Campaign · Proprietary · · 10 days

One CDNetworks breach tampered with four customers' files

An intruder logged directly into CDNetworks' content-upload servers in May 2014 and altered files belonging to several unrelated customers at once, including Buffalo's Windows driver downloads and Aiming's online game update files.

Draws together 2 incidents across 2 packages

Most distribution compromises in this archive begin at the vendor. This one did not. In May 2014 the content-delivery provider CDNetworks was entered directly on the servers customers used to upload what it would serve, and files belonging to several unrelated companies were altered in the same intrusion.

The customers had nothing in common except their supplier. Buffalo's Windows driver, firmware, and utility installers were replaced with builds that dropped a Japanese online-banking trojan. Aiming's update files for the online game Blade Chronicle were swapped for malware. GMO Pepabo's JUGEM blog content, H.I.S. via Recruit Marketing Partners, and other customer pages were tampered with in the same window. None of them had been breached; their supplier had.

CDNetworks disclosed on June 3 and concluded that the cause was on its own side, describing direct logins to the content-upload service most likely from a compromised internal terminal. It published a progress report on June 11 and a final report on June 27, and completed removal of the altered files by June 3.

The record exists because the individual incidents read as separate vendor failures unless the shared root cause is stated. Buffalo's own customers experienced it as Buffalo serving malware; the download server was CDNetworks', operated under contract, and one intrusion there reached every company whose content passed through it.

Notes

  • CDNetworks stated that the cause lay on its side, describing direct logins to the content-upload servers most likely from a compromised internal terminal. It disclosed on 3 June 2014, published a progress report on 11 June and a final report on 27 June.
  • Customers named as having content altered in the same intrusion are Buffalo, GMO Pepabo (JUGEM), H.I.S. via Recruit Marketing Partners, Aiming, and Recruit Marketing Partners' own pages. Only the Buffalo and Aiming cases are recorded as separate attacks here, because only those two altered software that users then installed; the others were website content.
  • Infostealer.Bankeiya.B is the malware family reported across the Buffalo case and associated May 2014 tampering. Contemporary reporting also links JUGEM and H.I.S. to the same family, but through separate site-tampering attacks using Flash rather than through this intrusion, so the family alone does not establish the link.

Incidents in this campaign

  1. Blade Chronicle update files swapped for malware
  2. Buffalo driver downloads delivered Bankeiya

Appendix · Affected packages

Samples and hashes sit on each incident page, linked above

References

  1. CDNetworks content tampering incident summary and timelinepiyolog.hatenadiary.jp
  2. Buffalo discloses tampered download files and malware infection riskinternet.watch.impress.co.jp

Source record: proprietary/campaigns/cdnetworks-2014/meta.yaml