Live data from Hacker News

Duqu 2.0 Hits Kaspersky Lab

securelist.com

31–40 of 60 posts

Re: Duqu 2.0 Hits Kaspersky Lab

#31
post #2

"By targeting Kaspersky Lab, the Duqu attackers probably took a huge bet hoping they’d remain undiscovered; and lost." That seems like a very nice spin on a successful attack that was eventually detected. How long were the attackers able to spy on their internal systems? Perhaps they didn't need ongoing access and simply wished to steal client files or documents.

"... or perhaps they don’t care much if they are discovered and exposed"

-- Kaspersky Labs

Re: Duqu 2.0 Hits Kaspersky Lab

#32
post #22

Earlier quoted context omitted.

Well, the malware used some quite innovative techniques, for example, consider this quote from Ars Technica article: >Kaspersky researchers have described it as a "0-day trampoline" because it allowed their malicious modules to jump directly into the Windows kernel, the inner part of the operating system that has unfettered access to system memory and all external devices. The trampoline exploit allowed the malware t…

Follow that thought. If the risk was exposing these techniques, and exposure meant that the attackers would need new techniques, and the attackers were willing to take the risk, then... Then they probably already have their new techniques all ready to go. Maybe even deployed in the field.

Perhaps they also knew that other bad actors had already discovered this particular 0-day and wanted it to be outed?

Re: Duqu 2.0 Hits Kaspersky Lab

#33
post #22

Earlier quoted context omitted.

From the Kaspersky link: I can think of several reasons why someone might want to try to steal our technical data, but each one of them doesn’t seem to be worth the risk. I don't get it: what's the risk here? As far as I can see, the only risk is that their malware is removed from the victim machines. The risk of blowback to the perpetrators is vanishingly small as far as I can see.

Well, the malware used some quite innovative techniques, for example, consider this quote from Ars Technica article: >Kaspersky researchers have described it as a "0-day trampoline" because it allowed their malicious modules to jump directly into the Windows kernel, the inner part of the operating system that has unfettered access to system memory and all external devices. The trampoline exploit allowed the malware t…

> Now this will be patched, and they will need something completely different for the next framework.

Which is probably already developed, tested, and deployed.

Re: Duqu 2.0 Hits Kaspersky Lab

#34
post #30

It's kind of cute how the technical report[1] goes to great lengths to finger Israel, without explicitly stating it (see page 43). [1] https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...

I wouldn't be surprised. KL tend to nettle (expose activity of) most western spy agencies while bypassing Russian and to a lesser extent Chinese hacking activities.

Re: Duqu 2.0 Hits Kaspersky Lab

#35
post #10

The Windows 0-day is CVE-2015-2360 from MS15-061, it appears to be the only one Microsoft admits to have been exploited or used to attack it's customers. https://technet.microsoft.com/library/security/ms15-061

Even if it's the only one they've admitted to, I think it's readily known that Microsoft has numerous zero-days (discovered or not) in their software. Combine that with their prevalence in Enterprise businesses, they're going to be a logical starting point for any top tier blackhat org.

Every OS that people actually use has boatloads of unpatched security issues.

Re: Duqu 2.0 Hits Kaspersky Lab

#36
post #27

The Duqu attackers have got a ridiculous bag of zero-days at the ready.

Downvote with no explanation. Someone disagrees that these guys use zero-days? Not to mention some of which include jumping to kernel mode?

2011: CVE-2011-3402

2014: CVE-2014-4148 CVE-2014-6324 CVE-2015-2360

Re: Duqu 2.0 Hits Kaspersky Lab

#37
post #10

The Windows 0-day is CVE-2015-2360 from MS15-061, it appears to be the only one Microsoft admits to have been exploited or used to attack it's customers. https://technet.microsoft.com/library/security/ms15-061

Even if it's the only one they've admitted to, I think it's readily known that Microsoft has numerous zero-days (discovered or not) in their software. Combine that with their prevalence in Enterprise businesses, they're going to be a logical starting point for any top tier blackhat org.

"I think it's readily known that Microsoft has numerous zero-days (discovered or not) in their software."

This is true for every single piece of software ever written. Msft is no different in this regard.

Re: Duqu 2.0 Hits Kaspersky Lab

#38
post #25

Earlier quoted context omitted.

I've heard that Iran calls US "great Satan", and Russia "small Satan"

I've heard that Iran calls Israel "small Satan", not Russia. A quick Google search finds lots of confirmation of that.

Wikipedia mentions both :)

http://en.wikipedia.org/wiki/Great_Satan

Re: Duqu 2.0 Hits Kaspersky Lab

#39
post #4

Related report from Symantec: http://www.symantec.com/connect/blogs/duqu-20-reemergence-ag... Eugene Kaspersky: "Why Hacking Us Was A Silly Thing To Do" http://www.forbes.com/sites/eugenekaspersky/2015/06/10/why-h...

From the Kaspersky link: I can think of several reasons why someone might want to try to steal our technical data, but each one of them doesn’t seem to be worth the risk. I don't get it: what's the risk here? As far as I can see, the only risk is that their malware is removed from the victim machines. The risk of blowback to the perpetrators is vanishingly small as far as I can see.

One plausible reason is that they wanted to see if some other as yet undisclosed attack has hit Kaspersky's radar. Peek into the detective's briefcase to see if he is investigating something that may expose your bigger caper. There is low risk to being found for your true caper.

Re: Duqu 2.0 Hits Kaspersky Lab

#40
post #25

Earlier quoted context omitted.

I've heard that Iran calls Israel "small Satan", not Russia. A quick Google search finds lots of confirmation of that.

Wikipedia mentions both :) http://en.wikipedia.org/wiki/Great_Satan

And so it does. I stand corrected. The USSR was indeed called the lesser Satan 35 years ago.

However the link that I provided to http://en.wikipedia.org/wiki/Iran%E2%80%93Russia_relations says that Iran and the USSR had poor relations (due to the whole atheism thing), but Iran and Russia have had good relations since the USSR fell. Do you have a reference to Iran calling Russia any version of Satan in, say, the last 15 years?

Post reply on HN