📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

The Most Mysterious File On The Internet

Cybernews34:54

Transcription

In an internet cafe, several rows of computers breathe loudly with only a fan mounted on the ceiling. Locals and soldiers sweat as they browse the internet. In the height of summer, the heat of Kabul is not easy to handle, even for the Afghans.

The doorbell rings. A soldier walks in. He patiently waits for his turn at a computer. Finally, a chair frees up. He sits down and logs in, checking his emails, Skype messages, and news. Nothing important, mostly spam. He reaches into his pocket and pulls out a USB stick. He plugs it in. A folder opens automatically. There it is. His military plan for the week. He scrolls through the PDF file. Nothing but bureaucratic BS. Very ordinary. Very mundane. Dizzy from the heat, he stands up, unplugs the USB, and turns off the computer.

The soldier has just made a huge mistake. Perhaps the worst of his career. His USB is no longer mundane. It is a vessel. And in a few hours, he will get back to work and plug it straight into his professional network. And in that moment, everything will begin. The US military will suffer its biggest breach in history. A network of roughly 15,000 networks and 7 million devices will be pierced by a beast. A beast with an unknown origin, destination, and mechanism. A wild creature that even 17 years later, we still know little about. The beast's name is Agent BTZ. And this is the story of the most mysterious file that was ever discovered on the internet.

In the summer of 2008, a young Finnish researcher named Miko received a malware sample to analyze. At the time, USB malware was pretty common, and this specific worm seemed just as unremarkable as the rest. Usually, all the malware at the cyber security firm with these characteristics was named FDC. But in this case, there were already a bunch of other FDC's cataloged. So to avoid confusion, he renamed it to BTZ, agent BTZ. Just a number, just another USB worm in the pile of samples.

The sample was sent to us through our sample submission system. We looked at it. It's a USB thumb drive worm. So we took a thumb drive like this. And then we we actually copied the files of one of these. We went to our labs and injected or inserted the thumb drive into the computer which was offline so we could securely do this and we observed that the computer got infected. The files from the thumb drive were automatically copied on onto the computer and then we later tried inserting clean thumb drives onto this computer and now these got infected as well. So it it had the behaviors of a USB worm.

USBs had a feature called auto run back then which automatically executed files from removable discs. Today this is seen as a huge security risk but at the time it was just considered user-friendly. Agent BTZ happened to exploit this feature just like many other worms at the time. However, there was a detail that did not seem so ordinary after all. Several months later, Miko began receiving an awful lot of questions about that particular sample. Intrigued and baffled, he wondered if there was something more to the story, something he couldn't see.

Maybe 2 3 months later, we started getting questions about this malware. Fellow researchers and colleagues from other security companies started to get in touch with me that, "Hey, Miko, you analyzed and and your lab analyzed this this particular worm in the summer. what do you know about this? Could you share share us with the sample? And and uh when I look at my old um communication I was curious like why is everybody suddenly asking about this case? What's so special? We we we've seen 100 different USB worms during the summer. Why is this one special?"

Miko looked inside the file once again and that's where the cracks began to appear. It became clear how Agent BTZ was infecting its victims. This was no ordinary USB worm.

Before we dissect this creature, make sure to like and subscribe to the channel. We put in a lot of hours and effort to present these stories, and your support keeps us going. And if you want to stay informed, check the link in the description for our newsletter. It's a weekly dose of the most important tech and infosc updates handpicked by our editorial team. Information that we think you actually need to know right in your inbox. Thanks. And now back to Agent BTZ.

Once Agent BTZ gains access to a device or system, the infection begins. Here is how it works. First, the malware decrypts the strings inside its body with file names, API names, registry entries, and other components necessary for the infection. Then, it searches for these specific APIs. APIs are a set of rules that allow software systems to communicate. Agent BTZ needs to know the location of these APIs so it can carry out one of its main objectives in the device. Inject malicious code into Internet Explorer. To do this, agent BTZ spawns several threads which are a sort of helper that will aid the malware in different tasks. One thread inspects the Windows registry. There it looks for details such as timeout periods, flags, and domain names from which additional components can be downloaded. These details help the malware locate its target and complete the rest of its mission. Then the malware uses two additional threads and downloads an encrypted binary from two specific locations. Even though they look like simple pictures, they're not. A malicious program is hidden inside these files. These fake images are saved to a specific file in the temporary directory, which is the folder that continually refreshes your downloaded temporary files. Then the malware updates the registry and loads Internet Explorer. After that, it decrypts the contents of the downloaded files, injects it into Internet Explorer, and spawns a remote thread in it. While we don't know the exact purpose of this thread, researchers believe that it was spawned inside the browser to communicate with a remote server, aka its master.

