Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

91–100 of 314 posts

Re: Kaspersky believes it found new CIA malware

#91

Earlier quoted context omitted.

Or they just ask, which is essentially how prism already worked for user data.

Yeah, I highly doubt there's any targeting there. The big tech Co.s are practically fronts for the US Gov.

> Yeah, I highly doubt there's any targeting there. The big tech Co.s are practically fronts for the US Gov.

https://en.wikipedia.org/wiki/War_Is_a_Racket (1935).

History doesn't repeat but it does rhyme.

It seems to be the natural state that centres of power co-operate with each other lest they lose their power.

Churches with Kings, Corporations with Government.

Re: Kaspersky believes it found new CIA malware

#92
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Seems reasonable to assume that a government saying "it wasn't us" or "it was them" is a heavily politically-motivated statement, not a strictly technical one. Regardless of it being accurate or not - there are reasons to keep quiet even if there's conclusive proof.

This is a case of a third party saying "we think it was probably X". You can't rule out other motivations here either, but there's a fair bit more room for it to be less politically motivated.

Re: Kaspersky believes it found new CIA malware

#93
post #62

Earlier quoted context omitted.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

>If I had to wager I'd always bet on national security agency of any powerful country lying, I don't see how anyone could come to another conclusion given their history. Let's not pretend the FSB and MSS don't also lie constantly. That you're more familiar with the CIA lying is a testament to the free press of the US, not the other way around. The point of the previous post is that it could easily be another security…

Wouldn't the fact that we know more about the CIA mean that they lie less, since there are verifiable claims to the contrary if they do lie? Like for example how the CIA can't claim it didn't infect Iran with Stuxnet without someone calling BS.

Re: Kaspersky believes it found new CIA malware

#94
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

The existence of their insane levels of funding and well known history of coups, lies, dirty tricks, and mass murder makes it extremely easy to believe US intelligence is capable of deploying computer bullshit lol. Of course, if there is credible evidence exhonorating them we can look at that.

Re: Kaspersky believes it found new CIA malware

#95
post #62

Earlier quoted context omitted.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

>If I had to wager I'd always bet on national security agency of any powerful country lying, I don't see how anyone could come to another conclusion given their history. Let's not pretend the FSB and MSS don't also lie constantly. That you're more familiar with the CIA lying is a testament to the free press of the US, not the other way around. The point of the previous post is that it could easily be another security…

> Let's not pretend

Who is pretending? The discussion is about the CIA.

When I discuss cats, there is no reason I should have to always qualify it by saying "yes, and dogs are cute, too."

Re: Kaspersky believes it found new CIA malware

#96

I may have missed it in the article, but as a sysadmin, i’m trying to figure out what I should do. It appears the CIA has created malware. I assume, if they have exploited some hole, others will too. While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?

While I have no information to share on this specific malware, here is the NSA's TAO Chief on what makes their jobs harder:

https://www.youtube.com/watch?v=bDJb8WOJYdA

Re: Kaspersky believes it found new CIA malware

#97
post #3

Aside: Kaspersky is a Russian company.

I find it interesting that this and a few other investigations have been released around times of great geopolitical tensions related to Russia. I think there are legitimate questions as to how/where this activity was observed and what led them to investigate it.

Personally, I don't know how closely they coordinate with Russian intelligence services, but some of the samples they get and the background/context they get can only be obtained if you are very close to the investigation. The way they phrase things like "we found this in a multi-engine scanner" raise the hair on the back of my neck, since I work in malware analysis and you don't just run across these types of samples by chance. They are either doing IR for organizations that were targeted (which you would just mention), or they are getting tipped off on where to look.

Whether or not this is intentional, or just happens to be a coincidence, it is something to be aware of.

Examples of suspicious timing: Flame paper released while there were massive protests in Russia around 2012, Regin/Equation Group/Duqu 2.0 paper released during Ukranian invasion circa 2014/15, and now this paper also released while tensions in Ukraine are ramping up and after the fallout from the SolarWinds stuff.

I think it would be less suspicious if places like Sputnik (a known propaganda arm of Russia) didn't immediately start pushing a specific narrative when Kaspersky has these malware releases.

Re: Kaspersky believes it found new CIA malware

#98

Earlier quoted context omitted.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

Sure, but isn't that true for any intelligence organization? CIA, NSA, FSB, MI5, Mossad, BND, etc?

Sure, I dont focus on them because I don't believe that Mossad or MI5 are the reason why my country has been at war my entire adult life, but I have witnessed the NSA and CIA justify those wars-that-arent-really-wars time and time again. How much blood was spilled over the 'yellow cake' line alone? Remember when they lost that ten thousand page report on torture right before it was to be delivered? Or the time they dosed unwilling people with LSD or when they smuggled cocaine and fueled the crack epidemic, or when they...

Re: Kaspersky believes it found new CIA malware

#99
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

The existence of their insane levels of funding and well known history of coups, lies, dirty tricks, and mass murder makes it extremely easy to believe US intelligence is capable of deploying computer bullshit lol. Of course, if there is credible evidence exhonorating them we can look at that.

There are plenty of other actors capable of "deploying computer bullshit". Why shouldn't one of them be the culprit here?

Re: Kaspersky believes it found new CIA malware

#100

> the malware samples appear to have been compiled seven years ago, in 2014 So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metada…

Don't overestimate government coders skills...

Often it's a massive team with people of very varied programming skills. The core exploit might be some super high tech, hand coded in assembly rootkit, but then the remote control stuff might ends up being some badly written powershell script or multi-megabyte dot-net, java or python binary pulling in every library under the sun.

Post reply on HN