Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

171–180 of 314 posts

Re: Kaspersky believes it found new CIA malware

#171
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

The CIA was caught lying and cheating several times in official investigations. Can you imagine what they have done when nobody else is looking?

Re: Kaspersky believes it found new CIA malware

#172
post #156

Earlier quoted context omitted.

But CIA developing malware isn't news to anyone. How is this a tit-for-tat then?

The tit-for-tat goes the other way: 1. expose malware the CIA doesn't want exposed 2. get accused by the CIA of being in bed with the Russians "working for the Russians" is the go to baseless political smear these days

I would like to point out that a russian security company almost certainly has ties with the russian government. Particularly a very large, well respected one. It would be like accusing oracle or amazon of having ties with the US government.

Re: Kaspersky believes it found new CIA malware

#173
post #62

Earlier quoted context omitted.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

>If I had to wager I'd always bet on national security agency of any powerful country lying, I don't see how anyone could come to another conclusion given their history. Let's not pretend the FSB and MSS don't also lie constantly. That you're more familiar with the CIA lying is a testament to the free press of the US, not the other way around. The point of the previous post is that it could easily be another security…

The CIA has a budget for lying and cheating that is an order of magnitude larger than anything else other countries have. I always assume that they are doing more damage than what we know about.

Re: Kaspersky believes it found new CIA malware

#174

Earlier quoted context omitted.

There's a fantastic example of this from fall of 2019. China was using an iPhone 0day which was extremely complicated to do internal surveillance, and the C2 for it was happening over http.

What is a C2?

Command & Control https://en.wikipedia.org/wiki/Command_and_control

Re: Kaspersky believes it found new CIA malware

#175

We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…

It's not impossible but it's complicated and the more complicated the harder to it is to keep secret. It's easier to just amass exploits for use when needed.

Re: Kaspersky believes it found new CIA malware

#176

Earlier quoted context omitted.

There's a fantastic example of this from fall of 2019. China was using an iPhone 0day which was extremely complicated to do internal surveillance, and the C2 for it was happening over http.

What is a C2?

command and control i think

Re: Kaspersky believes it found new CIA malware

#177
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

> Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

It's not genuine skepticism. It's people on social media wanting Internet points for pointing something out. It's devil's advocates and "well akshully..." people just saying something to make a point. People don't do it on CIA stories because it's not honest skepticism in the first place. It's not fun when the sarcastic and cynical responses make you even more jaded about your own country.

<--- Now, kindly do the needful, dear reader.

Re: Kaspersky believes it found new CIA malware

#178

Earlier quoted context omitted.

There's a fantastic example of this from fall of 2019. China was using an iPhone 0day which was extremely complicated to do internal surveillance, and the C2 for it was happening over http.

What is a C2?

Command and control

Re: Kaspersky believes it found new CIA malware

#179
post #42

I always wonder. The CIA/NSA must essentially target the big Amazon, google and microsoft clouds to get blanket access to everything running and stored there. Seems like a no brainer from their standpoint.

Or they just ask, which is essentially how prism already worked for user data.

They just ask: https://www.bbc.com/news/technology-51207744

Re: Kaspersky believes it found new CIA malware

#180

> the malware samples appear to have been compiled seven years ago, in 2014 So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metada…

Don't overestimate government coders skills... Often it's a massive team with people of very varied programming skills. The core exploit might be some super high tech, hand coded in assembly rootkit, but then the remote control stuff might ends up being some badly written powershell script or multi-megabyte dot-net, java or python binary pulling in every library under the sun.

It seems like this is simply the approach of any coder who's just trying to get X done without worrying about maintaining stuff. Academic code is often "crap" and it's written by smart people but smart people only concerned about getting the algorithm implemented.

Which is say to say, no one yet come up with an approach that combines "fast to write, fast to run, and easy to maintain".

Post reply on HN