When the Antivirus Company Gets Hacked

When the Antivirus Company Gets Hacked

Tech News hacking kaspersky malware security

So here's a fun one: the company whose entire business is telling you when malware is on your computer just admitted malware was on their computers. Kaspersky Lab put out a post a couple days ago saying they'd found a new, seriously advanced piece of spyware crawling around their own corporate network, and they're calling it Duqu 2.0.

If that name rings a bell, it should. The original Duqu showed up back in 2011 and shared enough code with Stuxnet that researchers figured they came out of the same shop — the one everyone assumes is a joint US/Israeli operation, though nobody official has ever said so out loud. Duqu 2.0 isn't just inspired by that old malware, it's apparently built by the same team, years later, with a much bigger budget and a much better sense of how not to get caught.

And that's the part that actually got my attention, not the "ha ha, the security guys got hacked" joke everyone's making on Twitter this morning (fair joke, but low-hanging fruit). This thing barely touches the hard drive. It lives almost entirely in memory, so a straightforward disk scan won't find much of anything, and it was reportedly using multiple Windows zero-days to spread itself around once it was in. On top of that, some of its drivers were signed with a legitimate digital certificate stolen from Foxconn (the same Foxconn that assembles a huge chunk of the world's phones and laptops), which means Windows just waved it through like it belonged there. That's the kind of detail that makes this whole thing feel less like a smash-and-grab and more like a small, well-funded engineering team that had months to get it right.

Kaspersky wasn't even the only target, from what's being reported. The same malware, or close variants of it, apparently turned up around venues connected to the P5+1 negotiations over Iran's nuclear program, and near events marking the 70th anniversary of the liberation of Auschwitz earlier this year. Put those next to each other and you get a pretty clear picture of who this was built for and what they cared about, and it wasn't stealing your credit card number.

I'll be honest, I go back and forth on how much of this stuff to take seriously versus how much is just security-industry theater designed to sell more product. Every antivirus company loves finding a scary new APT with a cool code name right before conference season, it's basically their version of a movie trailer. But this one's a little different because it's Kaspersky's own house that got broken into, and they're the ones who'd know better than almost anyone what a break-in looks like. If their network wasn't safe, I don't love what that implies about the rest of us running Norton or whatever on a five-year-old Dell and calling it a day.

(Small tangent, since I'm already complaining about security software: can we talk about how AV suites still manage to grind a machine to a halt during a scan in 2015? I've got a coworker whose laptop fan sounds like a hair dryer every single morning at 9am because that's when the scheduled scan kicks off. We've had solid-state drives for years now. Somebody's doing something wrong.)

Apple wrapped up WWDC this week too, and yeah, Apple Music and Swift going open source are the bigger headlines by a mile, everyone and their cousin has already written that post. But I keep coming back to the Kaspersky thing because it's the story that actually changes how I think about my own setup, not just what app icon I'll be tapping on in the fall. Stuxnet was the wake-up call that this kind of operation was even possible. Duqu 2.0 is the reminder that the people who built it never really stopped, they just got quieter and better funded.

Kaspersky says they've cleaned their network out and are still digging through exactly what was taken. I'd bet money we hear more about this before summer's out.