Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

101–110 of 314 posts

Re: Kaspersky believes it found new CIA malware

#101
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

There's a difference between Microsoft or Google or Symantec coming out and saying 'this was NK malware' and the CIA or NSA or FBI saying 'this was NK malware' - people would be more inclined to believe the former rather then the later, even though we would still have to imagine that it's possible they are saying this because of CIA/FBI/NSA influence.

Likewise, Kaspersky is more believable than if the FSB came out with this story, even if we must be cautious that it could be an FSB story.

Re: Kaspersky believes it found new CIA malware

#102
post #34
post #3

Aside: Kaspersky is a Russian company.

Aside: therecord.media is CIA propaganda. https://gcn.com/articles/2010/07/29/inqtel-google-fund-web-a...

Recorded Future = CIA? Solely based on them taking money from IQT?

IQT funds a ton of different companies, it doesn't make them fronts for the CIA. Cloudera, FireEye and a ton of others have taken money from IQT, it doesn't make them propaganda.

Re: Kaspersky believes it found new CIA malware

#103
post #82

Earlier quoted context omitted.

Almost all government created malware uses 0days that they've kept back or held back from public disclosure, so there's nothing really you can do (aside from waiting for disclosure). That's the point of a CIA hack isn't it? If there's something you can do, then they've failed at their job, and it's time for hiring the next batch of developers (yes these are developers with a paid day job - to make malware for the CIA…

The only thing you can truly do is look for anomalies in network traffic, processes, files, etc. This malware is not immune to that unless it has features specifically to hide from monitoring tools. Even then there will almost always be evidence if you log network traffic. But obviously this is very difficult.

> Even then there will almost always be evidence if you log network traffic.

You'd need to know what to look for though. It was shown that the CIA can hide its communication in metadata of legitimate traffic which is then recovered at intermediate hops to the target. So, do you know precisely what an innocent DNS packet looks like to detect this anomaly?

Re: Kaspersky believes it found new CIA malware

#104
post #78
post #52

Earlier quoted context omitted.

I’d say the likelihood of an American Big Tech without CIA covert operatives working there is essentially zero, even if there’s no direct cooperation. It doesn’t make sense to not utilize some of your most valuable assets.

Back in the 70s to 90s the CIA had presidents of Mexico as operatives (see LITEMPO). So, I wouldn't be surprised that nowadays some high level people at Google, Microsoft, etc are CIA assets.

Similarly, the KGB (as later exposed by VENONA) had their fingers in extremely sensitive pies during the early cold war period.

Re: Kaspersky believes it found new CIA malware

#105

Earlier quoted context omitted.

Sure, but isn't that true for any intelligence organization? CIA, NSA, FSB, MI5, Mossad, BND, etc?

Sure, I dont focus on them because I don't believe that Mossad or MI5 are the reason why my country has been at war my entire adult life, but I have witnessed the NSA and CIA justify those wars-that-arent-really-wars time and time again. How much blood was spilled over the 'yellow cake' line alone? Remember when they lost that ten thousand page report on torture right before it was to be delivered? Or the time they d…

I'm actually curious precisely what CIA justification you're referring to. What I'm aware of are [1] and [2].

[1] https://www.washingtonpost.com/politics/2019/03/22/iraq-war-...

[2] https://www.washingtonpost.com/archive/opinions/2003/11/28/m...

Re: Kaspersky believes it found new CIA malware

#107
post #33

Earlier quoted context omitted.

> without evidence of cooperating with the FSB That isn't true. This "without evidence" shit is rather silly when it comes to top-secret sources and methods. Blow decades of work and risk getting people killed to Prove that an ex-KGB officer helps an authoritative regime thats known to poison its enemies. People said the same shit about Huawei, then all the KPN shit. Link: https://www.bloomberg.com/news/articles/2017…

> This "without evidence" shit is rather silly when it comes to top-secret sources and methods. "We lie, we cheat, we steal". Literally from the mouth of the guy who ran it to your ears. I'm not sure how you find these source legitimate sans evidence, other than possibly they are you team. PS. Doesn't make the other jerks legitimate either.

> sans evidence

You're talking about an entity with the ability to fake any evidence that they would be able to provide you. So no matter what "evidence" they provide you would still need to make a choice to believe them.

Re: Kaspersky believes it found new CIA malware

#108
post #37

I may have missed it in the article, but as a sysadmin, i’m trying to figure out what I should do. It appears the CIA has created malware. I assume, if they have exploited some hole, others will too. While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?

If you want to be protected from the US made malware you do not go to US antimalware vendor. If you want to be protected against Russian malware you do not get antimalware from Russia. So pick your poison.

Solution: Install US and Russian antiviruses simultaneously.

Re: Kaspersky believes it found new CIA malware

#109
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

Now compare it to how fast US intelligence analysts are. They may conclude who is behind attack in a matter of days. (For example, recent solarwinds attack)

Correct, different campaign signatures can make attribution happen quickly, or slowly. Just depends what data the analyst has to work with.

Re: Kaspersky believes it found new CIA malware

#110

Earlier quoted context omitted.

Sure, but isn't that true for any intelligence organization? CIA, NSA, FSB, MI5, Mossad, BND, etc?

Sure, I dont focus on them because I don't believe that Mossad or MI5 are the reason why my country has been at war my entire adult life, but I have witnessed the NSA and CIA justify those wars-that-arent-really-wars time and time again. How much blood was spilled over the 'yellow cake' line alone? Remember when they lost that ten thousand page report on torture right before it was to be delivered? Or the time they d…

> my country has been at war my entire adult life

The US has been at war for most it’s existence.

Someone made a search tool to see how many years the US had been at war for, and then ran it on Wikipedia.

Interestingly, France performed worse (assuming one doesn’t like war), though being involved in things like ‘The 100 years war’ skews things a little.

https://freakonometrics.hypotheses.org/50473

Post reply on HN