{"id":11691,"date":"2019-10-24T11:08:23","date_gmt":"2019-10-24T15:08:23","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=11691"},"modified":"2020-12-09T13:42:45","modified_gmt":"2020-12-09T18:42:45","slug":"a-sneaky-online-security-threat-encrypted-malware-in-ssl","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/a-sneaky-online-security-threat-encrypted-malware-in-ssl\/","title":{"rendered":"A Sneaky Online Security Threat: Encrypted Malware in SSL"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Unfortunately, the bad guys use encryption, too<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every time you connect to the\ninternet, whether it&#8217;s from a phone, tablet, or computer, you accept a certain\nlevel of risk. Hackers continue to find new ways to exploit security flaws and\ncompromise your device or data. You need to be on alert at all times in order\nto avoid dangerous malware and other attacks that sometimes come from where you\nleast expect them. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you see a padlock icon at the top of your browser, it means that you\u2019re communicating with the site you are viewing via a connection encrypted with a valid SSL\/TLS certificate. But many people make the mistake of assuming that as long as an SSL certificate is present, then they are safe from all forms of attack, end of story. In this article, we&#8217;ll explore how new types of malware are actually being hidden behind this trusted symbol.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.thesslstore.com\/blog\/understanding-the-encryption-technology-behind-ssl\/\">SSL encryption<\/a> is critical for any site or application that requires\nsensitive information to be transferred. This includes passwords, credit card\nnumbers, and other financial data. SSL certificates are an excellent defense\ntactic against intruders who\u2019re trying to eavesdrop on your internet activity,\nprotecting your data from criminals. Here\u2019s the thing, though: bad guys can use\nencryption, too. And hackers and cybercriminals are using SSL\/HTTPS to hide\nmalicious code.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Firewalls &amp; Intrusion Detection Systems Have a Loophole<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Companies and organizations\nspend a lot of money and resources on IT security solutions. One popular\napproach is to combine intrusion detection systems and firewalls to monitor and\nanalyze all incoming traffic to your local network. The idea is for the system\nto automatically detect and block cyber attacks and hacking threats before any\nusers become vulnerable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, let\u2019s say Bob in\ncustomer service clicks on a link in a phishing email that leads to a URL with\nmalware. The organization\u2019s security systems\ncould detect and block this visit before Bob\u2019s machine can become infected with\nmalware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, there is an inherent loophole in how intrusion detection systems are built to operate. They involve the scanning of network traffic to identify patterns that correspond to malware or other malicious attacks. If the systems are unable to decode the full body of each incoming network request, then they remain blind to a certain portion of traffic. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, when you\ndownload a document from an external website, your firewall or intrusion\ndetection system can inspect the packets of data that come through the local\nnetwork. But if that communication is happening over an SSL connection, then\nthe system cannot see through the encryption to detect what is really inside\nthe document. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some newer intrusion detection solutions are introducing the concept of deep packet inspection, where the tool looks at the lower levels of each network request to understand more about its content. But not many organizations have this option available to them, which means that data passing over HTTPS could be a threat. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another technique for detecting the presence of SSL malware is <a href=\"https:\/\/www.thesslstore.com\/blog\/ssl-inspection\/\">SSL inspection<\/a>. This is the process of intercepting SSL\/TLS-encrypted internet communication between the client and server. Interception can be executed between the sender and the receiver, and vice versa (receiver to sender). This, strangely, is the same technique used in man-in-the-middle (MitM) attacks, but if deployed carefully can be used to filter out malware in SSL. (The key difference between inspection and a man-in-the-middle attack is that with SSL inspection, the network administrator modifies the computers to allow inspection only by the authorized device\/certificate.)<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Mechanics of SSL Malware <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To understand how hackers encrypt malware with SSL, we need to look at the Transport Layer Security (or TLS,) which refers to the encryption process that goes on behind SSL. The latest Google numbers tell us that <a href=\"https:\/\/transparencyreport.google.com\/https\/overview?hl=en\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">93% of the internet is now encrypted<\/a>. As discussed, it is designed to be locked to all outside parties, including firewalls that don&#8217;t support deep packet inspection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to SSL malware, hackers are not able to inject directly into existing streams of HTTPS content. For example, if you are shopping on Amazon and submit your credit card number to pay for a book, that information is transmitted over SSL. If a <a href=\"https:\/\/www.thesslstore.com\/blog\/linux-tcp-flaw\/\">hacker tries to modify that traffic<\/a> and inject malware, your browser will notice that the keys have changed and will automatically reject the request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, there are ways around this &#8220;problem.&#8221; One of the most common is for cybercriminals to get <a href=\"https:\/\/www.thesslstore.com\/blog\/fbi-issues-warning-about-https-phishing\/\">free SSL certificates for their sites that contain malware<\/a>. Though legitimate SSL certificates are not expensive  \u2014  particularly given their importance in protecting data from theft  \u2014  hackers may find it easier to get a free certificate without using any financial info that could be used to track them. