Infection vectors and infrastructures used by hackers to attack you

attack vectors towards users

To finish getting to know a little better these bastards, known as cybercriminals, with whom we have to share the Internet (pardon the expression); let’s finish with an article that I hope will help us to get to know our enemy a little better, following Sun Tzu ’s advice mentioned in a previous post.

Let’s see what are the common attack vectors they usually use to get to us, as well as the infrastructures they use to make it more difficult for us to get to them and hold them accountable.

In a future article we will see the hacking software tools they usually use to complete the topic without going too much in depth.

Common infection vectors

As hackers can be of different types, have different motivations and pursue different objectives, it is difficult to summarize in just a few lines the different attack vectors they use to reach us, not least because new ways of infection are being discovered every day.

But what we can do is, at least, mention the most common vectors they usually use:

  • Malvertising throughpop-ups: ** Have you ever encountered a sudden advertisement saying that your PC “is in danger” and offering you a supposedly miraculous solution?

Most likely, that little window is the real danger. As you can imagine, in reality, that simple action of clicking on this button is what will download or execute malware disguised as a supposed security tool.

On music, movie and pirated software download sites, and even on other disreputable ones, numerous small windows like the one above usually appear, inviting you to click on a well highlighted button to supposedly solve the problem.

I have been told that this kind of little windows are very frequent in pornographic sites, …but I can’t confirm this, maybe you know more about this than I do ;)        

  • **Malicious or compromised websites: ** A legitimate website could contain an alleged advertisement embedded with malicious code embedded by third parties. Or directly, the website could have been compromised as a result of some unpatched vulnerability.

In either case, the web visitor could end up being redirected to domains controlled by the attackers to extract personal information or simply receive malicious code packages that would be installed in the background without being noticed.

Regarding this topic, I will talk about some of the dangers of clicking on those QR codes that restaurants offer to read their menus directly from their website.

It has a certain similarity to those attacks we see in animal documentaries, when a lion stands waiting near a pond or watering hole with the certainty that sooner or later a number of animals will come to drink.

It doesn’t have to look far, it just has to wait for its victims to arrive and hunt them down there. That’s why this type of attack is known as a watering hole attack.

  • **Malicious software updates: ** As you will see, cybercriminals are constantly innovating.

One of the most sophisticated and effective attacks that have become fashionable in recent years are the so-called supply chain attacks, which have become an increasingly important and difficult to avoid. In this type of attack, hackers no longer bother to go after you directly, but instead compromise the software company that supplies you with the software updates that were supposed to provide you with new features and increased security by patching discovered vulnerabilities.

In the end, in addition to receiving the expected updates, along the way you also get hidden malware installed on your device that even the company supplying the updates was not able to detect. With this ingenious method, cybercriminals manage to massively infect thousands or millions of users who, with all their good faith and following one of the main recommended digital hygiene practices - updating software frequently - end up getting infected.

One of the most notorious examples to date was the incident suffered by the company SolarWinds. In any case, it is always better to take that risk than not updating the software regularly.      

  • **Software packages: ** And following on from the above, some programs, especially the free ones or those that you can find in some illegal forums or in P2P networks, such as  BitTorrent or eMule.

With the excuse that they have been cracked so that you can use them without paying, they may include various types of malware such as adware (invasive advertising) or spyware (spyware ). Either of these two types of malware can be installed in the background virtually unnoticed. Moreover, first of all, I do not recommend that you do so - it is neither ethical nor legal - and your decision to install pirated software downloaded from the Internet could affect family members who also use the same device at home. But in the event that your ethics have relaxed a bit and you still choose to ignore my advice, at least tell you that, be very careful if you see a .txt file accompanying that pirated software with a title similar to “README.txt” (Readme.txt).    This file will suggest that, in order not to be detected by the antivirus as pirated software, it is best to disable it before installation. If you do, you’ve just put it on a platter to install all kinds of bugs inside your device. And it’s not that you don’t deserve it, although I won’t be the one to judge you, because in my younger days, on more than one occasion I remember having also had my ethics somewhat relaxed (I still have regrets…).         As you can imagine, cybercriminals know very well that if you catch them, you are not going to go to the police and report them saying that your pirated software has been infiltrated by a series of nasty bugs that are wreaking havoc on your device. Also of concern is the use of FireTVs with pirated subscriptions. These devices, offered at low prices, can be used to perform DDoS attacks, spy or exfiltrate information from devices connected to the home network.

They have been booming lately, which shows that many people are willing to take risks in exchange for saving a few euros. These practices not only affect the piranhas, but also, by the way, some organized groups do it with the intention of damaging the economy of those great countries that create the software we all use.    

  • **Shared resources: ** Certain types of malware literally behave like worms, spreading automatically from one network to another, infecting files in shared folders or external storage devices (e.g. USB devices) without human intervention.

The issue of shared folders will be more likely to happen to companies, but when we talk about USB, it can happen to anyone.

My recommendation: if you ever encounter a USB -attack known as baiting-Never insert it in any of your devices, not even if you find it in the door of your house, in your garage or in your office, since hackers usually leave them there on purpose so that curious people can insert them in their computers and end up getting infected.

In short, if you find a USB in the street, the best thing to do is to throw it in the trash after having given it a good stomp, just in case someone else finds it!

Infrastructures and attack platforms

On the other hand, and to complete what was introduced at the beginning, to carry out their misdeeds hackers use different infrastructures from which they carry out their attacks:

  • In smishing campaigns (fraudulent text messages):

  • They use virtual telephones and VoIP (Voice over Internet Protocol) PBXs to falsify the identity of the sender.

  • SIM cards obtained with false credentials.

  • Or they use previously compromised or stolen mobile devices as “proxies” from which to attack third parties.

  • In phishing campaigns (fraudulent e-mails):

  • They use servers contracted in countries with overly permissive cybercrime legislation.

  • Mail servers of previously compromised companies, used to launch attacks from there.

  • Ad hoc servers that are set up on demand and can be quickly shut down to make investigation more difficult.

  • In other hacking campaigns:

Generally, they avoid using the IP address of their home or workplace.

They connect from public Wi-Fi access points (coffee shops, airports), or even from their neighbor’s Wi-Fi, so that if they are detected, the traces will lead to their neighbor and not to him or her (we will talk about this later when we look at the security of our home Wi-Fi).

Generally, cybercriminals hire cryptocurrency infrastructures (servers) from which they carry out their operations in countries with little international cooperation in the prosecution of cybercrime.

For example, if someone wants to attack a US infrastructure, remotely hiring a server in Russia or Iran from which to carry out the attack will provide them with certain guarantees that neither of these two countries will cooperate with the US justice system to find the cybercriminals.

For this reason, taking advantage of the infrastructures located in the enemy countries of the country where the final attack will take place is usually a very attractive action for them.

Even this often leads to other types of attacks known as “false flag attacks”. I’ll explain, it might look like you have been attacked by the Russians when, in fact, it was the North Koreans using a server hosted in Russia, to give an example.

In the end it all boils down to being very careful, because if a hacker has you in his sights, it is very likely that he will use social networks to get to you. He could pose as a casual friend of someone you know, such as a family member or friend, to gain the trust of your circle.

In this world I always say the same thing:

“Everyone is guilty until proven innocent.”

We must be absolutely suspicious of everything, and after a little analysis and a dose of common sense, decide whether to go ahead with an action or not.

With a little bit of cybersecurity culture, we, instead of being the weakest link in the chain, can become the “first defense filter” to prevent the success of those bastards’ tactics.