메뉴
BL
Ars Technica • 25일 전

무료 영화를 약속하는 이 기기, 설치 전 다시 생각하세요

IMP
7/10
핵심 요약

불법 스트리밍 미디어 플레이어 'SuperBox'가 사실상 레지덴셜 프록시 네트워크로 악용되며, 기기 내 거의 모든 안드로이드 보안 기능이 비활성화되어 원격 공격자가 인증 없이 루트 권한을 얻고 추가 악성코드를 설치할 수 있다는 것이 밝혀졌습니다. 보안 업체 Plume은 SuperBox뿐 아니라 유사한 수십 개 스트리밍 기기들이 동일한 위험을 안고 있다고 경고했습니다.

번역된 본문

온라인 서비스들이 악성 트래픽을 차단하는 능력이 향상되면서, 그 배후에 있는 공격자들과 사기꾼들은 표적에게 도달할 새로운 방법을 찾아야 했습니다. 이들이 선택한 대안이 이른바 '레지덴셜 프록시 네트워크(residential proxy network)'입니다. 이 시스템은 수백만 개의 가정 인터넷 연결을 하나의 통합 네트워크로 묶고, 프록시 운영자들이 공격자들이 이 연결을 통해 악성 트래픽을 라우팅하도록 유료로 허용합니다. 온라인 서비스들은 평판이 좋은 IP 주소와 눈에 띄지 않는 지리적 위치만을 보게 됩니다. 대부분의 경우 가정 사용자들은 자신의 인터넷 연결이 범죄, 심지어 국가 단위 공격에 이용되고 있다는 사실을 전혀 모릅니다.

이를 알고 있는 사용자들조차 대부분 크게 개의치 않습니다. 무제한 대역폭의 일부를 타인에게 임대해 주는 대가로, 많은 이들이 무료 영화 및 TV 프로그램 스트리밍을 받습니다. 제가 아는 이런 디지털 미디어 플레이어를 소유한 기술에 어두운 몇몇 사람들은, 미디어 플레이어가 자신들의 연결을 편승해 이용한다는 설명을 들은 후에도 그 콘텐츠 혜택이 그만한 가치가 있다고 말했습니다. 눈에 보이는 실질적 이익이 추상적인 해악보다 크다고 생각하는 것입니다.

이미 침해된 기기들을 감염시키다

월요일에 발표된 연구는 이 위협을 훨씬 명확하게 보여줍니다. 보안 업체 Plume은 불법 복제 콘텐츠를 제공하는 수많은 미디어 플레이어 중 하나인 SuperBox 사용자들을 정확히 겨냥한 방대한 악성코드 생태계를 조사·분류했습니다. 이 악성 앱들은 기기가 라우터 뒤에 있더라도 원격 공격자가 은밀하게 설치할 수 있습니다. 월요일의 심층 분석은 SuperBox에만 초점을 맞췄지만, Plume은 유사한 수십 개의 스트리밍 기기가 정확히 동일한 위협을 안고 있다고 경고했습니다.

Plume 연구자들은 "우리 연구진은 이러한 레지덴셜 프록시 네트워크가 단순한 수익화 도구가 아니라는 것을 발견했습니다. 이들은 추가 악성코드 배포의 표적으로 활발히 이용되고 있으며, 사이버 범죄자들이 이미 침해된 기기에 전혀 새로운 악성코드 계열을 감염시킬 수 있게 하면서도 기기 소유자에게는 거의 보이지 않습니다"라고 작성했습니다.

안드로이드 기반인 SuperBox는 OS 기반 보안 보호 기능이 거의 모두 꺼진 상태로 설정되어 있습니다. 사전 설치된 앱이나 SuperBox 앱 스토어를 통해 제공되는 앱들은 루트(root)로 실행되어, 즉 기기에서 제약 없는 관리자 수준의 시스템 권한을 갖습니다. 프록시 네트워크 유료 고객들도 몇 가지 리눅스 명령만으로 루트 권한을 얻을 수 있습니다. 이렇게 되면 앱이든 유료 고객이든 자신의 앱을 설치하고, 기기가 연결된 로컬 네트워크를 감시하고 참여할 수 있으며, 그곳에서 다른 연결된 기기와 동일한 시스템 권한을 갖게 됩니다.

SuperBox는 서명 검증, '알 수 없는 소스' 제한, 권한 검토 대화상자, Play Protect 스캔 등 안드로이드의 기본 방어 기능을 무력화합니다. 그 결과 기기의 ADB(Android Debug Bridge)가 인터넷에 노출됩니다. 더 심각한 것은, 하위 수준 시스템 권한을 가진 사용자가 일시적으로 관리자 수준 액세스를 얻을 수 있게 해주는 명령줄 인터페이스를 제공하는 su 바이너리가 인증 없이 루트 권한을 부여하도록 설정되어 있다는 점입니다. ADB가 인터넷에 노출되고 루트 접근에 인증이 없다는 조합은, 앱과 프록시 서비스 사용자 모두 기기에서 사실상 원하는 어떤 명령이든 실행할 수 있음을 의미합니다.

대부분의 사용자는 SuperBox를 가정용 라우터 뒤에 두며, 그렇게 하면 기기가 인터넷에 연결된 원격 공격자로부터 안전하다고 생각할 수 있습니다. 실제로 그런 안전감은 완전히 잘못된 것입니다. 많은 SuperBox 앱 내부에서 프록시 기능을 제공하는 바이너리는 프록시 서버로 나가는 연결을 열고 이를 통신 채널로 무기한 유지합니다. 이들이 의존하는 연결이 아웃바운드이며 SuperBox와 프록시 서버 사이에서 암호화되어 있기 때문에 라우터는 이 통신을 차단할 수 없습니다. 트래픽을 모니터링할 만큼 능숙한 사용자조차 (원문 여기서 끊김)

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav As online services get better at blocking malicious traffic, the attackers and scammers behind them have been forced to find new ways to reach their targets. The alternative of choice is now what are known as residential proxy networks. These systems funnel millions of home Internet connections into a unified network, and the proxy operators allow attackers to route their malicious traffic through these connections for a fee. The online services see only IP addresses with good reputations and geolocations that don’t stand out. More often than not, the home users have no idea that their connections are being used to facilitate crime and occasionally even nation-state attacks . Users who do know often don’t care much. In exchange for leasing out part of their unlimited bandwidth to others, many get free movie and TV show streaming. Several less tech-savvy people I know who own such digital media players have told me, after I explain how the media players piggyback off their connections, that the bonanza of content is worth it. They find the tangible benefits outweigh the abstract harm they pose. Infecting already compromised devices Research published Monday brings the threat into much clearer view. Security firm Plume cataloged a vast ecosystem of malware that preys squarely on users of SuperBox , just one of many media players offering pirated content. These malicious apps can be surreptitiously installed by remote attackers even when the devices are positioned behind a router. While Monday’s deep-dive analysis focused exclusively on SuperBox, Plume warned that dozens of similar streaming devices pose precisely the same threat. “Our researchers found that these residential proxy networks are not simply monetization tools,” Plume researchers wrote . “They are actively being used as a target for additional malware delivery, enabling cybercriminals to infect already-compromised devices with entirely new malware families while remaining largely invisible to the device owner.” The Android-based SuperBox is configured with almost all the OS-based security protections turned off. Apps that come pre-installed, or those that are available through the SuperBox app store, then run as root, meaning they have unfettered administrative system rights on the device. Paying proxynet customers can also gain root by issuing a handful of Linux commands. With that, either the app or the paying customer can install their own apps and surveil and join the local network the device is connected to, where they have the same system rights as any other connected device. The SuperBox neuters default Android defenses , including signature verification, the “unknown sources” restriction, the permission-review dialog, and Play Protect scanning. As a result, the box’s ADB ( Android Debug Bridge ) is exposed to the Internet. Worse, the su binary—the code that provides the command-line interface allowing users with low-level system rights to temporarily gain administrator-level access—is set to grant root without any authentication. The combination of the ADB being exposed to the Internet and the lack of authentication for root access means that both apps and users of the proxy service can execute virtually any command they want on the device. More often than not, users position their SuperBox behind their home router, where they may think their device is safe from Internet-connected remote attackers. In fact, that sense of security is completely false. The binary that provides proxy functions inside many SuperBox apps opens an outgoing connection to a proxy server and keeps it open as a communication channel indefinitely. Routers are unable to block the communications because the connections they rely on are outbound and encrypted between the SuperBox and the proxy server. Even users who are savvy enough to monitor traffic on their network never see anything that looks like an inbound connection to the ADB port. “The open ADB port plays the central role,” Plume researcher Gergely Eberhardt wrote in an email. “Combined with root access, a single pm install command can silently install any APK. This bypasses every one of Android’s default protections at once: signature verification, the “unknown sources” restriction, the permission-review dialog, and Play Protect scanning.” Intruders at gates The open ADB, along with the default presence of apps that have built-in proxy functionality, creates a dangerous mix that makes SuperBox a potent threat. “This combination results in further infections involving additional residential proxies or IoT botnets, and the attackers are often the very customers of the primary proxy network,” Plume wrote. “The device owners get multiple bots they never asked for and are not aware of, all competing for the same hardware, and an IP address whose reputation now reflects whatever those bots utilize it for.” Some of the proxy networking services that make use of SuperBox take measures to prevent their customers from accessing the local networks of SuperBox users. The recently disrupted Popanet, for instance, blocks local IP address ranges from outside the local network. Even then, Popanet users can access local IPs by specifying the special wildcard address 0.0.0.0, which Android then routes to the SuperBox IP 127.0.0.1. From that vantage point, proxy users can access the rest of the local network. Monday’s post also reported that even the Popanet network was facilitating live exploit attempts. Plume wrote: The internal-network protection issue that we described in the previous part isn’t just a theoretical concern. To confirm whether anyone is actually exploiting it, we ran a controlled experiment. We joined the Popanet network as a residential exit node and instructed the host that any connection coming through the tunnel targeting either port 5555 or 5858 (these are the most common ADB ports) would be redirected to our local honeypot. From the operator’s perspective, our node looked like any other regular residential endpoint serving customer traffic; from the inside, every attempt aimed to reach an ADB port through our node was captured. We let the node run for over three weeks; over that period, the honeypot recorded 1,352 distinct attempts at reaching the ADB through the gap we identified earlier. All the attacks could be split into two families of loopback addresses targeting the local machine. The first is 0.0.0.0, supplied either as a raw address or embedded in a hostname via a wildcard DNS service such as nip.io. The second is 127.0.0.1, which the proxy blocked via isLoopbackAddress() as we explained earlier. An email sent to info@mysuperboxtv.com seeking comment didn’t receive a response before this story’s publication. Intruding traffic attempted to install multiple malicious apps that made SuperBoxes a node in yet another proxy network or join botnets for use in DDoS attacks. The three primary apps were CECbot, a variant of Mirai, and Maskify. It’s hard to walk away from Monday’s report with anything other than the strong conviction that SuperBox—and virtually all of its peers—pose a tangible and imminent threat to the networks they’re connected to. Even savvy people who think they can be cordoned off from the Internet are at risk. If you’re using one, you should disconnect it and throw it away. If you find a family member using one, you should intervene. With the Popanet proxy service alone running through 2 million devices, according to Google, chances are good that a home network near you is, too. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independe