Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

111–120 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#111
post #106
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

Too many people without security clearance can access and modify Linux. In any real security environment, open-source is poison. Period, end of story.

So security through obscurity?

Re: Researchers crack open malware that hid for 5 years

#113

Earlier quoted context omitted.

I suspect your comment will be met harshly here, but I agree for at least a subset of users. If you regularly read HN, you probably can see the clear downsides of the so-called 'walled garden' approach. I can too. Then I have a 10-minute conversation trying to help my mother-in-law with whatever Best-buy recommended cheap PC she purchased 2 years ago, and I am convinced that she needs the walled garden.

I'm definitely an advocate of open source myself, and I never thought I'd be considering the other side's arguments. It's just that I see major data/security breaches increasing in the news, along with stories (like this one) about cyber-offensive capabilities growing more and more powerful. In the InfoSec world, it seems like anything is hackable, and the balance of power firmly lies with offensive tools. I'm just s…

What do you mean "attack"? Is there some specific harm being done that you want to protect against? Breach of defenses isn't itself an attack. A foreign agent inside your castle isn't an attacker until they start stabbing people, right?

I'm not personally worried about what Chinese and Russian hackers know about me, because none of that information is particularly useful for taking valuables from me. I am curious what your experience is, just so I can understand the context of your concern.

Re: Researchers crack open malware that hid for 5 years

#114
post #80
post #41

> The researchers went on to speculate that the project was funded by a nation-state, but they stopped short of saying which one. So ... does anyone, perhaps who doesn't have Kaspersky's business interests to protect, care to actually speculate? In other cases it's been seemingly well-known in the security community which APT attacks trace back to which countries, it's just apparently impolite to say it in public.

Russia, Iran, Rwanda... Let's assume the latter is a vector, not the target. (The attacker is sophisticated enough that we can assume Rwanda itself is of little interest). Rwanda also has fairly close ties to Russia, which strengthens the vector hypothesis. Russia+Iran suggests a western actor. Their biggest shared interest is Syria, I'd think. And look, the Syrian conflict is on since March '11, and the activity acc…

> and also isn't friends with Iran or Russia

Actually Israel is on very friendly terms with Russia. There are a ton of Russian immigrants in Israel to the point that Putin called them "Russian ambassadors".

It didn't start that way - part of the history of the creation of the modern state of Israel is Russia vs US proxy conflict (of sorts) via Egypt. But it's not like that anymore, not for a long time.

(The US and Russia have moved on to other proxies :)

Re: Researchers crack open malware that hid for 5 years

#115
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

I wouldn't call RHEL 6 ancient. Thankfully this may be going away at some point in the future, leaving it up to agencies to certify products or stacks on their own merits, or to instead have them be evaluated for specific purposes if sold as solutions: https://www.niap-ccevs.org/Documents_and_Guidance/ccevs/GPOS...

There's a STIG already for RHEL 7, for what it's worth.

Re: Researchers crack open malware that hid for 5 years

#116

Earlier quoted context omitted.

Okay first, it probably doesn't get information from air gapped computers without being plugged in, so let's quit with the voodoo right now. You guys are discounting the possibility of idiocy. Second, making partitions that windows doesn't see is trivially easy. I went out of my way to buy a 128gb flash drive nearly 10 years ago at great expense, it had a 4gb fat 32 partition which is what Windows would see. It had a…

"making partitions that windows doesn't see is trivially easy" Are we talking "partitions Windows wont mount because they aren't FAT/NTFS" or "partitions that literally do not show up to Windows Disk Management because the disk itself is showing a different capacity. EG: A 16GB USB reporting only 8GB, regardless of the OS installed" Like one of these, only malicious https://www.neowin.net/news/fake-chinese-500-gb-ext…

A big chunk of space would take some work, but if you only needed a few KB there is slack space (at least a handful of sectors) on the end of every USB drive that doesn't align with partition sizes. I've used it before to store data on how many times my reformatting tool was used on the disk.

Re: Researchers crack open malware that hid for 5 years

#117
post #37

I'm curious: How realistic is building malware like this? Is this something that has been done out in the open by researchers? Is there an example we can see, or is this all still rumors? The reason I ask is because there's actually value in spreading the rumor that a capability like this exists. Imagine if your adversary believed that you could gain access to their computers even when they're not connected to the in…

Read this as an "introduction" and then you'll be able to understand why the researchers can be so sure that specific kind of malware must be state sponsored:

http://www.nytimes.com/2012/06/01/world/middleeast/obama-ord...

http://www.langner.com/en/wp-content/uploads/2013/11/To-kill...

Simply, the goals ant he methods of the commercial malware are fundamentally different to those that can be recognized in the state-sponsored malware.

Re: Researchers crack open malware that hid for 5 years

#118

Earlier quoted context omitted.

>filling USB ports with epoxy This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. Those USB ports aren't perfect boxes, the epoxy would just run out all over the place. More than likely you'd have an OS-level security policy and bios block, which is trivial to do in a managed environment. I hear this…

> This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. The question is - where do you stop? The controller could be re-enabled from a lower level, etc. The rabbit hole goes very deep. Sometimes it's best to just take control of the physical layer and call it a day. > Those USB ports aren't perfect boxe…

> Sometimes it's best to just take control of the physical layer and call it a day.

If you want to stop your every day user from plugging in USB drives then this is probably all you need to do. In a scenario where you're concerned about insider threats with even a minimal level of computing knowledge, you have to lock down the BIOS and the OS layer as well. "Oh the IT guy put epoxy in the USB ports, guess I'll just take the case off and plug into the USB ports on the motherboard"

Re: Researchers crack open malware that hid for 5 years

#119
post #105

What's with all this nonsense about could have "been developed only with the active support of a nation-state"? Do nations suddenly have access to some sort of advanced, alien software development teams? Feels more like political sabre-rattling to get the public to eventually condone a future attack from our homeland shores of Oceania against the evil Eastasia or Eurasia.

It's not that the development techniques are so special, it's that the malware was clearly designed to penetrate ultra high security environments. If you are just making malware to try to steal money, or even most corporate secrets, you don't need to go to all that trouble, so there's little financial incentive for someone other than a nation-state to build malware with those capabilities.

Re: Researchers crack open malware that hid for 5 years

#120
post #105

What's with all this nonsense about could have "been developed only with the active support of a nation-state"? Do nations suddenly have access to some sort of advanced, alien software development teams? Feels more like political sabre-rattling to get the public to eventually condone a future attack from our homeland shores of Oceania against the evil Eastasia or Eurasia.

I believe it's less about fear mongering and more about understanding the level of sophistication of the software. Talk to anti malware analyst and they'll tell you how commoditized the malware game is nowadays. There's an endless stream of malware and ransomware which can be linked back to just a handful of frameworks. These types of malware families also fall under the spray-n-pray mentality for distribution. Spam,…

Everything you said is true, but I'd like to elaborate a bit further: sometimes state involvement can be inferred when the exploit involves computing resources which could only be reasonably wielded by a nation-state.

For example, suppose that this exploit involved the reversal of an MD5 hash (and this is simply an example, I'm not saying that the actual exploit did). How much computing power would be required to do this? I couldn't do this reliably on my home machine, nor could I afford the cloud-compute power to perform it. However, assembling a vast array of machines is within reach of a state sponsored intelligence agency.

So, that's often it: at some point, the computation would be so expensive that you'd have to infer that only a nation state could have financed it.

Post reply on HN