In the fall of 2017, the Russian "Kaspersky Laboratory" was threatened to lose most of its profitable American market. The reason is the suspicion of close ties with the FSB, and especially the information that the company deliberately stole the secret documents of the US National Security Agency, namely the source codes of viruses created by American intelligence officers. Evgeny Kaspersky said that the company received files by accident and immediately deleted it, but not everyone is ready to believe him ( read the details in the first part published earlier ). And if you still have not removed? The second part of the Radio Freedom investigation is about the world cyberwain that has been going on for 10 years, into which the Kaspersky Laboratory was involved, and how the secret archive came to it could cause the viral infection of the Chernobyl nuclear power plant, Russian police and chocolate factory from Tasmania.
Cyberhiroshima and other attacks by Equation Group
One warm evening in June 2010, the Belarusian programmer Sergei Ulasen had fun at a wedding with friends 400 kilometers from Minsk, when his phone came to his phone: the subscriber from Iran wanted to urgently contact Ulasen. The conversation dragged on: “Around there were funny girls with sparkling glasses in glasses, no one could understand why I needed to hang on the phone and explain to someone strange things in a strange language, despite the fact that I was in the forest at the wedding,” recalled Ulasen in an interview. For a couple of days before, at that time, the employee of the Small Belarusian Anti -virus company Virusoblokad was sent a letter to the Iranian client. The client complained about problems with computers on the network - some began to constantly reboot, and the “blue screen of death” appeared on others - the critical Windows error. At first, Ulasen decided that the matter was in the wrong configuration of the operating system, but after reading the report more carefully, I realized that the network suffered from a hacker attack. A computer security specialist from the client said that he would deal with her, but when by Saturday - the working day in Iran did not work out, he called the Belarusian colleague with a request for help. By Monday, the virus was isolated, and the methods of its spread and effective protection against detection have been studied. So the Stuxnet computer worm was discovered, which later began to be considered the first in history by offensive cyber weapons.
Programmable logical controller Siemens
Ulasen determined that the worm uses zero-day vulnerability (that is, previously unknown) Microsoft Windows spreads through flash drives and local networks and uses stolen digital certificates. Everything indicated that it was constructed by his specialists of a very high level. But why? A few days later, a German analyst was able to figure out a few days later, who studied the data posted by Ulasen on one of the messages: he found out that the unusual virus is designed to attack the programmable logical elements of Siemens-devices that are used to automate technological processes in production. In fact, Stuxnet was able to cause physical harm to equipment, forcing the equipment to work in abnormal mode, and imperceptibly for engineers. Switching of traffic light signals, adjusting the water supply systems, the operation of equipment of nuclear power plants - all this uses programmable logical elements that turned out to be vulnerable to the new virus. The worm looked like the first real threat to humanity that could get out of cyberspace into the physical world-with some of the films about James Bond, and independent experts, Microsoft and all the largest antiviral companies, including the Kaspersky Laboratory, took up the study of its functional part-unusually voluminous and difficult for a computer virus.
It was the specialists of the LC who were the first to establish that Stuxnet uses not one, but at least four vulnerabilities of the “zero day” - an indication that the creators of the virus have significant technological and financial resources. Then Yevgeny Kaspersky first suspected that the dangerous worm was designed in the interests of state structures, but in which? In November 2010, Symantec specialists installed, Stuxnet attacks frequency-regulating drives, devices, which controls centrifuges, for example, at the Uranus enrichment plant in the Iranian Natans.
Mahmud Ahmadinejad at the enrichment factory in Nathanz, Iran
The assumptions that Stuxnet is specially aimed at the Iranian nuclear program, sounded before this opening Symantec, and now they have received additional confirmation. The hypothesis that the virus was created precisely for this purpose, and the creators were jointly intelligence agencies of the United States and Israel, became more and more popular and found more and more indirect evidence - from convincing, such as the conformity of the release of the new versions of Stuxnet and the statements of officials under the Iranian nuclear program, for example, the constant is once found in the virus code 19790509, and on May 9, 1979, the Habib Elganyan industrialist was executed in Iran. But official evidence, of course, was not and not - neither from the alleged creators, nor from the victims of the attack. Surely it is also unknown whether Stuxnet was able to cause noticeable damage to the Iranian nuclear program - according to indirect data from the IAEA report , it can be assumed that about 1000 centrifugs were injured in the production of Nanza, which, however, were quickly replaced. By the way, in 2013, Evgeny Kaspersky, citing an anonymous source, said that Stuxnet infected the internal network of one of the Russian nuclear power plants. According to him, this happened during the greatest activity of the virus (that is, in 2009–2011). One way or another, the reputation of the “cyberchirosima” - the first cyber weapons in the history of cyber weapons.
