Notorious Malware, Spam Host "Prospero" Moves to Kaspersky Lab
krebsonsecurity.com
krebsonsecurity.com
Kaspersky operates an autonomous system (AS) and "Prospero" has traffic routed through that AS. Microsoft and Google also route all sorts of malware and spam through their ASes.
>The routing through networks operated by Kaspersky doesn’t by default mean provision of the company’s services, as Kaspersky’s automatic system (AS) path might appear as a technical prefix in the network of telecom providers the company works with
Censorship shouldn't happen at the AS level, anyways.
[0]: https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiqui...
For me, it was when he doxxed security researchers, claiming they were criminals with no evidence.
> I am trying to temper my dislike for krebs, but it is getting difficult.
I'm not. The guy lies for a living.Key takeaways from the article: Prospero is a Russian hoster trusted by top cybercrime groups. Especially popular is their bearhost brand, which provides great service since 2019 and openly invites you to operate botnets, brute-force attacks or phishing websites on their hosting service.
Kaspersky by contrast is barely mentioned in the original portion of the article, it's only the later updates that go into detail here
Edit: maybe stealth advertisement isn't quite the right word. I'm not implying monetary compensation or any business relation, only that better malware provides job security for the cyber security sector
1. Kaspersky AV had the strongest heuristics analyzer and the largest signature base
2. If you write malware, you want to test it periodically (in sandbox) if AV engines detect itNSA Contractor has a requirement for AV on all computers, it was installed on all computers and fact it's bad idea on select computers doesn't matter. Contract dictates, the contract gets.
1) a company like Kaspersky can easily be employing 1-5-10-50 KGB/FSB agents, even without them knowing about the existence of the other agents (so they rat on each other)
2) a company like Kaspersky can be arm-twisted and/or knee-capped to knowingly employ 1-5-10-50 employees (similar to US three letter agencies operating in US companies)(room 641A)(NOBUS MS Exchange hole that was there for 20 years, etc)
3) I remember as a sysadmin using McAfee ePO 20+ years ago to "check things and do stuff" on employees' PCs when my Microsoft SMS was not working
4) Russia just like China have a different sense of "rule of law". The supreme law is the "national interest " and Xi/Putin and their apparatus-es define it very freely.Krebs is ranking lower in my eyes with writing like that. First, that’s obviously malicious software. Secondly, this is muddling binaries and source code. Is the claim that Kaspersky gathered the source for malware off the machine? That’s not typical behavior. If the claim is it gathered the binary that was built, that feels like a nothing burger.
Even the response from Kaspersky makes Krebs seem alarmist for the sake of generating attention traffic rather than someone investigating if there’s anything out of the ordinary in the first place. Didn’t even give them a few days to respond before publishing the article.
It can be both: lots of malware exists in executable-source form, like PowerShell scripts and the like.