Russian antivirus firm faked malware to harm rivals, say ex-employees
reuters.com
reuters.com
Kaspersky's refusal isn't a sign of their integrity, but avoidance of an obvious trap. I'm not saying they don't have integrity, but even if they didn't, it would be very dumb to take that bribe, especially in a country very familiar with corporate blackmail.
"VirusTotal had no immediate comment."
"[...], Kaspersky denied using this technique. It said it too had been a victim of such an attack in November 2012, when an "unknown third party" manipulated Kaspersky into misclassifying files [...]"
"The former Kaspersky employees said Microsoft was one of the rivals [...] They declined to give a detailed account of any specific attack."
"In a subsequent interview on Wednesday, Batchelder declined to comment on any role Kaspersky may have played in the 2013 printer code problems or any other attacks. Reuters has no evidence linking Kaspersky to the printer code attack."
"Avast Chief Operating Officer Ondrej Vlcek told Reuters in April that he suspected the offenders were well-equipped malware writers and "wanted to have some fun" at the industry's expense. He did not respond to a request on Thursday for comment on the allegation that Kaspersky had induced false positives."
So, no one says it's Kaspersky, someone called "former employees" says it was, but can't provide any example...
edit: And of course this http://www.wired.com/2015/06/kaspersky-finds-new-nation-stat... from two months ago.
First, security breach; now, an attack on their reputation?
Hmmm.
There have been exposes by western AV firms too, but not as many and not as good. If there was obviously Russian govt malware out there, it'd surface sooner or later. We've seen American, Chinese, British, French, Israeli ...... seems odd that there's no Russian yet. But then I get the impression that Russian spying is overblown anyway. They seem to mostly focus inwards these days, or focus only on the former Soviet satellite states. USA has a much more aggressive global agenda.
like in that joke (an American says "we have freedom - we can criticize Reagan freely", and Russian responds "we have freedom too as we can criticize Reagan freely too") - Kaspersky was pretty active in uncovering StuxNet, i.e. shenanigans of the US/Israel governments :)
Notice again the title ;)
That said, Reuters IMHO is the top reporting authority worldwide along with AP.
Pretty hefty accusation on the integrity and journalistic ethics of the Associated Press. Do you have a reliable and credible source for this claim?
no one takes this seriously.
if you don't see how this matches either description fair dues to you.
I consider this to be propaganda. First time I've seen reuters accidentally a word too. Down further in my estimation!
Anyway, if you think that is propaganda you should perhaps visit Russia to see what real propaganda looks like.
Plenty here for you to peruse, enough to satisfy the 'often' condition, while simultaneously not always being 'on message'.
e.g. http://blogs.roosevelt.edu/hsilverman/files/2011/11/Reuters-...
That Reuters isn't a reliable source of information isn't a matter of motive or "agenda", it is common sense within educated circles.
And, their main development being done in Moscow, do you expect current employees to stick their heads up? There aren't a lot of protections for whistle blowers in Russia. I'm pretty sure they'd be declared traitors, if they did reveal something like this in a formal setting.
The only ways i can think of to prove innocence (in general) are a) an alibi b) finding who actually did it.
Both of these don't work here, you can't have an alibi for the whole company for 10 years, obviously. You can't find out who did "it" because there's no concrete example. At the very best you can prove that others did it too.
That said, the trick is pretty vile. Deliberately polluting public malware databases hurts us all.
I would be very skeptical of this entire article, having worked with researchers from Kaspersky for many years. They are terrific partners and care deeply about infosec.
Also, Kaspersky has been known in the past, which they have disclosed, for planting red herrings in malware archives, because they accused (and were right) of other vendors just looking at what Kaspersky blocks and just automatically copying it, without actually doing AV research. That's not what they are being accused of here...
Finally, Joseph is a great journalist, but this article stinks in terms of providing actual evidence.
(Web Archive shows this topic — initially about Avast breaking Windows by blocking tcpip.sys but turned into flame about “shitty free antiviruses”, their lack of analytics team, and pirated software quite soon — existed in 2012.)
