Live data from Hacker News

Russian antivirus firm faked malware to harm rivals, say ex-employees

reuters.com

21–30 of 102 posts

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#22
post #5

We have started seeing a lot of bad publicity and innuendos targeted toward Kaspersky after they uncovered and published about hacking attack against their infrastructure in recent past. Feels suspicious to me especially with comments attributed to 'former employees'.

Yeah, I have to agree, at least as far as the headline. Kaspersky is a serious and respected vendor in the industry and has been for a long time now. Identifying them as a "Russian antivirus firm" in this context sounds a little jingoist to me. (e.g. how often do you hear about "British CPU vendor ARM" or "Abu Dhabian semiconductor giant GlobalFoundries").

That said, the trick is pretty vile. Deliberately polluting public malware databases hurts us all.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#23
>In one technique, Kaspersky's engineers would take an important piece of software commonly found in PCs and inject bad code into it so that the file looked like it was infected, the ex-employees said. They would send the doctored file anonymously to VirusTotal.

>Then, when competitors ran this doctored file through their virus detection engines, the file would be flagged as potentially malicious. If the doctored file looked close enough to the original, Kaspersky could fool rival companies into thinking the clean file was problematic as well.

I don't quite understand - what about hashes? VirusTotal doesn't work as they say it works.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#24
post #9
post #5

We have started seeing a lot of bad publicity and innuendos targeted toward Kaspersky after they uncovered and published about hacking attack against their infrastructure in recent past. Feels suspicious to me especially with comments attributed to 'former employees'.

It's great that you read these things with some suspicion, but would you use the same suspicion when reading allegations against US or European companies? And, their main development being done in Moscow, do you expect current employees to stick their heads up? There aren't a lot of protections for whistle blowers in Russia. I'm pretty sure they'd be declared traitors, if they did reveal something like this in a form…

When a report comes out purely based some unnamed sources without any hard evidence, I am always suspicious irrespective of whether it is about US, European, Russian companies.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#25

The whole article sounds funny. "VirusTotal had no immediate comment." "[...], Kaspersky denied using this technique. It said it too had been a victim of such an attack in November 2012, when an "unknown third party" manipulated Kaspersky into misclassifying files [...]" "The former Kaspersky employees said Microsoft was one of the rivals [...] They declined to give a detailed account of any specific attack." "In a s…

Not a bit coincidental that said firm seems to be the only antivirus firm in recent memory (unless I'm mistaken) that seems to be able or willing to uncover government-level shenanigans. No, not a bit coincidental at all.

edit: And of course this http://www.wired.com/2015/06/kaspersky-finds-new-nation-stat... from two months ago.

First, security breach; now, an attack on their reputation?

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#26

The whole article sounds funny. "VirusTotal had no immediate comment." "[...], Kaspersky denied using this technique. It said it too had been a victim of such an attack in November 2012, when an "unknown third party" manipulated Kaspersky into misclassifying files [...]" "The former Kaspersky employees said Microsoft was one of the rivals [...] They declined to give a detailed account of any specific attack." "In a s…

Not a bit coincidental that said firm seems to be the only antivirus firm in recent memory (unless I'm mistaken) that seems to be able or willing to uncover government-level shenanigans. No, not a bit coincidental at all. edit: And of course this http://www.wired.com/2015/06/kaspersky-finds-new-nation-stat... from two months ago. First, security breach; now, an attack on their reputation?

It's also not coincidental at all that Kaspersky steers clear of exposing any shenanigans by Moskow. I mean, Eug himself claims Russia produces not only the best programmers but also the best exploit writers.... But surprisingly no exposés on them.

Hmmm.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#27
post #23

>In one technique, Kaspersky's engineers would take an important piece of software commonly found in PCs and inject bad code into it so that the file looked like it was infected, the ex-employees said. They would send the doctored file anonymously to VirusTotal. >Then, when competitors ran this doctored file through their virus detection engines, the file would be flagged as potentially malicious. If the doctored fil…

Hashes aren't the only thing that judge a file. Virus scanners today look for specific portions of files that look like malicious code, either by directly matching it or by tracing the code. Apparently some virus scanners traced too far into other parts of the executable's code, into the legitimate portions that are found as system components on computers today.

It's a neat attack.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#28

The whole article sounds funny. "VirusTotal had no immediate comment." "[...], Kaspersky denied using this technique. It said it too had been a victim of such an attack in November 2012, when an "unknown third party" manipulated Kaspersky into misclassifying files [...]" "The former Kaspersky employees said Microsoft was one of the rivals [...] They declined to give a detailed account of any specific attack." "In a s…

Pure propaganda/fluff piece to damage the company. The media has been going hard against Kaspersky in coordination with government agencies.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#29
post #5

We have started seeing a lot of bad publicity and innuendos targeted toward Kaspersky after they uncovered and published about hacking attack against their infrastructure in recent past. Feels suspicious to me especially with comments attributed to 'former employees'.

I agree that it smells a bit, but take a quick look at the author, Joseph Menn. He's been floating around tech reporting for a while and seems to have some netsec chops. This isn't an article coming out of the State Department or some anonymous blog; there's a name behind it of someone who'd have their reputation to lose if it turned out to be a bunch of false allegations. (Not that that's never happened before...)

[deleted]
Post reply on HN