Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

21–30 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#21
post #18

Earlier quoted context omitted.

Do you have any sources for this? I'm interested in reading more about it after seeing a lot of allegations. I don't recall ever seeing anything concrete.

Literally one google search gave me this.[1] You could have saved a lot of time writing "Kaspersky FSB GRU" in google than writing this comment to someone to cite their sources. [1] https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...

Could you quote a paragraph from that article that supports the claim

> Kaspersky was spying on international citizens for over a decade, providing data for both the FSB and GRU.

I read it through twice and aside from implication the strongest assertion was that Bloomberg had seen emails that confirmed Kaspersky had worked with the FSB to supply anti-DDOS systems that included counter measures (the ability to hack and disrupt hackers attacking systems) which wasn't denied by Kaspersky who maintained they do similar work with many governments and their 3-letter-agencies.

Re: Targeted attack on our management with the Triangulation Trojan

#22
post #17
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are they using iOS if they feel that way about it? Also: iOS 16 is not vulnerable and it was released on September 12, 2022 - why are those phones out of date for so long?

Does an OS upgrade remove this malware though? Maybe it doesn't and it's why so many phones were infected.

Re: Targeted attack on our management with the Triangulation Trojan

#23
post #22
post #17

Earlier quoted context omitted.

Why are they using iOS if they feel that way about it? Also: iOS 16 is not vulnerable and it was released on September 12, 2022 - why are those phones out of date for so long?

Does an OS upgrade remove this malware though? Maybe it doesn't and it's why so many phones were infected.

The article says:

>An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS.

So I assume that the malware stops working when iOS is updated. This highlights the tremendous importance of keeping software up to date.

Re: Targeted attack on our management with the Triangulation Trojan

#24
Adjacent topic but i have a friend who told me buying a refurbished iPhone from a local shop was a bad idea from a security perspective.

Is this true? I thought a hard reset and secure enclave etc. was enough? Can you put "stuff" in it that survives to a new user?

Re: Targeted attack on our management with the Triangulation Trojan

#25
post #24

Adjacent topic but i have a friend who told me buying a refurbished iPhone from a local shop was a bad idea from a security perspective. Is this true? I thought a hard reset and secure enclave etc. was enough? Can you put "stuff" in it that survives to a new user?

Theoretically yes. However, the chance of you encountering a second hand device with such an implant is relatively low I'd say.

I guess if you buy it off journalists or activists the chance would be higher but still relatively unlikely. But as with anything, consider if it suits your threat model and act accordingly.

Re: Targeted attack on our management with the Triangulation Trojan

#27

Didn’t read the article, because on my oldish phone the cookie options defaulted to disallowing necessary cookies and allowing all others. I’m fairly confident this is a bug

Aand I just reloaded and it bounced around between cookie modal and nothing before letting me in without further interaction

Re: Targeted attack on our management with the Triangulation Trojan

#29
post #18

Earlier quoted context omitted.

Do you have any sources for this? I'm interested in reading more about it after seeing a lot of allegations. I don't recall ever seeing anything concrete.

Literally one google search gave me this.[1] You could have saved a lot of time writing "Kaspersky FSB GRU" in google than writing this comment to someone to cite their sources. [1] https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...

Yeah sorry, I should have been more specific. I was looking for evidence that:

> Kaspersky was spying on international citizens for over a decade, providing data for both the FSB and GRU.

You linked a news article that states:

> The U.S. government hasn’t identified any evidence connecting Kaspersky Lab to Russia’s spy agencies

Maybe more evidence will be uncovered by the (alleged) targeted attack against Kaspersky though.

I'm interested in the technology created to perform these activities more than the politics surrounding it. How they do it, not why.

Re: Targeted attack on our management with the Triangulation Trojan

#30
> What actually happens in iOS is unknown to cybersecurity experts

Sounds like a skill issue to me. I'll eat my words if they were genuinely infected with something that lingered in such a way that it persisted past a reboot and completely broke all updates, but I would be very surprised if this was the case.

Post reply on HN