Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

21–30 of 314 posts

Re: Kaspersky believes it found new CIA malware

#21
I may have missed it in the article, but as a sysadmin, i’m trying to figure out what I should do. It appears the CIA has created malware. I assume, if they have exploited some hole, others will too.

While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?

Re: Kaspersky believes it found new CIA malware

#22
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

One reason would be the capability. There's no doubt that there are US citizens able to produce complex software including malware. Same could be said about China or Russia. But when it comes to North Korea, I really have doubts about their IT competence. Sure, they probably have some good programmers able to create ordinary IT systems. But working on edge of current technologies - that's what I have my doubts about.

This may be helpful then: https://www.newyorker.com/magazine/2021/04/26/the-incredible...

Re: Kaspersky believes it found new CIA malware

#24
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

Re: Kaspersky believes it found new CIA malware

#25
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

I mean, given the amount of malware made by the CIA and NSA, is it really a stretch that this is just one more?

Re: Kaspersky believes it found new CIA malware

#26
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Its probably because the US government is the single greatest force for evil in the world right now.

Re: Kaspersky believes it found new CIA malware

#28
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Its probably because the US government is the single greatest force for evil in the world right now.

This kind of hyperbole is neither instructive nor accurate. What is the intended purpose of this comment?

Re: Kaspersky believes it found new CIA malware

#29
post #3

Aside: Kaspersky is a Russian company.

Which makes them one of relatively few companies in this space that would publicly expose CIA ops. It's definitely reasonable to be sceptical here, but that goes both ways.

I think you make a valid point here - there are not a lot of companies willing to expose something like this. Even less so second time around.

[meta] I would REALLY love for people down-voting something to explain why they do this. Maybe as HN feature for the first 200 downvotes, you have to reply to the post or upvote one below that explains it...

Re: Kaspersky believes it found new CIA malware

#30

I may have missed it in the article, but as a sysadmin, i’m trying to figure out what I should do. It appears the CIA has created malware. I assume, if they have exploited some hole, others will too. While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?

> Kaspersky said that while it has not seen any of these samples in the wild, they believe Purple Lambert samples “were likely deployed in 2014 and possibly as late as 2015.”

You don’t do anything because you are not the target. It’s never been seen in the wild.

Post reply on HN