Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

61–70 of 314 posts

Re: Kaspersky believes it found new CIA malware

#61
post #33

Earlier quoted context omitted.

Or: "they're a company that has been accused without evidence of cooperating with the FSB in attacks against the US government by US entities aligned to the US-based actors that they have exposed". FTFY.

> without evidence of cooperating with the FSB That isn't true. This "without evidence" shit is rather silly when it comes to top-secret sources and methods. Blow decades of work and risk getting people killed to Prove that an ex-KGB officer helps an authoritative regime thats known to poison its enemies. People said the same shit about Huawei, then all the KPN shit. Link: https://www.bloomberg.com/news/articles/2017…

The problem with that is that those agencies also lie all the time. You can't have your cake and eat it too with a just trust us attitude and also make stuff up when it's convenient.

Re: Kaspersky believes it found new CIA malware

#62
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

>If I had to wager I'd always bet on national security agency of any powerful country lying, I don't see how anyone could come to another conclusion given their history.

Let's not pretend the FSB and MSS don't also lie constantly. That you're more familiar with the CIA lying is a testament to the free press of the US, not the other way around.

The point of the previous post is that it could easily be another security agency.

Re: Kaspersky believes it found new CIA malware

#63

Earlier quoted context omitted.

What does "force of evil" mean anyway? It seems like a subjective measurement based entirely on tribalism as a foundation.

> What does "force of evil" mean anyway? Yes, subjective. But here's my belief and how I believe it applies. I believe evil is the abandonment of reason in any way. Instigation of force or coercion is an un-reason-able act no matter whether done by an individual or group of people. Currently the US is engaged in numerous instigative forceful and coercive acts. Further, much of what the US does would not be possible w…

The people who define it differently than you also use reason -- just a different line of reasoning. This is the entire issue with the phrase to begin with, there's no universal definition of what it means. It assumes a shared value system.

Almost everyone who fights anyone else believes that they are right and has a reason for it.

Re: Kaspersky believes it found new CIA malware

#64
> the malware samples appear to have been compiled seven years ago, in 2014

So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metadata hygiene employed by journalists, whistleblowers etc

Re: Kaspersky believes it found new CIA malware

#65
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

Now compare it to how fast US intelligence analysts are. They may conclude who is behind attack in a matter of days. (For example, recent solarwinds attack)

Conclusion prefetching is awesome, isn't it?

Re: Kaspersky believes it found new CIA malware

#66

> the malware samples appear to have been compiled seven years ago, in 2014 So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metada…

I think it was based more on when the samples were found

Re: Kaspersky believes it found new CIA malware

#67
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

[deleted]

Re: Kaspersky believes it found new CIA malware

#68

Earlier quoted context omitted.

This kind of hyperbole is neither instructive nor accurate. What is the intended purpose of this comment?

It is accurate and not hyperbole. But the point is to help that poster understand why someone would not question the claim.

"I am the greatest cook in the world" is hyperbole, even if you believe it to be true. Please google the basic definitions of words before you use them.

Re: Kaspersky believes it found new CIA malware

#69
post #56
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

The Broadcom link in the posted tweet records [some of?] their reasoning. Things like very North America specific strings, activity happening M-F for certain things (compilation, etc), capability (access to zero days implying deep pockets to buy said zero days), and breadth of target, etc. That said - it ABSOLUTELY BOGGLES MY MIND that, if these are not leaked, but rather recovered from attempted attacks, how are _an…

> Or replace with preprocessor directives that you could setup to random values for production builds to use strings and timestamps that indicate some other entity?

They do, except they're not random. Check out the CIA Vault 7 leaks from a few years ago. They purposefully leave trails that point to other countries including using foreign languages for variable names/comments.

> “[D]esigned to allow for flexible and easy-to-use obfuscation” as “string obfuscation algorithms (especially those that are unique) are often used to link malware to a specific developer or development shop.”

> The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion, — but there are other possibilities, such as hiding fake error messages.

https://www.mintpressnews.com/wikileaks-reveals-marble-proof...

Re: Kaspersky believes it found new CIA malware

#70
post #42

I always wonder. The CIA/NSA must essentially target the big Amazon, google and microsoft clouds to get blanket access to everything running and stored there. Seems like a no brainer from their standpoint.

Or they just ask, which is essentially how prism already worked for user data.

Didn't some PRISM documents show that Google's internal use of TLS 1.2 was blocking a more widespread collection of data?

I'll see if I can find the slide that articulated the issue.

Post reply on HN