If your computer is connected to the internet, so you can imagine a laptop, which sometimes is on the internet, sometimes it's offline. When it has internet access, it can send files from your computers to a server on the internet, stealing files from your machine. And the attacker can send instructions to your computer which could do anything you can do. Open any file you can open. Delete any file you can open. It has the same rights on your computer as you do. And if your computer is in a network, it can access all the files in the network that you can access.

But that's not all. The malware has another important objective. Collect and reproduce. To do so, it drops its copy into this directory by using a random name constructed from parts of other files located in the same directory. This way, the system will think it's just another not so dangerous and not so suspicious file. Then it registers itself as an inprocess server to ensure it runs every time Windows starts. Then the malware goes into incognito mode. To do this, it randomizes certain processes and assigns itself a random ID so it can remain undetected. It also stores specific values in the registry so it can remember where certain information is. Think of it like a robber moving in the dark, memorizing every room before the robbery so it knows exactly where to go without raising suspicion. Once the malware is hidden, it begins collecting data. It does this by first gathering specific information about the computer and its user and placing it into a specific XML file. Then it asks Windows for network adapter information, including IP addresses and other crucial data about the device. All of this goes into the same file. The malware also records its own actions on the computer in this file. It logs things like when installation started, where it copied itself, what name it used, or what registry keys it altered. The malware will update this information every 24 hours. In the robber example, this would be a sort of diary where the robber logs what has already been stolen, what's left in the house, and how much time is left before the owners wake up.

Every time a clean thumb drive is inserted into the same computer, it gets infected immediately. Windows executed a script from this drive. We call it an auto run script which gives instructions to the computer and those instructions asked Windows to copy files from the thumb drive into Windows system folders and execute those files and also set Windows to work so that every time you boot up Windows again, it would again execute those files. And when you take this to another computer that gets infected as well. So, it spreads slowly but surely. It spreads. It's not a fast spreader. It doesn't use email. It doesn't use the web. It requires people to walk from one computer to another with their thumb drive spreading the infection. So, the spreading speed of USB worms is roughly the same as as spreading speed for flu or for COVID or for human viruses. It requires humans to travel. So the malware goes around the world and that's what happened um with Agent PDC in 2008.

Mike McConnell, the former director of the NSA, once said that his worst nightmare wasn't an army of soldiers, but a bunch of kids with beer, pizza, an internet connection, and nothing to do. Hacking a game or defacing a popular website was the first step. Soon it could escalate into hacking federal organizations or worse. This is how monsters like I love you were created. A worm that wre havoc via email in the 2000s. The thing is that malware, unlike a missile, has no return address. Enemies cannot be tracked and punished accordingly. And this old mindset was creating a massive issue. American networks were lagging behind their adversaries abilities to exploit them. Monsters were becoming larger, stealthier, and perhaps worst of all, more brutal. The Department of Defense lacked both the mindset and the structure to confront these unpredictable creatures.

However, in 2008, it looked like things could finally turn around. For the first time in history, the US had both the means and ideas to put the past behind it. President Bush agreed to sign a costly 5-year plan that if effectively implemented could have changed US cyber security for good. Unfortunately, although the commitment was there, the execution failed terribly. Both the mindset and infrastructure remained pretty much the same as in the past 15 years. As a result, the plan was not executed as its architect, McConnell, who was then the director of national intelligence, had intended. While the funding was technically assigned to defense, the NSA reframed much of it in what they called active defense. The NSA argued that this was better since it could be used for both defensive and offensive needs. But the reality was that defense was taking the back seat. Meanwhile, Homeland Security invested some of the money in upgrading the Einstein network, an intrusion detection system designed to spot malicious activity and send automatic alerts. The department also started drawing the blueprints for Einstein 3, an upgrade that would also help to repel intruders. However, the NSA pulled the plug and the project inevitably collapsed. By the end, the US was left with advanced technology, but the same core problems that the NSA had battled since the '90s. And since the Iraq war was still ongoing, most of the technology was put to good old use. Offensive cyber operations. History was not made. But worst of all, the United States had not rethought its defensive strategy.

October 24th, 2008, the day began like any other at Fort me. The NSA's advanced networks operations team sipped their first cups of coffee and worked on a fresh batch of logs, analyzing and monitoring military networks. Everything seemed normal, but then one of the analysts spotted something strange in the batch of logs. This was not entirely abnormal. Glitches did occur from time to time. However, upon closer inspection, he realized it wasn't a glitch. Something was inside the network. Something was emitting a signal, but where and how? There was no time for questions. The military networks had been compromised.

