Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

231–240 of 314 posts

Re: Kaspersky believes it found new CIA malware

#231

Earlier quoted context omitted.

It's nearly always about natural resources, just because the US has the largest oil reserves doesn't mean it's going to stop there. And the wars you mentioned are just the boots on the ground (or drones in the air) conflicts. Were still backing coups in Latin America (Honduras, Venezuela, Bolivia) so US friendly governments are put into place that will allow American companies to extract their resources.

which natural resources were we getting out of afghanistan

Afghanistan is strategically located at a major crossroads between Central and East Asia. This is useful for trade and military operations.

See also: https://en.wikipedia.org/wiki/Afghanistan_Oil_Pipeline

Re: Kaspersky believes it found new CIA malware

#232
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Until a few years ago, I was skeptical that North Korea had the technical expertise to pull off some of the hacking that was being attributed to them. In the past 5+ years, however, it's become increasingly clear that they have a well funded and dedicated team of competent hackers. The NSA and CIA, on the hand, are always assumed to have some of the best hackers in the world. So when I read that some huge exploit wit…

North Korean cyber capabilities were likely heavily thwarted for a long time by the fact that the United States could observe all the traffic entering and exiting the country.

As a result they operate units completely overseas. North Korean students launch attacks from Indian Universities. They have networks of individuals that spend all day cashing out ATMs in Malta. The Chilbosan Hotel in Shenyang, China is a front used by the RGB as a forward base for cyber operations.

Re: Kaspersky believes it found new CIA malware

#233

Earlier quoted context omitted.

>That silence resulted in the loss of at least one hundred and fifty thousand human beings needlessly Just gonna point out that non-Americans are human beings as well, and millions have died - directly as a result of this silence. The fact that Biden played a key part in enforcing this silence at various stages is particularly galling, and it's beyond fucked-up that he isn't held to account for it.

>Just gonna point out that non-Americans are human beings as well, and millions have died - directly as a result of this silence. 150k is the most conservative estimate I could find for Iraq. US and Iraqi deaths included. Some estimates are in the millions but I try to be as generous as possible to the other side of a argument I am making.

Iraq is not the only country where the Intelligence agencies were up to no good. But no, using American claims from sources linked to people justifying war about fatilities goes beyond being charitable.

Re: Kaspersky believes it found new CIA malware

#234
post #228

Earlier quoted context omitted.

> Here is just one example: Here's an example that in major parts contributed to a civil war going on to this day: The existence of a US military operation that manipulates social media trough sock-puppet accounts [0] was revealed around the same time Syrians were riled up to regime change trough.. social media [1]. Said social media presence kept announcing "Days of Rage" protests in Syria which initially no Syrian…

> How many domestic sponsored accounts have been banned? The Smith–Mundt Act makes it illegal to distribute propaganda where it may be consumed by a primarily US audience. Also from just a practical investment perspective, creating a bunch of sock puppets on Reddit to try and influence the opinion of Putin doesn't make sense. r/Russia for example only has 150k subscribers and most of the posts are in English. You wou…

> The Smith–Mundt Act makes it illegal to distribute propaganda where it may be consumed by a primarily US audience.

That hasn't been true for nearly a decade as the Smith-Mundt act was "modernized" in 2012 to allow for exactly that [0].

Even when it was in effect, I doubt anybody was seriously trying to abide by that. The closest thing to practically doing that would have been to completely skip on the English language, which I seriously doubt they did.

I put that denial into the very same camp as the NSA denying spying on American citizens: They say it because they are supposed to say that and admitting to it would put them in a world of trouble trough open admission of guilt.

> Also from just a practical investment perspective, creating a bunch of sock puppets on Reddit to try and influence the opinion of Putin doesn't make sense.

It makes a lot of sense, not just to manufacture consent, but also trough the fact how the US is the literally largest culture exporter on the planet. US social media isn't just populated by Americans: Facebook, Reddit, Twitter and whatnot are by now overwhelmingly used by international audiences.

