Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

41–50 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#41
> The researchers went on to speculate that the project was funded by a nation-state, but they stopped short of saying which one.

So ... does anyone, perhaps who doesn't have Kaspersky's business interests to protect, care to actually speculate? In other cases it's been seemingly well-known in the security community which APT attacks trace back to which countries, it's just apparently impolite to say it in public.

Re: Researchers crack open malware that hid for 5 years

#42

Earlier quoted context omitted.

Okay first, it probably doesn't get information from air gapped computers without being plugged in, so let's quit with the voodoo right now. You guys are discounting the possibility of idiocy. Second, making partitions that windows doesn't see is trivially easy. I went out of my way to buy a 128gb flash drive nearly 10 years ago at great expense, it had a 4gb fat 32 partition which is what Windows would see. It had a…

"making partitions that windows doesn't see is trivially easy" Are we talking "partitions Windows wont mount because they aren't FAT/NTFS" or "partitions that literally do not show up to Windows Disk Management because the disk itself is showing a different capacity. EG: A 16GB USB reporting only 8GB, regardless of the OS installed" Like one of these, only malicious https://www.neowin.net/news/fake-chinese-500-gb-ext…

I'm not sure. I lost the flash drive, despite living in a tiny one bedroom apartment in Manhattan. Maybe a 3 letter agency took it while I was away.

Re: Researchers crack open malware that hid for 5 years

#43
post #13

That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.

If your machine has a USB port, it's no longer properly isolated. Obviously that's a tremendous pain to work with, because you're limited to PS/2 keyboards and mice (etc etc), but given that there's no way of authenticating USB devices and they've already been used in various attacks, a serious airgap protocol has to ban USB ports. You could quite easily hide a USB mass storage device inside a mouse, or with a bit mo…

If you just leave away the USB mass storage kernel module when compiling the kernel, the mass storage device won't work anymore while the mouse still works. I wonder if this is a solution to this problem or not since it seems quite naive.

Re: Researchers crack open malware that hid for 5 years

#44

Earlier quoted context omitted.

This seems to be the crux of it: Part of what makes ProjectSauron so impressive is its ability to collect data from air-gapped computers. To do this, it uses specially prepared USB storage drives that have a virtual file system that isn't viewable by the Windows operating system. To infected computers, the removable drives appear to be approved devices, but behind the scenes are several hundred megabytes reserved for…

Okay first, it probably doesn't get information from air gapped computers without being plugged in, so let's quit with the voodoo right now. You guys are discounting the possibility of idiocy. Second, making partitions that windows doesn't see is trivially easy. I went out of my way to buy a 128gb flash drive nearly 10 years ago at great expense, it had a 4gb fat 32 partition which is what Windows would see. It had a…

>Okay first, it probably doesn't get information from air gapped computers without being plugged in, //

A hidden WiFi to create a mesh network, or use ultrasound, seems doable.

Re: Researchers crack open malware that hid for 5 years

#45

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

I suspect your comment will be met harshly here, but I agree for at least a subset of users. If you regularly read HN, you probably can see the clear downsides of the so-called 'walled garden' approach. I can too. Then I have a 10-minute conversation trying to help my mother-in-law with whatever Best-buy recommended cheap PC she purchased 2 years ago, and I am convinced that she needs the walled garden.

Re: Researchers crack open malware that hid for 5 years

#46

What is the role of an InfoSec professional in an environment where advanced threats like this are being deployed? I mean, a beat cop knows when it's time to call the FBI or the military. But the open nature of the Net means that firewall probes by script kiddies are interspersed with intrusions by nation-state actors. It's a weird state of affairs.

Work with stakeholders to minimize lateral movement after a breach, get monitoring in place to detect breaches, and have a response plan.

If you have company critical secrets or life-safety systems, you need to air gap where possible.

That's you're job. You cannot stop or prevent attacks, and if option don't have the metrics and logs, the FBI won't be able to do anything, assuming you can get them to give a shit.

Re: Researchers crack open malware that hid for 5 years

#47
post #14
post #2

Some at the NSA is having a bad day reading this.

Bizarrely, the NSA and other US security agencies seem to have very little interest in defence, preferring surveillance and attack capabilities.

That's a false statement. They work with NIST to develop the standards that are the basis of the infosed industry.

Re: Researchers crack open malware that hid for 5 years

#48

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

But what if the wall have holes in it and you don't even know about it? What if the "bad guys" will uncover the holes before you? Or what if you will know but you still can do nothing about them? What if the "bad guys" are the ones who built the wall, not to secure you but to contain you?

Re: Researchers crack open malware that hid for 5 years

#49

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

I suspect your comment will be met harshly here, but I agree for at least a subset of users. If you regularly read HN, you probably can see the clear downsides of the so-called 'walled garden' approach. I can too. Then I have a 10-minute conversation trying to help my mother-in-law with whatever Best-buy recommended cheap PC she purchased 2 years ago, and I am convinced that she needs the walled garden.

There was a pop up which said that there was a virus and I needed to click ok to get it removed

I swear to God I'd put adblock on that laptop to reduce this risk. Not to mention there must have been multiple click throughs for the different hurdles to install the malware. This is not a problem I envisage happening on Mums iPad though, and there's a lot to be said for that piece of mind

Re: Researchers crack open malware that hid for 5 years

#50

Earlier quoted context omitted.

Okay first, it probably doesn't get information from air gapped computers without being plugged in, so let's quit with the voodoo right now. You guys are discounting the possibility of idiocy. Second, making partitions that windows doesn't see is trivially easy. I went out of my way to buy a 128gb flash drive nearly 10 years ago at great expense, it had a 4gb fat 32 partition which is what Windows would see. It had a…

"making partitions that windows doesn't see is trivially easy" Are we talking "partitions Windows wont mount because they aren't FAT/NTFS" or "partitions that literally do not show up to Windows Disk Management because the disk itself is showing a different capacity. EG: A 16GB USB reporting only 8GB, regardless of the OS installed" Like one of these, only malicious https://www.neowin.net/news/fake-chinese-500-gb-ext…

[deleted]
Post reply on HN