{"id":15636,"date":"2019-06-25T20:49:16","date_gmt":"2019-06-26T04:49:16","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/06\/25\/news-9385\/"},"modified":"2019-06-25T20:49:16","modified_gmt":"2019-06-26T04:49:16","slug":"news-9385","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/06\/25\/news-9385\/","title":{"rendered":"Tracing the Supply Chain Attack on Android"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Tue, 25 Jun 2019 15:24:29 +0000<\/strong><\/p>\n<p>Earlier this month, <strong>Google<\/strong> <a href=\"https:\/\/security.googleblog.com\/2019\/06\/pha-family-highlights-triada.html\" target=\"_blank\" rel=\"noopener\">disclosed<\/a> that a supply chain attack by one of its vendors resulted in malicious software being pre-installed on millions of new budget Android devices. Google didn&#8217;t exactly name those responsible, but said it believes the offending vendor uses the nicknames &#8220;<strong>Yehuo<\/strong>&#8221; or &#8220;<strong>Blazefire<\/strong>.&#8221; What follows is a deep dive into the identity of that Chinese vendor, which appears to have a long and storied history of pushing the envelope on mobile malware.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-47972\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/06\/googgraphic.jpg\" alt=\"\" width=\"594\" height=\"281\" \/><\/p>\n<p>&#8220;Yehuo&#8221; (<a href=\"https:\/\/chinese.yabla.com\/chinese-english-pinyin-dictionary.php?define=%E9%87%8E\" data-ss1561470531=\"1\">\u91ce<\/a><a href=\"https:\/\/chinese.yabla.com\/chinese-english-pinyin-dictionary.php?define=%E7%81%AB\" data-ss1561470531=\"1\">\u706b<\/a>) is Mandarin for &#8220;<strong>wildfire<\/strong>,&#8221; so one might be forgiven for concluding that Google was perhaps using another dictionary than most Mandarin speakers. But Google was probably just being coy: The vendor in question appears to have used both &#8220;blazefire&#8221; and &#8220;wildfire&#8221; in two of many corporate names adopted for the same entity.<\/p>\n<p>An online search for the term &#8220;yehuo&#8221; reveals an account on the <strong>Chinese Software Developer Network<\/strong>\u00a0which uses that same nickname and references the domain <strong>blazefire[.]com<\/strong>. More searching points to a Yehuo user on <strong>gamerbbs[.]cn<\/strong> who advertises a mobile game called &#8220;Xiaojun Junji,&#8221; and says the game is available at blazefire[.]com.<\/p>\n<p>Research on blazefire[.]com via <a href=\"https:\/\/www.domaintools.com\" target=\"_blank\" rel=\"noopener\">Domaintools.com<\/a> shows the domain was assigned in 2015 to a company called &#8220;<strong>Shanghai Blazefire Network Technology Co. Ltd.<\/strong>&#8221; just a short time after it was registered by someone using the email address &#8220;<strong>tosaka1027@gmail.com<\/strong>&#8220;.<\/p>\n<p>The Shanghai Blazefire Network is part of a group of similarly-named Chinese entities in the &#8220;mobile phone pre-installation business and in marketing for advertisers&#8217; products to install services through mobile phone installed software.&#8221;<\/p>\n<p>&#8220;At present, pre-installed partners cover the entire mobile phone industry chain, including mobile phone chip manufacturers, mobile phone design companies, mobile phone brand manufacturers, mobile phone agents, mobile terminal stores and major e-commerce platforms,&#8221; reads a descriptive blurb about the company.<\/p>\n<p>A historic records search at Domaintools\u00a0on that tosaka1027@gmail.com address says it was used <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/06\/reverse-on-tosaka.txt\" target=\"_blank\" rel=\"noopener\">to register 24 Internet domain names<\/a>, including at least seven that have been conclusively tied to the spread of powerful Android mobile malware.