Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > DigiNotar: Iranians – The Real Target

    In this blog post, we present concrete evidence that the recent compromise of Dutch certification authority DigiNotar was used to spy on Iranian Internet users on a large scale.

    We found that Internet users in more than 40 different networks of ISPs and universities in Iran were met with rogue SSL certificates issued by DigiNotar. Even worse, we found evidence that some Iranians who used software designed to circumvent traffic censorship and snooping were not protected against the massive man-in-the-middle attack.

    Rogue SSL Certificates for Man-in-the-Middle Attacks

    SSL certificates are used for secure Web sessions like Internet banking and Google’s Gmail. Certification authorities issue and check the authenticity of SSL certificates. In July 2011, hackers managed to create rogue SSL certificates for hundreds of domain names, including google.com and even the entire .com top-level domain by breaking into the systems of certification authority DigiNotar in the Netherlands. This is very dangerous, as these rogue SSL certificates can be used in man-in-the-middle attacks wherein encrypted secure Web traffic can be read by a third party.

    On August 29, 2011, the rogue Google.com SSL certificate issued by DigiNotar was discovered. This rogue certificate makes snooping on Gmail traffic possible in man-in-the-middle attacks. Trend Micro has concrete evidence that these man-in-the-middle attacks indeed happened in Iran on a large scale.

    Our evidence is based on data that the Trend Micro Smart Protection Network has collected over time. The Trend Micro Smart Protection Network constantly analyzes data from the feedback of millions of customers around the world, including what domain names are accessed from which parts at a particular time. This feedback data makes it possible to protect against newly seen attack vectors in the blink of an eye.

    Attack Targeted Iranian Users

    In recent weeks, we saw a very remarkable pattern for domain, validation.diginotar.nl—it was mostly loaded by Dutch and Iranian Internet users until August 30, 2011. Domain name validation.diginotar.nl is used by Internet browsers to check the authenticity of SSL certificates issued by DigiNotar.

    DigiNotar is a small Dutch certification authority whose customers mainly reside in the Netherlands. We, therefore, expect this domain name to be mostly requested by Dutch Internet users and perhaps a handful of users from other countries but certainly not by a lot of Iranians.

    Analyzing Smart Protection Network data, we saw that a significant number of Internet users who loaded the SSL certificate verification URL of DigiNotar were from Iran on August 28, 2011. On August 30, 2011 most traffic from Iran disappeared and on September 2, 2011 almost all of the Iranian traffic was gone and DigiNotar received requests mostly only from Dutch Internet users, as expected.

    These aggregated statistics from the Trend Micro Smart Protection Network clearly shows that Iranian Internet users were exposed to a large-scale man-in-the-middle attack wherein SSL-encrypted traffic can be decrypted by a third party. Because of this, a third party was probably able to read all of the email messages an Iranian Internet user sent with his/her Gmail account.

    Closer analysis of our data revealed even more alarming facts like outgoing proxy nodes in the United States of anti-censorship software made in California were sending Web rating requests for validation.diginotar.nl to the cloud servers of Trend Micro. This very likely means that Iranian citizens who were using this anti-censorship software were victimized by the same man-in-the-middle attack. Their anti-censorship software should have protected them. In reality, however, a third party was able to spy on all of their encrypted messages.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    39 Responses to “DigiNotar: Iranians – The Real Target”

    1. Jeroen Says:

      Can you provide a graph of the development of the Iranian DigiNotar traffic over time? Now we can only see August 28 and 30, but it’s also interesting to see when the attack started.

    2. Mark Says:

      >Jeroen Says:
      >September 5th, 2011 at 8:36 am

      >Can you provide a graph of the development of the Iranian DigiNotar traffic >over time? Now we can only see August 28 and 30, but it’s also interesting to >see when the attack started.

      here you go: http://www.youtube.com/watch?v=wZsWoSxxwVY

    3. Anonymous Tor User Says:

      Hello,

      Could you please provide the (anonymized) data for the video above? (i.e. number of requests from inside Iran per, say, 10-20 minutes? IP addresses not needed, only number of requests over time.)

