In the wake of several high-profile breaches of government networks — from the exfiltration of Office of Personnel Management data on tens of millions of federal employees to the intrusion into the White House’s unclassified network — concerns over nation-state sponsored malware is on the rise.
However, while nation-state actors are usually well funded, trained and resourced, there is nothing particularly special about the work they’re doing, according to Joshua Pitts, director of security research at NopSec.
“Nation-state weapons really are not special or magical — they’re just developed in private,” Pitts said while addressing the crowd at Black Hat 2015 in Las Vegas.
Pitts offered a demonstration of how he was able to manipulate the OnionDuke malware — attributed to Russian-sponsored groups — to create a new exploit with a much lower detection rate by traditional anti-virus software. The process took knowledge of the malware and experience manipulating code, but was otherwise a simple repurposing of a known threat vector.
This is happening in hacking circles around the world right now, Pitts said — nation-state groups included.
“There’s little risk of legal retribution from the original authors,” he noted, as those authors would have to out themselves.
Pitts cited the Destover malware that attacked Sony Entertainment last year. The software was allegedly developed by North Korea, however it is only a few generations removed from the Wiper malware created and used by the NSA in 2012.
Wiper itself is a variation off of the Stuxnet malware that targeted several Iranian facilities, including a nuclear centrifuge. That malware is generally attributed to Israeli and American-sponsored groups, though neither country has officially admitted to having any role in its development.
Pitts said he expects OnionDuke will continue to evolve. (In fact, a variant on the malware — termed Minidionis — tried to infect my computer a few weeks ago.)
Future iterations will likely be very targeted, picking specific versions of Windows to attack and certain applications to spoof.
“It’s very modular,” he said. “It’s going to be seen again because they can recompile OnionDuke, change some settings and get it back to being undetectable again.”
What it won’t be is magic.




