This article is no longer available publicly. Please subscribe to read.

Hackers Add Backdoor To CCTV Security Pros / Dahua SmartPSS

Published Jun 22, 2021 13:56 PM

Hackers have inserted a backdoor into downloads of Dahua's SmartPSS from OEM / relabeller's "CCTV Security Pros" website, allowing attackers full control of compromised computers.

IPVM Image

In this report, we examine:

  • Details of the backdoor
  • The affected OEM and their feedback
  • Details on the hacking group
  • Potential for impact in surveillance
  • Small OEM cybersecurity threats

Backdoor *******

*** ******** *** ************* ** ********, ** ********** ******** ********, ** a **** **** ******. ******* ********** downloads ** *****'* ******** **** ** OEM's *******, ******** *** ******** ********** with ********* ************* ********** ******* ***** ******** ****** installation ** * ******** (***** "*********").

********* **** *** **********, ****** *** remote ***********, *** **** *************, ****** PowerShell ******** ** ** ********, *** without **** *********. ******** ******** ********* using **** ******** ** ******* *** on * ****** *******, ****** **** full ******* *** ****-**** ******* ** user **********.

******** **** **** *** ****** ***** contacted **** ******* ******, *** ****** should ****** ** ***** *******.

Background **** ******** ****

**** ******** **** **************************.*********** *** ** * ********** ** NJ:

IPVM Image

******** ****** ********:

IPVM Image

******* *** ***** *** *** **** commonly ******** ******** ** **************** **** 3 ****** ******* *** ~**,*** ****** shipped ** ****, ** ****:

IPVM Image

CCTV ******** **** ******* ******

***** *** ******** ****** **** *** name *** ******* ***** ****** *** Trojanized ******** ********, *** ****** * screenshot:

IPVM Image

*** ** ********** **** **** **** matches *** ******** ****** ******** ****' ********* ****(* ********** ***) *** ******* *** ** *** company *** *******, *** ********* (*** comments, *****). **** ******** **** ** currently ******* ** *** ***** ******* was ***********.

DarkSide ********** *********

*** ******* *** *** ** *** DarkSide ********** *****'* ***** ***** **********, which ******** ****** ** *******. ******** is **** ***** *** ***** ********** ** *** ******* **' ******** Pipeline. ** ***, ***** **** **** no ******* ** ******* ********* ****** from ******* ** *** ******** ********.

Likely *** ********** / *********** ****** *** *******

**** ******** ******** ** ****** *** widespread. **** ******** **** ** *** well-known, **** ***** ***** ***** ****, so ** ** ******** **** * large ****** ** ***** ********** *** Trojanized **** ***** ** *** *********.

************, **** ******** **** ******* **** is *** * *** *** *** searches *** ********, ********* ** *** second ** ***** **** ** ****** results, ****** ** ******** **** ***** would **** **** ** ****** ******* for ********, *.*., ********* "******** ********" or ****** "********."

CCTV ******** **** ********

******** *** ** **** ******** **** for *******, ** ******** ** ** the ***** **** *** ***** ** this ************* (******* ******** ** ******* that **** *** ******* *** ** them) *** **** **** *** ******* the ******** ******** *** ******** **** new.

** * ********* ****** ** ******** cameras *** ******* *** ********* ******** and ******* ** * ******* *******. As **** ** ** *** **** report ** *********** **** ****** *** removed *** ****. ** ** **:**** 6/17/2021 *** **** *** **** ******** with * ********** *** *********.

***** ** **** **** ***** ** notify ** *** ******* ******** *********, they *********:

*** **** * *** ******* ** our ******** ** ********* ** **** report **** ** *** *********. ******* our ********* ******* **** ****** ** our ********.

*******, ***** ** **** *** *** idea *** *** ****** ******** *** hackers **** **** ** ****** *** compromised *******, **** *********:

*** ******** ***** *** ******** ** us ******** **** *** ************* ** the ********* ** ****. **********, ** will ** ************* *** *** **** was *********** *** **** *** ********* actions.

