Sleuths Trace New Zero-Day Attacks to Hackers Who Hit Google
wired.com
wired.com
(not a Symantec employee, just following the links)
edit: That's a lot of bitly links to "Symantec Connect Community" https://bitly.com/u/threatintel.rss
I also found it no surprise that 0days in this case were routinely wrapped in shockwave to deliver payloads for guaranteed execution.
AV companies may be snake oil salesmen, but i hope they at least fund research like this a bit more aggressively.
1) A bountiful supply of cash 2) A reputation
#1 pays the bills, #2 gets them in the door. Symantec and others make their #1 with the snake oil such that they can afford to lose a bit of #1 in order to gain #2. With enough #2 they can hire big names, work with large companies and suddenly you have a pretty strong group that's capable of writing articles like this.
In all hopes we'll see this type of malware understanding get pushed through to the actual detection schemes. Instead of reactionary scanning and detection of files we can start to look towards behavioral scanning. False positives are probably the worst part to the consumer about this since they just want their snake oil without side effects.
I don't think any part of this is scary because, let's be honest, none of us are likely at all to ever be the target of such a sophisticated attack.