NOTA BENE

Notes, comment and buzz from Eugene Kaspersky – Official Blog

March 1, 2013

Back from the dead: the original virus writers.

Hi all!

A great many computer security events occur around the world all the time, but the RSA Conference is one of the most important of all of them. What exactly it’s all about here I’ll not go into; instead I’ll just share with you some pics from the gig. The photos were taken the day before it started while the stands were still being set up, so though all the installations aren’t ready, at least you can see the near-completed scene without throngs of visitors getting in the way…

RSA Conference 2013Stylish stands

RSA Conference 2013Gaudy stands

RSA Conference 2013Stand mash-up

RSA Conference 2013…and center stage…:)

RSA Conference 2013Red means “stop!”

RSA Conference 2013Green means “go!” That’s why we’re green. Unlike the amber gamblers :)

RSA Conference 2013All that trash – and the conf hasn’t begun yet. Agh – modern day packaging…

RSA Conference 2013Jeez! Who be it? Korea’s AL! Now that was a surprise. Blue. Eh?

RSA Conference 2013Enter the public (defense) sector big guns

RSA Conference 2013More red

RSA Conference 2013Just don’t mention “unique passwords”

RSA Conference 2013Green scene

RSA Conference 2013“Who are we”?

When all was set up, it was up to the plate for my speech:

RSA Conference 2013

Not long after that my path crossed that of several big-cheese gurus of both the antivirus industry and security journalism. Here are Mikko Hypponen, Jimmy Kyo, and moi:

RSA Conference 2013

And here’s one taken later on in the bar with the man himself, Brian Krebs:

RSA Conference 2013

All in all – great conf/exhib. But it was reports that originated thousands of miles from sunny San Fran that got me all excited most of all (not to mention concerned). My mind was totally blown by news of the appearance of a new Trojan – MiniDuke. I was in shock! Why? Read on…

These days I don’t normally look at code of new Trojan-extortioner-spy-whatever else’s. Alas, that hasn’t been my job for many years now (also, where would I even begin today – given that our virus analysis lab filters a wholly humungous stream of all sorts of Internet rubbish?). This time, however, an exception was made – and you’ll see why (clue: “old school”). Thus, I was thrown a bone – a piece of a disassembler, “just to have a look” (yeah, right). So I looked. And I was bowled over!

The last time I saw code like this was ~10 years ago. But this Trojan spy is not just written in the style of the old school. Something tells me it’s actually been created by the old schoolers themselves. Some of you may remember that back in the day there was a group of virus writers called 29A. Well, MiniDuke looks pretty much like their coding style! Interestingly, this was a virus writer group – not a cybercrime group (these chaps hail from an era before the dawn of cybercrime!).

So what does it mean? Well, actually… I’ll be damned if I know! All I know is that suddenly something resembling bad-old virus innovators – 29A-style – appear to have decided to return to the scene. Were they offered tasty contracts? Made offers they couldn’t refuse? I’m with Manuel on this one, but what I do know is that this is very bad news. If these kids – nope, add a decade – if these experienced old hands have decided to return to the arena of malware coding for Tinker-Tailor-Soldier-Spy objectives – this is reeaal bad news. Why? Simply put – they know their stuff.

Coders from back then (including the 29A gang) were the initiators of practically all present-day virus technologies. They came up with email worms (1999), flash-worms (2003), viruses for smartphones (2004), and a lot more besides. Then, for almost a decade, their presence all but disappeared, nowhere to be seen or heard – not a squeak. Until a few days ago…

So yep, what we’ve got here is (thought-to-be) long-dead virus-writing techniques rising from the grave to cause trouble – a unit of live undead, a jam of resurrection Joes, a return of the living dead… you get the macabre picture.

Must dash…

Later!

comments 1 Leave a note

Geoff Nicoletti

You need to focus on Stuxnet-like payloads…the old timers building payloads….you are talking about air craft carriers and I am talking nuclear weapons: the physical destruction, not digital, of systems from a distance…resonating till destruction…fans switched off…registers hammered…tracks of HDDS acting as if there is only one track. I’m talking the chaos of replacing devices; you’re talking being down for an hour. You just don’t get it.

0
Reply to conversation
Trackbacks 3

Jak przerażający może być “oldskulowy” programista? | Kaspersky B2C Poland

Researchers dismiss Mask research, say it relies on historical technology

10 years since the first smartphone malware – to the day. | TechWorldBD

Leave a note
August 28, 2015

Kamchatka-2015 – top to bottom!

In my humble opinion, Kamchatka is the most fascinating and beautiful place on the planet. Bold statement, I know; but coming from a power-globetrotter like myself, maybe you won’t reject it out of hand? If you do – read the upcoming series of posts on this year’s An-Kam (annual Kamchatka), and let’s see if you haven’t […]

August 27, 2015

Top-100 Series: North America, Part 2.

Hi folks, In continuation of my revised and revamped Top-100 of the most remarkable, interesting, enchanting and beautiful places and countries of the world, here’s the next installment: part 2 of the very best – IMHO – places to visit in North America, i.e., the North American continent, which (of course?:) includes Central American countries […]

August 24, 2015

Kamchatka-2015 – aperitif.

“Further [vertically] up there, there’s a path!” – Our guide, Fyodr.   Hi all! Phew! Back to civilization from the harsh wilds of Kamchatka, and beginning the slow acclimatization back to modern city life and all its creature comforts. In all we trekked 315km on foot, and probably traveled thousands of kilometers in all-terrain vehicles […]

August 21, 2015

Top-100 Series: North America – Part 1.

Howdy folks! I’ve started – so I’ll finish. In my lengthy prelude, I promised to lay before you my updated Top-100 Must-See Places in the World in several portions over several posts. You’ve already had my new – extra – Top-20 Cities. Next up is a set of Top-Non-City-Must-See-Places – actually 17 of them – […]

August 14, 2015

The abracadabra of anonymous sources.

Who killed JFK? Who’s controlling the Bermuda Triangle? What’s the Freemasons’ objective? Easy! For it turns out that answers to these questions couldn’t be more straightforward. All you have to do is add: ‘according to information from anonymous sources‘, and voila! — there’s your answer — to any question, about anything, or anyone. And the […]

August 12, 2015

My new Top-20: Cities.

Hi folks! Following on from the prelude, herewith, my recently formed list of what are to me the world’s Top-20 cities. In this post I’ll briefly describe and present pics of my Top-20 most interesting and unique districts, quarters or whole cities of the world that I recommend everyone should visit one day. It should […]

More