But far from the last: in September 2011, the Duqu virus was discovered - a Trojan program designed to steal information from an infected computer. Researchers - the Russian "Kaspersky Laboratory", the American Symantec and many others - immediately stated that the authors of Stuxnet created it, in any case, people who had access to the Stuxnet source code. Duqu infection also used the zero day of Microsoft Windows, Trojan used the stolen digital certificate belonging to the Taiwan Corporation. Further analysis showed that the majority of Duqu infections occurred in Iran, the initiators of the attack were interested in, as approved in the report prepared by the LC, “any information on production management systems in various industries of Iran, as well as information on trade relations of a number of Iranian organizations”. Interestingly, Duqu infection was not massive - in total, according to the reports, no more than 50 objects were affected by the attack. Symantec experts believe that Duqu was collecting data for a more accurate setting up the next version of Stuxnet.
In the spring of 2012, the Flame virus was discovered-like Duqu, this worm was engaged in collecting information: he could take screens of screens of infected computers, record audio using a built-in microphone, secretly transfer the collected data to the command-control server. Flame capabilities were extremely wide - the virus used a huge library of functions, this is a package of software modules with a total volume of 20 megabytes unprecedented for viruses (for comparison, the size of the functional part of the Stuxnet is only 500 kilobytes). A significant part of the Flame victims were in the Middle East, most of them are all in the same Iran (among the first discovered cases of infection were computers of the Iranian Ministry of Oil). Initially, LC experts considered Flame an independent project, which developed in parallel Stuxnet and Duqu, however, after a deeper analysis, they said that the authors were the same, and Flame as the platform was developed back in 2007-2008, and its modules were later used in Stuxnet. A few days after the LC published these conclusions, the Washington Post published in the publication: the authors, citing anonymous sources in the American intelligence community, said that Flame and Stxnet were joint development of the ANB, CIA and Israeli military, these tools were created as part Games ”, the task of which was to slow down the development of the Iranian nuclear program. The operation, allegedly, was started back in the mid-2000s, during the second presidential term George Bush Jr.. Sources told the newspaper that the April attack on the Iranian Ministry of Oil was carried out by Israel without coordination with the American side, and the subsequent detection of Flame caused discontent in the United States. Another certificate is the ANB document that mentioned that the Flame detection should be one of the discussion of representatives of the NSA and the electronic division of British intelligence GCHQ. Of course, there was no official confirmation, but the publication of WP became another confirmation of what has long been hinted at LC: Flame, Stuxnet, Duqu and some other viruses created on the same technological platform (for example, GAUSS, Trojan virus designed to steal financial intelligence information, primarily clients of Lebanese banks were affected), - Cyber weapons created by the efforts of the two states to attack the third state.
"Equation Group" and "shadow brokers"
In 2009, a certain scientist visited the International Conference in Houston, Texas. Some time later, he, like other participants, received a standard souvenir-a CD with photos from the conference. The scientist inserted him into his computer and began to look at the pictures, while he “had no idea that he became a victim of a powerful organization engaged in cyberspios and that had just infected his computer with harmful code, while using three exploits, two of which were exploits of zero day.” This story is about an anonymous scientist, the real name of which is not called for “protecting the secrets of private life”, is told in the LC blog, “powerful organization” is a grouping of hackers under the conditional name Equation Group, about the discovery of which Kaspersky experts announced at the Cybersecurity summit in Mexico City February in February 2015.
If Stuxnet, Flame, Duqu was simultaneously investigated by analysts from the largest antivirus companies in the world, then the Equation Group is its own trophy of LC. It was in the Moscow laboratory that this name was invented for “one of the most sophisticated hacker groups in the world”, it was Kaspersky specialists who released a detailed report on the activities of EG - almost simultaneously with the announcement of its existence.
