Equation Group Initial Impressions
cs.uic.edu
cs.uic.edu
I don't know enough about it, but I wonder what some reasons for intentionally making these mistakes could be, and would love to see that analysis (aka: informed speculation, instead of my guesses).
Maybe they're trying to seem less competent, so a target that finds these programs infecting their system won't think to look for (ex:) an infection in their Cisco ASA.
Maybe it's an evolution of a tool written by someone else. Either independent or a different nation state, leading to misattribution.
Maybe they want the encryption to be easy to break, for some reason I can't think of.
I'm assuming they're primarily using these tools with stolen data, and perhaps it's less critical to protect it from prying eyes than it is to accomplish some other goal that is met by using tools with these flaws.
* urandom -> srandom(3) -> random(3)
* OFB with SHA1(msg) as IV
Who does either of these things? Who even uses OFB?