[00:03.040 --> 00:09.640] So, well, first of all, what is the Electronic Frontier Foundation? [00:09.800 --> 00:24.720] If you're not familiar with our work, I did my research as part of the EFF, and we're a digital rights nonprofit, primarily based in the San Francisco Bay Area, although we do work all across the country and the world. [00:25.500 --> 00:40.040] If you have a local group here in New York and you're interested in the work that we do, you can become a member, but you can also possibly join our Electronic Frontiers Alliance group, which brings together people working on important issues. [00:41.380 --> 00:44.880] So we comprise of technologists, lawyers, and activists. [00:45.220 --> 00:47.040] I'm a technologist on staff. [00:47.040 --> 00:55.980] We have a number of lawyers here and a few people that are on our investigations team at EFF here. [00:56.360 --> 00:59.240] You can visit our booth in the main building. [01:00.380 --> 01:08.340] We fight for encryption, privacy, and security on the Internet, which is what I'm going to be talking about today. [01:08.340 --> 01:11.180] You can visit us at EFF.org. [01:12.260 --> 01:13.880] And who am I? [01:14.720 --> 01:16.460] I don't really look like that anymore. [01:18.420 --> 01:21.360] I am a senior staff technologist at EFF. [01:22.300 --> 01:25.420] I work in the public interest technologist team. [01:26.100 --> 01:28.580] We used to be called Tech Projects. [01:28.660 --> 01:29.960] I changed our name recently. [01:30.400 --> 01:43.280] And I work on a threat lab and cybersecurity policy working groups, kind of investigating threats and emerging threats to the security for the public sphere. [01:44.120 --> 01:53.800] Some of the previous work that I've done is HTTPS Everywhere was the lead developer for that from 2015-2018. [01:55.020 --> 01:55.660] Thank you. [01:55.660 --> 01:55.680] Thank you. [01:57.160 --> 01:59.080] One of our browser extensions. [02:02.200 --> 02:13.300] And it's, for those of you who aren't familiar with it, worked to encrypt your connections if an encrypted endpoint was available for the site you're visiting. [02:14.540 --> 02:23.840] And currently, well, I developed Panopticlick, which was actually, I should change the slide, because it's renamed now to Cover Your Tracks. [02:24.000 --> 02:27.200] And you can go and visit it at coveryourtracks.eff.org. [02:27.200 --> 02:29.600] It is a browser fingerprinting tool. [02:29.840 --> 02:42.200] So how can your browser send out little bits of information that are unique about it, and those can be combined into basically a replacement for cookies? [02:42.460 --> 02:50.720] So even though a lot of browsers are deprecating cookies as a tracking mechanism, you can still be tracked through this browser fingerprinting mechanism. [02:51.060 --> 02:53.880] So that's an ongoing project. [02:53.880 --> 03:10.420] And I recently, not too recently, a couple of years ago, introduced AP Keep, which is a command line tool, and you can download Android packages from various sources, Google Play, Huawei App Gallery, FDroid, and others. [03:12.800 --> 03:17.500] And more recently, I've been doing malware reversing, and with a focus on Android specifically. [03:19.200 --> 03:30.120] And with that, well, last time I was here at HOPE, I talked kind of specifically about this piece of malware that I had investigated. [03:30.120 --> 03:37.900] That was an Android malware dropper that used the Tor network to connect and to connect with command and control servers. [03:37.900 --> 03:43.820] And it was part of a... they called it a BNLion malware family. [03:46.860 --> 03:55.120] So BNLion is a class of malware that, with a relevant part here, is that it's modular. [03:55.380 --> 04:07.720] It can use independent modules, and they were launched at the beginning, and each of them, you know, handle separate jobs, and they modify, and they'll, you know, respond to command and control. [04:09.680 --> 04:24.560] And this implementation is clearly organized to easily welcome future modules, so you can see this kind of being broken down into different specific modules that are downloaded by the command, or instructed to be downloaded by the command and control center, [04:24.780 --> 04:27.420] and then used after that. [04:29.640 --> 04:37.300] So some of the modular components that they noted in this BNLion piece of malware were... [04:37.300 --> 04:58.400] Bulk SMS, which allowed you to, I mean, you know, the name is, all that explains it, basically, allows you to, or the malware operators, to send mass SMSs via your device to dynamically inject code into running applications, install different apps without permission, [04:58.900 --> 05:22.680] and lock and disable notifications, you know, disable pin codes, you know, send individual SMSs, and, you know, take screenshots of specific apps, and then send them, and there's also the TeamViewer, which is a legitimate application, but it uses the TeamViewer API to allow it to have real-time [05:22.680 --> 05:24.080] access to your screen. [05:28.500 --> 05:48.780] So, with all that investigation in the past, I got this email from a security researcher, Daniel Milicic, in Canada, and he had noticed that I published this thing about the malware dropper that I had looked into, and spoke about last time at HOPE. [05:48.780 --> 06:11.240] And, you know, he's done some research on these different Android set-top boxes that you get, and they come via, say, Amazon, and right out of the box, you plug it in, connect it to the Internet, and you're already infected with malware. [06:11.240 --> 06:11.940] How convenient. [06:13.440 --> 06:14.160] How convenient. [06:14.160 --> 06:25.080] You can see the supported Internet, you know, supported Internet services, Skype, Facebook, Picasa, Flickr, YouTube, and predominantly malware manufactured in China. [06:26.160 --> 06:39.440] Well, that wasn't mentioned in the advertisement for the Amazon product, but if you look in the review section, it's not that hard to find. [06:39.440 --> 06:40.460] Yeah. [06:41.140 --> 06:41.280] Yeah. [06:41.280 --> 