Neto  06:16
Yeah, that exactly. It's Maui's assets platform.

Marc Laliberte  06:21
And how did you like stumble across it? How did you find this

Euler Neto  06:26
one? In one of the investigations, I work in the attestation team with Ryan Estes. That's another

Marc Laliberte  06:39
frequent podcast guest, mr. Ryan Estes. Yep,

Euler Neto  06:42
yeah, and in one of this the case, I saw a PowerShell command command, which is a little odd. So after a certain time, I saw the semi-power command. Well, whoa, this is strange. It's a there's a pattern here. So I started to investigation. I found many many others comment like this. So I I separate each one of the start to investigate each one. That's awesome. So I I saw many cases that we'll discuss.

Marc Laliberte  07:25
Yeah, and for those that maybe have missed one of the episodes where Ryan was on, the attestation team at WatchGuard-they're the team responsible for that kind of last mile for our endpoint security, where if you deploy it in what we call lock mode by default, we block all untrusted applications. Period. And if the various detection tools and the endpoint security can't make a strong, like definitive, this is absolutely goodware or this is absolutely malware, and block it outright. If there's some uncertainty in there, it ends up on our attestation team's plate to go and analyze that malware and make that call. So the end of the day, there's no suspicious file in our endpoint security. It is it's goodware or it's badware. And if what would have been that suspicious file, Euler and Ryan and others on the team are the ones that go in and make that call. So one of the things you started out with in your analysis that you wrote on cyclicity, one of the big pieces of this campaign, is using a technique that we've talked about a couple times on the show called Click Fix. But I guess for a quick refresher, do you want to explain what Click Fix is and why it's become so effective.

Euler Neto  08:44
Well, it's so effective because some some people call it the new version of social media because it's very complex and much more efficient. Many, many, many people are affected by because we are so opposed to see captured to to. To

Marc Laliberte  09:26
pretend that we're not a human in this case, like especially now, I think in the world of artificial intelligence, right, where there's so many bots going around, like CAPTCHA has become very important for websites.

Euler Neto  09:40
Yeah, we need to to do many many tasks. There are many different tasks, and we will see something like, "Oh, we're not this commanding. We are so optimistic to do different tasks. Oh, okay, yeah, we do this task.

Marc Laliberte  09:55
Yeah, like traffic light, or click on the bicycle, or move this puzzle piece. Like there's a bunch of different forms of capture, right?

Euler Neto  10:04
Yeah, and we have circles. Circles might just see different things, and I say, oh, one comment. I just just one more thing to to do to update this access. So we will, I will do it, and it's efficient.

Marc Laliberte  10:23
I think you're right on the nose with that. Like, if you look back 10 years ago, CAPTCHA used to be here's five fuzzy letters and numbers, and enter in those letters and numbers, and that's it. But I suspect like object recognition from artificial intelligence has improved to the point where it's pretty easy for a bot to like solve that traditional style of CAPTCHA of entering the the letters and numbers. So you've seen new versions of it. Like the next step was Google's recaptcha, where they would take like Google Street View pictures, where you're actually helping train their AI in the background by pointing out like what little blocks have a traffic light in it, which ones have a stop sign, which ones have a motorcycle, and you're both solving a CAPTCHA while helping train their AI. But even that, like automation, has gotten better at solving them. I know some of the ones I've seen recently are like move a puzzle piece into the right spot, or like click in the certain order of what these shapes need to be, or like what was another one like spin circles and stuff to make it line up. And so it makes sense for like an untrained user that just knows, oh, I'm trying to prove I'm not a bot. Oh, enter in this command. Hit Control Windows, Control R or Control V, and Enter. Like they don't know that's actually opening them up to a huge amount of risk.

Euler Neto  11:52
At this point, it gives the. It's about how it's efficient. These comments are blindness for the the security controls. If when you you you paste the the code the the copy and tell oh the user adjusting copying some some information so it's nothing that flag it Suspicious, and when you open the terminal, you you the own user are open the the terminal. So the the security says, oh, the user just open the terminal. There's nothing nothing suspicious here. Yeah, it helps to to evade the difference.

