4 ms·
> the malware samples appear to have been compiled seven years ago, in 2014 So it was possible then to analyze the metadata of the files and determine when the
by cyberlab 5y ago
> the malware samples appear to have been compiled seven years ago, in 2014
So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metadata hygiene employed by journalists, whistleblowers etc
- asimpletune 5y agoI think it was based more on when the samples were found
- hugh-avherald 5y agoMaybe it's less suspicious to have benign metadata than no metadata.
- londons_explore 5y agoDon't overestimate government coders skills... Often it's a massive team with people of very varied programming skills. The core exploit might be some super high tech, hand coded in assembly rootkit, but then the remote control stuff might ends up being some badly written powershell script or multi-megabyte dot-net, java or python binary pulling in every library under the sun.
- Godel_unicode 5y agoThere's a fantastic example of this from fall of 2019. China was using an iPhone 0day which was extremely complicated to do internal surveillance, and the C2 for it was happening over http.
- distribot 5y agoWhat is a C2?
- scottyah 5y agoCommand & Control https://en.wikipedia.org/wiki/Command_and_control https://en.wikipedia.org/wiki/Command_and_control
- hello333 5y agocommand and control i think
- GraemeMeyer 5y agoCommand and control
- joe_the_user 5y agoIt seems like this is simply the approach of any coder who's just trying to get X done without worrying about maintaining stuff. Academic code is often "crap" and it's written by smart people but smart people only concerned about getting the algorithm implemented. Which is say to say, no one yet come up with an approach that combines "fast to write, fast to run, and easy to maintain".