      Iranian Tor users have reported that the MITM attack was not constant but periodic (occurring every couple hours). There is some spectral analysis that could be done to would confirm this, and provide more insight into the attack.

      Thank you for everything.

    4. yek nafar Says:

      why can’t I ready all the comments?

    5. McAllenC Says:

      I’ve already read other whitepapers regarding DigiNotar, I’m just a bit curious to read Trend Micro research team’s findings and analysis about it.

    Trackbacks

    1. DigiNotar, Iran, Certificates and YOU » CounterMeasures
    2. DigiNotar et le vrais-faux certificat de Google : une affaire plus complexe qu'il n'y parait
    3. Fake DigiNotar certificates targeting Iranians?
    4. Diginotar beschuldigt Iran van ‘politieke hack’ « Rick Doorakkers
    5. Evidence shows Iranians were target of web spying operation | | Answers MerajugaadAnswers Merajugaad
    6. Evidence shows Iranians were target of web spying operation | Usefulref
    7. Hackers consiguen certificados SSL falsos de la CIA, MI6, Mosad y otros - FayerWayer
    8. Sertifikatene stjålet for Man-In-The-Middle-angrep på befolkningen. | 123sikker.no
    9. Diginotar: Iranians The Real Target | Remove spyware and malware, latest IT security news
    10. Evidence shows Iranians were target of web spying operation | Datacentre Management . org
    11. Hacker crea 531 certificados SSL apócrifos para sitios web como Facebook, Twitter, la CIA y el MI6 | bSecure
    12. Fake DigiNotar certificates targeting Iranians? (Digital Trends) | LocatePC | Locate your stolen computer or stolen laptop - Works for both Mac and PC
    13. Christians digest for September 6th | Christians lifestream
    14. Evidence shows Iranians were target of web spying operation | TryOutBlog
    15. Nearly 300000 Iranian IP Addresses Likely Compromised « system-ON-key
    16. Teknologeek.com » Hackean Certificados SSL de la CIA, MI6, Mosad, Twitter, Microsoft, Yahoo, Skype, Facebook, etc.
    17. Nearly 300,000 Iranian IP Addresses Likely Compromised : Tera Code – Portal Information Service
    18. Hackers consiguen certificados SSL falsos de la CIA, MI6, Mosad y otros | News of today world news every day
    19. Nearly 300000 Iranian IP Addresses Likely Compromised | Usefulref
    20. Nearly 300000 Iranian IP Addresses Likely Compromised | A3RN.com
    21. DigiNotar: Los iraníes, el verdadero objetivo » blog.trendmicro.es
    22. Claimed DigiNotar hacker: I have access to four more CAs - News Feed Centre
    23. Claimed DigiNotar hacker: I have access to four more CAs | Technology News - Computers, Internet, Invention and Innovation Tech from News247
    24. Nearly 300,000 Iranian IP Addresses Likely Compromised | Freedom Messenger
    25. maccad» Claimed DigiNotar hacker: I have access to four more CAs
    26. IT Secure Site » Blog Archive » DigiNotar breach due to disastrous security
    27. Iranian hacker claims responsibility for rogue Google certs | OFW … – Overseas Filipino Workers Updates
    28. Episode 469 – Hydra 33% Rewritten, G+: Identity Repository, GoogleSheep, MS11-070 to MS11-074 & Oh Apple… | InfoSec Daily
    29. Apple finally purges Mac OS of disgraced DigiNotar certs - News Feed Centre
    30. maccad» Apple finally purges Mac OS of disgraced DigiNotar certs
    31. Trend Micro Asia Pacific News Library - DigiNotar: Iranians – The Real Target
    32. DigiNotar, Iran, Certificates and YOU | Simply Security
    33. DigiNotar: Iranians – The Real Target | Simply Security
    34. Five Important Bulletins for September Patch Tuesday | Simply Security


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice