Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

81–90 of 314 posts

Re: Kaspersky believes it found new CIA malware

#81
post #69
post #56

Earlier quoted context omitted.

The Broadcom link in the posted tweet records [some of?] their reasoning. Things like very North America specific strings, activity happening M-F for certain things (compilation, etc), capability (access to zero days implying deep pockets to buy said zero days), and breadth of target, etc. That said - it ABSOLUTELY BOGGLES MY MIND that, if these are not leaked, but rather recovered from attempted attacks, how are _an…

> Or replace with preprocessor directives that you could setup to random values for production builds to use strings and timestamps that indicate some other entity? They do, except they're not random. Check out the CIA Vault 7 leaks from a few years ago. They purposefully leave trails that point to other countries including using foreign languages for variable names/comments. > “[D]esigned to allow for flexible and e…

Ah OK good, thanks for the link. Right, this seems like something _I_ could probably handle with a weekend or two's worth of research (meaning it's pretty simple because I'm no hacker).

And Broadcom _does_ note that they associate with Vault7 group via the whole picture, but it's weird they present the strings and dates data without noting that it would be trivial to fake, and don't give any specificity to the other data points.

I guess for this type of work the only thing you _really_ have is the code's intent, if you can figure that out.

Re: Kaspersky believes it found new CIA malware

#82

I may have missed it in the article, but as a sysadmin, i’m trying to figure out what I should do. It appears the CIA has created malware. I assume, if they have exploited some hole, others will too. While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?

Almost all government created malware uses 0days that they've kept back or held back from public disclosure, so there's nothing really you can do (aside from waiting for disclosure). That's the point of a CIA hack isn't it? If there's something you can do, then they've failed at their job, and it's time for hiring the next batch of developers (yes these are developers with a paid day job - to make malware for the CIA…

The only thing you can truly do is look for anomalies in network traffic, processes, files, etc. This malware is not immune to that unless it has features specifically to hide from monitoring tools.

Even then there will almost always be evidence if you log network traffic. But obviously this is very difficult.

Re: Kaspersky believes it found new CIA malware

#83
post #33

Earlier quoted context omitted.

> without evidence of cooperating with the FSB That isn't true. This "without evidence" shit is rather silly when it comes to top-secret sources and methods. Blow decades of work and risk getting people killed to Prove that an ex-KGB officer helps an authoritative regime thats known to poison its enemies. People said the same shit about Huawei, then all the KPN shit. Link: https://www.bloomberg.com/news/articles/2017…

The problem with that is that those agencies also lie all the time. You can't have your cake and eat it too with a just trust us attitude and also make stuff up when it's convenient.

"We'll know our disinformation program is complete when everything the American public believes is false." - William J. Casey, former CIA Director

That said, I think the safest default assumption is both that any large national intelligence agency lies all the time, and also that any entity that a national intelligence agency has the means and motive to compromise is probably compromised. So Kaspersky is probably an FSB asset (but so too is Amazon a CIA/NSA asset) but the CIA is probably lying 99% of the time too.

Re: Kaspersky believes it found new CIA malware

#84
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

Sure, but isn't that true for any intelligence organization? CIA, NSA, FSB, MI5, Mossad, BND, etc?

Re: Kaspersky believes it found new CIA malware

#85
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

>But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting. This thread also isn't full of calls for sanctions against the US or talk of overthrowing the government. I don't actually doubt many of the reports claiming North Korea or whoever were behind some attack, I know they are likely engaging in such activities. I just…

Yea, I cautiously share this viewpoint. I don’t want a cyber "Remember the Maine! To hell with Spain!" event.

https://en.m.wikipedia.org/wiki/USS_Maine_(1889)

Re: Kaspersky believes it found new CIA malware

#86

> the malware samples appear to have been compiled seven years ago, in 2014 So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metada…

Maybe it's less suspicious to have benign metadata than no metadata.

Yeah, which is why I suggest faking metadata than simply stripping it. There are anti-forensic tools for doing that.

Re: Kaspersky believes it found new CIA malware

#87
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Yeah, and CNN saying Chinese or Russian hackers always

Even if you think CNN is bad it still might be true.

Re: Kaspersky believes it found new CIA malware

#88
post #36

Earlier quoted context omitted.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

I've come to a conclusion that, from the evolutionary standpoint, lying (and stealing) is one of the most important forms of the intelligent behavior. We see it in the animal world, so this unavoidably should be seen as such in the world of humans...

Trying to take the optimal route in prisoners dilemma would make smart animals stop this behaviour

Re: Kaspersky believes it found new CIA malware

#89
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Likewise, Kaspersky always seems to ferret out CIA activities quite frequently; but never seems to get the same kind of discoveries on his own countries hacking exploits and activities.

Re: Kaspersky believes it found new CIA malware

#90
post #33

Earlier quoted context omitted.

Or: "they're a company that has been accused without evidence of cooperating with the FSB in attacks against the US government by US entities aligned to the US-based actors that they have exposed". FTFY.

> without evidence of cooperating with the FSB That isn't true. This "without evidence" shit is rather silly when it comes to top-secret sources and methods. Blow decades of work and risk getting people killed to Prove that an ex-KGB officer helps an authoritative regime thats known to poison its enemies. People said the same shit about Huawei, then all the KPN shit. Link: https://www.bloomberg.com/news/articles/2017…

> This "without evidence" shit is rather silly when it comes to top-secret sources and methods.

"We lie, we cheat, we steal". Literally from the mouth of the guy who ran it to your ears.

I'm not sure how you find these source legitimate sans evidence, other than possibly they are you team.

PS. Doesn't make the other jerks legitimate either.

Post reply on HN