And the Wii was General Alexander, President Bush, Vice President Cheney, Director of National Intelligence Mike McConnell, and myself were sitting in a conference room and someone passed me a note that said, "We've detected a malware on the Cypernnet." And my problem was I'm sitting there with the president of the United States, the vice president, the director of NSA, the director of national intelligence, and I've got a piece of information that says we have a problem. I decided not to disrupt that meeting, but soon as the meeting was over, I went to see General Alexander and and then we made the announcement soon thereafter that we had detected something. Richard and Alexander gathered their teams. Pizzas were ordered. Coffee was brought in. No one was going home. What should have been a routine Friday became one of the most stressful days in NSA history. Operation Buckshot Yankee has just begun.

Agent BTZ was inside Cippernet. How it got there was a mystery and probably will remain one for all eternity. One guess is that far away in the Middle East, a soldier purchased an infected USB stick from a kiosk in Kabul, Iraq. He returned to the base and inserted it into his work computer connected to the military network. Another theory is that the USB stick was left behind randomly in a parking lot, perhaps waiting for an unsuspecting GI to pick it up. But there was one last theory, perhaps the most plausible one, that suggested that the infection did not come from a USB, but from an infected computer in an internet cafe. In this version, an unlucky American soldier plugged his personal USB into the public device and later on into his work computer.

Or you could say, okay, here's here's the internet cafe where it first started. somebody came in, inserted something into, you know, an internet cafe computer, and then anybody who used that computer afterward that had a a memory device that connected to it, you know, went away with a with a present. in NATO, in the military. It could be a morale welfare uh organization, a non-governmental organization that provides um you know telephone service or computer service or something for military personnel. And and so it's a any place where there's a a concentration of military personnel using open network connectivity, there's a possibility that that something could be targeted through that. Or just put it there and and see where it ends up. That's a possibility as well. The NSA never determined if it was that or the worm got in their networks through other means. Patient zero was never discovered, but that wasn't important anymore. The military networks were pierced through and through. The main question now was how to stop the beast. How to prevent it from rampaging and collecting America's secrets.

There were cypernet terminals that were in shipping containers that were coming out of Iraq and Afghanistan. And if they were infected and they came back and the reserve unit reestablished their network at their home base and again somebody put a a memory device into the computer, they could transmit that infection to another computer and and and so forth. There was an entire logistics system, a chain of chains that now served as a distribution network for Agent BTZ. Any of those containers could have transported the worm, ready to jump onto all of the others as soon as a network connection was established. But maybe there was a way to cut that at its source. Maybe just like Agent BTZ hijacked America's logistics to spread, maybe there was a way to hijack its connection with the master and kill the beast this way. If the beacon was programmed to send instructions to a remote server, all they had to do was get inside and reroute it to a storage bin. It was a promising idea. The technical team got to work and within a few hours came up with a software capable of detecting and responding to the beaconing of agent BTZ. All that was left was to try it. On Saturday evening, a couple of strong men loaded a computer server onto a truck and drove it to the Defense Information Systems Agency. Richard and his team injected Agent BTZ onto the test server. The software ran and the rerouting instructions were sent to the beast. It obeyed. The team gave it one final order. Seconds later, Agent BTZ slipped into a permanent slumber. The NSA headquarters sighed in relief. They could finally go home and sleep for a couple of days. However, the worst part was still ahead. They had a house completely infected with computers that needed to be isolated, taken offline, and cleaned thoroughly. First of all, as Richard recalls, they had no idea how many terminals were infected, who was in charge of those terminals, and perhaps more worrisome, what kind of new variants may have spawned.

And this is where the chance to turn a past failure into an opportunity was found. Remember how a few months earlier, President Bush signed an expensive cyber defense plan? The money went towards offensive security, that is not defense at all. The NSA put it into its capability to conduct cyber attacks. Perhaps this money wasn't wasted after all. Perhaps the offensive security could be used to salvage the situation. The NSA brought in tailored access operations, a secretive unit dating back to the '90s, and playing a crucial role in almost every cyber attack US intelligence agencies performed. TAO's activities weren't confined to military networks. The unit had a frightening ability to reach out to nearly every device in the world, and it did that to search for Agent BTZ.

And we began looking for we could test the system to say are we seeing agent.btz in other places and are we seeing variants of agent.btz being developed. The actor the malevolent actor would say okay I need a new version because this one's already been detected. Because at that time most detection was done based on signatures of of of the malware. Uh where we've got behavioral models today, we've got other sorts of implementations of artificial intelligence looking for what's changed in a data flow that is out of the ordinary. So there are other indicators of compromise that we have today that we didn't have back in in 2008.