**** ******** **** ******** ** ******* further ******* ***** **** ********.

Old *** ******* / ********** ****** ** ****** *****

******** **** *** ***** "******** *****" are ******** ******** **** *** ************, at *** **** ********'* ****** *** released, **** ******** **** *** ******* their ********* ** ******* ******** ***** ** ******** **** ******* (V2.002.0000007.0.R.181023). ** ********, ***** ***** ***** downloads ** ***** *** ********, *** the***** ****.

Dahua ********

*****'* ******** *** *** ******* **** details ******** ** **** ****, *** reiterated ***** ******* ************* ******:

*. ** ********** *******’* **** ** exposing **** ***. ******** ******** ** this **** ***** ** ********* **** in *** ********* *** *** *************.*. Dahua *** ** ********* ******* *** set ** ********* *** *********** *** dealing **** ***************. *** ******** ** built ****** ************* ** ** **-***** process **** ******* ********** ******* *** improvement ** ********.*. ***** *** *********** protocols, ********** **** **** ******** ** the ********, *** ******** **** ***** newly ********** ******** ****** *** ******* for **** ** * ****** ******.*.***** takes *** ******** *********. ********** **** best ********, ** ****** ** ******* pen *******, **** **** ******** **********, and ******* ****** *********.

Small *** ************* ******

******** **** ************ ******** ************* ****** have ******* ** ***** *******, **** backdoor *********** *** ********* ****** ***** by ****** ******** ***** ****. **** of ***** ************* *** **** ***** and ***************, ******* *** **-***** ********* required ** ****** ***** ************** ******* this **** ** ******. ******* ** this, **** *** ** * ***** target *** *********, ********** *** **********-**** attacks, ***** *** ****** ** * single ****** ****** *** ****** ** potentially ***** *** **** *** ******* a ***** ********** ****.

Comments (22)
U
Undisclosed #1
Jun 22, 2021

*** *****’* **** * ****** *** wearing * ******?

(1)
(1)
(4)
SF
Shay Fogel
Jun 22, 2021

** ***** ** ***** ** **** vulnerability ** *****'* ******** ******** **** allowed ** ** *** "**********", ***** this ****** ***** ** ******* ** almost *** ***** ******** *********.

(5)
(1)
UI
Undisclosed Integrator #2
Jun 22, 2021

* **** ** ***** **** **** F. ***** **** *******. ** ** not *****'* ************** ** ****** ***** party ***'* ********. ******* ***** ** impossible ****. **** **** ** ****** vector *** ******* *** * **** long ****. (** * ** *** a ***** ***, *** ** *** are ***** ********* **** ** ***** use *** ** *** *'*** **** can ** **** *********** ***.)

*** ***** **** ******** (****):

****** ******** *** ** *** "********" in ******** ** ***** **** ********* | *****

(3)
JH
John Honovich
Jun 22, 2021
IPVM

** *** *** ***** ********* ****

**'* * ******* *********** ** **** happened ********* ********* ********* **** *** OEM *** **** *****. ** *** read *** ****, ***** ** ***** being **********?

(2)
JH
John Honovich
Jun 22, 2021
IPVM

*** ***** **** ******** (****): ****** explains *** ** *** "********" ** hundreds ** ***** **** ********* | ZDNet

***, **** **** / ***** ******* with ***** ******* *** **** ******* as *** *****, ***** *** ******** is *** (** **** **** *****'* SmartPSS) ** * *** ******* ** the ******, ** ***** ******** ** Linux.

(3)
UI
Undisclosed Integrator #2
Jun 22, 2021

****'* **** ** *** ***** * am ****** ****. ** ** ****** easy ** **** ******** ***** ***** software *** * *** ** ****** don't ******** *** ****** ** **** they *** ***********.

'*********' *** **** **** * ****** harsh, *** **** *** ***** ** the ******* **** ******* *****/***** ****** that ***** ** ** *****. *** reality ** *** ********* ** **** CCTV ******** **** ******* ***** ** download * *********** ******* ** *****'* SmartPass ********.

*** ****** *****'* ***** *** ***** in *** ***** ******** *****, *** I ***'* *** *** ***** ***** have ********** *********/********* **** **** ** issue.

