Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

71–80 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#71

Is the implication that there must be someone who connects the special USB drives to these air-gapped computers? So the attacker must have local people on the ground.

Well one of the linked/related attacks, called "Equation," was apparently distributed at least once via CD without a person on the ground (near the target, at least). It says that the CD, containing data about a recent research expedition, was mailed to an academic. It was apparently intercepted in the mail, compromised, and forwarded on.

This the other kind of MiTM attack: Man in the Mail.

Re: Researchers crack open malware that hid for 5 years

#72
post #57
post #24

Earlier quoted context omitted.

Cut USB cable; splice new device into cable. Or, open mouse/keyboard case, wire device into USB bus connections.

Wireless RF keyboard+mouse, external antennas outside of the shielded case?

Can be defeated by a phone charger.

http://samy.pl/keysweeper/

Re: Researchers crack open malware that hid for 5 years

#73
post #60

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

> By analogy, there's a reason that many ancient cities were circled by a wall. Walls around cities were likely very poor at stopping small, stealthy groups of infiltrators. They were designed for much more brute force attacks. Apple's walled garden helps quite a bit with the deluge of crap that would be available without it. Without it there would be an order of magnitude more crap (in quantity and quality). That sa…

I'm not sure that is a good analogy for the wall. Is it a different wall protecting thousands of cities or one of maybe ~10 walls (the main OS's) that is reused? Would it be that hard to build a few good walls? As you said though, there are always alternative ways to be attacked - robbed on the highway (man in the middle?) etc.

Re: Researchers crack open malware that hid for 5 years

#74
post #37

I'm curious: How realistic is building malware like this? Is this something that has been done out in the open by researchers? Is there an example we can see, or is this all still rumors? The reason I ask is because there's actually value in spreading the rumor that a capability like this exists. Imagine if your adversary believed that you could gain access to their computers even when they're not connected to the in…

It would take an inordinate amount of time for a person to build something like ProjectSauron, but after reading the link, it uses a wide range of publicly-known techniques (windows key loggers, password filters, DNS/ICMP exfil, named pipes, etc etc). This software seems to do a good job at amalgamating a wide range of methods.

Re: Researchers crack open malware that hid for 5 years

#75
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

I wouldn't call RHEL 6 ancient. Thankfully this may be going away at some point in the future, leaving it up to agencies to certify products or stacks on their own merits, or to instead have them be evaluated for specific purposes if sold as solutions: https://www.niap-ccevs.org/Documents_and_Guidance/ccevs/GPOS...

Re: Researchers crack open malware that hid for 5 years

#77
post #13

Earlier quoted context omitted.

If your machine has a USB port, it's no longer properly isolated. Obviously that's a tremendous pain to work with, because you're limited to PS/2 keyboards and mice (etc etc), but given that there's no way of authenticating USB devices and they've already been used in various attacks, a serious airgap protocol has to ban USB ports. You could quite easily hide a USB mass storage device inside a mouse, or with a bit mo…

If you just leave away the USB mass storage kernel module when compiling the kernel, the mass storage device won't work anymore while the mouse still works. I wonder if this is a solution to this problem or not since it seems quite naive.

This is not sufficient. One known vector is to emulate a USB network device that provides a nameserver via DHCP, but no default route,allowing the attacker to MitM chosen connections. And of course you have a plethora of different USB device types with default drivers that probably contain exploitable bugs.

Re: Researchers crack open malware that hid for 5 years

#78

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

[deleted]

Re: Researchers crack open malware that hid for 5 years

#79

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

I suspect your comment will be met harshly here, but I agree for at least a subset of users. If you regularly read HN, you probably can see the clear downsides of the so-called 'walled garden' approach. I can too. Then I have a 10-minute conversation trying to help my mother-in-law with whatever Best-buy recommended cheap PC she purchased 2 years ago, and I am convinced that she needs the walled garden.

I know exactly what you are talking about. I'm just really afraid of what the knock-on effects are going to be of starting kids out in walled gardens. I wouldn't be an engineer today if it wasn't for the fact that it was possible for me to play with various languages, or start distro hopping in high school with a 433Mhz PC. These walled gardens make it easy to keep everything working, but come at a high cost of actually learning what the device does.

Re: Researchers crack open malware that hid for 5 years

#80
post #41

> The researchers went on to speculate that the project was funded by a nation-state, but they stopped short of saying which one. So ... does anyone, perhaps who doesn't have Kaspersky's business interests to protect, care to actually speculate? In other cases it's been seemingly well-known in the security community which APT attacks trace back to which countries, it's just apparently impolite to say it in public.

Russia, Iran, Rwanda... Let's assume the latter is a vector, not the target. (The attacker is sophisticated enough that we can assume Rwanda itself is of little interest). Rwanda also has fairly close ties to Russia, which strengthens the vector hypothesis.

Russia+Iran suggests a western actor. Their biggest shared interest is Syria, I'd think. And look, the Syrian conflict is on since March '11, and the activity according to Kaspersky reaches back to June '11. I'd say that's quite close.

Neither the US nor Europe were that deeply invested in Syria. There is, however, one small middle-east country that has quite an interest in the entire region, and also isn't friends with Iran or Russia. And it just so happens that Israel is somewhat of a close affiliation of Rwanda.

None of that is in any way conclusive, but it certainly is probable.

Post reply on HN