June 7, 2019

eSurvAgent RTD

How Lookout Detects and Protects Against Threats like eSurvAgent

Lookout Security Intelligence teams are continuously discovering and researching new threats to protect and advise our customers by combining static and dynamic analysis with our machine learning engine. We classified the eSurvAgent as surveillanceware when it it started to use HTTPS pinning, asymmetric encryption used for C2 traffic tunneled through HTTPS, and GUIDs being used for all parts of API endpoint URLS and directory paths. Devices with Lookout installed have detected and alerted to eSurvAgent since March 2018. Lookout also protects against other sophisticated surveillanceware that could go undetected.

Key Facts

  • Appears to have been created for the lawful intercept market
  • Works by abusing Apple's enterprise app provisioning system.
  • Functionality is controlled through push payloads, so an attacker can specify what data is to be retrieved

Background and Discovery Timeline

Early in 2018, Lookout investigated eSurvAgent, a sophisticated Android surveillanceware agent with links to an Italian company called eSurv, formerly known as Connexxa. Also known as Exodus, the agent seems to have been under development for at least five years and is a multi-stage threat with a dropper, a large second stage payload, and a final stage to obtain root access to the device. Recently, Lookout researchers uncovered the iOS component of the same threat, which was delivered to users through phishing sites that imitated customer support sites. Furthermore, through the abuse of Apple’s enterprise provisioning system, eSurv applications were signed with legitimate Apple-issued certificates.

Capabilities and Affected Parties

The iOS variant contained a subset of the functionality the Android releases offered and did not have full capabilities to exploit a device. However, this version was still able to take advantage of Apple’s certification process to appear legitimate and deploy on iOS devices to exfiltrate the following types of data:

Contacts | Photos | GPS Location | Audio Recordings | Videos | Device information

The software was discovered on phishing sites that imitated Italian and Turkmenistani mobile carriers, as well as in the Italian Play Store. It has since been removed from official Play store and Apple has revoked the appropriate certificates.

Authors

Lookout

Cloud & Endpoint Security

Lookout is a cybersecurity company that makes it possible for tens of millions of individuals, enterprises and government agencies to be both mobile and secure. Powered by a dataset of virtually all the mobile code in the world -- 40 million apps and counting -- the Lookout Security Cloud can identify connections that would otherwise go unseen and predict and stop mobile attacks before they do harm. The world’s leading mobile network operators, including AT&T, Deutsche Telekom, EE, KDDI, Orange, Sprint, T-Mobile and Telstra, have selected Lookout as its preferred mobile security solution. Lookout is also partnered with such enterprise leaders as AirWatch, Ingram Micro, Microsoft, and MobileIron. Headquartered in San Francisco, Lookout has offices in Amsterdam, Boston, London, Sydney, Tokyo, Toronto and Washington, D.C.

Discovered By
Lookout
Entry Type
Threat Guidances
Threat Type
Spyware
Platform(s) Affected
iOS
Platform(s) Affected
Android
Threat Type
Malware
Platform(s) Affected
Lookout
Threat Guidances
Spyware
iOS
Android
Malware

Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.

HeaderHeaderHeaderHeader
CellCellCellCell
CellCellCellCell
CellCellCellCell
CellCellCellCell