(1)
(1)
JH
John Honovich
Jun 22, 2021
IPVM

** ** ****** **** ** **** modified ***** ***** ********

******* *****/***** ****** **** ***** ** at *****

**** ******** **** ******* ***** ** download * *********** ******* ** *****'* SmartPass ********.

** **** ****, **** ******** **** is ** ********** ***** *******. **** what ** ***, *** *** ** reported ****, *** ****** ************** ** on **** ******** **** *** ***** has ********* ************** ** *** **** provide *** ********* ***** ******** ** distribute ********.

** *** *****'* *** ****** ******, they *** ********, *********:

*** **** *** ***********.

(1)
(2)
UI
Undisclosed Integrator #2
Jun 22, 2021

******. * ***** ** *** ****** the **** ***** ** ********* ****.

SF
Shay Fogel
Jun 23, 2021

***** *** ********* ************** ** *** they ******* *** ********* ***** ******** to ********** ********.

**'* *** **********. ***** ******** **** not ***** ***** *** ***** ** control ********.

JH
John Honovich
Jun 23, 2021
IPVM

****, ***** *******, ****'* ********* ** Dahua.

**** ******** **** **************************.***** * **** ********** ** ** with * *** *********:

IPVM Image

***** ** * *****-******* *********** **** tens ** ********* ** *********:

IPVM Image

***** ***** **** ** * *** hours **** '**** ******** ****' ***** in * ****.

** ***** ** ** ******* ***** cybersecurity ** **** ***, ***** *** enforce ********** ***** **** **** ******** like '**** ******** ****'.

*****/********?

(3)
UI
Undisclosed Integrator #6
Jun 23, 2021

***** *** ******* ********** ***** **** tiny ********

** **** *** *** **** ** seriously *********** ******** ** ****** *********, sure. ***** **** **** ** **** broader ***** ***** *****'* ***** ** having ******** ***** ****.

**'* **** **** ** ****** ******* security. * ****, ** **** *** SolarWinds **** * ******* **** ******** a *** ** ***** *******. ** a ******* ** *** ** ********** can ** ****, *** *** *** know ** **** *** ******* ***'* going ** ** *** **** *****?

** *** *** * ********* **** you **** ** ** **** ****** serious ************* ** **** ********. *** is ***** ***** ** ** ****? With ** **** ********, ** **** have ** *** ** * *** department ********* ** ***** ******** ***********? Maybe **** ***** ******** ** *** to ******** ****** ********? **** **** I **** ******* **************., *** "** hey, ** ******* **** **** **** IP ******* *** **** ** ****..."

*** *** **** ******* **, *** small ********* ****** *** ** **** in *** ***** *****? "*** *** attackers *** ** *** *** **** I ****** *** ** * *** HTTP ****** *** ****** ******* ** Same **** - **** ** ***** words ****?" **** ** *** **** programmers *** *** ********** ******* *****, do *** **** ******* ** ***** who *** ***** ****** ******* ****** strong *********, ******** ********, ******* ********* and ******** *******, ***? *** *** protect **** *** ****** *****? ***** was * ********** ** *** ***** Wire *** ***** *** **** *** on *** **** **** ***** ********* generally ***'* **** *** ***** ** deal **** ********.

** **** *****'* ***********, **** *** you ***** ** **? *** * bunch ** ***** ** ** *********** that **** ********* **** ** **** partners? **'* **** ** *** ** being ********** ** ****. **'* ****** to **** **** *** *** *****.

*******, **** ********* ****** ** **** than **** *****. **** ******** **** is ********* ******** ******* **** *** an ***. *** ** *** ***-***, non-Dahua ******* *** ********* **** ** have * *** ******* *** ********* available *** ********* ** ********. ***** what? **** **** ** ** *** same ****. *** ** ***** ** a *** ******** ** * ******** engineered **** ******* *** *** ******** to **** **** *** ******* *** mess ** *** *********. (*** ***** interested, ** ** *****'* **** **** yet.) ***** ** *** ******* ***** know **** ** **** ******** * way ** ******** ***** ******? *'* not **** **** *** **** ** have * *******. **** ** *** download ****** ****** ** *** ****** website ******* ** * ******** ** our ******, ****** *** ***** ** could ****** **** ** ***** ** a ********* ********.

