3 ms·
> Kaspersky has [...] actively pursued state actors that are hostile to Russian interest, for example The Equation Group (https://en.wikipedia.org/wiki/Equation
by Tech-Noir 9y ago
> Kaspersky has [...] actively pursued state actors that are hostile to Russian interest, for example The Equation Group (https://en.wikipedia.org/wiki/Equation_Group https://en.wikipedia.org/wiki/Equation_Group), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company.
According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking". Targeting hacking tools seems to me exactly what a security software company should be doing.
>Such an "innocent" company would have no reason to get involved in cyberwarfare between state-actors, while Kaspersky is heavily involved in such activities and pouring considerable resources into them.
Even if we assume these tools can only target governments and not businesses or individuals, perhaps Kaspersky wishes to obtain contracts with the governments targeted. I don't see how this is particularly sinister or illegitimate.
> This is especially damning since they are clearly targeting state-actors that are antagonistic to Russian interest, such as the US (Equation Group) and its allies (Israel)
Your Wikipedia link states: "The Shadow Brokers announced that it had stolen malware code from the Equation Group [...] Exploits against Cisco Adaptive Security Appliances and Fortinet's firewalls were featured in some malware samples released by The Shadow Brokers [...] Juniper also confirmed that its NetScreen firewalls were affected. The EternalBlue exploit was used to conduct the damaging worldwide WannaCry ransomware attack."
Three American companies and vast numbers of individual users and civil government institutions around the world (including the UK Health Service). Are they all Russian interests?
- dunpeal 9y ago> According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking" Are we reading the same Wikipedia page? Here's what mine says: > The Equation Group, classified as an advanced persistent threat, is a highly sophisticated threat actor suspected of being tied to the United States National Security Agency (NSA). Kaspersky Labs describes them as one of the most sophisticated cyber attack groups in the world and "the most advanced ... we have seen", operating alongside but always from a position of superiority with the creators of Stuxnet and Flame. Most of their targets have been in Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali. Kaspersky is preoccupied with this group, that by their own description, targets state actors that are hostile to the US. They've obsessively documented 500 of their alleged attacks worldwide, which would be negligible blip on the radar for any normal, purely commercial cyber-security company. Doesn't it strike you as odd? > Even if we assume these tools can only target governments and not businesses or individuals, perhaps Kaspersky wishes to obtain contracts with the governments targeted. I'm going to take a wild guess that none of the targets of the Equation Group like Afghanistan or Syria will trust Kaspersky enough to hire them for a sensitive project. These countries are very busy with ground wars and have no attention or money to spend on cyber security. The only government that may and probably does employ Kaspersky is the Russian one. Which of itself hints at heavy collusion between these two.
- nl 9y agoKaspersky is preoccupied with this group, that by their own description, targets state actors that are hostile to the US. They've obsessively documented 500 of their alleged attacks worldwide, which would be negligible blip on the radar for any normal, purely commercial cyber-security company. You keep saying this, and it is completely wrong which detracts from your point (which is right!). All commercial cyber-security companies collect and report on hacking groups. Here's the Mandiant/FireEye report on APT-1: https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf https://www.fireeye.com/content/dam/fireeye-www/services/pdf... and here is the APT_28 one: https://www2.fireeye.com/apt28.html https://www2.fireeye.com/apt28.html Here's the report by a group of companies on the Chinese Axiom group: http://www.novetta.com/wp-content/uploads/2014/11/Executive_Summary-Final_1.pdf http://www.novetta.com/wp-content/uploads/2014/11/Executive_... And finally, here's the FireEye one I linked to previously talking about the Equation Group: https://www.fireeye.com/content/dam/fireeye-www/company/events/infosec/threat-landscape-overview-fireeye-summit-paris.pdf https://www.fireeye.com/content/dam/fireeye-www/company/even... The only government that may and probably does employ Kaspersky is the Russian one. That's not true either as a quick Google shows, eg: https://www.crn.com.au/news/kaspersky-to-protect-prime-minister-cabinet-405256 https://www.crn.com.au/news/kaspersky-to-protect-prime-minis...
- seabird 9y ago>Doesn't it strike you as odd? No, not in the slightest. Of course a security company tracks security threats, especially when those security threats utilize multiple zero day vulnerabilities that could end up in the wild after they are finished with them. Use your head, man. I get it, "better dead than Red" and all, but let's not lose our shit purely because of the speculation of an "anonymous source close to the case."