4 ms·
>Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validat
by Jerry2 3y ago
>Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validators, an implant and its modules.
Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] was behind this but my money's on the NSA.
[1] https://eugene.kaspersky.com/2011/11/02/the-man-who-found-stuxnet-sergey-ulasen-in-the-spotlight/ https://eugene.kaspersky.com/2011/11/02/the-man-who-found-st...
[2] https://www.washingtonpost.com/world/national-security/israel-hacked-kaspersky-then-tipped-the-nsa-that-its-tools-had-been-breached/2017/10/10/d48ce774-aa95-11e7-850e-2bdd1236be5d_story.html https://www.washingtonpost.com/world/national-security/israe...
- luch 3y agono way in hell the NSA forcibly tries to reinfect targets over and over, that's not their modus operandi. Instead they would have spend money to find a persistence on the infected device. The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.
- cvalka 3y agoThis is not the first time the NSA infiltrated Kaspersky. Avoiding persistence was one of the desired requirements of the attack.
- saagarjha 3y agoPersistence on iOS is really, really hard.
- luch 3y agoI agree with you on that, but the USA (and probably China) is the nation state least likely to skimp on iOS persistence when targeting Russian AV analysts :D
- saagarjha 3y agoI can only guess at motivations but I would think that when targeting security researchers you’d aim to not have persistence since that would make require leaving evidence of infection on the device.
- munchinator 3y agoIt wasn't clear to me from reading the blogpost that persistence _wasn't_ achieved?
- saagarjha 3y agoThey mentioned that the suspicious traffic stopped after a restart.
- munchinator 3y agoI'm not seeing that mentioned in this blogpost, was it mentioned in one of the other ones?
- qup 3y agohttps://securelist.com/operation-triangulation/109842/ https://securelist.com/operation-triangulation/109842/ They talk about it here, under "what we know so far"
- teachrdan 3y agoFTA: "Once the device rebooted, all the suspicious activity stopped."
- mcphage 3y ago> but my money's on the NSA Why is your money on the NSA?
- gunsec 3y agobecause it is the only boogeyman he knows how to blame with no evidence