<\/p>\n<p>Two of those domains registered to tosaka1027@gmail.com &#8212;\u00a0<a href=\"https:\/\/blog.angelalonso.es\/2016\/03\/triada-malware-hitting-android-core_22.html\" target=\"_blank\" rel=\"noopener\">elsyzsmc[.]com and rurimeter[.]com<\/a> &#8212;\u00a0were implicated in propagating the <a href=\"https:\/\/www.kaspersky.com\/blog\/triada-trojan\/11481\/\" target=\"_blank\" rel=\"noopener\">Triada malware<\/a>. Triada is the very same malicious software Google said was found pre-installed on many of its devices and being used to install spam apps that display ads.<\/p>\n<p>In July 2017, Russian antivirus vendor <strong>Dr.Web<\/strong> <a href=\"https:\/\/news.drweb.com\/show\/?i=11390&amp;lng=en\" target=\"_blank\" rel=\"noopener\">published research<\/a> showing that Triada had been installed by default on at least four low-cost Android models. In 2018, Dr.Web <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/banking-trojan-found-in-over-40-models-of-low-cost-android-smartphones\/\" target=\"_blank\" rel=\"noopener\">expanded its research<\/a> when it discovered the Triada malware installed on 40 different models of Android devices.<\/p>\n<p>At least another five of the domains registered to tosaka1027@gmail.com &#8212; <a href=\"https:\/\/blog.zimperium.com\/wp-content\/uploads\/2016\/08\/HummerTrojan-IOCs.pdf\" target=\"_blank\" rel=\"noopener\">99youx[.]com<\/a>, <a href=\"https:\/\/blog.zimperium.com\/wp-content\/uploads\/2016\/08\/HummerTrojan-IOCs.pdf\" target=\"_blank\" rel=\"noopener\">buydudu[.]com<\/a>, <a href=\"https:\/\/www.reverse.it\/sample\/d6f8bf6b55aa81aa6ca549081faf3153d06fef794656a384c5ee0ac2187efda7?environmentId=100\" target=\"_blank\" rel=\"noopener\">kelisrim[.]com<\/a>, <a href=\"https:\/\/www.virustotal.com\/gui\/file\/3b548b5aa8f071a02738c180b915af337d5296e422f779dbe81d215e75df951a\/detection3b548b5aa8f071a02738c180b915af337d5296e422f779dbe81d215e75df951a\" target=\"_blank\" rel=\"noopener\">opnixi[.]com<\/a> and <a href=\"https:\/\/blog.zimperium.com\/wp-content\/uploads\/2016\/08\/HummerTrojan-IOCs.pdf\" target=\"_blank\" rel=\"noopener\">sonyba[.]com<\/a> &#8212; <a href=\"https:\/\/www.cmcm.com\/blog\/en\/security\/2016-06-29\/995.html\" target=\"_blank\" rel=\"noopener\">were seen as early as 2016 as distribution points for the Hummer Trojan<\/a>, a potent strain of Android malware often bundled with games that completely compromises the infected device.<span id=\"more-48061\"><\/span><\/p>\n<p>A records search at Domaintools for &#8220;Shanghai Blazefire Network Technology Co&#8221; returns 11 domains, including blazefire[.]net, which is registered to a <strong>yehuo@blazefire.net<\/strong>. For the remainder of this post, we&#8217;ll focus on the bolded domain names below:<\/p>\n<p>Domain Name\u00a0 \u00a0 \u00a0 Create Date\u00a0 \u00a0Registrar<br \/> <strong>2333youxi[.]com<\/strong> 2016-02-18 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<br \/> 52gzone[.]com 2012-11-26 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<br \/> 91gzonep[.]com 2012-11-26 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<br \/> <strong>blazefire[.]com<\/strong> 2000-08-24 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<br \/> <strong>blazefire[.]net<\/strong> 2010-11-22 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<br \/> <strong>hsuheng[.]com<\/strong> 2015-03-09 GODADDY.COM, LLC<br \/> jyhxz.net 2013-07-02 &#8212;<br \/> <strong>longmen[.]com<\/strong> 1998-06-19 GODADDY.COM, LLC<br \/> longmenbiaoju[.]com 2012-12-09 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<br \/> oppayment[.]com 2013-10-09 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<br \/> <strong>tongjue[.]net<\/strong> 2014-01-20 ALIBABA CLOUD COMPUTING (BEIJING) CO., LTD<\/p>\n<p>Following the breadcrumbs from some of the above domains we can see that &#8220;Blazefire&#8221; is a sprawling entity with multiple business units and names. For example, <strong>2333youxi[.]com<\/strong> is the domain name for <strong>Shanghai Qianyou Network Technology Co., Ltd.