New State-Sponsored Malware "Gauss" Making the Rounds
EliSowash writes "A newly uncovered espionage tool, apparently designed by the same people behind the state-sponsored Flame malware that infiltrated machines in Iran, has been found infecting systems in other countries in the Middle East, according to Kaspersky researchers. Gauss is a nation-state-sponsored banking Trojan which carries a warhead of unknown designation. Besides stealing various kinds of data from infected Windows machines, it also includes an unknown, encrypted payload which is activated on certain specific system configurations. Just like Duqu was based on the 'Tilded' platform on which Stuxnet was developed, Gauss is based on the 'Flame' platform."
I want to name the next Malware Browncoat, because that is what Mal wears.
Clandestine operation have plenty of use for unofficially raised funds. Remember Iran-Contra?
I'M A LEBANESE
Pics or... wait, I misread that.
"Have you ever thought about just turning off the TV, sitting down with your kids, and hitting them?"
Governments releasing digital weapons on the internet. Thanks for the R&D!
COPY/PASTE.
"Kill 'em all and let Root sort 'em out"
I'M A LEBANESE
Pics or... wait, I misread that.
I just imagined some very very hairy large women .......*chokes back vomit*
Just De-Gauss the infected hard drive
We all know who you are... Just STOP.
Yes, it matters.
Would an article about a new APPICATION not reference what OS it runs on?
"This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
How do these researchers determine where the code was written? I never understood that.
tonyaldo.com
is a gaussian distribution news?
Sheesh, evil *and* a jerk. -- Jade
If the infections are targeted, perhaps the font is dropped to allow found printed documents to be linked to one of the targets?
Is state-sponsored malware and having e-spies in all aspects of everything online...
Is this something that's going to 'solve the problem' or 'become the problem' would you say?
Flailing!
I believe the word you are searching for is "payload."
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
It's amusing to see how much the term "State Sponsored" is thrown around regarding these variants. Sooner or later, everything will be labeled as such to the point where truly "state sponsored" won't even matter. Further disturbing is the annoying mechanisms in which companies like Kaspersky wildly and broadly word their articles often allowing for insane inferences to be made. For example, floating around is news that the US did this to follow the money trail for terrorists. Really? Because a national security letter to Visa, Mastercard and Paypal wouldn't get them the data quicker? Not to mention SWIFT, PROMIS and other controls are in place and have been for years
If you follow the verbiage from Kaspersky over the last few years, one may infer he outright hates the US, is working for the FSB or something way out there. So I quote what I saw on Twitter: World according to Kaspersky: 's:^:US developed (Gauss\|Stuxnet\|Flame):g' || if [ -e $MALICE ]|\then|\ echo USA|\ fi
Whoever interferes with your crappery must be KGB or at least FSB. Or at least French - that is nearly as bad for you.
Instead of doing stupid comments here which only waste bandwidth, why don't we write some software to help the cause of Arab Freedom ? There is still no translation into Arabic for GPG !
I did something minor - a strong paper cipher which can secure combat radio messages: http://alkindicipher.wordpress.com
C-C-C-C-C-Combo Breaker!
Wouldn't it be easier to just send them all an e-mail: "Hello, I am Mrs. Kadafi, wife of the late ruler of Lybia. My husband left me with 300 millions USD in a Swiss account..."
HexaByte - he's a square and a half!
When China strikes back it will be a lot more interesting. Is US ready? If Israel with US think it's ok to infect computers in friendly and neutral countries they can't blame China on doing this too.
In "The Diamond Age", sovereign powers and those with the means engage in (more or less) open conflict using nanomachines colloquially referred to as "mites". Particularly vicious "battles" in these conflicts manifest as smog-like pollution formed by mites of opposing factions destroying each other and leaving inert carcasses hanging in the air and settling over streets, building, etc. like a kind of artificial dust. Those unlucky enough to be caught outside during these times breath them in and have no end of resulting health problems. One of the secondary characters in the story actually ends up in a chronic/palliative care facility as a result of such ill health. Such are the collateral damages in this imagined world. Things like Stuxnet and now the subject of this article appears to be the manifestations of a software form of this type of "armed conflict" (if you can call it that.) Similarly, when non-targeted individuals become infected or otherwise gets caught in the cross-fire, collateral damages result in the form of lost productivity or perhaps just general nuisance. So......
Ask slashdot:
Can you think of an effective way for non-government affiliated denizens of the Internet to respond to such emerging scenarios where geo-politically driven cyber-conflicts have the potential to harm non-participants? For example, would it be appropriate to form an Internet version of the International Red Cross?
========== "Hello World" in my programming language of choice: ATG - LET THERE BE LIFE - TAG ==========
surely I will be successful this time!!!
