So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.
I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.
Kaspersky believes it found new CIA malware
171–180 of 314 posts
Re: Kaspersky believes it found new CIA malware
#172Earlier quoted context omitted.
But CIA developing malware isn't news to anyone. How is this a tit-for-tat then?
The tit-for-tat goes the other way: 1. expose malware the CIA doesn't want exposed 2. get accused by the CIA of being in bed with the Russians "working for the Russians" is the go to baseless political smear these days
Re: Kaspersky believes it found new CIA malware
#173Earlier quoted context omitted.
If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.
>If I had to wager I'd always bet on national security agency of any powerful country lying, I don't see how anyone could come to another conclusion given their history. Let's not pretend the FSB and MSS don't also lie constantly. That you're more familiar with the CIA lying is a testament to the free press of the US, not the other way around. The point of the previous post is that it could easily be another security…
Re: Kaspersky believes it found new CIA malware
#174Earlier quoted context omitted.
There's a fantastic example of this from fall of 2019. China was using an iPhone 0day which was extremely complicated to do internal surveillance, and the C2 for it was happening over http.
What is a C2?
Re: Kaspersky believes it found new CIA malware
#175We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…
Re: Kaspersky believes it found new CIA malware
#176Re: Kaspersky believes it found new CIA malware
#177So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.
I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.
It's not genuine skepticism. It's people on social media wanting Internet points for pointing something out. It's devil's advocates and "well akshully..." people just saying something to make a point. People don't do it on CIA stories because it's not honest skepticism in the first place. It's not fun when the sarcastic and cynical responses make you even more jaded about your own country.
<--- Now, kindly do the needful, dear reader.
Re: Kaspersky believes it found new CIA malware
#178Re: Kaspersky believes it found new CIA malware
#179I always wonder. The CIA/NSA must essentially target the big Amazon, google and microsoft clouds to get blanket access to everything running and stored there. Seems like a no brainer from their standpoint.
Or they just ask, which is essentially how prism already worked for user data.
Re: Kaspersky believes it found new CIA malware
#180> the malware samples appear to have been compiled seven years ago, in 2014 So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metada…
Don't overestimate government coders skills... Often it's a massive team with people of very varied programming skills. The core exploit might be some super high tech, hand coded in assembly rootkit, but then the remote control stuff might ends up being some badly written powershell script or multi-megabyte dot-net, java or python binary pulling in every library under the sun.
Which is say to say, no one yet come up with an approach that combines "fast to write, fast to run, and easy to maintain".