5 ms·
Kaspersky Lab Discovers 'Gauss'
- picklefish 14y agoThis was a better read for me: https://www.securelist.com/en/blog?weblogid=208193767 https://www.securelist.com/en/blog?weblogid=208193767 saw it on slashdot
- apawloski 14y ago"Another key feature of Gauss is the ability to infect USB thumb drives, using the same LNK vulnerability that was previously used in Stuxnet and Flame." Do we have to repeat the same debate about this one's origin?
- spec_laconic 14y agoThat .lnk vulnerability is now in metasploit; I don't think we can safely say that Gauss is from the same org from this one piece of evidence.
- duaneb 14y agoThe viruses (this and skywiper) appear to be both targeting the middle east... Maybe they're all just chumps and easy targets out there, but it also makes sense that they have the same people behind them.
- duaneb 14y agoProbably just a continuation of the same virus that's been going around for years at this point: http://www.crysys.hu/skywiper/skywiper.pdf http://www.crysys.hu/skywiper/skywiper.pdf Kaspersky tends to exaggerate how novel these viruses are.
- sounds 14y agoFrom the article: "... the installation of a special font called Palida Narrow, and the purpose of this action is still unknown." Would this perhaps be a tracking ability, as described at https://panopticlick.eff.org https://panopticlick.eff.org (specifically, the list of "System Fonts") It would require the users to visit a site that is collecting this tracking information, but it isn't impossible to imagine a popular site among the target audience being strong-armed by a nation-state into installing something to do this. The tracking is practically invisible to end users.
- malenm 14y agoJust read the same thing [1] - that does seem to be a logical use for a 'custom' font [1] http://blog.crysys.hu/2012/08/on-the-palida-narrow-mystery-of-gauss-malware-and-possible-remote-detection/ http://blog.crysys.hu/2012/08/on-the-palida-narrow-mystery-o...
- lallysingh 14y agoMy first guess was that system font renderers are probably less hardened against exploits, and that the font is exactly that. The name sounds generic enough to look like it fits in with the rest.
- TazeTSchnitzel 14y agoAlso, you could make it the default font for documents, meaning you could trace their origins, perhaps.
- delinka 14y agoYour EFF link says Chrome on iOS is 1 in ~93,000 while a Chrome incognito tab is 1 in ~89,000. Incognito is less unique and more identifiable that a regular tab. Interesting results.
- icegreentea 14y agoWhat? If you are less unique, then you are also less identifiable.
- delinka 14y agoI certainly got my adjectives mixed up. I usually proofread better than that. Oops. s/less/more/
- bdittmer 14y agoThat is incredibly clever.
- forgotusername 14y agoWhat now.. a heavily cybermilitarized nationstate so broke it needs to skim its own citizens' bank accounts? Advanced Persistent Phish? Trying to remember the last time I didn't read about some ultra-dooper-al-quaeda-cyber-virus. Seems any kid with a C compiler these days pumping out cutpasted code qualifies as a complex threat. Coming up: 50 page white paper on the seemingly "innocuous" font (translation: obviously some previously unknown 0day secret intelligence 007 cyber warhead) and its implications for national security funding.
- ktizo 14y agoWhat now.. a heavily cybermilitarized nationstate so broke it needs to skim its own citizens' bank accounts? Well, at least we have a shortlist then. UK, Iceland, Greece, Spain... Advanced Persistent Phish? - Is that some kind of really annoying halibut, armed with lasers?
- Torgo 14y agoThis virus could be used to track the flow of money in terror networks. It could also be used offensively to surprise-defund them, or to grab off-the-books cash for your own nation's agents in the field.
- forgotusername 14y agoApplying Occam's razor we're left with a teenage drop out who has found a way to sell bank account details on the black market, to fund his new car. But of course not, obviously it's Al Quaeda. How else will the security industry succeed in strangling more cash and evil, preferential, freedom-damaging policies from central government?
- daeken 14y agoAbsolutely no one is even suggesting it's Al Quaeda. Did you read the article at all? It points to the US and/or Israel above all else...
- 14y ago
- nvmc 14y agoI like how they call it a "nation-state sponsored cyber-espionage toolkit", and then go on to refer to its unknown creators.
- sgt101 14y agoOh ho - and suddenly Standard Chartered is fingered for transactions with Iran! Yuk Yuk Yuk - I wonder what is going on with this then!
- jsannemo 14y agoReading their analysis of Gauss, it appears 0xACDC is used for XOR encryption when communicating with the C&C servers. Didn't we just read about another security company and AC/DC...? http://news.ycombinator.net/item?id=4286696 http://news.ycombinator.net/item?id=4286696