5 ms·
It certainly feels like a nation state's work, or, at the very least, an "advanced persistent threat" group. The packet capture pre-filter aspect, at very least
by notakio 4y ago
It certainly feels like a nation state's work, or, at the very least, an "advanced persistent threat" group. The packet capture pre-filter aspect, at very least, is strongly reminiscent of code I've seen from a couple of particular SE Asian APT-designated groups.
- prvit 4y agoWhat reason do you have to believe that besides the targets? Feature-wise this isn't significantly more advanced than public LD_PRELOAD kits like Umbreon, developed by literal children. A basic BPF filter isn't fancy or difficult to implement.
- notakio 4y agoPrimarily, similarity to forensics samples I've seen via incident response. But you're right; the individual aspects of this aren't particularly outstanding or complex, it's the lack of uncrossed T's and undotted I's, overall, that makes me lean toward the conclusion I'm making. Kids tend to be sloppier than criminal malware organizations, as criminal malware organizations tend to be sloppier than APT groups.