06:41.780] Has malware. [06:42.000 --> 06:42.700] Buyer beware. [06:43.180 --> 06:43.960] Loaded with malware. [06:44.280 --> 06:45.040] Do not buy. [06:45.520 --> 06:45.840] Well. [06:46.520 --> 06:47.700] Well, now you know. [06:50.160 --> 06:52.240] So, this was... [06:52.240 --> 07:00.160] Daniel had published this work and gotten in contact with a few media outlets, such as Wired. [07:00.160 --> 07:14.060] And they had publicized the fact that your Android TV has malware if you buy one of these cheapo no-name brand TV being sold by third parties. [07:14.360 --> 07:20.580] And if you look at the email that he sent me, specifically mentioned Amazon and AliExpress. [07:27.730 --> 07:32.710] So, this is really a kind of element of the digital divide. [07:32.830 --> 07:34.190] Why do we care about this at EFF? [07:34.650 --> 07:43.050] This is something that disproportionately affects those that can't actually afford higher-end devices. [07:43.050 --> 07:55.670] The digital divide kind of points to this problem of those that can afford the latest and greatest devices will be the only ones to actually be able to afford the security that they bring with them. [07:56.610 --> 07:59.390] Secure devices do exist, and they're available. [07:59.790 --> 08:09.710] But cheaper Android devices from no-name manufacturers will come without any added, you know, add protections that, say, Google Play Protect provides to a device. [08:11.190 --> 08:18.010] And disproportionately, at-risk populations, those that need these protections the most, are going to go without them. [08:18.590 --> 08:21.830] So, this is a real problem for consumers in general. [08:21.830 --> 08:25.130] And we're added to botnets in the U.S. [08:25.690 --> 08:29.430] And a lot of the, you know, these set-top boxes are available all across the globe. [08:29.590 --> 08:41.850] But, you know, then they're bought and are provided to, well, you know, those that are unsuspecting of the malware that comes on them. [08:42.370 --> 08:48.970] So, I bought one of these devices to confirm the findings of the researcher. [08:48.970 --> 08:51.070] It was not a hard analysis. [08:51.670 --> 08:59.870] Basically, it sent some DNS requests specifically to the command and control servers that you could see plainly by a dynamic analysis. [09:00.290 --> 09:03.350] And, okay, you know, that's confirmed. [09:03.350 --> 09:14.590] So, I published a blog post about it with, you know, after fact-checking and doing that work, confirming that this was a problem. [09:14.910 --> 09:21.610] You know, don't buy these devices that will compromise your security. [09:23.210 --> 09:34.030] And six months later, we had an article, a very extensive research done by a security firm called Human Security. [09:34.290 --> 09:38.970] And they looked much deeper into what this was actually doing. [09:39.910 --> 09:49.050] So, they found that there were a lot of modules that this specific type of malware included. [09:50.070 --> 09:54.190] So, yeah, just kind of read this if you'll bear with me for a moment. [09:54.670 --> 10:02.710] At its simplest, Badbox is a global network of consumer products with firmware backdoors installed and sold in the normal hardware supply chain. [10:02.710 --> 10:08.490] These backdoors find their way into the homes and offices of unsuspecting owners. [10:08.490 --> 10:15.530] And they immediately connect to a CNC server and get the instructions to do the next stage of the attack. [10:17.550 --> 10:21.470] And those attacks include ad fraud. [10:21.970 --> 10:26.410] And so, this will happen on a web view in Android. [10:26.410 --> 10:30.590] And those will not be connected to any specific application running. [10:30.590 --> 10:40.370] It'll, you know, go through and display a web view disconnected from any, you know, specific application that you've installed. [10:47.530 --> 10:48.990] I saw it on my screen. [10:49.170 --> 10:50.150] It's not exactly mirrored. [10:50.750 --> 10:51.390] Okay. [10:52.110 --> 10:52.890] All right. [10:53.910 --> 10:54.550] Okay. [10:54.890 --> 10:56.270] I think there might be a delay. [10:56.970 --> 11:00.490] So, residential proxy services is a big one. [11:00.490 --> 11:11.490] It basically means that the botnet operators are able to use your home connection as the endpoint for a VPN that they control. [11:12.250 --> 11:25.370] And that opens up all sorts of risks to you because you don't know what the botnet operators or those that they're selling to are doing with that home connection. [11:26.070 --> 11:38.970] So, it can look like you're, you know, committing crimes and buying drugs and, you know, buying, you know, humans, whatever the case may be. [11:39.370 --> 11:43.410] And, you know, it just all looks like it's coming from your home connection. [11:43.410 --> 11:50.150] And so, that exposes these customers to extreme legal risk. [11:52.930 --> 12:04.290] Also, they observed this fake email campaign and basically intercepting SMS messages when a one-time password is sent to the device. [12:04.290 --> 12:18.470] They suspect this is to register you for Internet messaging, you know, a signal or, you know, your WhatsApp accounts that need that verification process to happen. [12:18.670 --> 12:26.210] Well, they'll interrupt that OTP and be able to register an account that they can use for, presumably for spam, but who knows. [12:28.350 --> 12:35.810] And then also, go on and install further applications onto your set-top device. [12:39.040 --> 12:46.820] So, just to go into the fraud network operation that they found, it was not only Android devices that were targeted. [12:47.060 --> 12:52.460] Android devices were targeted with the badbox component, which is the pre-installed malware component. [12:52.460 --> 12:59.640] But a lot of iOS devices had this other component of the fraud operation called Peach Pit. [12:59.820 --> 13:07.980] And that means that you have to go and manually install an application that has this component that's, you know, baked into it. [13:08.120 --> 13:14.700] And that'll allow your iOS device to then, you know, participate