As Richard's team joined forces with the Department of Defense to clean the infected machines, the first frictions appeared. Some officials proposed offensive tools to get rid of the malware on non-military networks, including those in other countries. However, seniors did not like this. Malware could not justify such an aggressive response. Therefore, the NSA implemented a few other solutions to prevent further propagation.

Ultimately, we did track all of the computers going in, all the computers coming out. Um, we developed a capability to scan USB devices. A lot of the battle management activity in theater was contained on a they would do a a an operation. that operation was loaded onto a a a USB device and it might go to a Blackhawk helicopter. It might go to a unit deployed with laptop and and whatever. And so we had to find a way to ensure that as we were propagating operational orders, we weren't also propagating the infection. there for a period of time the chairman uh Admiral Mullen said no flash drives no no no thumb drives no USB devices in theater well unfortunately that's how operations ran the USB ban was perhaps one of the most controversial solutions especially because it came with additional countermeasures these new orders included significant resource inensive actions that many soldiers considered counterintuitive additionally the specialized orders used very technical technical language without proper context, leaving many confused about how to proceed. It was clear that another solution was needed and as fast as humanly possible.

And so we needed a solution developed very quickly. We developed something called magic eraser and it was essentially you could put a flash drive into a computer. It would scan it, look for the infection agent.ptz, either eradicate it or declare it clean. And so you knew that you had a a device that was not going to transmit the infection further by putting it into another machine.

In total, it's estimated that it took around 14 months to fully clean all computers. However, by the 6 week mark, military networks went back to business as usual. It did take a long time to track all of the units that had come in and and gone out of uh Iraq and Afghanistan to to really understand which ones are clean because equipment was in shipping containers. It it might come back and not get unpacked for 2 months. And so that took a a fairly long time to sort of get to the okay, we're absolutely sure that there's there's there's no infection left.

The US intelligence agencies learned how to fight the monster. But this didn't mean the fight was over. The fight just stopped being so one-sided. In the coming years, dozens of new variants of agent BTZ were detected. They were found everywhere across the entire globe on tens of thousands of devices with new ways to spread and obiscate. Who was creating all these versions? More importantly, why? While the beast's initial spread was almost entirely inside the military networks, it was no longer very effective there. The awareness, the new restrictions, and the NSA's efforts made the US military a much less lucrative target for whoever created Agent BTZ. If it was designed to steal American military secrets, then its mission should have been over. Yet, it wasn't. In 2013, various versions of Agent BTZ were detected on nearly 14,000 devices in over a 100 countries. Its wings were cut, its connections with the master severed. Yet, the beast was still walking. It was still spreading, collecting secrets and storing them, even when the possibility of sending them home was no longer an option. It was like a zombie aimlessly wandering around and going through the motions it memorized while still being alive.

But then some researchers began noticing a weird detail. Agent BTZ had parasites. Between 2010 and 2013, some samples of new malware were displaying strange behavior. After they infected the machine, they would search for the traces of Agent BTZ. One of them was a Trojan named Red October. It had a module named USB Stealer, which would search for two files created by Agent BTZ as it was infecting networks. The second one of those files was a container, the storage where Agent BTZ would collect and encrypt the secrets it stole. Red October would take that file and send it to its creators along with things like the victim's credentials. Another interesting piece of malware was discovered in 2012. It was called Flame with a few minor variants called Goss and Mini Flame. All of these variants followed a similar name convention called OCX extension while Flame was using this one. Agent.btz was using this one. Very similar. Now, here's where it gets interesting. Miniflame knew about the thumbs. DVB file of agent.btz of BTZ and conducted a search for it on USB sticks. For what purpose? It's unclear. However, when you consider these two details together, coincidences can be ruled out. Flame developers were well acquainted with Agent BTZ, and it is reasonable to think that they used it as a source of inspiration for later activities. Whether the goal was to steal secrets or simply to draw inspiration, somebody was using a brain dead beast for their own advantage.

Well, anybody could have done this, of course. Agent BTZ's habit to hoard stolen data was no secret. Creating an algorithm that would piggy back on its cash or simply develop a new beast from its ashes was a trivial task. That's probably what hackers behind Red October did.