He explains it had been done a couple of years back to demonstrate the problem to Computer Bild journalists. A number of executable files with “funny” code that could not do any actual harm were made and 50% of them were added to Kaspersky's detection list under distinctive names. Then they all were shared on VirusTotal (and thus with other vendors). Surprisingly enough, only those “viruses” that triggered Kaspersky Antivirus on VirusTotal started spreading through others' databases, often with the same name. Still, there was no article written on that for some reason. These results were later presented to analytics and investors visiting Kaspersky's conference (Security Analyst Summit 2012).
So what's left is to ask Computer Bild if they participated in something like that test and/or someone who was on that conference.
"Avira Antivirus update cripples millions of Windows PCs ..." "Broken McAfee DAT update cripples Windows workstations" "Update gone wrong. Panda antivirus removing system files ..." "Bad BitDefender Antivirus Update Hobbles Windows PCs ..."
Kaspersky labs has defended against US government malware so they might also get into trouble for that.
Kaspersky has demonstrated a weakness: that the firms copy each other's data and blindly trust each other as well as the initial submissions. They have a submission process for infected files which can be demonstrably abused to inject false positives.
Also this:
> Then, when competitors ran this doctored file through their virus detection engines, the file would be flagged as potentially malicious. If the doctored file looked close enough to the original, Kaspersky could fool rival companies into thinking the clean file was problematic as well.
What?? Infected files are always similar to clean files. An infected MS Word 2010 still looks mostly like MS Word 2010 and is even usable as such. Knowing clean from infected is the bread and butter of anti-virus. They are supposed to take doctored files, and register them as malicious, while recognizing clean ones as clean. If similarity between dirty and clean them causes a false positive, you would think that this is a fundamental problem. It shows they are using some weak heuristics to guess that files are clean instead of, say, strong checksums. They are guessing whether that DLL belonging to MS Word 2010 is clean or not because they have no idea what clean looks like, and Kaspersky has shown that they can be induced to guess wrong.
A proper implementation would detect so much as a single bit difference between a clean file and an altered one. Rather, they must be working off the assumption that there is some minimum difference between a viable infection and the clean file. In keeping with this, there is a database of the known dirty files only, and not of the clean reference files. Anything close to the dirty example within some small "edit distance" is just a variation on dirty and is declared dirty. Anything distant is either a different, unknown form of dirty, or clean. Either way it is declared clean. If that's how things work in an AV program, it has a weakness. Competitors should be merciless in identifying and exposing that weakness, because that's good for the consumer in the end.
>Then, when competitors ran this doctored file through their virus detection engines, the file would be flagged as potentially malicious. If the doctored file looked close enough to the original, Kaspersky could fool rival companies into thinking the clean file was problematic as well.
I don't quite understand - what about hashes? VirusTotal doesn't work as they say it works.
It's a neat attack.
FYI virus scanners have been doing that for ~25 years.
Most worrisome is what other unscrupulous behavior is he willing to engage in? Is he willing to do the bidding of the motherland at the expense of the trust customers put into the product?
The signatures that triggered it were in 3rd party installer code that we used. If you think of it, it is a perfect attack method as by targeting shared installer many products were made false positive with little effort.
Perhaps a mod should step in and cleanup the title a bit? I realize it's technically the original, but it's still misleading.
"Microsoft's antimalware research director, Dennis Batchelder, told Reuters in April that he recalled a time in March 2013 when many customers called to complain that a printer code had been deemed dangerous by its antivirus program and placed in 'quarantine'."
Accusation is presented as fact.
This would be a better title: "Russian antivirus firm faked malware to harm rivals - say ex-employees"
Especially in the absence of actual evidence.
If these claims have any truth to them at all, then it is completely irrelevant that Kaspersky is a Russian firm.
It's "principle", not "principal". They are very different.
I see this a lot, used in the other direction, on job postings "Principle Engineer" as opposed to "Principal Engineer".
Embarrassing errors like using "'s" to form a plural, instead of the correct "s"?
Done on internationally to see how quickly my helpful comment would find someone looking for a way to take me down. I figured it was easier to just offer-up three errors and get it over with.
Yes, there are two more you missed.
I'd certainly reconsider my Kaspersky license if I had one.
Well, giving ring 0 access to security software made by a company that is very near to a "not so friendly" state would worry me more than the fact that they play dirty with competition.
It sounds like they took advantage of the fact that most malware fingerprinting uses md5 to create collisions with known good files, then uploaded bad files with a matching signature to the places that aggregate bad md5s.
Again, all allegedly.