Contd. Infecting Users with Malware
TSG’s in-path injection capability system allows for sophisticated targeting of this malicious
code for the specific user, facilitating on-the-fly modifications across a variety of file
formats, including HTML, CSS, and JavaScript, in addition to Android APK files, Windows
EXE files, macOS DMG disk images and Linux RPM packages. Furthermore, TSG can alter
several image formats such as JPG, GIF, PNG and SVG, and various archive formats such as
ZIP and RAR, along with office documents, PDF, JSON, and XML files. This is also
complemented by Cyber Narrator, which possesses analytical functionalities that can
identify the most appropriate URLs to hijack in order to infect specific individuals. For
instance, it can target a person’s frequently visited websites that do not utilize Transport
Layer Security (TLS).
As an example of this capability, instead of just trying to guess how to target a user,
Geedge’s government clients can go back in time to look at an internet user’s activities to
see if they have previously done something that would make them vulnerable to having
their device hacked, with the intention to infect them in the future by exploiting this
vulnerability.
DDoS As A Service
The functionality described above can be used to infect users with mercenary spyware
offered by any other company. However, it is notable that Geedge networks has attempted
to weaponize this functionality themselves.
One of the most bewildering offerings from Geedge Networks identified in the leaked
dataset is DLL Active Defence, a product you might usually find in cybercrime black
markets. At first glance, it appears to be a system designed to protect against Distributed
Denial of Service (DDoS) attacks; however, a closer examination reveals that it is actually a
platform for launching DDoS attacks against websites and other internet services deemed
politically undesirable. This would appear to be Geedge's own implementation of China's
Great Cannon, as described in a 2015 Citizen Lab report .13
This functionality means that, while the national firewall can block websites for citizens
within a country, the DLL Active Defense function can make the website inaccessible for
every internet user in the world, not just within the bounds of the national firewall.
DLL accomplishes this by utilizing internet scanning to identify traffic amplification points,
such as recursive DNS servers, which can serve as launch pads for reflective denial of
service attacks. It uses the in-path injection capability in TSG to effectively recruit
unsuspecting users' computers to participate in the attack, thereby creating a botnet. This
marks the first confirmed instance of a cybersecurity company offering what is essentially
a “booter” DDoS-for-hire solution to its clients.