Open Source 2017-05-02 · 4 days ·Data Exfiltration

HandBrake mirror delivered Proton RAT

An official HandBrake download mirror, download.handbrake.fr, was compromised while hosting the macOS release.

Story

HandBrake's 2017 incident hit a mirror, not the source tree. Between May 2 and May 6, the download.handbrake.fr mirror served a trojanized HandBrake-1.0.7.dmg for macOS. The main site stayed legitimate, but the official mirror path was enough.

The replacement package carried OSX/Proton.B. The malware used activity_agent, decrypted strings from a .hash resource, asked the user for a password under the cover of installing codecs, and then used that password to obtain higher privileges.

Proton was built for control and theft. Public analysis described keylogging, password and keychain theft, browser credential theft, file exfiltration, screenshots, remote shell, and remote access capabilities. HandBrake told affected users to change passwords stored in macOS Keychain and browsers.

The project said users who downloaded during the window had about a fifty percent chance of infection because not every download came from the compromised mirror. Built-in updates from HandBrake 1.0 and later were reported safe because update verification would reject the malicious file.

Affected Artifacts

handbrake

· download.handbrake.fr · Binary Archive
Observed
2017-05-02 to 2017-05-06
Compromised Versions
Fixed
Not listed
Hashes
  • sha256:0935a43ca90c6c419a49e4f8f1d75e68cd70cb90b79306ce0cc7af2716aaa377
  • sha1:32176407013738cb03959d0945993c13373f9590
  • sha256:013623e5e50449bbdf6943549d8224a122aa6c42bd3300a1bd2b743b01ae6793
  • +1 more

Incident Context

Motive
Credential Theft
Attribution
Group
Cause
Compromised Infrastructure
Transitive
No
Actor
Cybercriminal Gang

External References

Source record: oss/attacks/handbrake/meta.yaml