May 15, 2019 By David Bisson 2 min read

Threat actors have launched a new malware campaign that uses a man-in-the-middle (MitM) attack to infect unsuspecting users with the Plead backdoor.

At the end of April 2019, ESET observed several attempts to distribute the Plead backdoor using what was most likely a MitM attack. Each of these attempts created and executed the malware through “AsusWSPanel.exe,” a legitimate process belonging to the Windows client of ASUS WebStorage. Researchers also confirmed that each of the discovered Plead samples used “Asus Webstorage Upate.exe” as their file name.

In its analysis of these infection attempts, ESET proposed that ASUS Cloud Corporation, the developer of ASUS WebStorage, could have suffered a supply chain attack. But the researchers admitted that some findings, including the fact that the same update mechanism delivered legitimate ASUS WebStorage binaries, likely ruled this scenario out.

They said it was far more likely that digital attackers used a MitM attack at the router level to modify the update check of the ASUS WebStorage software. ESET’s researchers observed this activity in the wild when threat actors inserted a new URL that pointed to a malicious file hosted at a compromised gov.tw domain.

Peering Into Plead’s History

The actors behind Plead are known to use a router scanner to search for vulnerable routers. Once they’ve compromised a router, they use its virtual private network (VPN) feature to register the device as a virtual server. They can then leverage this asset as a command-and-control (C&C) server for delivering malware.

Researchers have learned much about Plead since the threat first became active in 2012. In June 2017, for instance, Trend Micro uncovered common denominators between Plead and two other attack tools named Shrouded Crossbow and Waterbear. These commonalities led the security firm to conclude that all three utilities fit into the arsenal of the threat group BlackTech.

The malware has been involved in other attack campaigns since then, too. In July 2018, for example, ESET identified a campaign that abused code-signing certificates to spread the threat.

How to Defend Against a Malware-Laden MitM Attack

Security professionals can help defend their organizations against MitM attacks by using network monitoring tools to analyze network traffic in real time for risks and vulnerabilities. This solution should also help security teams prioritize risks and vulnerabilities based on where data is stored.

Organizations should also leverage unified endpoint management (UEM) to monitor their devices for suspicious activity, including what could be malicious behavior.

More from

CVE-2023-20078 technical analysis: Identifying and triggering a command injection vulnerability in Cisco IP phones

7 min read - CVE-2023-20078 catalogs an unauthenticated command injection vulnerability in the web-based management interface of Cisco 6800, 7800, and 8800 Series IP Phones with Multiplatform Firmware installed; however, limited technical analysis is publicly available. This article presents my findings while researching this vulnerability. In the end, the reader should be equipped with the information necessary to understand and trigger this vulnerability.Vulnerability detailsThe following Cisco Security Advisory (Cisco IP Phone 6800, 7800, and 8800 Series Web UI Vulnerabilities - Cisco) details CVE-2023-20078 and…

X-Force data reveals top spam trends, campaigns and senior superlatives in 2023

10 min read - The 2024 IBM X-Force Threat Intelligence Index revealed attackers continued to pivot to evade detection to deliver their malware in 2023. The good news? Security improvements, such as Microsoft blocking macro execution by default starting in 2022 and OneNote embedded files with potentially dangerous extensions by mid-2023, have changed the threat landscape for the better. Improved endpoint detection also likely forced attackers to shift away from other techniques prominent in 2022, such as using disk image files (e.g. ISO) and…

The compelling need for cloud-native data protection

4 min read - Cloud environments were frequent targets for cyber attackers in 2023. Eighty-two percent of breaches that involved data stored in the cloud were in public, private or multi-cloud environments. Attackers gained the most access to multi-cloud environments, with 39% of breaches spanning multi-cloud environments because of the more complicated security issues. The cost of these cloud breaches totaled $4.75 million, higher than the average cost of $4.45 million for all data breaches.The reason for this high cost is not only the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today