How to catch a wild triangle
securelist.com
securelist.com
I'd have liked to see where they pointed the finger in terms of who they think sent these off, but in case you're too lazy to read: a .watchface file sent over iMessage was used to hoist up enough power to delete all records of the iMessage and open two-way encrypted communications with a local binary.
Figuring that out led to (I think?) four zero-day reports to Apple, and a substantial homegrown MITM proxy poisoner designed specifcally to compromise the encryption used to protect the exploit server's comms channel with the devices.
Just because you're paranoid doesn't mean they aren't out to get you if you're Kaspersky, I guess.
Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] was behind this but my money's on the NSA.
[1] https://eugene.kaspersky.com/2011/11/02/the-man-who-found-st...
[2] https://www.washingtonpost.com/world/national-security/israe...
The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.
They talk about it here, under "what we know so far"
Why is your money on the NSA?
When security helps attackers... that's a bit ironic.
Anyway, this article is exactly why I don't want to work in computer security, you constantly have to look behind you, and government A/government B/black hats etc will always try funny things, because they belong to side A or B or whatever, and I bet a lot of security people got either threatened or even had targets on their backs or just assassinated.
I don't really know if some of them got assassinated, because that might not make the news, but that's not a really a domain I would like to work in.
I guess it attracts people who like competition, but I don't really see the value of working in security, for the same reason I don't see the point of joining an army to learn how to fight.
Security means money and can mean violence.
There are computer security people who work for intel agencies, those are the people I am talking about.
Even people who work for securing data of companies, those people might also be targets.
This kind of constant striving and failing until finally succeeding would be such an incredibly frustrating experience for me.
Kudos to them though, it's serious perseverance.
It's a mindset/perspective difference.
Would love to see a subsequent post in this series about attribution. Are there any code or other TTP similarities to APTs from known actors?
This is why your corporate network should MitM all TLS connections by default.