in the click fraud operation. [13:14.700 --> 13:22.400] So, there's badbox, which is pre-installed Android set-top boxes predominantly, but other Android devices. [13:22.700 --> 13:29.820] And then there's, you know, the Peach Pit component of it, which is just the installed applications that, you know, operated on iOS. [13:30.360 --> 13:38.920] And the app market was able to remove those pretty quickly, but they had infected a large amount of iOS devices. [13:38.920 --> 13:40.560] I'll go into exactly how many in a minute. [13:41.560 --> 13:50.000] Supply chain infection that was multi-platform indicates really kind of comprehensive, large-scale operation that's happening. [13:50.560 --> 13:53.260] And it's not just some small-time operation. [13:53.800 --> 13:58.880] Peach Pit had been installed on 121,000 Android devices. [13:58.880 --> 14:06.780] So, yeah, the applications that comprise Peach Pit are both, you know, installed Android applications and installed iOS applications. [14:09.000 --> 14:12.080] And 159,000 iOS devices. [14:12.520 --> 14:25.380] So, this was generating traffic for this ad fraud network on a rate of 4 billion ad clicks a day, which is pretty significant. [14:25.380 --> 14:39.300] So, they noted that it was a variant of a Triada malware, which is actually very similar to Bien Leon, in that it's a modular piece of malware that allows for, you know, new installation of different components of it. [14:40.420 --> 14:40.920] Yeah. [14:41.380 --> 14:44.460] But it's a variant of a Triada malware, Bien Leon. [14:44.540 --> 14:53.180] You can see this is some of the whitelist of applications from a communication with the command and control center. [14:53.180 --> 15:01.260] And this is specifying what applications to attach the malicious functionality to. [15:01.540 --> 15:03.000] These are persistent applications. [15:03.240 --> 15:09.840] The DBG launcher, I think, was the one where we did for the TV set-top box, the T95. [15:11.300 --> 15:16.780] And that application was basically running in the background. [15:16.840 --> 15:18.300] It's an application launcher. [15:18.300 --> 15:25.880] And so, it is running in the background all the time and able to persist in that way. [15:29.120 --> 15:42.300] This is a graphic of the Triada malware family that Kaspersky, the recently banned Kaspersky, had kind of come up with. [15:42.300 --> 15:52.580] And they had a pretty good graphic of what the kind of infrastructure of the Triada malware really looks like. [15:52.760 --> 16:01.180] This Zygote process, which is a low-level Android application that helps basically spawn other Android applications. [16:01.180 --> 16:13.220] And it allows you to share the code between numerous applications on the Delvic or Arc VM that Android devices are running. [16:13.520 --> 16:20.120] And so, it'll embed itself into each of these applications, in turn, as they're launched. [16:20.120 --> 16:25.060] And so, they'll see, oh, this is a, say, you know, the phone application. [16:25.920 --> 16:38.680] And, you know, being that this is a phone application, I am, you know, this is the piece of malware that's embedded in that specific application, com.android.phone, will identify, oh, okay, this is the phone application. [16:38.680 --> 16:44.800] I will enable mobile networking and, you know, check for incoming SMS messages. [16:45.640 --> 16:48.400] Oh, okay, this is the settings application. [16:48.400 --> 16:51.580] And I'm going to allow, you know, the sending of SMSs. [16:51.920 --> 16:56.260] Oh, okay, this is, you know, some filtered app that, you know, there's nothing happening in. [16:56.620 --> 17:04.240] So, it's kind of embedded in itself in each of, kind of, each of the applications running on an Android system. [17:04.560 --> 17:13.940] And then it'll interact with the modules of the malware in order to specify, oh, okay, this is a new piece of code that goes into Zygote. [17:13.940 --> 17:20.260] And then Zygote will deploy that to all the applications in turn. [17:20.500 --> 17:24.900] So, it allows for this kind of code sharing that's throughout the Android system. [17:28.360 --> 17:36.640] So, yeah, this kind of explains how Triada works and how, kind of, it is able to persist. [17:37.140 --> 17:42.920] One of the most significant parts of this is that it's a ROM malware. [17:42.920 --> 17:48.580] So, it embeds itself very low in the system ROM. [17:49.020 --> 17:54.320] And it is, you know, not dependent on, you know, running any specific application. [17:54.320 --> 18:01.640] So, and it makes it so that it is really hard to detect and really hard to get rid of on your system. [18:02.480 --> 18:06.540] So, it kind of attacks very low level permissions. [18:07.140 --> 18:13.840] And it's, you know, embedded in the live Android runtime, which is, you know, part of the memory of all running applications. [18:13.840 --> 18:34.880] And so, what the researchers at Human kind of discovered it doing is the live Android runtime was launching installation of this com.jar app that would, that would basically initiate the initial communication with command and control center. [18:37.900 --> 18:49.820] And so, some open questions on this, like, okay, so which devices, other than the ones that we've seen directly, are actually initiating this attack? [18:50.120 --> 18:53.560] With the ones that we've observed, obviously, but which others? [18:54.660 --> 18:57.020] And how widespread is this operation? [18:57.840 --> 18:59.560] Like, is it just these? [18:59.880 --> 19:06.560] Or is, like, is there a, like, new pieces of hardware being developed all the time? [19:06.760 --> 19:21.040] Well, we've seen a few generations that there is the T95 and then the T95 Max, which are two different set-top boxes that were, you know, had this malware implanted somewhere in the manufacturer process before it's delivered to the resellers. [19:21.040 --> 19:23.480] So, this is kind of an ongoing operation. [19:23.780 --> 19:24.760] How widespread is it? [19:25.060 --> 19:33.320] And are there other operations that are just like this one, that aren't