
The software, which, according to the WikiLeaks project, was developed by the CIA for the inconspicuous receipt of data from other people's computers and the code of which imitates the products of the Kaspersky Laboratory, is really not a product of the Laboratory. This was announced in his microblog on the social network Twitter, the creator of the company Yevgeny Kaspersky.
“We conducted an investigation in connection with the Vault-8 report and confirm that the certificates issued under our name are fake. Our users, personal passwords and services are safe and were not affected, ”the message said.
The report mentioned by Kaspersky was published by the Wikileaks project on November 9. The report claims that the American intelligence agencies created the Hive program, which allows you to quietly download user data of interest to CIA from computers. At the same time, the program code indicated in WikiLeaks, imitates the antivirus programs of the Kaspersky Laboratory: it contains three elements designed to simulate the company's antivirus certificate.
As a result, an organization undergoing an attack using HIVE, when viewing traffic emanating from the system, is most likely to conclude that the abduction of data is carried out using the Laboratory program, TASS news agency from the WikiLeaks report reports.
Smartphone with screen lock / pixabay.com
The report was a continuation of WikiLeaks Valut investigations about computer programs that were created specifically for the CIA. WikiLeaks has previously talked about programs that allow the CIA to hack various devices and systems of American and European production. Among the other discoveries of WikiLeaks was the AThena project, with the help of which special services could break Windows.
As for Hive, it, according to Wikileaks, provides the opportunity to send information to the CIA servers and receive instructions from operators. At the same time, according to WikiLeaks, each operation that the user performs on an infected computer is anonymously recorded on at least one third -party domain that performs the cover. Such a domain sends “safe” content to the server - in case the traffic decides to check, the RBC news agency reports.
We add: after the publications of the Wikileak report, Russian politicians ironically reminded the topic of “Russian hackers” popular in the Western media and the Kaspersky Laboratory allegedly on the cooperation of the “Kaspersky Laboratory”. “Who told us stories about“ Russian hackers ”? They are the same “Russians” as I am the ballerina of the Bolshoi Theater, ”Dmitry Rogozin, Deputy Prime Minister of the Russian Federation, wrote on his page on the Facebook social network. And the head of the Federation Council Committee on International Affairs, Konstantin Kosachev, on his page on the same network, expressed the opinion that the American media will “shut up” this information.
“It should have been a sensation of an universal scale. But it will not. The authors of previous sensations will not agree <...> when there are enemies around, and friends do not get anywhere but to be with us loved. And all and all sorts of media will again bend in a rag. Because a rag on the companies was thrown tasty, for a long time and for a long time, ”he believes .
Aleksey Raevsky, General Director of Zecurion, who is developing DLP systems to protect against information leaks, consulting and conducting research in the field of information security, agreed to talk with Polit.ru. According to him, the incident can be considered a serious precedent and it must be carefully dealt with.
“Speech here is not so much about the product itself as about a fake certificate. The product here is the tenth business, it was not said about it, but about the certificate. A certificate is an electronic key that is needed in order to make sure that traffic belongs to the person who signed it. That is, it is a kind of electronic digital signature, encryption.
In principle, the issuance of certificates is a fairly rigidly regulated process. And the question of how and who managed to make a fake certificate, I think, requires a serious proceedings. Because otherwise, in general, the whole structure is thus in this way.
The fact is that certificates are produced by some certifying centers that enjoy common trust in the industry. They have special procedures that ensure the reliability of their work; They do not do what they do not declare. And if it was possible to somehow release such a certificate, this is a very serious precedent, ”explained Alexei Raevsky.
He emphasized that this is precisely about the precedent - before nothing like this happened. “Yes, this was not there before,” the expert confirmed. According to him, it is impossible to evaluate how it was done - for this there is still not enough data.
Photo collage. Double code / pixabay.com“We must understand how this happened - the information is not enough. But there are two options: either the company that issues certificates has violated some of its own regulations and “rolled out” such a fake certificate, or in its software there was some kind of vulnerability that allowed someone to do this. But in both cases, what happened is a very bad precedent, ”said Alexei Raevsky.
He explained that the certificate for the software product was not forged, but a digital certificate, an analogue of digital signature. “This is not a certificate for a software product, but a digital certificate, an analogue of digital signature. It has an indirect relationship to software - it exists as if separately from the software product and is needed for electronic signature and encryption.
Some media write about the virus, which allegedly posed as a product of the Kaspersky Lab, but this is not entirely true. The virus is a virus, and then everything rested precisely on the certificate necessary for encrypting traffic that this virus created, ”said Raevsky.