Sure, there are countries that try to ban these platforms, but that doesn't stop the USG from still trying to get something going [1]

> You would need to ask WeChat, VK, Weibo, Douyin, and OK for transparency reports on how many state-sponsored accounts they have terminated.

But none of these are in any way widely used outside of their respective countries, their very limited reach and lack of language diversity, makes them inherently inferior to the globally dominating US social media platforms.

Yet that's where the "opinion wars" are won, where the international Overton window is defined: On the global stage, not on comparatively obscure domestic platforms.

[0] https://foreignpolicy.com/2013/07/14/u-s-repeals-propaganda-...

[1] https://www.theguardian.com/world/2014/apr/03/us-cuban-twitt...

Re: Kaspersky believes it found new CIA malware

#235
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I’d say it’s likely they were instructed to sit on it until the time is right

What's more likely:

* CIA malware is discovered by a (Russian) Security company and they release a report about it.

* CIA malware discovered a year or more ago by a (Russian) security company and they tell the CIA about it and the CIA asks them to wait 1y+ to release the report, and they obliged.

Re: Kaspersky believes it found new CIA malware

#236
post #62

Earlier quoted context omitted.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

>If I had to wager I'd always bet on national security agency of any powerful country lying, I don't see how anyone could come to another conclusion given their history. Let's not pretend the FSB and MSS don't also lie constantly. That you're more familiar with the CIA lying is a testament to the free press of the US, not the other way around. The point of the previous post is that it could easily be another security…

I wish we could discuss the malware at hand, and the fascinating world of state sponsored hacking instead of once again devolving into a dick measuring argument about which nations intelligence agency is better.

Re: Kaspersky believes it found new CIA malware

#237

Is there a link to any actual posts or blog by Kaspersky on the matter? This seems to be missing from their official communications...

The link is included in the article ("Kaspersky’s full description is below, from its quarterly APT report released today.") The linked article's url is https://securelist.com/apt-trends-report-q1-2021/101967/ , which is from a site called "SECURELIST by Kaspersky".

That link says nothing about the CIA

Re: Kaspersky believes it found new CIA malware

#238
post #200

Earlier quoted context omitted.

That was part of it. The other part was "Do what we tell you, or you'll be Joe Nacchioed" In a 2013 interview, Marissa Meyer made it abundantly clear this is why Yahoo "voluntarily" joined PRISM. One can assume the rest were similarly influenced.

Reference: https://en.wikipedia.org/wiki/Joseph_Nacchio

Thank you.

Re: Kaspersky believes it found new CIA malware

#239

Earlier quoted context omitted.

I think it’s much more likely for both these orgs to be telling the truth when they’re accusing their enemies of doing bad things than it is when they’re denying that they’ve done bad things themselves. It’s not a simple case of one consistently telling the truth, and the other consistently lying...

So when the CIA tells me some foreign government is doing something bad, I should believe them? Then when the CIA denies they lied about the foreign government was doing something bad, I should ignore them? This advice makes no sense to me.

> So when the CIA tells me some foreign government is doing something bad, I should believe them?

Honestly, yes.

> Then when the CIA denies they lied about the foreign government was doing something bad

When have they done this? A few times probably, but not really a high percentage.

At any rate, P(CIA telling the truth about a foreign govt|foreign govt is doing something bad) is much higher than P(CIA lying about foreign govt|foreign govt is not doing something bad). The rational thing is to put higher weight on such statements than when the CIA is trying to cover their own ass.

Re: Kaspersky believes it found new CIA malware

#240
post #154

Two weeks ago, the NSA accused the Russian SVR (intelligence agency) of exploiting vulnerabilities in US networks and suggesting that they were behind the SolarWinds compromise[1]. Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real). The timing does not seem to be a coincidence. Tit-for-tat? [1]…

> which is suspected to be affiliated with Russian intelligence - possibly unwillingly

I have yet to see actually compelling evidence that this is the case.

Post reply on HN