Skip to main content

Security Firm Kaspersky Hacked!






In an ironic twist of fate, security firm Kaspersky on Wednesday announced that it was hacked."The bad news is that we discovered an advanced attack on our own internal networks," the company's chairman and CEO, Eugene Kaspersky, wrote in a blog post. "It was complex, stealthy, it exploited several zero-day vulnerabilities, and we're quite confident that there's a nation state behind it. We've called it Duqu 2.0."
Kaspersky said the attackers—believed to be the same group behind 2011's Stuxnet-like Duqu worm—were mainly interested in spying on its technologies, especially its solutions for discovering and analyzing sophisticated attacks known as Advanced Persistent Threats (APTs). The attackers were looking to find out about Kaspersky's ongoing investigations into advanced attacks, detection methods, and analysis capabilities.
Apparently, they weren't all that successful. Kaspersky said that none of its products or services were compromised and that its customers "face no risks whatsoever due to the breach."
Still, it was one of the most advanced attacks the company has ever seen. The attackers used a number of tricks that made it extremely difficult to detect and neutralize.
"We found something really big here," Kaspersky wrote. "Indeed, the cost of developing and maintaining such a malicious framework is colossal. The thinking behind it is a generationahead of anything we'd seen earlier."
Kaspersky said it was clear the people behind Duqu 2.0 were "fully confident" they'd remain under the radar. The company was able to detect the attack thanks to an alpha version of its Anti-APT solution designed to tackle sophisticated, targeted attacks.
"Attacking us was hardly the smart move: they've now lost a very expensive technologically advanced framework they'd been developing for years," Kaspersky said.
But Kaspersky wasn't the only target. The attackers behind Duqu 2.0 also spied on several other "prominent targets," Kaspersky found, including participants in the international negotiations on Iran's nuclear program and the 70th anniversary event of the liberation of Auschwitz.
Kaspersky didn't name names, but said it believes the attack was a "nation-state sponsored campaign," which relied heavily on zero-day flaws and cost around $50 million to maintain—far more than an everyday cyber criminal would be willing to invest. According to a report from The Guardian, the malware is linked to Israel, and was also discovered on the networks of three hotels that recently hosted the Iran nuclear talks.
"Governments attacking IT security companies is simply outrageous," Kaspersky wrote. "We're supposed to be on the same side as responsible nations, sharing the common goal of a safe and secure cyberworld."
For more, check out Kaspersky's FAQ [PDF] about the attack.
Credits:PCMAG

Comments

Popular posts from this blog

Powerful words from Steve Jobs on his sick bed

Powerful message. Steve Jobs’ Last Words - I reached the pinnacle of success in the business world. In others’ eyes, my life is an epitome of success. However, aside from work, I have little joy. In the end, wealth is only a fact of life that I am accustomed to. At this moment, lying on the sick bed and recalling my whole life, I realize that all the recognition and wealth that I took so much pride in, have paled and become meaningless in the face of impending death. In the darkness, I look at the green lights from the life supporting machines and hear the humming mechanical sounds, I can feel the breath of god of death drawing closer… Now I know, when we have accumulated sufficient wealth to last our lifetime, we should pursue other matters that are unrelated to wealth… Should be something that is more important: Perhaps relationships, perhaps art, perhaps a dream from younger days ... Non-stop pursuing of wealth will only turn a person into a twisted being, just l...

How to Send SMS to any number anonymously

In this technology era, many of us want to send messages anonymously! the reasons might be maintaining privacy, franking etc. But many sees it as impossible! Today I'm going to take you through steps to send SMS/Text message without exposing your identity. This method is actually based on sending SMS using some online websites that will allow you to send SMS without entering any personal details. So just have a look on the websites to send free Anonymous SMS. List of Websites To Send Anonymous SMS To Any Number :- 1   Seasms.com This is the one of the best site that supports 160 character message to send to any number online and you will not need to register any personal details and can send free SMS to any of number. Must try this. 2   Spicesms.com This site only allows you to send SMS in india. The message service of this site is very fast as the message will be send instantly to the receiver end. 3   Smsti.in This website allows to send SMS in...

Turn your Word doc into a PDF with a live table of contents

A long report needs to be broken up into sections. Readers will want shortcuts to the chapters that most interest them. So, if you’re distributing your reports as PDFs, you’ll want live tables of contents in which readers can easily go to the chapters they want to read. Fortunately, this is easy to do in Word 2010 or 2013 (I haven’t tested this in earlier versions). First of all, you need to set up your document properly. Use Word’s outline styles— Heading 1, Heading 2 , and so on—to organize your report. For instance, you might want to assign large section titles as Heading 1, chapter titles as Heading 2, sub-chapters as Heading 3, and so on. By the way, using these headings has other advantages. You can select View>Outline and work on your document as a collapsible outline. Also, the left tab of the Navigation pane uses these styles. But back to the table of contents. When you’re ready to distribute your document, select the References tab and click...