Kaspersky Lab Discovers 'Gauss'
kaspersky.com
Kaspersky Lab Discovers 'Gauss'
1–10 of 25 posts
Re: Kaspersky Lab Discovers 'Gauss'
#2Do we have to repeat the same debate about this one's origin?
Re: Kaspersky Lab Discovers 'Gauss'
#3Kaspersky tends to exaggerate how novel these viruses are.
Re: Kaspersky Lab Discovers 'Gauss'
#4Would this perhaps be a tracking ability, as described at https://panopticlick.eff.org (specifically, the list of "System Fonts")
It would require the users to visit a site that is collecting this tracking information, but it isn't impossible to imagine a popular site among the target audience being strong-armed by a nation-state into installing something to do this.
The tracking is practically invisible to end users.
Re: Kaspersky Lab Discovers 'Gauss'
#5From the article: "... the installation of a special font called Palida Narrow, and the purpose of this action is still unknown." Would this perhaps be a tracking ability, as described at https://panopticlick.eff.org (specifically, the list of "System Fonts") It would require the users to visit a site that is collecting this tracking information, but it isn't impossible to imagine a popular site among the target audi…
[1] http://blog.crysys.hu/2012/08/on-the-palida-narrow-mystery-o...
Re: Kaspersky Lab Discovers 'Gauss'
#6"Another key feature of Gauss is the ability to infect USB thumb drives, using the same LNK vulnerability that was previously used in Stuxnet and Flame." Do we have to repeat the same debate about this one's origin?
Re: Kaspersky Lab Discovers 'Gauss'
#7Re: Kaspersky Lab Discovers 'Gauss'
#8From the article: "... the installation of a special font called Palida Narrow, and the purpose of this action is still unknown." Would this perhaps be a tracking ability, as described at https://panopticlick.eff.org (specifically, the list of "System Fonts") It would require the users to visit a site that is collecting this tracking information, but it isn't impossible to imagine a popular site among the target audi…
Re: Kaspersky Lab Discovers 'Gauss'
#9"Another key feature of Gauss is the ability to infect USB thumb drives, using the same LNK vulnerability that was previously used in Stuxnet and Flame." Do we have to repeat the same debate about this one's origin?
That .lnk vulnerability is now in metasploit; I don't think we can safely say that Gauss is from the same org from this one piece of evidence.
Re: Kaspersky Lab Discovers 'Gauss'
#10Trying to remember the last time I didn't read about some ultra-dooper-al-quaeda-cyber-virus. Seems any kid with a C compiler these days pumping out cutpasted code qualifies as a complex threat.
Coming up: 50 page white paper on the seemingly "innocuous" font (translation: obviously some previously unknown 0day secret intelligence 007 cyber warhead) and its implications for national security funding.