"By targeting Kaspersky Lab, the Duqu attackers probably took a huge bet hoping they’d remain undiscovered; and lost." That seems like a very nice spin on a successful attack that was eventually detected. How long were the attackers able to spy on their internal systems? Perhaps they didn't need ongoing access and simply wished to steal client files or documents.
"... or perhaps they don’t care much if they are discovered and exposed" -- Kaspersky Labs
Duqu 2.0 Hits Kaspersky Lab
41–50 of 60 posts
Re: Duqu 2.0 Hits Kaspersky Lab
#42Earlier quoted context omitted.
Wikipedia mentions both :) http://en.wikipedia.org/wiki/Great_Satan
And so it does. I stand corrected. The USSR was indeed called the lesser Satan 35 years ago. However the link that I provided to http://en.wikipedia.org/wiki/Iran%E2%80%93Russia_relations says that Iran and the USSR had poor relations (due to the whole atheism thing), but Iran and Russia have had good relations since the USSR fell. Do you have a reference to Iran calling Russia any version of Satan in, say, the last…
I agree with your overall conclusion that it's possible the attack was carried out by some special agencies, and that it might be reasonable from their standpoint.
But the chain of causality you draw looks to me as an arbitrary fantasy; or to say better, only one of many possible explanations. It puts together several unverified assumptions - statements which are not 100% true, but only probable to some degree.
The probability of all that happen together is a multiplication of all the probabilities, and therefore a small number.
There is no evidence that Kaspersky Labs work for Russian intelligence. Yes, there were articles where journalists say "oh, he worked in KGB, so we can imagine they still cooperate". The fact we can imagine something doesn't mean it's true. All we can say for sure, Kaspersky Labs maybe work for KGB, or maybe not (including they work for somebody else, why not imagine this).
Does Russia want to support Iranian nuclear program, up to providing cyber security? IMHO unlikely, but again - maybe yes, maybe no.
Even if Russia decided to support Iran, there is no proof Russia employed Kaspersky and not a proper department of intelligence service - maybe Kaspersky detected stuxnet fairly, during their anti-virus research (their primary business, isn't it possible)?
Even that stuxnet is an US intelligence creature is not a 100% fact; there were strong evidence to support that, but we don't know 100%.
0.1 * 0.2 * 0.4 * 0.9 = 0.0072
Put your own number if you find your assumptions more realistic:
P(Kaspersky Labs work for KGB) = 0.8
P(Russia wants so provide cyber security for Iranian nuclear program) = 0.5
P(Kasperky Labs detected stuxnet specifically because
of intelligence order, as russian intelligence
has no other cybersecurity departments) = 0.5
P(stuxned is developed by US intelligence to attack Iran) = 0.95
Anyway, the combined probability of 0.8 * 0.5 * 0.5 * 0.95 = 0.19Re: Duqu 2.0 Hits Kaspersky Lab
#43"Despite the beefed up operational security of the malware, its unmistakable connection to the Duqu 1.0 and the times of day Duqu attackers manually entered Kaspersky's network leave little doubt in the minds of company researchers that the 2011 and 2014 attacks were carried out by the same group." Not only is this a total stretch, it's complete hearsay. The reasons for hackers to go after Kaspersky are just as numer…
Re: Duqu 2.0 Hits Kaspersky Lab
#44It's kind of cute how the technical report[1] goes to great lengths to finger Israel, without explicitly stating it (see page 43). [1] https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
His speech to congress was unprecedented and a sign he was possibly being kept out of the loop in the negotiation deals. I wouldn't blame Obama, Bebe's emotions (or delusions) seem to get in the way of any attempts at peace talks.
Re: Duqu 2.0 Hits Kaspersky Lab
#45It's kind of cute how the technical report[1] goes to great lengths to finger Israel, without explicitly stating it (see page 43). [1] https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
Re: Duqu 2.0 Hits Kaspersky Lab
#46"Despite the beefed up operational security of the malware, its unmistakable connection to the Duqu 1.0 and the times of day Duqu attackers manually entered Kaspersky's network leave little doubt in the minds of company researchers that the 2011 and 2014 attacks were carried out by the same group." Not only is this a total stretch, it's complete hearsay. The reasons for hackers to go after Kaspersky are just as numer…
Re: Duqu 2.0 Hits Kaspersky Lab
#47Related report from Symantec: http://www.symantec.com/connect/blogs/duqu-20-reemergence-ag... Eugene Kaspersky: "Why Hacking Us Was A Silly Thing To Do" http://www.forbes.com/sites/eugenekaspersky/2015/06/10/why-h...
The internet was designed to survive a war. Can it handle being the battlefield?
----
> We protect those people in the face of such risks ... generally speaking, deliberately attacking medics on a battleground is simply despicable and disgraceful.
No further comment.
Re: Duqu 2.0 Hits Kaspersky Lab
#48It's kind of cute how the technical report[1] goes to great lengths to finger Israel, without explicitly stating it (see page 43). [1] https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
I wouldn't be surprised. KL tend to nettle (expose activity of) most western spy agencies while bypassing Russian and to a lesser extent Chinese hacking activities.
Re: Duqu 2.0 Hits Kaspersky Lab
#49Earlier quoted context omitted.
Follow that thought. If the risk was exposing these techniques, and exposure meant that the attackers would need new techniques, and the attackers were willing to take the risk, then... Then they probably already have their new techniques all ready to go. Maybe even deployed in the field.
Perhaps they also knew that other bad actors had already discovered this particular 0-day and wanted it to be outed?
Re: Duqu 2.0 Hits Kaspersky Lab
#50The Duqu attackers have got a ridiculous bag of zero-days at the ready.
Downvote with no explanation. Someone disagrees that these guys use zero-days? Not to mention some of which include jumping to kernel mode? 2011: CVE-2011-3402 2014: CVE-2014-4148 CVE-2014-6324 CVE-2015-2360