Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

131–140 of 314 posts

Re: Kaspersky believes it found new CIA malware

#131
post #3

Aside: Kaspersky is a Russian company.

Dude, it is well known that US is the single most powerful cyber warfare practitioner. They even had a few very successful operations in Iran and may be in China and Russia (you can guarantee that those countries won't disclose the incidents). TBH, one should be happy that US possess such power. US might be biased, but the country is at least rational.

> Dude, it is well known that US is the single most powerful cyber warfare practitioner. They even had a few very successful operations in Iran and may be in China and Russia (you can guarantee that those countries won't disclose the incidents).

I don't follow that logic:

> >1: The US is the single most powerful cyber warfare practitioner

> >2: Successful operations in Iran, China and Russia

> >3: But those countries won't disclose such incidents

So how you can be so sure about point 1?

Re: Kaspersky believes it found new CIA malware

#132
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

and to think thats because they seemingly randomly decided to go back and re analyze this older stuff

>seemingly randomly decided

Re: Kaspersky believes it found new CIA malware

#133

Earlier quoted context omitted.

> my country has been at war my entire adult life The US has been at war for most it’s existence. Someone made a search tool to see how many years the US had been at war for, and then ran it on Wikipedia. Interestingly, France performed worse (assuming one doesn’t like war), though being involved in things like ‘The 100 years war’ skews things a little. https://freakonometrics.hypotheses.org/50473

I probably wouldn't be complaining if I was born in the 1930's, WW1 and 2 were fairly well justified. However what are the current wars even still about? WMD? No, that was a fabrication. Bin Laden? He's long dead. Oil? With fracking, the US has the largest oil reserves on the planet. ISIS? Essentially gone, not much of a threat to US citizens in any case. There was no reason for these wars, there is certainly no reas…

Don't look too closely at how we got into World Wars 1 and 2, if you want to maintain that opinion.

Re: Kaspersky believes it found new CIA malware

#134

Earlier quoted context omitted.

Sure, I dont focus on them because I don't believe that Mossad or MI5 are the reason why my country has been at war my entire adult life, but I have witnessed the NSA and CIA justify those wars-that-arent-really-wars time and time again. How much blood was spilled over the 'yellow cake' line alone? Remember when they lost that ten thousand page report on torture right before it was to be delivered? Or the time they d…

I'm actually curious precisely what CIA justification you're referring to. What I'm aware of are [1] and [2]. [1] https://www.washingtonpost.com/politics/2019/03/22/iraq-war-... [2] https://www.washingtonpost.com/archive/opinions/2003/11/28/m...

The NIE that the CIA wrote up was declassified. It makes it very clear that they believe with "high confidence" (a very specific term in intelligence which means "we're pretty damn sure, normally enough to start a war over") that Iraq was continuing to make active progress on their nuclear weapons program and delivery systems in contrast to their UN sanctions.

There's been a bunch of opinions since then that they were actually just misrepresented, but their own words from 2002 speak for themselves, IMO.

https://www.scribd.com/doc/259216899/Iraq-October-2002-NIE-o...

Re: Kaspersky believes it found new CIA malware

#136
post #52
post #42

I always wonder. The CIA/NSA must essentially target the big Amazon, google and microsoft clouds to get blanket access to everything running and stored there. Seems like a no brainer from their standpoint.

I’d say the likelihood of an American Big Tech without CIA covert operatives working there is essentially zero, even if there’s no direct cooperation. It doesn’t make sense to not utilize some of your most valuable assets.

From another point of view, we can see American Big Tech and CIA (and some other agencies) as the two faces of a same coin : america leadership, as usa are raising their power from economical and cultural supremacy over other country. I may have a blurry foreigner (french) view on your country, but I really see this intrication as real and substential as it was in URSS. In a much robust way, of course, making your country so powerfull.

Re: Kaspersky believes it found new CIA malware

#137

Earlier quoted context omitted.

> Let's not pretend the FSB and MSS don't also lie constantly How do you go from reading "the CIA is lying" to "the FSB is telling the truth"? Do you understand the difference between those statements? Reminds me of a stand up bit, "are you a Jew or an antisemite?"

>How do you go from reading "the CIA is lying" to "the FSB is telling the truth"? The link is a Kaspersky press release, so there’s potential for an FSB connection: https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...

Yet it wasn't until relatively recently that they stopped selling Kaspersky at major retailers. Even if they have an FSB connection they are basically saying, well we now know that company we let get loose on millions of consumer desktops and enterprise/government systems in the US is connected to Russian intelligence. Oops!

Re: Kaspersky believes it found new CIA malware

#138

> the malware samples appear to have been compiled seven years ago, in 2014 So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metada…

Don't overestimate government coders skills... Often it's a massive team with people of very varied programming skills. The core exploit might be some super high tech, hand coded in assembly rootkit, but then the remote control stuff might ends up being some badly written powershell script or multi-megabyte dot-net, java or python binary pulling in every library under the sun.

There's a fantastic example of this from fall of 2019. China was using an iPhone 0day which was extremely complicated to do internal surveillance, and the C2 for it was happening over http.

Re: Kaspersky believes it found new CIA malware

#139
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I’d say it’s likely they were instructed to sit on it until the time is right

Re: Kaspersky believes it found new CIA malware

#140
post #108
post #37

Earlier quoted context omitted.

If you want to be protected from the US made malware you do not go to US antimalware vendor. If you want to be protected against Russian malware you do not get antimalware from Russia. So pick your poison.

Solution: Install US and Russian antiviruses simultaneously.

Won't it led to an instant annihilation?
Post reply on HN