But it should be pointed out that in the arms race it should generally be expected that the mid-level underground is always pretty much exactly one step ahead of Symantec etc. It's the nature of the arms race that they are in that the attackers have the temporal advantage. The question is less about whether a given technique works today and more about how long it works. The big advantage an intelligence agency and a large attacker has that doesn't apply to the mid-level underground is that their malware won't (or shouldn't) be detected by the various early-detection techniques that the anti-virus companies have, because they aren't necessarily just going to release their stuff into any place the antivirus company will see. Ideally, they'll simply never see it, which is why its interesting when these "escape".