run by the same fraudsters, but are operated by similar? [19:34.920 --> 19:42.920] And what's the likelihood of any given app that I might buy that just some, you know, new name manufacturer creates? [19:43.020 --> 19:47.320] What's the likelihood that it's just, you know, comes out of the box infected with malware? [19:49.340 --> 19:54.120] And that'll, you know, obviously open consumers up to a significant risk, if it is. [19:54.400 --> 19:58.940] And there are other motivations other than just the profit motive at play here. [19:59.140 --> 20:04.740] Is it something else that is, you know, are there, like, nation states that are engaging in this? [20:05.400 --> 20:12.480] Which we didn't, to be clear, we didn't observe, but, you know, are there other kind of motivations at play? [20:14.900 --> 20:26.100] And, yeah, like, these devices are installed throughout a country and kind of various locations, whoever happens to buy the box and install it on their network. [20:26.100 --> 20:40.460] So, since these are, you know, throughout a locality, then is it a threat that they might be in close proximity to some critical infrastructure? [20:40.460 --> 20:53.460] For instance, if, you know, it's installed on a work center or a workspace, you know, for instance, close to some, you know, water supply or something like that. [20:53.580 --> 21:03.400] Is that going to then attack the water supply and really have this kind of really pernicious effect that we can see? [21:04.700 --> 21:09.260] And kind of like, you know, a meta question to all these questions is, like, how do we even start looking? [21:09.840 --> 21:12.120] Like, how do we start answering these questions? [21:12.540 --> 21:17.780] Where do we start looking just to ask the question or no questions that even ask? [21:19.630 --> 21:35.890] So, some of the questions have been answered by human security, like 74,000 individual products were observed across 227 countries that they had... [21:35.890 --> 21:45.330] Basically, human security kind of runs this piece of, I guess, a real-time antivirus like that. [21:45.430 --> 21:51.250] It will monitor infection on your device and then it all kind of allow... [21:51.250 --> 21:53.550] It kind of allows some insights to them. [21:54.090 --> 22:02.630] And they observed this kind of broad array of devices being, you know, having this. [22:03.610 --> 22:19.730] And the Satori team, which is their researchers, found that there were 200 different Android devices operating in this bad box malware pre-installed on devices. [22:20.590 --> 22:26.630] And mobile phones, tablets, and the TV products that we've observed. [22:30.450 --> 22:50.130] So, methodologically, how do we kind of look into how we might test devices to see whether they have malware in some comprehensive way and detect whether the instance of compromise and how generalizable to the whole... [22:50.130 --> 22:50.810] Yeah. [22:51.330 --> 22:51.570] Yeah. [22:51.570 --> 22:55.250] In a way that's generalizable to the entire Android ecosystem. [22:56.150 --> 23:06.090] And that we can kind of have a test that basically indicates that we've discovered this. [23:07.030 --> 23:09.130] So, we're thinking broad picture, right? [23:09.750 --> 23:16.190] And we're thinking, like, how do we even start to get the scale of this attack? [23:17.530 --> 23:25.150] And it's a few different methodologies that I think might be effective. [23:25.930 --> 23:27.670] So, random sampling, right? [23:28.470 --> 23:44.410] Select a number of devices from different little-known manufacturers that might have this malware and conduct some in-depth investigation into whether it, in fact, does have this, you know, malware included when it's being sold. [23:44.410 --> 23:50.790] And then generalize those results over the entire app or the entire device ecosystem. [23:52.370 --> 23:56.430] Then there might be something like you can do with a backbone traffic analysis. [23:56.430 --> 24:13.010] So, you might want to coordinate with some backbone provider, say Akamai, and analyze historical or real-time communication with known C2 servers in some kind of privacy-protecting manner. [24:13.010 --> 24:40.210] There's different novel privacy-protecting information-sharing techniques like distributed aggregation that will allow you to get some of these statistics and then kind of just infer how many devices that are infected through, you know, seeing how many unique endpoints have been affected in this. [24:43.150 --> 24:57.790] So, I proposed this to the IEEE and they kind of accepted this research proposal that will look into how much, you know, Android, how broad this supply chain attack actually is. [24:58.510 --> 25:03.970] And what we might do about it significantly what we might actually do about it, right? [25:04.810 --> 25:11.990] So, let me talk about these two different methodological tactics in depth a little bit more. [25:12.350 --> 25:22.890] So, you can, you know, taking a random sampling of devices, do this preliminary review, which involves known indications of compromise. [25:24.470 --> 25:30.110] There's, you know, some IOCs that have been published in the Human Security Report. [25:31.230 --> 25:43.370] And then, you know, you can take, you know, the compromised or injected app IDs and look at those and see if, well, okay, there's this attachment process that happens. [25:43.370 --> 25:53.190] Well, okay, this means that it might be a legitimate app that actually is, you know, not, it's not, you know, just positive. [25:53.350 --> 26:02.590] It's not guaranteed that that is an infected app because there's this injection that happens to the app. [26:02.590 --> 26:22.080] So, but if there are malware operators or the list that I showed you before are not really, you know, well-known apps, they can change and they can, they could, you know, make it some, some, you know, widely deployed app. [26:22.080 --> 26:33.800] But right now we've seen that they're really targeting these very specific apps like DBG launcher and things like that, that are not, you know, something that everyone has installed. [26:34.580 --> 26:41.300] So we can look at those app IDs and see if one of those are, you know, is installed on the system. [26:42.760 --> 27:03.380] And you can look at if they are actually connecting with command and control centers and if they're sending some mystery traffic, something that you might not be able to see, or you may be able to see if you use tools like Frida to unpin an app's connection with a command and control centers. [27:04.020 --> 27:12.380] So you can kind of do introspection of HTTPS traffic using Frida, which is a little bit of methodology that I covered in the last talk at HOPE. [27:15.020 --> 27:22.420] You can look for the presence of core Java, which is kind of the working directory of this malware, this strain of malware. [27:23.220 --> 27:32.060] There are a few directories that it creates in order to, you know, basically keep track of its own operations. [27:32.500 --> 27:40.900] And so these, the presence of these will be a pretty good indication of malware compromise on that device. [27:40.900 --> 28:08.240] And then you can check resources that collect the app hashes of known malware and compare the list of apps that are installed on any given device with, you know, say like the VirusTotal resource, which we'll collect and you can, you know, look up the apps and see if they're compromised on [28:08.240 --> 28:08.980] VirusTotal. [28:11.500 --> 28:20.400] And then, you know, that kind of will give us some, you know, surface level idea of whether it's worth following up on at all. [28:21.320 --> 28:38.980] But we can do some more in-depth analysis by checking out manifests, by checking, you know, the presence of obfuscated or, you know, reversing the code and seeing whether there's, you know, obfuscation involved in the code. [28:38.980 --> 28:42.300] A lot of apps will do obfuscation which aren't malicious. [28:42.680 --> 28:44.860] So that in itself is inconclusive. [28:45.180 --> 28:51.820] But a lot of malware, most malware will employ some kind of obfuscation technique. [28:53.780 --> 29:09.000] So we kind of have some methods available to us to detect whether there is malware installed on a, you know, random piece of hardware that we buy from a no-name manufacturer. [29:12.100 --> 29:16.460] But we might want to look at this other methodology of a backbone Internet traffic analysis. [29:16.860 --> 29:24.940] And I think that, you know, we can look at some indicators of, okay, the shape of the traffic that is being sent. [29:24.940 --> 29:45.020] You know, certain timing characteristics or package size or, you know, maybe there's a weirdness in the X509 certificate that is, that's part of the HTVS communication between the command and control center. [29:45.420 --> 29:54.260] And if they're, you know, even encrypted traffic, it might be a useful template for discovering whether there's communication happening with the C2. [29:55.620 --> 30:11.400] We can kind of combine this with showdown.io, which is kind of a search engine for devices, or fofa.info, which is similar, but will center on the East Asian part of the globe. [30:11.580 --> 30:13.940] And we can use those to detect malware. [30:15.560 --> 30:31.140] We can look into whether there's identical certificates with known compromised devices that are, you know, that they're communicating, that they might have with another, you know, potential, oh, were you sure this is a C2 server? [30:31.140 --> 30:35.880] Well, if it's an identical certificate, then we might discover that. [30:36.680 --> 30:51.340] Looking at the user agent string that's been used on a known C2 endpoint, and searching for that via fofa.info. [30:52.500 --> 30:57.260] So we might begin to kind of, you know, peel back the layers. [30:57.480 --> 31:06.080] And, you know, like I started this analysis, and I think that I learned some things, I just kind of went down the rabbit hole. [31:08.380 --> 31:30.800] We kind of get a shape of, like, what C2 servers are out there, but we just follow a small thread, you know, for me, without access to a backbone provider, I am able to look at, you know, this IP, for instance, has the same certificate as these other IP addresses, [31:30.820 --> 31:42.460] you know, serving, they were actually serving malware, or, you know, operating a C2 server in, and then, you know, this user agent string that, you know, was present, was, you know, present on this. [31:42.620 --> 31:57.780] So you kind of start to get the outlines of the operation, but without some broad Internet survey, some large traffic analysis that, you know, you can't, you only tug at some small threads, I think. [32:00.460 --> 32:03.300] So I think that there needs to be some follow-up research. [32:04.220 --> 32:09.240] And, you know, what, uh, well, that's my thread. [32:11.380 --> 32:19.240] Yeah, so, so, um, what other ways are more vulnerable populations put at greater digital security risk? [32:19.240 --> 32:25.580] Um, it is, uh, kind of, uh, uh, topic of, of, um, relevance here. [32:26.000 --> 32:29.200] And I think that could be, uh, a lot more research done in that. [32:30.420 --> 32:34.080] And who is behind this bad box, Peach Pit Fraud Network? [32:34.280 --> 32:41.340] We, you know, have started to, we were looking at them from behind the screen, but what is the fraud? [32:41.420 --> 32:43.020] Was a fraud network kind of socially? [32:43.180 --> 32:44.120] How is it constructed? [32:46.080 --> 32:50.840] What accountability measures can be effective, uh, for this network? [32:51.140 --> 33:04.000] And what can we do as activists, as, uh, as, you know, public interest technologists, et cetera, to, to kind of, you know, make these accountability measures, you know, come to bear? [33:05.040 --> 33:11.300] What damage has the proxy network for, you know, on people's endpoint devices done already? [33:13.080 --> 33:22.260] And what, uh, potential for harm is, you know, in critical infrastructure, for instance, is, is, um, these, are, are these compromised devices doing? [33:22.920 --> 33:30.780] Can we kind of pivot the findings that we find here to, uh, discover additional