EternalRocks
EternalRocks is a network worm that exploits multiple vulnerabilities in the Microsoft Windows operating system. Discovered in May 2017, it uses seven exploits developed by the United States National Security Agency (NSA) and leaked by the hacking group known as the Shadow Brokers. Unlike other malware, EternalRocks does not contain a payload, such as ransomware or spyware, but instead focuses on spreading itself across networks. As of October 2023, it remains a significant example of how sophisticated exploitation techniques can be used for widespread network infiltration.
Overview
EternalRocks is a worm that targets Microsoft Windows systems by exploiting vulnerabilities using tools developed by the NSA. It was first identified in May 2017, shortly after the WannaCry ransomware attack, which also utilized some of the same NSA exploits. EternalRocks is unique in its use of seven different exploits, making it more versatile in spreading across networks. The worm does not carry a destructive payload but instead focuses on propagation, making it a potential precursor for future attacks.
History
EternalRocks was discovered by a Croatian security researcher in May 2017. The worm emerged in the wake of the WannaCry ransomware attack, which had caused widespread disruption globally. EternalRocks uses exploits leaked by the Shadow Brokers, a group that released several NSA-developed hacking tools in April 2017. Unlike WannaCry, which used two exploits, EternalRocks employs seven, making it more robust in its ability to spread across vulnerable systems. The worm's discovery highlighted the ongoing risks posed by leaked government-developed cyber tools.
Technical characteristics
EternalRocks is notable for its use of seven NSA-developed exploits: EternalBlue, EternalChampion, EternalRomance, EternalSynergy, SMBTouch, ArchTouch, and DoublePulsar. These exploits target vulnerabilities in the Server Message Block (SMB) protocol, which is used for file sharing in Windows networks. EternalBlue, for example, exploits a vulnerability in SMBv1, allowing remote code execution on unpatched systems. EternalRocks uses these exploits to propagate across networks, seeking out vulnerable systems to infect.
The worm operates in two stages. In the first stage, it downloads and installs Tor, a software that enables anonymous communication, to connect to its command and control (C2) server. In the second stage, it downloads the seven exploits and begins scanning for vulnerable systems. Unlike other malware, EternalRocks does not include a kill switch, making it more difficult to stop once it begins spreading.
Infection vector
EternalRocks spreads through the exploitation of vulnerabilities in the SMB protocol. It primarily targets systems that have not applied security patches released by Microsoft in March 2017. The worm scans networks for open SMB ports and attempts to exploit them using the seven NSA-developed tools. Once a system is infected, EternalRocks installs Tor to communicate with its C2 server, from which it downloads additional components to continue its spread.
Notable campaigns
As of October 2023, there have been no major campaigns directly attributed to EternalRocks. The worm's primary function is to spread across networks, and it does not carry a payload that causes immediate harm. However, its ability to propagate widely makes it a potential threat for future attacks that could leverage its network access capabilities. The discovery of EternalRocks served as a reminder of the dangers posed by leaked government-developed exploits and the importance of timely patching.
Detection and mitigation
Detecting EternalRocks involves monitoring network traffic for unusual activity, such as scanning for open SMB ports or unexpected connections to Tor nodes. Security tools that can identify the presence of the seven NSA exploits may also help in detecting the worm. Mitigation primarily involves applying security patches released by Microsoft to address the vulnerabilities exploited by EternalRocks. Network administrators should ensure that all systems are updated and that SMBv1 is disabled where possible. Additionally, implementing network segmentation and monitoring can help limit the spread of the worm within a network.
EternalRocks Propagation Process
Comparison of Exploits Used by EternalRocks and WannaCry
See also
- WannaCry ransomware
- Shadow Brokers
- NSA exploits
Sources
- https://attack.mitre.org/software/S0154/
- https://cve.org/CVE-2017-0144
- https://nvd.nist.gov/vuln/detail/CVE-2017-0144
- https://cisa.gov/news-events/news/eternalrocks-worm-exploits-seven-nsa-tools
- https://securelist.com/eternalrocks-analysis/78238/
- https://unit42.paloaltonetworks.com/eternalrocks-worm-analysis/
- https://bleepingcomputer.com/news/security/eternalrocks-worm-uses-seven-nsa-exploits/