Marc Laliberte  12:45
Very good point there too, where it's not like it's telling the user to download malware.exe and run it. Like that's obvious, and even traditional antivirus would very easily catch that. But with this, it's they're just copying and pasting something into command prompt or PowerShell or whatever, and running it, and EDR like like radr can catch that, but traditional anti malware and anti virus protection on an endpoint would totally miss that because it's just normal activity. So yeah, very good point on that one. Another thing you highlighted in the research is something called ether hiding, which it's been a while since we've talked about that on the podcast. Can you like quickly explain what ether hiding is to people listening?

Euler Neto  13:34
This is a little more complex, but this campaign is about these three concepts. The or these two concepts: the click fix and the at the hind, in the at the hind involving the use of smart contracts, which is contracts that that are in the blockchain network, so they are publicly they are in the the blockchain, which is a publicly ledger in other words, and the this con contract has a a code on on it. It's using a legitimate process, like like a contract in your wood. When you have to, when you do something, there's a contract on it. But with a smart contract, you can develop develop your action to be done when certain conditions are met. So, Cortney more developed are abusing this this feature to and transformating a command control.

Marc Laliberte  14:59
Yeah, I've heard. Like Ethereum, which is what this is based off of, described as like a distributed computer, where these smart contracts can be run on the different nodes that participate in the blockchain. They can run like an actual application. Like what was it? Do you ever see CryptoKitties when that was a thing on Ethereum like three or four years ago. It's a think of it like Pokemon or Neopets, but on but on the blockchain. And I remember we made Corey a CryptoKitty way back then before Black Hat. But anyways, like you can build even like games or other applications on the blockchain, and that means both compute and data storage, and I think what you're saying is ether hiding lets them store the data. In this case, like a script or a command on the blockchain, where then like a anything that can interact with the blockchain, like a Python-based library or something, can retrieve that data and then use it in the malware. Is that correct?

Euler Neto  16:04
Yeah, that's exactly it.

Marc Laliberte  16:08
And like, why do you think they're doing this? Does decentralizing it on the blockchain make it harder to take it down or disrupt

Euler Neto  16:19
it? Yeah, It's the main point. Main point, because it's so effective. It's because in hiding you can you can modify the the command control server in the the contract, and you can you can't take it out because it's a contract that are in the blockchain. You can't take out the the blockchain.

Marc Laliberte  16:50
Yeah, it's that's one of the selling points of Ethereum and blockchain technology as a whole is it's immutable. Like once it's there, it never leaves. You can't get rid of it, and so anything that can interact with the blockchain can always retrieve that data or that file. There's no takedown request that you can send. So you said the the main story from here is those two techniques like click fix and ether hiding, leading to this malware campaign. Maybe do you want to walk me through like what happens to a user once they interact with that click fix social engineering attack and copy paste in the script and hit run on their machine? What happens behind the scenes after that?

Euler Neto  17:37
Well, behind the scenes, different of the movies and series that many pop pop-ups are on the screen when there's a marification and everything power here. No, that's not about. You just see nothing. You you press the the entry and you did enough, but in the back row, many many things are happening. So it's totally silent

Marc Laliberte  18:07
as it's happening, is what you're saying. For the user, it doesn't. They don't see anything.

Euler Neto  18:13
Yeah, it's totally silence. But in the back row, there are many communications with command control. Many, many. operations by the bar? If the info, it's a info stealer. Yeah, they are collecting your information to send you. I've seen nothing there.

Marc Laliberte  18:36
I'm presumably though, like endpoint security would see all of this, right? Like all of these PowerShell commands and the connections to command and control. It would at least show up in telemetry, right?

Euler Neto  18:51
Yeah, these security solutions. I've seen all these actions, of course, but I, I say that they use them. They use them in same thing, but for sure the security solutions are seen in in blocking the the things.

Marc Laliberte  19:10
But I liked your your comment about all the pop ups because I remember like when I was a kid, I infected a lot of computers with malware accidentally as I was learning the internet and learning internet safety in production, as we say, and back then it was, you know, you would run a file that you downloaded from LimeWire, and up comes pop-ups of like either ransom demands or like the virus actually running or whatever it's trying to do, as it's ruining your day. But in this case, like this is totally silent from once it all kicks off. It's fileless malware that runs behind the scenes, just in PowerShell and other scripting engines. And to the user, they just think they solved the captcha. And it might not even raise any alarms for them. But so, like once it runs, it eventually downloads this malware as a service toolkit, which seems like it has a lot of other tools that was delivering, or at least a lot of techniques or capabilities. Like you wrote about the credential stealing pieces, the the DLL side loading, browser injections. Was there any technique that stood out to you as like really surprising or interesting?

Euler Neto  20:33
No, what surprised me was exactly the amount of the different techniques that and other famous that I saw in this company, and as I said said in the beginning, I separate separate all the the cases and invest analyze each one individual, not deeper, because there are many communications. But I saw how different campaigns and involved that use it each ref yes in each access for the this campaign investigators in the other side loaders Loaders domain ear traffic is a loader method, and loaders are you using them to to facilitate to to be loaded in the in effective device.

Marc Laliberte  21:36
Got it. So air traffic is just a loader, so attackers would use it for that kind of first stage, and then from there, download other things to run on the endpoint, like a robot access trojan, or maybe ransomware in the future, or something like that.

Euler Neto  21:53
Yeah, that's a second.

Marc Laliberte  21:57
Got it. Okay. So I noticed another thing. Like you called out a couple times, some of these components were like compiled Go Lang applications. Do you see that becoming more common with malware these days? Is Go as a language would you say more popular than it has been in the past, or still kind of a small piece of

Euler Neto  22:23
the pie. Oh, many many cases with malware that using Go. There are some some of them using Rust too, but Go is the demo. I'm seeing these days.

Marc Laliberte  22:38
Wonder why do you think that is? I can think of maybe a couple of ideas, but I'm curious if, since you're a little closer to the malware operators, like why do you think they're pivoting to go right now?

Euler Neto  22:51
I don't know exactly, but as a developer, it's most efficient than than C or C plus plus, so I think that they using due to efficient in the language to be analyzed was more difficult in the the past, but the the secret solutions for to for reverse engineering year, like Ida and Gidra, are more advanced these days to analyze binaries in Go.

Marc Laliberte  23:30
Okay, so it could just be like software developers in general are moving towards Go Lang and Rust as programming languages, and malware developers just-they're not any different. They're also moving to those because it's popular right now. That sounds plausible. Now, so your job is to detect and classify these threats to like help protect WatchGuard's customers that use endpoint security. But like on the defensive side, if you put on your IT hat, if you were someone like me that's managing these security tools deployed within an environment, like, do you have any guidance on what you should look out for to detect this kind of attack internally?

Euler Neto  24:19
For so many IT in general cyber security. Yeah, someone in IT,

Marc Laliberte  24:25
let's say.

Euler Neto  24:29
Yeah, someone works with infrastructure, for example. You can see if there are legitimate websites communicating with the the blockchain Ethereum networks, many read comments.

Marc Laliberte  25:00
That makes sense. So, like commute, like you're saying, indicators of compromise, like connections to blockchain endpoints, or maybe using like blockchain libraries, kind of stuff that like normal users in a business probably aren't doing a lot of activity with with blockchain technologies like that, like Polygon, for example. And so, if you saw someone someone's computer communicating to the Polygon blockchain, that's a red flag that something sketchy is going on. Is that right?

Euler Neto  25:32
Yeah, is the this chain of of communications legitimate website with WordPress, a cultural polygon in in RPC, RPC nodes in polygon, and after that, you see that a tab now is running executes in PowerShell.

Marc Laliberte  26:01
God, it's like the chain of activity. Then, of someone goes to a WordPress website, then the blockchain communications, and then a bunch of PowerShell popping up, communicating with a bunch of things. So, like, you would need like visibility into that telemetry and something capable of like piecing all of that together to catch the threat, because I don't know about you. Like I don't manually go and read logs on a regular basis because that's really boring, and would definitely need like automated tools to do a bunch of this analysis work.

Euler Neto  26:36
Yeah, that's the the spot that this stream. It's it's always this. In all the cases that are analyzing this this pattern,

Marc Laliberte  26:49
it's one of those where like this is where correlation is so important. Like a user visiting a WordPress website on its own, that's not really suspicious. Some users interacting with Polygon blockchain or some other blockchain-it's weird, but that's not really suspicious on its own. Some users using PowerShell-that could be pretty normal depending on the user, but like the the chain of events like that of unexpected WordPress website blockchain activity, PowerShell, and then like other access from that PowerShell process tree, that altogether is where this becomes a suspicious event that needs investigating. Is that right?

Euler Neto  27:33
Yes, exactly.

Marc Laliberte  27:35
Now, put on your prediction hat. Do you think click fix and ether hiding techniques are going to stick around for a while. Do you think they'll get more popular, or do you think attackers will pivot to something else?

Euler Neto  27:53
No, it's so popular that that's a funny story about this article. Me and Cristobal, other teammates that wrote other article about this. We we wrote these articles in. We didn't talk with each other. We we wrote, and my the article that I wrote was was published in in the blog, and after that, the the article that he wrote was published. After that, we we talking. Oh, we wrote about it too. That's because there are many many cases about that about the click fix. Okay,

Marc Laliberte  28:41
that is a very good point. It was three days after yours published. Cristobal had his published as well from malware using Ethereum blockchain to a to hide and specifically, like you said, targeting Portuguese users as well. And that is funny. It is very popular as a technique, and probably not going anywhere anytime soon. This has been awesome. And by the way, so your article that you wrote in Crystal Balls as well goes into way more technical detail than we're covering here. Like you went and showed decompiling a lot of the applications that were being used to show exactly how everything kind of interacts with each other. So I would recommend anyone listening right now that wants to get a little more in the weeds definitely check out the post on the the Sexplicity blog on WatchGuard.com. But Euler, I guess to like kind of wrap things up. If you had to pick one thing for everyone to remember from this research, is there like a tip or something that you'd want to have everyone walk away with?

Euler Neto  29:56
Well, be be. Every time, because me as a cybersecurity professional, I mostly run one these comments before Nickis was popular. I saw this. Oh, I run the commit, but with my knowledge, I saw that when I pass the the comment, that's a partial comment. Oh, this this is suspicious, but I almost hit anything. So that's something that if you you did have a tissue, you can easily be infected. So, and it's something relatively complex, but it's very true to be infected without technically very

Marc Laliberte  30:55
good point. That like you and I, first time we saw ClickFix, like it is obvious to a trained professional not to paste and run commands that you get from the internet into a on your computer, but to the untrained professional, just the normal user, it's not obvious, and that is absolutely why this is working. So I think like having everyone remember to treat everything with skepticism that you see, don't just follow directions blindly from, especially from websites that you come across on the internet. It's very good advice on this one, Euler. I really appreciate you taking time out of here on this. The article is amazing. I'm looking forward to seeing what you decide to spend time researching next because it's always very interesting, at least from my perspective as a security professional. But thank you for hopping on here. I appreciate it.

Euler Neto  31:55
All right, thanks. Thanks for the inviting. It's nice to be here talking with you.

Marc Laliberte  32:01
Yeah, of course. We'll have to have you on again sometime in the future.

Euler Neto  32:04
Oh, let's see.

Marc Laliberte  32:11
Well, hey everyone, thanks again for listening. As always, if you enjoyed enjoyed today's episode, don't forget to rate, review, and subscribe. If you have any questions on today's topics or suggestions for future episode topics, or if you just want to pick Euler's brain on some more technical details, you can reach out to at least me. I'm on it's mark.me on Blue Sky. All of us are collectively at WatchGuard underscore Technologies on Instagram. And thanks again for listening. And you will hear from us again next week.