Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

51–60 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#51
post #41

> The researchers went on to speculate that the project was funded by a nation-state, but they stopped short of saying which one. So ... does anyone, perhaps who doesn't have Kaspersky's business interests to protect, care to actually speculate? In other cases it's been seemingly well-known in the security community which APT attacks trace back to which countries, it's just apparently impolite to say it in public.

The list of countries with a known infection suggests a Western nation acting alone, or in cooperation with others (for instance, the "Five Eyes").

Alternatively, one of the infected nations could also be responsible. Infecting selected systems inside your border could be a way to deflect attention when the hunt for the malware' authors began.

Pure speculation on my part, and nothing particularly new.

Re: Researchers crack open malware that hid for 5 years

#52
post #4
post #2

Some at the NSA is having a bad day reading this.

The article says it was first deployed in 2011. Five years is a pretty good run. I wonder what they're deploying right now?

>Five years is a pretty good run.

For a project this big & complex, and for something that cost hundreds of millions of dollars to develop, 5 years is paltry. Duqu remained hidden for 11+ years.

Re: Researchers crack open malware that hid for 5 years

#53

Is the implication that there must be someone who connects the special USB drives to these air-gapped computers? So the attacker must have local people on the ground.

Supposedly, the "drop USB drives in the parking lot" works pretty well to get around air-gapped systems. As well as mailing USB drives to the receptionist, mail room, etc. Also, this thing was running as a local admin on a domain controller. So either the DC's weren't patched or some zero-days were used. Or perhaps an inside job.

Well it worked on Mr Robot at least

Re: Researchers crack open malware that hid for 5 years

#54
post #14

Earlier quoted context omitted.

Bizarrely, the NSA and other US security agencies seem to have very little interest in defence, preferring surveillance and attack capabilities.

That's a false statement. They work with NIST to develop the standards that are the basis of the infosed industry.

Might be a false statement, but it's effectively true. Defense is part of their charter, but American government and corporations are clearly very vulnerable and are compromised routinely.

At this point I'd argue Google's security bounties have done more to secure the industry.

Re: Researchers crack open malware that hid for 5 years

#55

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

The walled garden doesn't mean it lacks hidden doors (intentional or via hacks) for bad actors. It just means you, the user, have less control of your machine than the OS does. It's as likely to wall you in with malware you can't remove, as to wall it out.

Re: Researchers crack open malware that hid for 5 years

#56
post #37

I'm curious: How realistic is building malware like this? Is this something that has been done out in the open by researchers? Is there an example we can see, or is this all still rumors? The reason I ask is because there's actually value in spreading the rumor that a capability like this exists. Imagine if your adversary believed that you could gain access to their computers even when they're not connected to the in…

From Kaspersky Lab's analysis:

>What would ProjectSauron have cost to set up and run?

>Kaspersky Lab has no exact data on this, but estimates that the development and operation of ProjectSauron is likely to have required several specialist teams and a budget probably running into millions of dollars.

https://securelist.com/analysis/publications/75533/faq-the-p...

Re: Researchers crack open malware that hid for 5 years

#57
post #24
post #21

Earlier quoted context omitted.

Personally? PC gets locked in a box with some sort of venting. Keyboard / Mouse are plugged in by IT and no one unauthorized has physical access to the PC itself. If they're serious enough about finding 0 days and exploits to the USB or OS to load this shit any physical access to the box itself is off limits.

Cut USB cable; splice new device into cable. Or, open mouse/keyboard case, wire device into USB bus connections.

Wireless RF keyboard+mouse, external antennas outside of the shielded case?

Re: Researchers crack open malware that hid for 5 years

#59
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

>I remember hearing there were going around filling USB ports with epoxy.

And we all laughed at PS/2 keyboards and mouseeses

Re: Researchers crack open malware that hid for 5 years

#60

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

> By analogy, there's a reason that many ancient cities were circled by a wall.

Walls around cities were likely very poor at stopping small, stealthy groups of infiltrators. They were designed for much more brute force attacks. Apple's walled garden helps quite a bit with the deluge of crap that would be available without it. Without it there would be an order of magnitude more crap (in quantity and quality). That said, there's a vibrant black market for people that can't stand the oppressive policies of Apple.

Additionally, once you have a wall in place, it's easy to make a decision to tax certain types of traffic through it because the capability is now there, whether or not it's in the best economic interest of the people inside. Apple didn't skimp on this area. The wall was erected with tithes and taxation in mind, and collection booths at all the gates.

So, does it help? Well, it prevents roving bands of bandits from riding in, terrorizing and robbing the people unlucky enough to be in their path, and making a hasty exit, so yes, but if you're a tasty enough target, getting past the wall isn't really a problem. There are myriad ways to do that as long as you're careful. For example, the numerous secret tunnels through the wall. They aren't large, and they are constantly being filled in by the city engineers, but there's always some they haven't found if you are willing to ask the right people (or dig your own).

Okay, I believe I've tortured this analogy enough...

Post reply on HN