Hikvision Trojan Mobile App

Published Sep 22, 2015 04:00 AM
PUBLIC - This article does not require an IPVM subscription. Feel free to share.

With a vengeance.

The last time, the industry mostly shook it off. This time, it is clearly much worse.

In this note, we examine Hikvision's trojan horse app, the company's response, why this is a major concern and who stands to benefit from this.

Hacking History

Just 6 months ago, a Chinese province's Hikvision devices were hacked. This was enabled by fundamental security weaknesses in Hikvision's products and, most likely, basic errors in the province's network administration. The public notice of that issue caused Hikvision's stock price to briefly plunge and trading of the stock temporarily halted.

In addition, the most infamous was Wired's article on Hikvision: HACKERS TURN SECURITY CAMERA DVRS INTO WORST BITCOIN MINERS EVER. Also, there was a buffer overflow vulnerability found later in 2014 allowing remote DVR access.

And now there is the new incident.

Trojan Mobile App

A number of (mostly Chinese) companies shared a malicious copy of Apple's mobile development kit (Xcode) via an online forum, rather than getting it from Apple directly.

Update: One execuse is that these companies did it because China's firewall makes downloading from Apple slow, though an IPVM member from Shenzhen showed he could download Xcode from his house in a little more than an hour.

Hikvision then used this code in their production iVMS-4500 app, publishing it and allowing their users worldwide to download this malware on to their mobile devices.

This malware is designed to phone home to the hacker's servers with your personal information (see the original malware disclosure post). Equally bad, it is "capable of receiving commands from the attacker" including "Prompt a fake alert dialog to phish user credentials" and "Read and write data in the user’s clipboard, which could be used to read the user’s password if that password is copied from a password management tool."

Critically, this is not a vulnerability that maybe, if someone had the time or talent to exploit, might become compromised (as some risks are). This was designed to be actively exploited from the start. 

Response From Hikvision

In Hikvision's official statement (see here), they recommend deleting the current iVMS app (v 4.20) and replacing it with the new non-malware one.

Hikvision also noted that they have established a Security Response Center and that they have quickly fixed the issues this time and the last time (see version 5.3 firmware tested).

VOTE

3500 Engineers

Hikvision enjoys bragging about their '3500 engineers' and how they are #1 in the market.

In fairness, they are now the clear #1 in getting hacked. And it casts great doubt on the quality and/or organization of their engineers.

Spinning

Worse, Hikvision finds itself getting hacked right after a truly surreal marketing campaign / webinar they ran about "Cybersecurity and Video Surveillance: How to Protect Your IP Video Network [link no longer available]." In the webinar, Hikvision pretended their products had not been hacked repeatedly, as if somehow they were responsible and cyber secure.

The most bizarre moment came when the Hikvision employee cited prominent hacking cases this year. Of course, he did not cite his own companies, preferring to focus on the US Office of Personnel Managment.

China Connection

Ironically, US government officials believe the Personnel Management hack was launched from China, joining this malware attack.

Hikvision wants to downplay its Chinese connection, but Hikvision is partially owned by the Chinese government and has benefited tremendously from incredibly lucrative Chinese government contracts.

Hacking from China is a real risk for US users. Probably Hikvision is just incompetent here but the risk is clearly magnified that it could be more.

Update: More Spinning From Hikvision

After publishing this post, a Hikvision employee lept to the defense of his employer:

What nonsense. Hikvision uploaded the malicious code. If Hikvision did not do this, there would have been no hack. For example, why were the Axis, Avigilon, ACTi, etc. apps not hacked? Because those companies did not submit trojan apps. 

This compounds the problem. Is Hikvision going to take responsibility for these serial hacks or is everything someone else's fault?

Selling Hikvision Now

If you sell Hikvision going forward, we feel you have an ethical responsibility to disclose this risk up front to your customers. Hikvision has tremendous advantages (low price, strong image quality, solid support and reliability) but with so many incidents in such a short time frame, you would be negligent not to make this clear up front. Even if Hikvision is serious now about cybersecurity, who knows that other vulnerabilities still exist and will be uncovered in the next year.

Winners and Losers

Obviously, Hikvision is a big loser here and so are their dozens of re-labelers, companies like ADI and Tri-Ed who we validated run Hikvision's 'risky' old firmware.

Since Hikvision is the #1 threat to nearly ever camera manufacturer in the world, everyone else wins. However, on the low cost side, two companies really stand to gain:

Dahua: Their down the block domestic blood rival has a great opportunity to capitalize on this. Dahua has struggled to build their branded sales and marketing organization but this might be the opening they can use to differentiate themselves.

Hanwha / Samsung: The Wisenet Lite series shows Samsung is serious about competing for the low-end / budget market. Now, they can use this to help differentiate both not being 'Chinese' and not having their surveillance products serially hacked.

Of course, you never now who will be hacked next, so it is hard to say anyone is safe, but Hikvision has a commanding 'lead' in this race so far.

Comments are shown for subscribers only. Login or Join