4 ms·
Interesting that the story references this malware's similarities to Project Sauron, and that the two main modules here are named GollumApp and Cahnadr, which l
by jack6e 9y ago
Interesting that the story references this malware's similarities to Project Sauron, and that the two main modules here are named GollumApp and Cahnadr, which looks not entirely dissimilar from how one might play with the Russian version of "Gandalf" if one were to convert the Cyrillic letters into approximate English look-a-likes.
- bhouston 9y agoWould Kaspersky Labs report on Russian malware?
- jack6e 9y agoThe meta-game at this point is open to just about any type of psychological trick. We know/suspect Kaspersky helping FSB/GRU, but we also know that CIA/NSA store and use fingerprints from other nation states and can assume Russia does the same. So if something looks Russian but Kaspersky reports on it, does that mean it is NSA trying to false flag Russia? Or is it Kaspersky deflecting Russian suspicions and pointing to the US by bringing it to light...6 years later? The abilities and willingness of certain nation states to wage cyber warfare and make it appear like someone else are so great at this point, that only solid forensic evidence, and usually not even that, can be indicative.
- Dolores12 9y ago>So if something looks Russian but Kaspersky reports on it, does that mean it is NSA trying to false flag Russia? It could be Russian, it could be not. What is really important that only the Kaspersky reported it.
- __jal 9y agoThe way to understand this sort of thing is to try to think like someone in their shoes. First, you're innocent. What would you do over time to try to survive the accusations and suspicion? Next, you're implicated in past bad acts. Maybe you were forced to stick malicious code in a past version, or maybe you had a rogue employee. What would you do to try to move on? Finally, you're an active part of the state intelligence apparatus. What would you do to try to appear like one of the other hypotheticals? There are other possibilities; people get themselves in all sorts of weird situations, but most of them are some shade of the above.
- Jerry2 9y agoThey have and they do. https://securelist.com/masha-and-these-bears/84311/ https://securelist.com/masha-and-these-bears/84311/
- fulafel 9y agoIf you are an av company you can't just whitelist every other piece of malware.
- drb91 9y agoThere's a rich history of Russian appreciation of Lord of the Rings, see e.g. https://en.wikipedia.org/wiki/The_Last_Ringbearer https://en.wikipedia.org/wiki/The_Last_Ringbearer.
- zaarn 9y agoThat is quite an interesting premise for a book. Probably in the same spirit as the subreddit /r/EmpireDidNothingWrong (or how they call it) which claims Star Wars is also a series of movies written by the victors (with a heavy dosage of memes)
- bowmessage 9y agowhich is exactly the kind of string symbol the US might use :)
- qaq 9y agoCahnadr Гандальф how is it similar :)?
- mintplant 9y agoI can see the visual similarity. Г=C, а=a, н=H, д=n...
- NelsonMinar 9y agoOTOH the article says explicitly "Text clues in the code suggest it is English-speaking.", so I'm gonna go with non-Russian as a first guess. They also note "accurate attribution is always hard, if not impossible to determine, and increasingly prone to manipulation and error".