36 ms·
Duqu 2.0 Hits Kaspersky Lab
- eli 11y ago"By targeting Kaspersky Lab, the Duqu attackers probably took a huge bet hoping they’d remain undiscovered; and lost." That seems like a very nice spin on a successful attack that was eventually detected. How long were the attackers able to spy on their internal systems? Perhaps they didn't need ongoing access and simply wished to steal client files or documents.
- AnonymousPlanet 11y agoThat was my first thought aswell. One of the main takeaways from this is that Kaspersky Labs was probably compromised. Or at least there was an attempt. And the attacker is related to Stuxnet in some way. At least according to Kaspersky Lab.
- r721 11y ago>Kaspersky Labs was probably compromised Relevant quote: "Company officials were unable to provide Ars with an estimate of how many megabytes or gigabytes of data were extracted from their network, in part because the custom network connections Duqu used may have bypassed normal logging procedures. The company hasn't ruled out the possibility the attackers obtained Kaspersky Lab source code, but there are no signs they tried to compromise any of Kaspersky's 400 million users." from http://arstechnica.com/security/2015/06/stepson-of-stuxnet-stalked-kaspersky-for-months-tapped-iran-nuke-talks/ http://arstechnica.com/security/2015/06/stepson-of-stuxnet-s...
- gesman 11y ago"... or perhaps they don’t care much if they are discovered and exposed" -- Kaspersky Labs
- imglorp 11y agoThat's probably a big indication the attackers were making a withdrawal. If they were depositing something into production AV products, they would take super extra care to not be detected.
- r721 11y agoRelated report from Symantec: http://www.symantec.com/connect/blogs/duqu-20-reemergence-aggressive-cyberespionage-threat http://www.symantec.com/connect/blogs/duqu-20-reemergence-ag... Eugene Kaspersky: "Why Hacking Us Was A Silly Thing To Do" http://www.forbes.com/sites/eugenekaspersky/2015/06/10/why-hacking-us-was-a-silly-thing-to-do/ http://www.forbes.com/sites/eugenekaspersky/2015/06/10/why-h...
- CWuestefeld 11y agoFrom the Kaspersky link: I can think of several reasons why someone might want to try to steal our technical data, but each one of them doesn’t seem to be worth the risk. I don't get it: what's the risk here? As far as I can see, the only risk is that their malware is removed from the victim machines. The risk of blowback to the perpetrators is vanishingly small as far as I can see.
- pja 11y agoAt the very least, you use up the particular 0-day attacks you used to gain access to the system - since they had to keep re-using them in order to re-infect machines over reboots there was a pretty high chance that once detected, Kaspersky would discover the exploits being used. Apart from entities like the NSA themselves you probably couldn’t choose a more security aware target. Any large nation state probably has a nice cache of 0-days ready to roll out at any given time, but they’re still a limited resource that could be used to attack other targets. Attacking Kaspersky pretty much guarantees that the 0-days are blown once the infiltration is discovered.
- r721 11y agoWell, the malware used some quite innovative techniques, for example, consider this quote from Ars Technica article: >Kaspersky researchers have described it as a "0-day trampoline" because it allowed their malicious modules to jump directly into the Windows kernel, the inner part of the operating system that has unfettered access to system memory and all external devices. The trampoline exploit allowed the malware to bypass digital signature requirements designed to prevent the loading of malicious code into the OS kernel space. >"What is really impressive here—what I call really amazing—is the entire malware platform depends on this zero-day to work," Raiu said. "So if there is no zero day to jump into kernel mode this doesn't work." Now this will be patched, and they will need something completely different for the next framework.
- dbhattar 11y agoI cannot but wonder what would have been the response here if similar attack had occurred inside Google or Facebook.
- shthed 11y agoThey might have been attacked too, just not disclosed or even discovered it yet.
- shthed 11y agoThe Windows 0-day is CVE-2015-2360 from MS15-061, it appears to be the only one Microsoft admits to have been exploited or used to attack it's customers. https://technet.microsoft.com/library/security/ms15-061 https://technet.microsoft.com/library/security/ms15-061
- joecasson 11y agoEven if it's the only one they've admitted to, I think it's readily known that Microsoft has numerous zero-days (discovered or not) in their software. Combine that with their prevalence in Enterprise businesses, they're going to be a logical starting point for any top tier blackhat org.
- ryanlol 11y agoEvery OS that people actually use has boatloads of unpatched security issues.
- yunong 11y ago"I think it's readily known that Microsoft has numerous zero-days (discovered or not) in their software." This is true for every single piece of software ever written. Msft is no different in this regard.
- ryanlol 11y agoI don't think it's fair to say "every single piece of software", as the claim that it's impossible to write secure software is just a myth. It's not very hard to write a secure "hello world". Then there's also Coq and such. Of course, usually the amount of vulnerabilities exponentially correlates to the size of the codebase.
- concernedctzn 11y agoImpressive to see most of the infections lived solely in memory. Along with the zerodays burned for this attack, you can tell this is a very professional team.
- sarciszewski 11y agoSo, correct me if I'm wrong: A non-technical user on their network DIDN'T have EMET running? Or did they, perhaps, have an EMET bypass in their shellcode? If it's the latter, that's what I would be more interested in.
- rjaco31 11y agoWhat makes you think that EMET can't be bypassed?
- bhouston 11y agoThis appears to be Israel from the technical report both because of the targets (Iran) and also the timezone data.
