The developers of the Pidgin instant messaging client, which works with networks such as Jabber/XMPP, Bonjour, Gadu-Gadu, IRC, Novell GroupWise, Lotus Sametime, and Zephyr, have announced the discovery of malicious code in the ss-otr (ScreenShareOTR) plugin available in the community-developed plugin catalog. The plugin was added to the catalog on July 6, was distributed in binary form only, and allowed users to share screens using the OTR (Off-the-Record) protocol. On August 16, security researchers identified malicious activity in ss-otr, which involved the launching of a keylogger and the sending of screenshots to external servers.
An analysis of the malicious modifications conducted by ESET revealed the presence of code in the pidgin-screenshare and libotr libraries for downloading and executing scripts and executables from attackers (jabberplugins.net). For Windows users, a typical malware known as DarkGate was downloaded and installed from the server, which supports modules for a wide range of malicious activities, including mining, keylogging, remote access, and stealing personal information, keys, and passwords from popular applications. Linux builds also had functionality for downloading and executing third-party code (what exactly was downloaded to Linux systems is still unclear). server To reduce the risk of similar incidents in the future, the Pidgin developers intend to include only plugins in the catalog whose code is available under open licenses approved by the OSI. They also plan to reference only third-party plugins that have undergone security verification.
The developers of the Pidgin instant messaging client, which works with networks such as Jabber/XMPP, Bonjour, Gadu-Gadu, IRC, Novell GroupWise, Lotus Sametime, and Zephyr, have announced the discovery.
Source: opennet.ru