** *******, ******** ** ****, **** small ********** *** *** ** **, and * ****** ** *** *********.

JH
John Honovich
Jun 23, 2021
IPVM

** *** *** * ********* **** you **** ** ** **** ****** serious ************* ** **** ********. *** is ***** ***** ** ** ****?

**** *** ****** **** *****, *.*., Dahua ***** *** '*** ******** **** use ******** ***** **** ***** ******** website / *****.' * ***'* ***** it's * ****** ******* ******* *** everything.

(1)
UI
Undisclosed Integrator #6
Jun 23, 2021

****, *** ***** **** ** ****** every ******* ******* *** **** **** there's ** ******** ****, *** ******* that **** ***** ** *****'* ******** page (*** *** ****** * ********* above). *** **** ****, ** *** know **** **** ******** *** ******** the *********? **** ** *** ***** that **** **** **** ******** *** a **** ** * ****** ***** file?

(1)
JH
John Honovich
Jun 23, 2021
IPVM

*** *** *** **** ******** ** counter ********* ********, *.*. ***'* *** your ******* *** * ****** **** says:

** ****** "**** ****" ***** ******* customers.

*** ***** *******:

****, *** ***** **** ** ****** that ***** ******** **** *** **** your **** *****. *** **** ****, do *** **** ** ********* ***'* do ** **** **** *** ** the *** ****? **** ** **** do ** **** ** ******** *** looking? **** ** **** **** **** mama ***** **** ************ ********?

** ***** ** ****. * ******* can *** *** **** '*** ******** must *** ******** ***** **** *** official ******* / *****' *** *** penalties ** **. ******** *** ******* the **** *** **'* ***** **** it ** * **** **** ********* for ***** ******.

(1)
UI
Undisclosed Integrator #6
Jun 23, 2021

**, * *** **** ***'** ******. Sorry, **** *'* ** ****** **** I **** ** **** ** ** absolute **********.

(1)
SF
Shay Fogel
Jun 24, 2021

*** **** ******** ***** ***** ********? 😉

* ***** **** ***. ******** **** - **** ***'* **** ** ** it. **** *** ** ********** *** their ******** ** **** **?

UI
Undisclosed Integrator #5
Jun 23, 2021

***** ******** **** *** ***** ***** the ***** ** ******* ********.

*** **** ************* ****** ** **** to ***** ********** ********* **** ***** subordinate **** ******* *********** ************. ****************************** *********************************. **** ************* *** ****** ** protect ***** *****.

(1)
(1)
(1)
UM
Undisclosed Manufacturer #3
Jun 22, 2021

***** ** ***/***** ***** **** ********* the ****** ** ***** **** *** involved ** ************ *** ********, *********** it, ******* **, ***. *** **** makes ** ****** *** ************* ** happen *** ** *********. * ****** that ***** ***** ******** ** ***** website *** *****'* **** **** ** other *** ********, ****** **** ** somewhat **** ******...??

** *** ****** *** ****** *** hash ** *** *****, **** ***** have ****** (** ******), ******** ***** to ****** **** *** ******** *** been *******.

** ***** ** **** **** ************* don't **** *** **** ******, *** most ****** ***'* ****** ********.

(2)
(3)
UD
Undisclosed Distributor #4
Jun 23, 2021

*****, **** ******** ********** ***** ********* with ******** ****** ****** ** ** with.

(6)
(8)
JH
John Honovich
Jun 23, 2021
IPVM

******* **** ****** ****** *******:

******* *** ***** *** *** **** commonly ******** ******** ** **************** **** 3 ****** ******* *** ~**,*** ****** shipped ** ****, ** ****:

IPVM Image

(2)
SF
Shay Fogel
Jun 24, 2021

* ***** **** *** ******* ***** serves **** *** ****** (*** ******** to *** ***) *** ***** ** security *** *** ******* *****. ** simply **** *** *** *** *******'* price ***** ********** ** ***** ****.

(1)
JH
John Honovich
Jun 24, 2021
IPVM

** ***** ***** ** ******* **** its ****** ****** ** ** ***** and *** *** **** ******** ** not ***** ** **** **** *** do **. *** *** ** ***** about *****’* ****** ******* **** *** Dahua’s ****** ******** ******** ****** ******** seriously.

(1)
(1)