Live data from Hacker News

German Chaos Computer Club analyzes and releases government malware

ccc.de

1–10 of 67 posts

German Chaos Computer Club analyzes and releases government malware

#1
From the press release: "The largest European hacker club, "Chaos Computer Club" (CCC), has reverse engineered and analyzed a "lawful interception" malware program used by German police forces. It has been found in the wild and submitted to the CCC anonymously. The malware can not only siphon away intimate data but also offers a remote control or backdoor functionality for uploading and executing arbitrary other programs. Significant design and implementation flaws make all of the functionality available to anyone on the internet."

German Chaos Computer Club analyzes and releases government malware
ccc.de

Re: German Chaos Computer Club analyzes and releases government malware

#5
I wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it.

Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it.

I'm not doubting them, it would just be very interesting.

Re: German Chaos Computer Club analyzes and releases government malware

#6
post #5

I wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it. Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it. I'm not doubting them, it would just be very interesting.

there was a big public discussion about the government trojaner in germany. they government also has to report how often it is used. so you can be sure thats the work of some government part.

Re: German Chaos Computer Club analyzes and releases government malware

#7
post #5

I wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it. Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it. I'm not doubting them, it would just be very interesting.

The first paragraph: > Dem Chaos Computer Club (CCC) wurde Schadsoftware zugespielt, deren Besitzer begründeten Anlaß zu der Vermutung hatten, daß es sich möglicherweise um einen „Bundestrojaner“ handeln könnte. Einen dieser Trojaner und dessen Funktionen beschreibt dieses Dokument, die anderen Versionen werden teilweise vergleichend hinzugezogen.

Translates to: > The Chaos Computer Club (CCC) received malware, whose owners who had reason to believe that it could possibly be the "Federal Trojan". One of these and its function is described by this document, other versions have been used for comparisons.

I guess they won't publish any more information to protect their sources.

Re: German Chaos Computer Club analyzes and releases government malware

#8
I think it's also possible that some of those safeguard provisions were left out of the software so that in case the malware was detected, it could have been attributed to standard hacker groups as opposed to German government organizations who play within a specific set of rules and regulations. Obviously, this plan failed and it has been identified as government-sponsored malware.

Re: German Chaos Computer Club analyzes and releases government malware

#9
The press release and the analysis are unfortunately poorly written and make it appear as if a couple of overeager teenagers wrote this, although their conclusion is accurate given the information given in the analysis.

Releasing the binaries alone to back up such a statement might be good enough for the hacker community but if you want to persuade the public you need to be more professional in your choice of words.

Even though this is a great achievement and I hope that this will have significant impact.

Re: German Chaos Computer Club analyzes and releases government malware

#10
post #8

I think it's also possible that some of those safeguard provisions were left out of the software so that in case the malware was detected, it could have been attributed to standard hacker groups as opposed to German government organizations who play within a specific set of rules and regulations. Obviously, this plan failed and it has been identified as government-sponsored malware.

A standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.
Post reply on HN