Live data from Hacker News

Duqu 2.0 Hits Kaspersky Lab

securelist.com

21–30 of 60 posts

Re: Duqu 2.0 Hits Kaspersky Lab

#21
post #4

Related report from Symantec: http://www.symantec.com/connect/blogs/duqu-20-reemergence-ag... Eugene Kaspersky: "Why Hacking Us Was A Silly Thing To Do" http://www.forbes.com/sites/eugenekaspersky/2015/06/10/why-h...

From the Kaspersky link: I can think of several reasons why someone might want to try to steal our technical data, but each one of them doesn’t seem to be worth the risk. I don't get it: what's the risk here? As far as I can see, the only risk is that their malware is removed from the victim machines. The risk of blowback to the perpetrators is vanishingly small as far as I can see.

At the very least, you use up the particular 0-day attacks you used to gain access to the system - since they had to keep re-using them in order to re-infect machines over reboots there was a pretty high chance that once detected, Kaspersky would discover the exploits being used. Apart from entities like the NSA themselves you probably couldn’t choose a more security aware target.

Any large nation state probably has a nice cache of 0-days ready to roll out at any given time, but they’re still a limited resource that could be used to attack other targets. Attacking Kaspersky pretty much guarantees that the 0-days are blown once the infiltration is discovered.

Re: Duqu 2.0 Hits Kaspersky Lab

#22
post #4

Related report from Symantec: http://www.symantec.com/connect/blogs/duqu-20-reemergence-ag... Eugene Kaspersky: "Why Hacking Us Was A Silly Thing To Do" http://www.forbes.com/sites/eugenekaspersky/2015/06/10/why-h...

From the Kaspersky link: I can think of several reasons why someone might want to try to steal our technical data, but each one of them doesn’t seem to be worth the risk. I don't get it: what's the risk here? As far as I can see, the only risk is that their malware is removed from the victim machines. The risk of blowback to the perpetrators is vanishingly small as far as I can see.

Well, the malware used some quite innovative techniques, for example, consider this quote from Ars Technica article:

>Kaspersky researchers have described it as a "0-day trampoline" because it allowed their malicious modules to jump directly into the Windows kernel, the inner part of the operating system that has unfettered access to system memory and all external devices. The trampoline exploit allowed the malware to bypass digital signature requirements designed to prevent the loading of malicious code into the OS kernel space.

>"What is really impressive here—what I call really amazing—is the entire malware platform depends on this zero-day to work," Raiu said. "So if there is no zero day to jump into kernel mode this doesn't work."

Now this will be patched, and they will need something completely different for the next framework.

Re: Duqu 2.0 Hits Kaspersky Lab

#24
"Despite the beefed up operational security of the malware, its unmistakable connection to the Duqu 1.0 and the times of day Duqu attackers manually entered Kaspersky's network leave little doubt in the minds of company researchers that the 2011 and 2014 attacks were carried out by the same group."

Not only is this a total stretch, it's complete hearsay.

The reasons for hackers to go after Kaspersky are just as numerous as state sponsored teams to. I find it hard to say it was definitively one or other without further evidence. But in this "government surveillance" panic people are currently in, it's easy to just point a finger and say it was the NSA because this version "looks similar" to another version already deployed.

It's about as solid as saying there were similarities between the type of malware used in the Sony Pictures attack and code used to attack South Korea last year - which was laughed off by most of the info sec community.

Re: Duqu 2.0 Hits Kaspersky Lab

#25
post #18

Earlier quoted context omitted.

In recent history, Russia and Iran have indeed been allies. See http://en.wikipedia.org/wiki/Iran%E2%80%93Russia_relations for verification. And the US has repeatedly found itself on the opposite end of geopolitical conflicts with both countries. For a random example, both Iran and Russia have been supportive of Assad's government in Syria, while the US is opposed. Of course interests shift over time. We are indeed d…

I've heard that Iran calls US "great Satan", and Russia "small Satan"

I've heard that Iran calls Israel "small Satan", not Russia.

A quick Google search finds lots of confirmation of that.

Re: Duqu 2.0 Hits Kaspersky Lab

#26
post #22

Earlier quoted context omitted.

From the Kaspersky link: I can think of several reasons why someone might want to try to steal our technical data, but each one of them doesn’t seem to be worth the risk. I don't get it: what's the risk here? As far as I can see, the only risk is that their malware is removed from the victim machines. The risk of blowback to the perpetrators is vanishingly small as far as I can see.

Well, the malware used some quite innovative techniques, for example, consider this quote from Ars Technica article: >Kaspersky researchers have described it as a "0-day trampoline" because it allowed their malicious modules to jump directly into the Windows kernel, the inner part of the operating system that has unfettered access to system memory and all external devices. The trampoline exploit allowed the malware t…

Follow that thought. If the risk was exposing these techniques, and exposure meant that the attackers would need new techniques, and the attackers were willing to take the risk, then...

Then they probably already have their new techniques all ready to go. Maybe even deployed in the field.

Re: Duqu 2.0 Hits Kaspersky Lab

#28
post #22

Earlier quoted context omitted.

Well, the malware used some quite innovative techniques, for example, consider this quote from Ars Technica article: >Kaspersky researchers have described it as a "0-day trampoline" because it allowed their malicious modules to jump directly into the Windows kernel, the inner part of the operating system that has unfettered access to system memory and all external devices. The trampoline exploit allowed the malware t…

Follow that thought. If the risk was exposing these techniques, and exposure meant that the attackers would need new techniques, and the attackers were willing to take the risk, then... Then they probably already have their new techniques all ready to go. Maybe even deployed in the field.

Yeah, this is actually addressed in the further paragraphs:

>Raiu went on to say the reliance on the highly unusual vulnerability is one of the things underscoring Duqu developers' extraordinary talent and the plentiful number of additional unpatched security bugs with the same unusual capabilities they likely have at their disposal.

>"These guys are so confident to develop their entire platform based on this zero day it means if they get caught and this zero day is patched they probably have another one they can use, which I would say is a pretty scary thought," he said. "Nobody develops an entire malware platform based on just one simple assumption that this zero day will work forever, because eventually it will be discovered and patched. And when it is patched your malware is not going to work anymore. I think that's also very scary and quite impressive."

Still the attackers' resources are not unlimited - they lost some development time, and maybe some unique opportunities which were possible only with this particular zero-day.

Re: Duqu 2.0 Hits Kaspersky Lab

#29
post #11

The geopolitics of this one is fascinating. Stuxnet was a combined Israeli/US attack on Iran's nuclear capability. Kaspersky is a Russian security company which was started with government support, and is believed to still have connections there. Russia and Iran are allies. Now look at how it played out. The US and Israel attacked Iran. Kaspersky tracked it down and publicized it to the world. And now some combinatio…

> a Russian company started with government support From what I know this is simply not true. Got a source? But I think your overall point holds. Kaspersky's 400 million user base includes a boatload of US/Western users, including enterprise and government clients. This simply cannot NOT be of some concern to respective countries, so it's perfectly logical that they would want to keep an eye on the situation.

I thought I had a source, but when I went looking I found tons of interesting connections (eg Kaspersky having gotten started in anti-virus while he was KGB) but no actual proof of involvement.

Given how Russian business works, though, it would seem likely that there is a connection.

But http://www.bloomberg.com/news/articles/2015-03-19/cybersecur... is an article that gives more recent reason for why Kaspersky is a potentially interesting target for Western spies.

Post reply on HN