On virus announcements, why don't they ever mention vulnerable operating systems? Not all malware can infect all operating systems. It would be nice to know the specifics.
Then again, maybe Microsoft wouldn't like the bad PR.
That's our life, the big wheel of shit. - The Fat Man, Blue Tango Salvage
If these events cause mass flight from Microsoft products, the NSA or whoever wrote the darn thing might want to think twice before they go to Microsoft asking for any back doors or any other favors, I suspect Ballmer won't take too kindly to the idea of exploiting Windows in the name of national security if it takes a big ding out of their bottom line...
Communication with the command & control servers is encrypted by XORing with 0xACDC (Flame didn't encrypt C&C traffic).
ACDC... now is anybody else wondering what that mysterious encrypted payload could be?
Can't we just say sponsored by the US instead of acting like we don't know who created this?
Perhaps that one infection was the source of the other 2,446 infections?
Iran is a major player in Lebanon after all.
Countries that release stuff like this into the wild are criminal rogue states. It's like dumping agent-orange not just on the jungles of Vietnam during war, but on the entire planet as a whole.
There are no borders on the Internet. What you release is not limited to your target and affects everyone.
One can only hope that the governments that released Flame, Stuxnet, and now this, become victims of their own weapons.
Yes, I do know who that likely means. I certainly hope it comes back to bite us like a torpedo circling around and targeting its own submarine. Maybe then someone will learn a thing or two about not shitting where you eat.
--
BMO
No the ICRC is an awful example and exactly what one wouldn't want: wasteful global corruption preying on good intentions and shortsighted feel-good ideals, an organization that quickly moved from noble beginnings (including triage by killing, technically murder) into doing far more harm than good when assessed after fairly short time-scales (the total resulting effect a few decades after actions taken). I am not making the argument but the ICRC is led by the kind of people one could reasonably argue should be killed even if one assumes an eventual and unavoidable man-made immortality and the resurrection of all dead sentient life throughout history (bound to happen if sentience survives a billion years, hell it might become reality within this millennium considering the rates of improvements we're already seeing).
However what one does want is already in existence and growing: novel (and still very young) entities akin to Anonymous. There's already a handful of them and that's just the public and "intentional" ones. Yes most people don't get such "disorganizations" yet but within the next few decades most will as they realize by that time that they're already (in the future) part of them. By then it will be even less confined to the "digital world" and might even start to become part of formal societal structure (i.e. part of general society and "governance", which in case people haven't noticed is painfully slowly dying an ugly disease-ridden death all across the world right now --not that disorganizations will replace this but they will likely function as midwifes for whatever does).
Disorganizations don't even need unique names or apparent existence, as an example people who use Tor, I2P or similar are already seeding and sustaining such disorganizations through simple straightforward 'individual reward' without realizing it or the aggregate effect (that's how emergent properties work).
Kaspersky's report notes the XOR key used for data encryption is 0xACDC, yet there is only a single reported infection in Iran.
I made that mistake verbally in 4th grade when I didn't really know what the word meant. There was a kid in our class from Lebanon. We were talking about how you can tell where a person is from by the shape of their skull or something, so we were all shouting out different nationalities. I shouted "Lesbian!" Haunts me to this day.
That would be nice to hear, that Iran now uses it against the developers.
Yeah, the island of Lesbos isn't big enough to be considered a nation. Any 4th grader should know at least that much geography.
Insert self-referential sig here.
IF & when ALL the trolls have around here is downmodding that post w/out justifying WHY (on topic why, as in computer technical mistakes that are present in it (none))?
* Then, I've made my case & won, simply by issuing this challenge for them to disprove ANY of the points listed in it...
(They can't)
Heck - They tried for years, to no avail, not even disproving 1 of the points it contains on how practicing "layered-security"/"defense-in-depth" get the end user:
---
1.) Better online speed/bandwidth
2.) Better "layered-security"/"defense-in-depth" online OR offline
3.) System stability
---
& more...
APK
P.S.=> All they have is their woman-like b.s. effete "retaliation" via a "hit & run" downmod... nothing more!
... apk
Compared to you, & those LIKE you, troll? I may as well be Eddie Morra from the film I noted in my subject-line aboev:
http://www.youtube.com/watch?v=THE_hhk1Gzc&feature=related
(At position 1:03 on the YouTube player - Says it all for me):
---
Robert DeNiro: "You do know you're a freak, don't you? What's your secret??"
Eddie Morra: "Medication..."
---
* "No scenario? I see EVERY SCENARIO. I see 50 scenarios: That's WHAT IT DOES, Carl - it puts me 50 moves ahead of you..."
APK
P.S.=> "How many of us know what it is to become the PERFECT version of ourselves?"
(Since compared to a "ne'er-do-well" TROLL like you?? I practically am!)
... apkb