Campaign · Proprietary · · 10 days

One CDNetworks breach tampered with four customers' files

An intruder logged directly into CDNetworks' content-upload servers in May 2014 and altered files belonging to several unrelated customers at once, including Buffalo's Windows driver downloads and Aiming's online game update files.

Draws together 2 incidents across 2 packages

Most distribution compromises in this archive begin at the vendor. This one did not. In May 2014 the content-delivery provider CDNetworks was entered directly on the servers customers used to upload what it would serve, and files belonging to several unrelated companies were altered in the same intrusion.

The customers had nothing in common except their supplier. Buffalo's Windows driver, firmware, and utility installers were replaced with builds that dropped a Japanese online-banking trojan. Aiming's update files for the online game Blade Chronicle were swapped for malware. GMO Pepabo's JUGEM blog content, H.I.S. via Recruit Marketing Partners, and other customer pages were tampered with in the same window. None of them had been breached; their supplier had.

CDNetworks disclosed on June 3 and concluded that the cause was on its own side, describing direct logins to the content-upload service most likely from a compromised internal terminal. It published a progress report on June 11 and a final report on June 27, and completed removal of the altered files by June 3.

The record exists because the individual incidents read as separate vendor failures unless the shared root cause is stated. Buffalo's own customers experienced it as Buffalo serving malware; the download server was CDNetworks', operated under contract, and one intrusion there reached every company whose content passed through it.

Notes

  • CDNetworks stated the cause lay on its side, describing direct logins to the content-upload servers most likely from a compromised internal terminal. It disclosed on 3 June 2014 and published a final report on 27 June.
  • Customers named as having content altered in the same intrusion are Buffalo, GMO Pepabo (JUGEM), H.I.S. via Recruit Marketing Partners, Aiming, and Recruit's own pages. Only Buffalo and Aiming altered software that users installed.
  • Infostealer.Bankeiya.B is the family reported across the Buffalo case and associated May 2014 tampering. Reporting links JUGEM and H.I.S. to it through separate Flash-based site tampering, so the family alone does not establish the link.

Incidents in this campaign

  1. Blade Chronicle update files swapped for malware
  2. Buffalo driver downloads delivered Bankeiya

Appendix · Affected packages

Samples and hashes sit on each incident page, linked above

References

  1. CDNetworks content tampering incident summary and timelinepiyolog.hatenadiary.jp
  2. Buffalo discloses tampered download files and malware infection riskinternet.watch.impress.co.jp

Source record: proprietary/campaigns/cdnetworks-2014/meta.yaml