criminal fraud networks, um, putting the public at risk? [33:31.520 --> 33:36.180] And, uh, what resources can we leverage to harden the supply chain in general? [33:36.760 --> 33:53.620] Um, there's been, for instance, since he's, uh, uh, a lot in the cybersecurity and information security agencies, uh, procurement plan, a lot of, uh, uh, you know, uh, manifests basically of, of, uh, uh, what components do, does this, um, software that we're, [33:53.620 --> 33:55.360] what we're procuring have? [33:55.360 --> 34:16.020] And, um, when there's a vulnerability that's found, for instance, in some software that we've, uh, deployed, uh, in the federal government, for instance, then, um, you know, we're, we're able to reference that manifest and see, okay, well, these agencies need to deploy these fixes in order to blah, [34:16.040 --> 34:16.300] blah, blah. [34:20.240 --> 34:26.720] So, I think that there are some effective remedies that can come from, like, regulatory bodies here. [34:27.120 --> 34:39.120] Say, the FTC, um, you know, which controls trade and the Consumer Protection Bureau on the federal level, Congress, yeah, no. [34:40.160 --> 35:01.020] Executive branch, there have been some executive orders that have been given, um, kind of ineffectively, and, um, in February, the Biden administration, uh, issued an executive order that banned, uh, you know, the sale of, uh, data broker collected data to countries of interest. [35:01.200 --> 35:07.480] Well, actually, we would just like our data not to be sold to anyone, not just countries of interest. [35:08.020 --> 35:13.260] Well, okay, but it does show that they can issue effective executive orders, at least. [35:13.260 --> 35:16.320] Um, so, um, so that might be a remedy. [35:17.100 --> 35:25.140] Um, you know, there might be something that can come from trade agreements to ensure that there is regulation, uh, in consumer products. [35:27.280 --> 35:33.580] But, you know, these manufacturers are mainly based in China and, uh, methods of directly sanctioning. [35:33.720 --> 35:38.420] The companies that manufacture these devices aren't, uh, really effective. [35:38.420 --> 35:41.100] And they kind of have limited effect. [35:42.600 --> 35:47.700] The resellers are still making these devices available. [35:48.200 --> 35:57.840] Like, that screenshot of these devices available on Amazon is, like, two days ago when I put these slides together. [35:57.840 --> 36:08.300] And so, yeah, these are not, uh, these, these are, these are devices that are still, you know, available on the public markets that are still being sold. [36:08.440 --> 36:14.040] They're still, uh, opening up VPN endpoints on anyone that plugs them in. [36:14.040 --> 36:20.680] So, we, uh, at EFF issued a complaint to the FTC. [36:21.140 --> 36:27.600] And we said, hey, this is, these are devices that are still being manufactured. [36:27.820 --> 36:29.000] They're still being sold. [36:29.000 --> 36:46.320] Uh, and, uh, the, the, the fraud network itself had been kind of, uh, due to a lot of really great research and a lot of exposing it, um, that these, the, the malware, the, um, the malware network, the fraud network, a lot of the servers were taken down, [36:46.340 --> 36:54.800] um, kind of directly as a result of a lot of the, uh, reporting that human security and, uh, Daniel Milicic and, and, and, you know, we brought to it. [36:54.800 --> 37:00.080] And so, um, but this is just a general problem. [37:00.220 --> 37:19.360] This doesn't, it doesn't prevent this from just happening again, um, from another malware fraud network from, from just manufacturing devices, which they sell on Amazon and give to anyone, uh, and to make a huge killing off of, uh, you know, people's home connections. [37:19.360 --> 37:43.000] So we issued a, uh, complaint letter to the FTC, uh, not about the manufacturers, but about the resellers, because the FTC has regulatory obligation to ensure that, uh, unfair and deceptive business practices, like not notifying customers that there might be malware or there is malware that we've [37:43.000 --> 37:48.920] documented, install on these devices, um, that they're, that, that you're, they're selling these devices. [37:48.920 --> 37:53.120] And they're not notifying their customers that, yeah, this is a TV box that also has malware. [37:53.360 --> 37:57.720] Um, they're, that's unfair and deceptive and deceptive. [37:57.800 --> 38:04.160] And FTC's mandate is to ensure that unfair and deceptive business practices do not occur. [38:04.440 --> 38:10.100] Um, or at least we're protected from them via measures that FTC can take. [38:10.100 --> 38:17.100] Uh, we also cc'd, uh, CISA, um, Jenna Easterly, as this is a supply chain attack. [38:17.380 --> 38:24.880] Uh, we, uh, cc'd the, uh, the, uh, director of CISA and, uh, you know, let them know about it. [38:25.060 --> 38:35.700] So there, uh, is some regulatory action that we hope, uh, will be taken, um, and we're going to be following up with the FTC. [38:35.700 --> 38:43.480] We're going to be conducting more research and we're going to explore avenues of, of shutting this kind of attack down. [38:44.000 --> 38:47.900] Um, it's very preliminary stages, but we'll do what we can. [38:49.060 --> 38:57.200] Um, yeah, with that, I think, that brings us to our Q and A if we have time for it. [39:09.730 --> 39:12.790] Yes, we do have, we do have time. [39:17.400 --> 39:19.780] So it looks like we have time for a few questions. [39:19.960 --> 39:20.220] Yes. [39:20.720 --> 39:22.200] Ah, and now the mic works. [39:22.300 --> 39:24.000] So we do have time for a couple of questions. [39:24.160 --> 39:27.000] So please line up here or ask in the matrix. [39:30.570 --> 39:32.410] Hey, uh, excellent talk. [39:32.570 --> 39:34.350] This is really important stuff. [39:34.510 --> 39:40.170] I think in terms of supply chain risk seems to be an increasingly relevant topic or maybe just one we're increasingly aware of. [39:40.170 --> 40:01.130] Uh, my mind went to recently what was revealed with regard to xzutils and the, uh, you know, the open-source