Earlier quoted context omitted.
The Broadcom link in the posted tweet records [some of?] their reasoning. Things like very North America specific strings, activity happening M-F for certain things (compilation, etc), capability (access to zero days implying deep pockets to buy said zero days), and breadth of target, etc. That said - it ABSOLUTELY BOGGLES MY MIND that, if these are not leaked, but rather recovered from attempted attacks, how are _an…
> Or replace with preprocessor directives that you could setup to random values for production builds to use strings and timestamps that indicate some other entity? They do, except they're not random. Check out the CIA Vault 7 leaks from a few years ago. They purposefully leave trails that point to other countries including using foreign languages for variable names/comments. > “[D]esigned to allow for flexible and e…
And Broadcom _does_ note that they associate with Vault7 group via the whole picture, but it's weird they present the strings and dates data without noting that it would be trivial to fake, and don't give any specificity to the other data points.
I guess for this type of work the only thing you _really_ have is the code's intent, if you can figure that out.