- btilly 11y agoThe geopolitics of this one is fascinating. Stuxnet was a combined Israeli/US attack on Iran's nuclear capability. Kaspersky is a Russian security company which was started with government support, and is believed to still have connections there. Russia and Iran are allies. Now look at how it played out. The US and Israel attacked Iran. Kaspersky tracked it down and publicized it to the world. And now some combination of the US, Israel, or close allies launched a spying attack on Kaspersky. Which, for all we know, may actually be an important part of the Russian cybersecurity infrastructure. For all that organizations like the NSA do wrong (like spying on all of us), this is the kind of thing that we actually wanted them doing when they were created.
- avodonosov 11y agoWith your fantasy you can work in tabloids like Wired. Russia and Iran are allies? US is going to use Iran against Russia to sell Iranian gas and oil to Europe and subdue Russian influence - that's why US decided to fix relations with Iran and come to a deal allowing to finish the sanctions. It's more like competitors than allies.
- btilly 11y agoIn recent history, Russia and Iran have indeed been allies. See http://en.wikipedia.org/wiki/Iran%E2%80%93Russia_relations http://en.wikipedia.org/wiki/Iran%E2%80%93Russia_relations for verification. And the US has repeatedly found itself on the opposite end of geopolitical conflicts with both countries. For a random example, both Iran and Russia have been supportive of Assad's government in Syria, while the US is opposed. Of course interests shift over time. We are indeed doing things to improve relations with Iran. But that doesn't change the fact that in recent history we've been calling them part of "the axis of evil" and they have been calling us "the great Satan".
- avodonosov 11y agoI've heard that Iran calls US "great Satan", and Russia "small Satan"
- shthed 11y agoWill be interesting to see who else was targeted by this, looks like Kaspersky is just the first to disclose it: http://www.kaspersky.com/about/news/virus/2015/Duqu-is-back http://www.kaspersky.com/about/news/virus/2015/Duqu-is-back "Kaspersky Lab would like to reiterate that these are only preliminary results of the investigation. There is no doubt that this attack had a much wider geographical reach and many more targets. But judging from what the company already knows, Duqu 2.0 has been used to attack a complex range of targets at the highest levels with similarly varied geo-political interests."
- omgitstom 11y agoTechnical details were released yesterday: https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns.pdf https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
- deleted 11y ago[deleted]
- at-fates-hands 11y ago"Despite the beefed up operational security of the malware, its unmistakable connection to the Duqu 1.0 and the times of day Duqu attackers manually entered Kaspersky's network leave little doubt in the minds of company researchers that the 2011 and 2014 attacks were carried out by the same group." Not only is this a total stretch, it's complete hearsay. The reasons for hackers to go after Kaspersky are just as numerous as state sponsored teams to. I find it hard to say it was definitively one or other without further evidence. But in this "government surveillance" panic people are currently in, it's easy to just point a finger and say it was the NSA because this version "looks similar" to another version already deployed. It's about as solid as saying there were similarities between the type of malware used in the Sony Pictures attack and code used to attack South Korea last year - which was laughed off by most of the info sec community.
- igravious 11y agoIncorrect. https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns.pdf https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
- mirimir 11y agoYes, once malware has been found, it can be reverse-engineered and reused. Also, I recall reading that the NSA relied in part on independent consultants in developing Stuxnet etc. Maybe some of those consultants have other pseudonyms, and other clients. So we have malware proliferation. And it's far worse than, for example, nuclear proliferation. Because it's all just bits.
- rjaco31 11y agoDid you actually read the report? There are similarities that are way more consistent than just "looking similar". I tend to agree that attribution is usually a hard guess, but in this case, it's pretty hard to argue against them. Keep in mind that most of those similarities are totally not on the exploit parts, but on the very little quirks on how to handle the 'trivial' things that are extremely specific to your coder. (Also keep in mind that developing such a framework takes tons of time & money, we're talking about years & millions).
- nerdy 11y agoThe Duqu attackers have got a ridiculous bag of zero-days at the ready.
- nerdy 11y agoDownvote with no explanation. Someone disagrees that these guys use zero-days? Not to mention some of which include jumping to kernel mode? 2011: CVE-2011-3402 2014: CVE-2014-4148 CVE-2014-6324 CVE-2015-2360
- stirlo 11y agoYour comment adds nothing of value to the conversation and provides no sourcing. This is why you have been downvoted.
- dmgbrn 11y agoIt's kind of cute how the technical report[1] goes to great lengths to finger Israel, without explicitly stating it (see page 43). [1] https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns.pdf https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
- mc32 11y agoI wouldn't be surprised. KL tend to nettle (expose activity of) most western spy agencies while bypassing Russian and to a lesser extent Chinese hacking activities.
- brosefstalin 11y agoSigh. I'll go get my tinfoil hat.
- alirazaq 11y agoWhile I do think it was silly of them to mention the 70th anniversary of Auschwitz's liberation, there were not many who openly opposed the Iran nuclear deal as strongly as Netanyahu's government. His speech to congress was unprecedented and a sign he was possibly being kept out of the loop in the negotiation deals. I wouldn't blame Obama, Bebe's emotions (or delusions) seem to get in the way of any attempts at peace talks.
- mirimir 11y agoOutsiders have no clue about Israel's role in the Equation Group. Or who the Equation Group actually serves, for that matter.
- mike_hearn 11y agoEquation Group was very clearly the NSA, given that actual NSA codenames appeared in the binaries.
- mirimir 11y ago