contributor that appears now to have just been a cutout potentially for like a nation state funded, you know, contributor, uh, uh, persona to insert a vulnerability into an open-source [40:01.130 --> 40:08.310] library and get that more widely, uh, distributed across the, um, the industry just everywhere. [40:08.310 --> 40:16.050] Uh, so it made me think of kind of the, the S bombs that you mentioned, like the software manifest, uh, uh, software bills and materials. [40:16.270 --> 40:18.030] And I think that's an important effort. [40:18.390 --> 40:32.190] Uh, also heard chatter and, and some thought about like us, like the feds trying to put together like a us gov nix distro, you know, something that they would consider like a trusted platform to build on top of. [40:32.190 --> 40:35.330] And I just wonder if you've heard of that or have any thoughts of that. [40:35.690 --> 40:47.630] Um, my thinking would be that, you know, if they would do that and then that would be relied on by anybody like five eyes or even outside of that, like why would any, like, then it just becomes, you know, who's, who do you trust? [40:47.630 --> 40:58.910] Or, you know, if that's not going to be source that you personally can inspect or that, you know, the community can inspect that it's just another, you just pick your poison, you know, who do you want building a back door into your platform? [40:58.910 --> 40:59.090] Right. [40:59.590 --> 41:00.150] Yeah. [41:00.470 --> 41:08.170] Um, as an anarchist, I'm not really, uh, fond of creating distros that are manufactured directly by the U.S. government. [41:08.170 --> 41:16.690] And even if they're open-source can have, you know, subtle vulnerabilities that can lead to compromise with xz utils, for instance. [41:17.210 --> 41:28.050] Um, they only discovered it after a, uh, researcher, or sorry, a developer that, um, worked on PostgreSQL, uh, basically did some benchmarking. [41:28.050 --> 41:32.290] And found that it was running hot. [41:32.610 --> 41:34.030] And why is it running hot? [41:34.310 --> 41:35.810] It isn't doing anything right now. [41:35.930 --> 41:45.670] And we discovered that, uh, oh, actually it's subtly adding some keys into your manifest, or your, uh, your, uh, your SSH, or authorized keys or something like that. [41:45.830 --> 41:56.150] Like, not directly, but effectively, um, in order to, uh, allow someone to access, uh, your SSH server. [41:56.150 --> 42:03.090] Uh, after that, I installed fwknop, uh, which is a port knocker, um, all my public, uh, facing servers. [42:03.090 --> 42:07.590] Yeah, that's, that's kind of, um, yeah. [42:07.870 --> 42:19.650] How do we, I think that here, like, the answer is just more rigorous testing and making sure that, well, a government, all the resources that they would put into U.S. [42:19.830 --> 42:20.830] or, you know, U.S. [42:20.930 --> 42:21.890] gov distro or something. [42:21.890 --> 42:35.350] Why don't they, like, just give those a project that are already doing this work to harden, say, like, the kernel, um, to, um, you know, um, there's, uh, you know, you know, for instance, graphene, which was copperhead OS is hardening, hardening the Android kernel. [42:35.350 --> 42:43.510] And, and, yeah, there are some usability concerns with that, but I think that, um, that's a good effort, a good kind of, you know, use of time and energy. [42:43.970 --> 42:45.430] So, you know, the U.S. [42:45.570 --> 42:48.790] government can, can, you know, give to those existing efforts, I think. [42:48.790 --> 42:56.990] Um, and that would be a lot more trustworthy than creating their own thing, which is possibly opaque and, yeah. [42:58.790 --> 43:01.130] We have one question from Matrix. [43:01.530 --> 43:08.210] Uh, if you could explain in a bit of detail how the Bianlian payload got permissions to install apps. [43:08.730 --> 43:09.330] Mm-hmm. [43:10.050 --> 43:15.250] So, in the Bianlian, um, it was a direct installation. [43:15.250 --> 43:22.410] So, that was the case of malware that I, uh, looked into a couple of years ago and presented here at HOPE. [43:23.090 --> 43:30.110] Um, and for the Bianlian family, uh, it was the installation of fake banking. [43:30.350 --> 43:33.130] It was all, you know, largely fake, fake banking apps. [43:33.470 --> 43:51.070] And then it would use accessibility permissions in Android, which is a very broad permission that allows, uh, Android, that allows apps to, um, well, presumably, well, legitimate apps allows them to help people with, um, with, uh, uh, accessibility concerns to, [43:51.410 --> 43:59.150] to, you know, um, do things on the, uh, to allow it to do things, uh, for people that suffer from that. [43:59.150 --> 44:06.390] And so, it's using this permission that, that's, um, very low-level, uh, accessibility permission. [44:06.910 --> 44:14.490] Um, and then we observed that you click on allow that permission that it opens a bunch of windows really quickly and does this permissions thing. [44:14.630 --> 44:18.750] And then it kind of, you know, it, it stops that app from running. [44:18.970 --> 44:21.470] And, yeah, very shady shit. [44:21.930 --> 44:27.330] Um, but, uh, that's how the Bianlian, uh, malware that I investigated did it. [44:27.330 --> 44:32.990] It was banking, you know, largely, though, banking apps that you install and then it asks for accessibility permissions. [44:33.890 --> 44:34.450] Okay, cool. [44:34.730 --> 44:37.390] Thank you very much for your presentation and for all the work you do. [44:37.850 --> 44:43.930] Um, and also thank you for sharing with us the indication, indications of compromise that we can look into. [44:44.670 --> 44:50.930] Um, my question is, how can we help educate the less technical, uh, folks on these kinds of things? [44:51.070 --> 44:55.250] Is there, you know, what strategies would you recommend for, for protecting these people? [44:55.250 --> 45:04.430] Because as you say, um, this is the kind of thing that, uh, disproportionately impacts those who are of lower, uh, social economic class or, uh, technical ability. [45:04.850 --> 45:04.970] Yeah. [45:05.090 --> 45:05.210] Thank you. [45:05.350 --> 45:05.450] Yeah. [45:06.030 --> 45:23.170] So I think that one thing we can do is to let people know that if they're buying a no-name device from a no-name manufacturer that doesn't have the investment in their reputation from, you know, uh, some malware being installed on the devices that they control. [45:23.170 --> 45:43.070] If they're buying from these no-name manufacturers that they just take a bit of time to research, you know, this device malware, um, just pop that into Google and that'll give you some indication of we, if we know that that device has already been compromised. [45:43.070 --> 45:49.250] Um, that being said, I would kind of just discourage people from buying these no-name devices. [45:49.650 --> 46:09.390] Um, they might want to invest if they can, if they have the resources to, uh, instead of a Internet connected IOT device, you might, um, you know, want to invest a little bit of money into some home, uh, assistant device or some, some, uh, uh, device that uses a wireless, [46:09.390 --> 46:13.050] uh, network that is not Internet connected. [46:13.050 --> 46:14.590] Like ZigBee or Z-Wave. [46:14.810 --> 46:18.650] Um, those are possibilities if you're like looking into IOT things. [46:19.030 --> 46:28.550] Um, but it's a hard problem because by and large people are going to choose products that are, you know, the cheapest and that's available to them. [46:28.850 --> 46:37.710] Um, uh, and so we, we kind of, I would just encourage product research, um, before buying. [46:37.710 --> 46:40.070] Um, and that's, I guess, the best you can do. [46:42.470 --> 46:50.370] Okay, um, so I'm just going to try to, I think you're kind of asking for input, so I'm going to try to offer that. [46:50.930 --> 46:55.410] Um, and, um, I, all I can do is just try to say the quiet part out loud. [46:55.730 --> 47:00.530] Um, which is that in the short to medium term, nothing is going to protect the general public from this. [47:00.690 --> 47:06.870] None of the, um, um, official, um, um, branches of government are going to do anything substantial. [47:06.870 --> 47:12.790] And nothing that we can do in the short to medium term can, uh, make a big dent to it, in it for the general public. [47:13.210 --> 47:17.350] Um, and nothing may be done about it until perhaps this is used in a world war. [47:17.750 --> 47:24.490] Um, and I think we, um, and I think we, uh, um, I think we just have to acknowledge these are very difficult problems. [47:24.690 --> 47:42.490] Um, and the, and the root of the problem is that, um, since, um, the popularization of Internet devices, um, the, um, a big part of the power structure, the corporate world is very invested in the idea that, um, the, um, electronics and the, um, they did, [47:42.550 --> 47:51.470] sorry, the digital world and the Internet allows you to do all sorts of things behind the consumer's back that are not in the consumer's interest and that you don't want the consumer finding out about. [47:51.990 --> 48:00.310] Um, and so we, so you, if you, there's no way to make a dent in this, in the problems you mentioned without confronting that. [48:00.770 --> 48:03.650] Um, so in the long-term, what you have to do is change the culture. [48:04.170 --> 48:20.390] Um, you have to work on these very long-term efforts that build towards, that, um, work towards building awareness that, no, it, you, you are not safe just trusting, um, these one, the, um, these digital devices that are so hyped and, um, not looking... [48:20.390 --> 48:21.590] I partially agree with you. [48:21.870 --> 48:23.030] I partially agree with you. [48:23.090 --> 48:28.630] I think that there are some things that we can do to mitigate the harms that are being done. [48:28.770 --> 48:37.910] You know, for instance, you know, the existence, say, of, uh, Google Play services, for instance, uh, we are, uh, you know, verifying apps running in real-time. [48:37.910 --> 48:50.530] The existence of, say, Copperhead and Graphene OS, um, that can, uh, really, you know, uh, kill, uh, uh, apps, um, that are doing shady, um, you know, initiation of process, um, things. [48:50.850 --> 48:56.830] So I think that we can kind of begin to eat, you know, down at some of the vulnerabilities. [48:56.830 --> 49:08.990] Um, we've seen effective mechanisms that are at play, um, with, for instance, um, you know, uh, a, uh, you know, not certificate transparency, but, but app transparency. [49:09.290 --> 49:14.810] And, and, you know, there, you know, you need to assign an app in order for it to be deployed. [49:14.810 --> 49:31.510] And there's been a lot of work in the Linux world where, for instance, in, um, you know, the fact that, uh, you have reproducible builds, um, that the source code is directly translated into the, um, you know, the, uh, the, uh, the product that you get, [49:31.710 --> 49:33.350] the binary that's produced. [49:33.570 --> 49:36.250] So I think that, like, there, there are mitigation strategies. [49:36.530 --> 49:50.530] I agree that a lot of the vulnerabilities that we see are going to make a large and possibly disastrous impact on, that's why I mentioned, for instance, uh, critical infrastructure, right? [49:50.530 --> 49:59.990] And, um, and yeah, um, I think that we can just do our best to, to try to make that situation or avoid that situation. [50:00.990 --> 50:02.550] Unfortunately, we're out of time. [50:02.670 --> 50:06.010] Where can people find you if they still have questions after the talk? [50:06.090 --> 50:08.410] Yeah, you can email me bill at EFF.org. [50:08.730 --> 50:14.870] You can also go to our website EFF.org and see some of the, uh, research that I've done. [50:14.870 --> 50:29.290] Um, um, um, if you, uh, want to see more of it and want to see us kind of investigate this class of, of, of, uh, malware and in this kind of supply chain attack more, you can go to EFF.org slash supporters and, uh, and donate to us. [50:29.650 --> 50:30.510] Um, yeah. [50:31.010 --> 50:33.250] Thanks a lot and huge round of applause to Bill. [50:33.250 --> 50:33.910] Thank you.