Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
United States Security

Security Firm Kaspersky Believes It Found New CIA Malware (therecord.media) 17

Cybersecurity firm Kaspersky said today it discovered new malware that appears to have been developed by the US Central Intelligence Agency. From a report: Kaspersky said it discovered the malware in "a collection of malware samples" that its analysts and other security firms received in February 2019. While an initial analysis did not find any shared code with any previously-known malware samples, Kaspersky has recently re-analyzed the files and said it found that "the samples have intersections of coding patterns, style and techniques that have been seen in various Lambert families." Lamberts is the internal codename that Kaspersky uses to track CIA hacking operations. Four years ago, after WikiLeaks exposed the CIA hacking capabilities to the public in a series of leaks known as Vault7, US security firm Symantec publicly linked the Vault7 hacking tools to the CIA and the Longhorn APT (another industry name for Lamberts).
This discussion has been archived. No new comments can be posted.

Security Firm Kaspersky Believes It Found New CIA Malware

Comments Filter:
  • lol (Score:5, Interesting)

    by hjf ( 703092 ) on Wednesday April 28, 2021 @01:19PM (#61324790) Homepage

    Russian security firm say a US agency is responsible for hacks.

    Let this one pass boys, we have a US security firm blaming Russia and China for hacks every day.

    The cold war never ended. Don't feed the spooks.

    • by raymorris ( 2726007 ) on Wednesday April 28, 2021 @01:33PM (#61324826) Journal

      US government agencies certainly do surveillance, so that wouldn't be surprising at all.

      The only thing that I, as someone in that field, find mildy surprisingly would be if Kaspersky has enough samples of different CIA tools that they are able to have significant confidence in cross-referencing. Just because the US uses a different approach than China or Russia.

      The US NSA taps providers, so the large-scale collection doesn't use "hacking tools" like Kaspersky is talking about. Whole Russia and China spread malware broadly both for industrial espionage and to be a PITA to rival countries, the US is much more targeted in their operations. Generally, the US wants to get information from the highest levels of the Chinese government; they aren't looking to just increase the infosec costs of random Chinese food company. They don't tend to use the broadcast strategy that puts their tools out there for everyone to see.

    • That's why you any cybersecurity professional needs to be informed.

      Thanks to Wikileaks and whistleblowers and forensic journalism we know about the tools, and the very stupid policies, that foster this kind of activity by the CIA/NSA.

      We also know that by and large, claims coming from the US administration and US based Media are questionable at best.

      When New Knowledge hired an internet PR firm based in Russia to run ads, then used those ads as proof Russia was trying to interfere with elections which both th

    • by Z00L00K ( 682162 )

      If the CIA does it so do GRU and about 25 other intelligence agencies too.

    • Re: lol (Score:5, Interesting)

      by reanjr ( 588767 ) on Wednesday April 28, 2021 @02:05PM (#61324960) Homepage

      If you are worried about security, you should definitely be paying attention to Kaspersky. Just like Russians worried about security should be checking in with ESET or others from time to time. The reality is all these firms have huge blindspots for their local government, including American ones.

      • by Anonymous Coward

        That's only true so far is what Kaspersky says is true, otherwise you could be wasting your time looking for something that isn't there, meanwhile a real threat from Russia that Kaspersky keeps quiet about sneaks right on by.

        Chasing ghosts isn't harmless, it creates negative value, it wastes your time and can cause you to miss real threats. Misdirection is a key trait of Russia's modern asymmetrical warfare arsenal. They're more than willing to create easy to catch malware, attribute it to the CIA to get fo

      • You should be paying attention to Kaspersky, China anti virus / infosec guys, and some from the "western world" if you plan to get a fuller picture of whats actually going on.

        Trusting any one of them only, when each of them probably have their own known / unknown blind spots makes you blind to certain things as well.

    • Re:lol (Score:5, Interesting)

      by detritus. ( 46421 ) on Wednesday April 28, 2021 @02:22PM (#61325040)

      That russian security firm's heuristic scanning identified a shit-ton of US government zero-days an ex-government employee exfiltrated onto a box running Kaspersky and it automatically uploaded it to them.

      I trust their analysis a hell of a lot more than any US firm, who probably has secret whitelisting deals.

    • by khchung ( 462899 )

      Russian security firm say a US agency is responsible for hacks.

      Because only Russian firms dare to expose US spying, as they are relatively safe from US retaliation.

      Next excuse.

  • by oldgraybeard ( 2939809 ) on Wednesday April 28, 2021 @01:34PM (#61324830)
    So they are only 2 years behind the bad guys ;)
    • ... often, we ARE one of the bad guys!

      • We are all the heroes of our own stories.

        We're always the "good guys" unless we want to think of ourselves as "bad guys".

        But every good guy is likely a bad guy from someone else's point of view.

  • So ... (Score:5, Funny)

    by fahrbot-bot ( 874524 ) on Wednesday April 28, 2021 @02:21PM (#61325032)

    ... it found that "the samples have intersections of coding patterns, style and techniques ...

    The CIA copies and pastes some of their code from Stack Overflow [slashdot.org] too. :-)

Ocean: A body of water occupying about two-thirds of a world made for man -- who has no gills. -- Ambrose Bierce

Working...