Author Topic: DoubleAgent attack  (Read 2445 times)

0 Members and 1 Guest are viewing this topic.

Offline anarkii

  • Jr. Member
  • **
  • Posts: 54
DoubleAgent attack
« on: March 23, 2017, 02:03:50 PM »
Hi people,
Just wanted to post this here as this could have the potential to really do some damage.

Quote
A new Zero-day attack has emerged that may endanger your antivirus (irony, much?). The new attack, termed DoubleAgent, has the ability to control your antivirus using a Microsoft technology called Application Verifier, and a 15-year old Windows XP era vulnerability.

The hacker may use the Application Verifier, which is a runtime verification tool, in order to discover and fix bugs in applications. He can then inject his own custom verifier into any particular application, in this case, an antivirus. This undocumented ability of the application may allow the attacker to have complete control over the program , which enables him or her to wreak havoc on your system.

The cyber-security research team explains:

Once the attacker has gained control of the antivirus, he may command it to perform malicious operations on behalf of the attacker. Because the antivirus is considered a trusted entity, any malicious operation done by it would be considered legitimate, giving the attacker the ability to bypass all the security products in the organization.
The POC code was tested on the following vendors:

Avast (CVE-2017-5567)
AVG (CVE-2017-5566)
Avira (CVE-2017-6417)
Bitdefender (CVE-2017-6186)
Trend Micro (CVE-2017-5565)
Comodo
ESET
F-Secure
Kaspersky
Malwarebytes
McAfee
Panda
Quick Heal
Norton
What makes DoubleAgent worse than other attacks is that in most hacks, the attacker needs to work a little harder to avoid the antivirus. An attack from something like this gives them the freedom to do as they please, without fear of interference. In essence, there would be no obstacle to stop them fromdestabilizing your system.

Usage cases for DoubleAgent coud be:

Turning the Antivirus into malware
Modifying the Antivirus' internal behavior
Abusing the Antivirus' trusted nature
Destroying the machine
Denial of Service
Additionally, the hacker could run persistence mechanisms on your system, which allows for a permanent presence on that system, even after reboots, updates, reinstalls, patches, etc. Another possibility is the use of a Generic Code Injection Technique to insert malicious code into legitimate processes.

Microsoft has provided vendors with Protected Processes to mitigate code injection attacks by only allowing trusted, signed code to load. No antivirus other than Windows Defender has implemented this design, even though it has been available for three years.

Your best bet right now would be to use Windows Defender, and at least one former Mozilla engineer recommends it.

Could Avast, and other AV products please use that protected process in a update to combat this? Makes me worried that my, and other systems could fall victim to this code.

Source - http://cybellum.com/doubleagent-taking-full-control-antivirus/

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: DoubleAgent attack
« Reply #1 on: March 23, 2017, 02:08:40 PM »

Offline Alikhan

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2220
Re: DoubleAgent attack
« Reply #2 on: March 23, 2017, 04:34:03 PM »
Only Avast 12.3 (and older) version is vulnerable.


Also don't worry about anti malware processes, all our services are anti-malware processes in both Avast/Avg (starting version 17)

Assuming you're using version 17, you are not affected.
Windows 10 Home 64-bit • Avast Free (latest stable version) •  Malwarebytes 4 Premium (On-Demand) • Windows Firewall Control • Google Chrome • LastPass • CCleaner • O&O ShutUp10 •

REDACTED

  • Guest
Re: DoubleAgent attack
« Reply #3 on: March 24, 2017, 11:41:18 PM »
I wonder if this is what happened to me today. (See my new post for details.) I'm not sure what version i was using, but i usually update when prompted. Havoc occurred after installing the update. How do I test if this was the cause? And What can i do about it?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89116
  • No support PMs thanks
Re: DoubleAgent attack
« Reply #4 on: March 24, 2017, 11:57:19 PM »
I wonder if this is what happened to me today. (See my new post for details.) I'm not sure what version i was using, but i usually update when prompted. Havoc occurred after installing the update. How do I test if this was the cause? And What can i do about it?

Given the quoted text in the first post (and the link in Reply #1) I rather doubt it was that, or you would have some very serious issues.

Also if you have avast 17.x.x then that isn't vulnerable according to other topics.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: DoubleAgent attack
« Reply #5 on: March 25, 2017, 04:00:41 AM »
Rajni this issue was fixed long ago and is not a problem if you are using the latest version of avast!