Ο founder της Kaspersky Labs εμφανίστηκε με εύθυμη διάθεση σε μια συνέντευξη Τύπου στο Λονδίνο, για να προσφέρει διευκρινίσεις σχετικά με την επίθεση που δέχτηκε η εταιρεία του, από μια από τις πιο μυστηριώδεις προηγμένες μόνιμες απειλές (advanced persistent threat ή APT) που έχουν ταυτοποιηθεί μέχρι σήμερα.
Eugene Kaspersky did not provide information as to who was behind Kaspersky Labs's attack and avoided giving a specific timetable when the violation took place. But he has rushed to highlight the complexity of the platform that was used, the second-generation Duqu that 2014 first discovered after two years of absence from the internet.
He stated that the malware and tactics used by APT allowed him to be virtually invisible on the network for quite some time.
The ingredients of Duqu 2 were found in the APAC security company's home network in the spring, but Eugene Kaspersky said it was there for a long time, maybe a few months.
Apparently, Kaspersky Labs will try to gather more information about the malware's infrastructure in the near future software approach and analyze the technologies used. His activity was uncovered during an internal security audit of the systems.
The reason that was not identified from the beginning is that it left no trace to the infected systems and was in memory.
Except installation του στη μνήμη RAM, το κακόβουλο λογισμικό δεν δημιουργούσε πολύ κίνηση (traffic), which could trigger Kaspersky's anti-APT systems. The malware also pretended to be the system administrator, a tactic that prevented detection.
It is believed that Duqu 2 is a government malware targeting high profile companies in the west, Asia, the Middle East and Russia, which their cost is estimated by Kaspersky starts from 10 million dollars.
Eugene Kaspersky said Kaspersky Labs researchers will report safely only when they look at the source code of the malware, and its administration and control servers. There was no government at the press conference.
The interview ended with him Eugene Kaspersky to state:
“Don't hack me! That's a bad idea"