Back to the NSA. Once computers were finally clean, the NSA found itself staring at a pink elephant in their headquarters. A huge pink elephant. Operation Buckshot Yankee was a statement about the state of cyber security in the Department of Defense. Its chaos and destruction had little to do with its complexity or maliciousness. It had everything to do with the military's inability to cope with a minor threat. An investigation was launched. First, the NSA tried to locate how and where the infection had started. But as we have mentioned in the previous episodes, patient zero was never found, and eventually they just gave up. Even to this day, nobody knows the truth. Next, experts tried to understand agent BTZ, perhaps to figure out what it was doing in the network. However, nobody came to a solid conclusion. Some say it was capable of sending the collected information to a specific device back home, at least when there was an internet connection. But in many cases of the networks agent BTZ infected, there was no internet. Due to its very nature, the worm spread itself onto offline devices, airgapped machines, entire networks cut off from the outside world, and it sat there collecting data undetected for years. Based on the knowledge we have now, the theory that the malware required specific instructions seemed to be more plausible. This theory would also mean that the malware could steal data but needed commands from a master system to proceed. This is coherent with agent.btz's behavior. It would explain why it injected malicious code on Internet Explorer and beaconed outward and it would also explain how the analysts managed to track it down.

Now, one question was still left to answer. Perhaps the most pressing one for the NSA. Who was Agent BTZ sending the information to?

We know that Agent.BTZ was linked to the Russian. I think that's been been published in a number of reports that there was linkage, but I don't know who generated it, why it was generated, you know, for for what purpose. Was it originally developed as a reconnaissance tool that then was upgraded to be a collection mechanism? reconnaissance and and mapping of of a a registry.

Both Agent BTZ and some of the malware that collected its data seem to have been written by Russian speakers. Moreover, the file used some obscure naming conventions that were repeated in its successors. File names, encryption methods, and other details used by Agent BTZ overlapped with both Red October and Flame. Whoever wrote those Trojans had extensive knowledge of Agent BTZ, perhaps too much. Another threat actor with more than direct connection to Agent BTZ is Tura, an extremely capable state sponsored hacking group, sometimes attributed to Russia's FSB. Tura's malware is popularly known as Snake and also has a lot in common with Agent BTZ. It basically carries the same fingerprints. It took many years for us to get any kind of conclusion about where agent PTC might have been coming from. In 2008, we we really had no idea. But then years later in 2014 when the snake malware known also as urabus malware was found, there are very clear links between the code of agent PTC from 2008 and Snake from 2014. It's highly highly likely that the author of Snake was also the author of Agent BTC years earlier.

Several months after the Buckshot Yankee operation, Fort Me had a grim atmosphere. Things had failed enormously and military personnel were dissatisfied and bitter. The NSA decided that it was time to turn things around and this time for good. If cyerspace was as critical to operations as land, sea, air, and space, why couldn't the cyber domain have the same tight operational structure? At the time, all they had was a loose confederation of joint task forces dispersed both geographically and institutionally. So, the NSA crafted a plan to bring together the joint task force global network operations. It would be a special force named cyber command and work under the umbrella of the NSA. The Cyber Command would have three missions. First, lead the day-to-day protection of all defense networks and support military and counterterrorism missions. Second, provide a clear and accountable way to marshall cyber warfare resources from across the military and oversee major commands. And third, they would work with a variety of partners inside and outside the US government. It had problems. Collaboration with it wasn't always easy, but it was light years better than whatever the US military had before. A lackluster collection of efforts that were powerless to prevent Agent BTZ's rampage.

I think Cyber Command brought some structure to like the the cyber teams that that were created. So, how do you go out and and look for for problems? I think creation of cyber com command caused new tools to be created and new methodology and and and I'll say operational doctrine to be created. But the problem has also morphed tremendously over that 15-year period. You know, now there's a discussion about standing up a cyber force. So Navy's got 10th fleet. Air Force has you know their their organization Mars Cyber is is for the Marine Corps and now a new entity being discussed which is a cyber force which is also a now department of war element and what will that relationship be? I I I think what we've we've continued to do is try to better understand the problem, better understand operationally how do we affect change? uh what's the best way to do that? I think cyber command was part of this evolutionary learning.

In the meantime, malware advanced. Threat actors became faster, smarter, and stealthier. It's unavoidable. Things are more complicated now. And in this equation, technology matters, but not as much as humans. There's no such thing as perfect security, but but we can get much much better than what we are if we just have human beings that that do the the right do things right, do things correctly and are diligent about the things that they do. They understand their role in security. It's not the IT people. It It's not the security people. It's all of us that touch a keyboard on on any network today. We have a shared responsibility.

Agent BTZ is one of the most enigmatic pieces of malware to target the US. It seems that it may have been related to other Russian cyber operations that continue to intrigue us, such as Tura and Moonlight Maze. If you're interested, remember to subscribe. We may explore those in the very near future. Thank you for watching and see you in the next one. Heat. Heat. N.