Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

161–170 of 314 posts

Re: Kaspersky believes it found new CIA malware

#161

Earlier quoted context omitted.

I probably wouldn't be complaining if I was born in the 1930's, WW1 and 2 were fairly well justified. However what are the current wars even still about? WMD? No, that was a fabrication. Bin Laden? He's long dead. Oil? With fracking, the US has the largest oil reserves on the planet. ISIS? Essentially gone, not much of a threat to US citizens in any case. There was no reason for these wars, there is certainly no reas…

It's nearly always about natural resources, just because the US has the largest oil reserves doesn't mean it's going to stop there. And the wars you mentioned are just the boots on the ground (or drones in the air) conflicts. Were still backing coups in Latin America (Honduras, Venezuela, Bolivia) so US friendly governments are put into place that will allow American companies to extract their resources.

About the development of, distribution of, and continued stability of access to natural resources... which benefits everyone.

Re: Kaspersky believes it found new CIA malware

#162
post #154

Two weeks ago, the NSA accused the Russian SVR (intelligence agency) of exploiting vulnerabilities in US networks and suggesting that they were behind the SolarWinds compromise[1]. Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real). The timing does not seem to be a coincidence. Tit-for-tat? [1]…

Interesting. But if you had cited "my ass" as a source it would be more reliable, because the NSA is probably better at lying.

The parent commenter was sourcing "the NSA accused..." with the accusation, not making a claim as to whether the accusation was true.

Re: Kaspersky believes it found new CIA malware

#163

I may have missed it in the article, but as a sysadmin, i’m trying to figure out what I should do. It appears the CIA has created malware. I assume, if they have exploited some hole, others will too. While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?

Why would you rely on a company that is banned? https://www.nextgov.com/cybersecurity/2019/09/us-finalizes-r...

Re: Kaspersky believes it found new CIA malware

#164
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Until a few years ago, I was skeptical that North Korea had the technical expertise to pull off some of the hacking that was being attributed to them. In the past 5+ years, however, it's become increasingly clear that they have a well funded and dedicated team of competent hackers.

The NSA and CIA, on the hand, are always assumed to have some of the best hackers in the world. So when I read that some huge exploit with multiple complex 0-days chained together has been discovered, and it's being attributed to the USA and/or Israel, I usually assume that's true because very few other countries have the ability to pull it off.

Re: Kaspersky believes it found new CIA malware

#165

Is there a link to any actual posts or blog by Kaspersky on the matter? This seems to be missing from their official communications...

The link is included in the article ("Kaspersky’s full description is below, from its quarterly APT report released today.")

The linked article's url is https://securelist.com/apt-trends-report-q1-2021/101967/ , which is from a site called "SECURELIST by Kaspersky".

Re: Kaspersky believes it found new CIA malware

#166

Earlier quoted context omitted.

I'm actually curious precisely what CIA justification you're referring to. What I'm aware of are [1] and [2]. [1] https://www.washingtonpost.com/politics/2019/03/22/iraq-war-... [2] https://www.washingtonpost.com/archive/opinions/2003/11/28/m...

https://en.m.wikipedia.org/wiki/Niger_uranium_forgeries Folks inside the CIA knew that the yellow cake uranium was a lie and at best, did not make any of this knowledge public as the justification for war was coming together. That silence resulted in the loss of at least one hundred and fifty thousand human beings needlessly and a war that has lasted decades.

>That silence resulted in the loss of at least one hundred and fifty thousand human beings needlessly

Just gonna point out that non-Americans are human beings as well, and millions have died - directly as a result of this silence.

The fact that Biden played a key part in enforcing this silence at various stages is particularly galling, and it's beyond fucked-up that he isn't held to account for it.

Re: Kaspersky believes it found new CIA malware

#167
post #60

Earlier quoted context omitted.

Surely no-one believes the CIA always behaves ethically. Especially after the post-9/11 kidnap, torture and murder rampage. Perhaps you meant a lot of people question if the CIA ever behaves ethically.

I’m sure the people that work there think they are a thin line against the harm others would like to do to America. “The ends justify the means”.

I would hope they're smarter than that, but apparently not many are.

Re: Kaspersky believes it found new CIA malware

#168
post #156
post #154

Two weeks ago, the NSA accused the Russian SVR (intelligence agency) of exploiting vulnerabilities in US networks and suggesting that they were behind the SolarWinds compromise[1]. Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real). The timing does not seem to be a coincidence. Tit-for-tat? [1]…

But CIA developing malware isn't news to anyone. How is this a tit-for-tat then?

The tit-for-tat goes the other way:

1. expose malware the CIA doesn't want exposed

2. get accused by the CIA of being in bed with the Russians

"working for the Russians" is the go to baseless political smear these days

Re: Kaspersky believes it found new CIA malware

#169

Earlier quoted context omitted.

Don't overestimate government coders skills... Often it's a massive team with people of very varied programming skills. The core exploit might be some super high tech, hand coded in assembly rootkit, but then the remote control stuff might ends up being some badly written powershell script or multi-megabyte dot-net, java or python binary pulling in every library under the sun.

There's a fantastic example of this from fall of 2019. China was using an iPhone 0day which was extremely complicated to do internal surveillance, and the C2 for it was happening over http.

What is a C2?

Re: Kaspersky believes it found new CIA malware

#170
post #144

Earlier quoted context omitted.

I’d say it’s likely they were instructed to sit on it until the time is right

Did you take occam’s razor into account? Why is this likely?

The timing is very sus given recent and ongoing spy mania in eastern europe (if you’ve been following)
Post reply on HN