Live data from Hacker News

Kaspersky Lab Discovers 'Gauss'

kaspersky.com

1–10 of 25 posts

Re: Kaspersky Lab Discovers 'Gauss'

#4
From the article: "... the installation of a special font called Palida Narrow, and the purpose of this action is still unknown."

Would this perhaps be a tracking ability, as described at https://panopticlick.eff.org (specifically, the list of "System Fonts")

It would require the users to visit a site that is collecting this tracking information, but it isn't impossible to imagine a popular site among the target audience being strong-armed by a nation-state into installing something to do this.

The tracking is practically invisible to end users.

Re: Kaspersky Lab Discovers 'Gauss'

#5
post #4

From the article: "... the installation of a special font called Palida Narrow, and the purpose of this action is still unknown." Would this perhaps be a tracking ability, as described at https://panopticlick.eff.org (specifically, the list of "System Fonts") It would require the users to visit a site that is collecting this tracking information, but it isn't impossible to imagine a popular site among the target audi…

Just read the same thing [1] - that does seem to be a logical use for a 'custom' font

[1] http://blog.crysys.hu/2012/08/on-the-palida-narrow-mystery-o...

Re: Kaspersky Lab Discovers 'Gauss'

#6

"Another key feature of Gauss is the ability to infect USB thumb drives, using the same LNK vulnerability that was previously used in Stuxnet and Flame." Do we have to repeat the same debate about this one's origin?

That .lnk vulnerability is now in metasploit; I don't think we can safely say that Gauss is from the same org from this one piece of evidence.

Re: Kaspersky Lab Discovers 'Gauss'

#8
post #4

From the article: "... the installation of a special font called Palida Narrow, and the purpose of this action is still unknown." Would this perhaps be a tracking ability, as described at https://panopticlick.eff.org (specifically, the list of "System Fonts") It would require the users to visit a site that is collecting this tracking information, but it isn't impossible to imagine a popular site among the target audi…

My first guess was that system font renderers are probably less hardened against exploits, and that the font is exactly that. The name sounds generic enough to look like it fits in with the rest.

Re: Kaspersky Lab Discovers 'Gauss'

#9

"Another key feature of Gauss is the ability to infect USB thumb drives, using the same LNK vulnerability that was previously used in Stuxnet and Flame." Do we have to repeat the same debate about this one's origin?

That .lnk vulnerability is now in metasploit; I don't think we can safely say that Gauss is from the same org from this one piece of evidence.

The viruses (this and skywiper) appear to be both targeting the middle east... Maybe they're all just chumps and easy targets out there, but it also makes sense that they have the same people behind them.

Re: Kaspersky Lab Discovers 'Gauss'

#10
What now.. a heavily cybermilitarized nationstate so broke it needs to skim its own citizens' bank accounts? Advanced Persistent Phish?

Trying to remember the last time I didn't read about some ultra-dooper-al-quaeda-cyber-virus. Seems any kid with a C compiler these days pumping out cutpasted code qualifies as a complex threat.

Coming up: 50 page white paper on the seemingly "innocuous" font (translation: obviously some previously unknown 0day secret intelligence 007 cyber warhead) and its implications for national security funding.

Post reply on HN