Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

181–190 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#181

Earlier quoted context omitted.

Case intrusion sensors are a thing. And i swear i have seen cases with loops for padlocks.

Padlocked cases are common on school computers.

Yeah i should have suspected. Have not set foot back there in ages though. Thinking about it i guess schools may be some of the most hostile computing environments in civilian life.

Re: Researchers crack open malware that hid for 5 years

#182
post #14
post #2

Some at the NSA is having a bad day reading this.

Bizarrely, the NSA and other US security agencies seem to have very little interest in defence, preferring surveillance and attack capabilities.

Part of the military culture, there's no glory, no medals, no promotions in a successful defence

"Department of Defence" is so PC, things were much more honest back when it it was called the "Department of War"

Re: Researchers crack open malware that hid for 5 years

#183
>> so advanced in its design and execution that it could probably have been developed only with the active support of a nation-state

Why is advanced technology automatically assumed to have the backing of nation-states? Cant several highly motivated and smart individuals create the technology without a nation-state behind them?

Re: Researchers crack open malware that hid for 5 years

#184
post #139

Earlier quoted context omitted.

But a military contractor type of company has lots of obfuscation leeway with "top secret" type of things, doesn't it? And I'd imagine a defence contractor is the type of company that would be interested in the kind of info this kind of malware can gather.

There is some evidence that CITIC Group, a Chinese company, is heavily involved in corporate espionage and the manipulation of foreign nations. There's no particular reason that other large companies, no matter their home countries, could not also be engaged in these types of activities.

link: http://www.securityweek.com/chinese-attackers-conduct-cybere...

Re: Researchers crack open malware that hid for 5 years

#185
post #183

>> so advanced in its design and execution that it could probably have been developed only with the active support of a nation-state Why is advanced technology automatically assumed to have the backing of nation-states? Cant several highly motivated and smart individuals create the technology without a nation-state behind them?

Not only that, but if I was creating some malware I'd mimic every single one of the TTPs that are supposedly used by all these "Advanced Persistent Threat" groups that are anointed by "threat research" groups. Sprinkle in some Russian/Chinese strings, and an obvious string for how I'd like everyone to refer to me (Sauron in this case) and call it a day.

Re: Researchers crack open malware that hid for 5 years

#186
post #183

>> so advanced in its design and execution that it could probably have been developed only with the active support of a nation-state Why is advanced technology automatically assumed to have the backing of nation-states? Cant several highly motivated and smart individuals create the technology without a nation-state behind them?

That's why they said "probably".

You need to look at things like the complexity of the malware, how many staff it would take to develop and maintain it operationally, the targets selected and what sort of payloads are executed. Criminals tend to have simpler malware that used known exploits or a small number of zero days. They generally cast a wide net for their targets and their payloads typically aim to directly raise funds(ransom, mining, card theft, etc).

In contrast, nation-states tend to have complex malware with multiple zero days, greater care is taken to avoid detection, their targets are chosen carefully and their payloads focus on gathering information and specialized operations.

Re: Researchers crack open malware that hid for 5 years

#187
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

Just put the software in the device in ROM, a forgotten technology. No malware will survive a power cycle. It's like I read that malware could infect your "internet of things" thermostat and then hackers could remotely turn off your heat until you pay ransom. Just put the dang thermostat code in ROM. Power cycle, goodbye malware. For more critical stuff, just have it regularly power cycle itself.

> No malware will survive a power cycle.

Not true at all.

Re: Researchers crack open malware that hid for 5 years

#188

Earlier quoted context omitted.

Padlocked cases are common on school computers.

Yeah i should have suspected. Have not set foot back there in ages though. Thinking about it i guess schools may be some of the most hostile computing environments in civilian life.

> Thinking about it i guess schools may be some of the most hostile computing environments in civilian life.

Long time ago, I've briefly managed an environment like that. It was crazy. Kids are really good at breaking stuff in creative ways.

Re: Researchers crack open malware that hid for 5 years

#189
post #180
post #159

Earlier quoted context omitted.

Not the person you're replying to but opposite of open source is closed source, and isn't that basically a black box to you since you don't know what it's doing? Is there something more subtle I'm missing?

Yes. Microsoft offers source access to Windows. IBM and Oracle will rent you people who know the details of their software. None of those companies' offerings are particularly ‘black box’-y, in spite of being very closed source. ‘Open source’ is more about the development model (and freedoms) than about the nature of ‘knowing what the software is doing’. Heck, I could argue that Linux is a black box to most people wh…

At the level of security where you need to be paranoid about the operating system developers, how do you know the source code Microsoft shows you, corresponds to the Windows binaries running on your machines? (Let alone to the sum and total of all binary patches applied thereto?)

Re: Researchers crack open malware that hid for 5 years

#190

Earlier quoted context omitted.

Just put the software in the device in ROM, a forgotten technology. No malware will survive a power cycle. It's like I read that malware could infect your "internet of things" thermostat and then hackers could remotely turn off your heat until you pay ransom. Just put the dang thermostat code in ROM. Power cycle, goodbye malware. For more critical stuff, just have it regularly power cycle itself.

> No malware will survive a power cycle. Not true at all.

Please explain.
Post reply on HN