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another variation on this technique for the delivery of SSL malware is for criminals to use <a href=\"https:\/\/www.thesslstore.com\/blog\/58-of-phishing-websites-now-use-https\/\">SSL certificates on phishing sites<\/a> that deliver malicious code to victims\u2019 systems while looking like a legitimate websites. The hacker will send out a series of fraudulent emails that look like they are coming from a reputable sources. If users click on them, they will be directed to websites that look secure because they have free SSL certificates. At that point, the hackers can embed their malware into the encrypted traffic and try to bypass any firewall system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These types of attack are becoming worryingly prevalent. Security Week <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.securityweek.com\/ssl-increasingly-abused-malware-phishing-report\" target=\"_blank\">reported<\/a> in 2017 that in the first half of that year, Zscaler\u2019s products blocked roughly 600,000 threats hidden in encrypted traffic every day. That number grew to 800,000 in the second half of the year, which represents an increase of 30%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other security analysts have also raised concerns. As Bill Conner, CEO of SonicWall, <a href=\"https:\/\/www.techrepublic.com\/article\/why-ssl-is-part-of-the-problem-behind-a-dramatic-increase-in-malware-and-ramsomware-in-q1-2018\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">told TechRepublic<\/a> earlier this year, SSL is now implicated in 4.2% of malware. That represents, he says, a 400% increase over the previous year. \u201cThat&#8217;s because of the ease of finding bad SSL certificates,\u201d he continued, but also because \u201conly 5% of customers are turning on DPI, deep packet inspection for SSL.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The important thing to remember is that SSL does not guarantee safety. It simply ensures that your requests are encrypted. But the actual data being transmitted can still contain dangerous elements, including viruses and other forms of malware. Therefore, you should always be suspicious when visiting a new website. (Note: If the website in question is using an organization validation [OV] or extended validation [EV] SSL certificate, which are very hard for hackers to get, you can check their certificate details to get additional details about the organization that\u2019s running the website.)<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">7 Tips For Protecting Yourself <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Staying safe online requires\na consistent level of diligence. Your best bet is to take proactive steps to\ncontrol and protect your online privacy. Here are a few tips to protect against\nSSL malware and other threats:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>You should always look for the padlock symbol in your browser to confirm that the site you are using has SSL encryption enabled. But don&#8217;t assume that&#8217;s sufficient because, in fact, many nefarious websites spoof their own SSL certificates to <a href=\"https:\/\/www.thesslstore.com\/blog\/smoke-loader-malware-ssl-enabled-site-pushing-fake-meltdown-spectre-fix\/\">appear legitimate<\/a>. <\/li><li>Any time that you enter personal information or make a financial transaction, take an extra minute to consider the platform you are using and whether the URL in your browser and any organization details on the SSL certificate correspond to the correct organization. <\/li><li>Advanced DNS spoofing can even provide seemingly correct URLs that will capture user credentials. Strong <a href=\"https:\/\/privacycanada.net\/best-password-manager\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">password managers often protect against this<\/a> by cross referencing URLs but users need to be vigilant when entering login info.<\/li><li>Consider adding a <a href=\"https:\/\/surfshark.com\/learn\/what-is-vpn\">virtual private network<\/a> (VPN) to your online security regimen. This moderately priced service is deployed by an increasing number of internet users. It\u2019s easily available by subscription and uses different forms of encryption than SSL to secure and anonymize your online session. <\/li><li>Ensure your organization has correctly configured firewalls and intrusion detection systems. Hackers aren\u2019t getting any dumber with their cyberattacks, which means that even if you take all of the right precautions, there is still a chance you could be vulnerable to malware. While we recounted the limitations of intrusion detection systems earlier, you\u2019d be silly not to use them. Even if some of the hacker\u2019s packets make it into your system, there is at least a decent chance your intrusion detection strategy will detect and quarantine it before too much damage is done.<\/li><li>Be sure your organization is using deep packet inspection and\/or SSL inspection to ferret out threats in encrypted web traffic.<\/li><li>Invest in credible anti-virus tools from reputable sources and keep them up to date! While not foolproof, there is no better way, given current technology, to protect yourself than having a firewall and anti-malware and anti-virus software watching your back.<\/li><\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Don\u2019t make the mistake of blaming this on SSL. Without it, the internet would be a MUCH more dangerous place. With the current level of hacking, going anywhere online would be hazardous. You would not be able to trust that your passwords and credit card numbers were being sent safely anywhere. The larger point here is that even when an SSL connection is present, remain aware that you still can be a target thanks to malware or other threats hidden inside of SSL traffic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">No need to be afraid. Just be vigilant with your cybersecurity strategy. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> <em>As always, leave any questions or thoughts in the comments!<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Unfortunately, the bad guys use encryption, too Every time you connect to the internet, whether it&#8217;s from a phone, tablet, or computer, you accept a certain level of risk. Hackers&#8230;<\/p>\n","protected":false},"author":15,"featured_media":11692,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130,10200],"tags":[],"class_list":["post-11691","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","category-monthly-digest","post-without-tags"],"views":32153,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/10\/malware-encryption.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11691","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=11691"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11691\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/11692"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=11691"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=11691"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=11691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}