<\/strong>, a firm that says it is &#8220;dedicated to the development and operation of Internet mobile games.&#8221;<\/p>\n<p>Like the domain blazefire[.]com, 2333youxi[.]com also was initially registered to\u00a0tosaka1027@gmail.com and soon changed to Shanghai Blazefire as the owner.<\/p>\n<p>The offices of Shanghai Quianyou Network &#8212; at Room 344, 6th Floor, Building 10, No. 196, Ouyang Rd, Shanghai, China &#8212; are just down the hall from <strong>Shanghai Wildfire Network Technology Co., Ltd., <\/strong>reportedly at Room 35, 6th Floor, Building 10, No. 196, Ouyang Rd, Shanghai.<\/p>\n<p>The domain tongjue[.]net is the Web site for\u00a0<strong>Shanghai Bronze Network Technology Co., Ltd.<\/strong>, which appears to be either another name for or a sister company to <strong>Shanghai Tongjue Network Technology Co., Ltd.<\/strong>\u00a0 According to its marketing literature, Shanghai Tongjue is situated one door down from the above-mentioned Shanghai Quianyou Network &#8212; at Room 36, 6th Floor, Building 10, No. 196, Ouyang Road.<\/p>\n<p><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/06\/tongjue-dot-net.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-47975\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/06\/tongjue-dot-net.jpg\" alt=\"\" width=\"595\" height=\"453\" \/><\/a><\/p>\n<p>&#8220;It has developed into a large domestic wireless Internet network application,&#8221; reads a help wanted ad published by Tongjue in 2016.\u00a0 &#8220;The company is mainly engaged in mobile phone pre-installation business.&#8221;<\/p>\n<p>That particular help wanted ad was for a &#8220;client software development&#8221; role at Tongjue. The ad said the ideal candidate for the position would have experience with &#8220;Windows Trojan, Virus or Game Plug-ins.&#8221; Among the responsibilities for this position were:<\/p>\n<p>-Crack the restrictions imposed by the manufacturer on the mobile phone.<br \/> -Research and master the android [operating] system<br \/> -Reverse the root software to study the root of the android mobile phone<br \/> -Research the anti-brushing and provide anti-reverse brushing scheme<\/p>\n<h4>WHO IS BLAZEFIRE\/YEHUO?<\/h4>\n<p>Many of the domains mentioned above have somewhere in their registration history the name &#8220;Hsu Heng&#8221; and the email address yehuo@blazefire.net. Based on an analysis via cyber intelligence firm <a href=\"https:\/\/www.4iq.com\" target=\"_blank\" rel=\"noopener\">4iq.com<\/a> of passwords and email addresses exposed in multiple data breaches in years past, the head of Blazefire goes by the nickname &#8220;Hagen&#8221; or &#8220;Haagen&#8221; and uses the email &#8220;<strong>chuda@blazefire.net<\/strong>&#8220;.<\/p>\n<p>Searching on the phrase &#8220;chuda&#8221; in Mandarin turns up <a href=\"http:\/\/www.youxiguancha.com\/chuangyeguanli\/24454.html\" target=\"_blank\" rel=\"noopener\">a 2016 story<\/a> at the Chinese gaming industry news site Youxiguancha.com that features numerous photos of Blazefire employees and their offices. That story also refers to the co-founder and CEO of Blazefire variously as &#8220;Chuda&#8221; and &#8220;Chu da&#8221;.<\/p>\n<p>&#8220;Wildfire CEO Chuda is a tear-resistant boss with both sports (Barcelona hardcore fans) and literary genre (playing a good guitar),&#8221; the story gushes. &#8220;With the performance of leading the wildfire team and the wildfire product line in 2015, Chu has won the top ten new CEO awards from the first Black Rock Award of the Hardcore Alliance.&#8221;<\/p>\n<p>Interestingly, the registrant name &#8220;Chu Da&#8221; shows up in the historical domain name records for <a href=\"https:\/\/web.archive.org\/web\/20160325045051\/http:\/\/www.longmen.com\/\" target=\"_blank\" rel=\"noopener\">longmen[.]com<\/a>, perhaps Shanghai Wildfire&#8217;s oldest and most successful mobile game ever. That record, from April 2015, lists Chu Da&#8217;s email address as yehuo@blazefire.com.<\/p>\n<div id=\"attachment_47969\" style=\"width: 579px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-47969 size-full\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/06\/chuda.jpg\" alt=\"\" width=\"569\" height=\"374\" \/><\/p>\n<p class=\"wp-caption-text\">The CEO of Wildfire\/Blazefire, referred to only as &#8220;Chuda&#8221; or &#8220;Hagen.&#8221;<\/p>\n<\/div>\n<p>It&#8217;s not clear if Chuda is all or part of the CEO&#8217;s real name, or just a nickname; the vice president of the company lists their name simply as &#8220;Hua Wei,&#8221; which could be a real name or a pseudonymous nod to the <a href=\"https:\/\/www.cnbc.com\/2019\/06\/07\/pentagon-huawei-is-too-close-to-the-government.html\" target=\"_blank\" rel=\"noopener\">embattled Chinese telecom giant by the same name<\/a>.<\/p>\n<p>According to <a href=\"https:\/\/webcache.googleusercontent.com\/search?q=cache:W7Xcals_ElYJ:https:\/\/www.tianyancha.com\/human\/2023620582-c3223835591+&amp;cd=18&amp;hl=en&amp;ct=clnk&amp;gl=us\" target=\"_blank\" rel=\"noopener\">this cached document from Chinese business lookup service TianYanCha.com<\/a>, Chuda also is a senior executive at six other companies.<\/p>\n<p>Google declined to elaborate on its blog post.\u00a0Shanghai Wildfire did not respond to multiple requests for comment.<\/p>\n<p>It&#8217;s perhaps worth noting that while Google may be wise to what&#8217;s cooking over at Shanghai Blazefire\/Wildfire Network Technology Co., Apple\u00a0<a href=\"https:\/\/itunes.apple.com\/cn\/developer\/\/id848782271?mt=8\" target=\"_blank\" rel=\"noopener\">still has several of the company&#8217;s apps available for download from the iTunes store<\/a>, as well as <a href=\"https:\/\/itunes.apple.com\/us\/developer\/shanghai-qianyou-network-technology-co-ltd\/id1120623601\" target=\"_blank\" rel=\"noopener\">others from Shanghai Qianyou Network Technology<\/a>.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2019\/06\/tracing-the-supply-chain-attack-on-android-2\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/06\/googgraphic.jpg\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Tue, 25 Jun 2019 15:24:29 +0000<\/strong><\/p>\n<p>Earlier this month, Google disclosed that a supply chain attack by one of its vendors resulted in malicious software being pre-installed on millions of new budget Android devices. Google didn&#8217;t exactly name those responsible, but said it believes the offending vendor uses the nicknames &#8220;Yehuo&#8221; or &#8220;Blazefire.&#8221; What follows is a deep dive into the identity of that Chinese vendor, which appears to have a long and storied history of pushing the envelope on mobile malware.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[10462,22093,16695,22094,22095,22096,1670,22097,22098,22099,5883,16696,22100,22101,22102,22103,22104,17061,22105,22106,9463,22107],"class_list":["post-15636","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-android","tag-blazefire","tag-breadcrumbs","tag-chu-da","tag-chuda","tag-dr-web","tag-google","tag-haagen","tag-hagen","tag-hsu-heng","tag-ltd","tag-neer-do-well-news","tag-shanghai-blazefire-network-technology-co-ltd","tag-shanghai-bronze-network-technology-co","tag-shanghai-qianyou-network-technology-co","tag-shanghai-tongjue-network-technology-co","tag-shanghai-wildfire-network-technology-co","tag-the-coming-storm","tag-tosaka1027gmail-com","tag-triada-malware","tag-wildfire","tag-yehuo"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15636"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15636\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15636"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}