According to this report, the group has operated at least since 2001, and possibly earlier-from 1996. During this time, hackers have developed several malicious software platforms, which became the basis for Stuxnet, Flame, Duqu, Gauss and even Regin attacks, which is associated with the British GCHQ electronic intelligence department (literally “Government Communication Center”). It turns out that the Equation Group is a prefabricated division of intelligence of the USA, Israel and Great Britain? LC, as usual, does not speak directly about this anywhere, but gives enough hints. For example, in the EG software modules, some keywords are “forgotten”, including “GROK”, “StritaCid”, “Drinkparsley”, “Stealthfighter”. These words coincide (or extremely similar) with the names of some projects and files Tailored Access Operations, the cyber unit of the NSA, which are mentioned in the secret presentation of the NSA , merged by an unknown insider by the German magazine Der Spiegel in 2013 , and given to journalists Edward Snowden in 2014.
The authors of the report do not say directly that Stuxnet, Flame and other well -known “state” cyber attacks are the work of the Equation Group, but make it clear that they used similar exploits, software modules, and had close sets of targets. “[EG] has been interacting with other influential groups for many years, such as Stuxnet and Flame,” they evasively suggest in LC. By the way, the list of the most affected countries, eloquently given in the LC report, looks like another confirmation of the connection between the NSA and EG: it is mainly Iran and Russia, as well as Pakistan, Afghanistan, India, China, Syria and Mali. Some of the EG attacks were directed very accurately, in particular, at visitors to the forums of Islamic jihadists, with some exceptions: visitors from Turkey, Egypt and Jordan should not have been subjected to infection.
So, many facts indicate that “Equation Group tools” (which may only exist on paper and in the imagination of LC experts) - cyber weapons developed by special exploration divisions of several countries, primarily the TAO, which is part of the USA of the USA. And this weapon soon fell into other hands - and showed to humanity what could turn out to be Cyberatak in the modern world.
Iranian nuclear plant in Nathanz
In May 2017, computer viruses for some time became the main characters of the editorials: mass infection of the Wannacry worker for some time paralyzed the work of some departments of the Ministry of Internal Affairs in Russia, Renault factories in France, an energy company in Spain, a Taiwan, a chocolate factory in Tasmania. A message appeared on the screen of infected computers that all the data is encrypted and decrypted only by paying a ransom - bitcoins in the equivalent of 300 US dollars. In total, more than half a million devices around the world were attacked, but most cases of infection were recorded in Ukraine, Russia and India. Later, the experts found that the attackers earned only a few tens of thousands of dollars, and the system for receiving the ransom key was originally implemented with an error, that is, there was no point in sending the hackers. Who stood behind this attack is still unknown.
A month later, another very similar attack occurred. The Monk virus, which experts dubbed Petya2.0 or notpetya, primarily struck the state and commercial companies of Ukraine, including the government network, the National Bank, the airports of Kyiv and Kharkov, and even the radiation control of the Chernobyl nuclear power plant, which was forced to temporarily disconnect from the Internet. Later, devices were subjected to infection in other countries - Russia, Western Europe, USA and India. Like Wannacry, the Petya2.0 virus required a ransom for decoding data - and again this was not the point in this, in other words, the attack was not made for the sake of profit, but to cause damage. The Russian company Group-Ib believes that this attack is the Black Energy group. However, in fact, Blackenergy is the name not a group, but a hacker attack made on Ukrainian energy facilities in December 2015. This virus is associated with the Russian group Sandworm, regularly attacking Ukrainian objects against the backdrop of the conflict between the two countries.
Both attacks, in addition to pseudo -rejuvenation and emphasis in Ukraine, are united by a curious fact: they used the vulnerabilities, allegedly developed by the Equation Group. These tools somehow fell into the disposal of the mysterious hacker group The Shadow Brokers, which in the summer of 2016 put them up for an open auction.
The screen of a computer infected with an extortionist Wannacry
The Shadow Brokers arose in the summer of 2016 as if from nowhere. On August 13, in the newly created Twitter account @shadowbrokess, there was a link to the invitation to participate in the “Equation Group cyber arrangement”. In a broken (perhaps even deliberately), its authors report: “We hacked the Equation Group. We have found a lot of equation group cyber weapons. You see the pictures. We offer you some Equation Group files for free, see? Is this enough proof? Do you enjoy !!!”.
It’s as if the US Army stole the Tomagavk missiles
One of the instruments laid out by the Eternalblue exploit was exploited, and it was on it that Wannaacry and Petya2.0 attacks were built after a few months. On the day the Wannacry attack was discovered, on May 14, 2017, Microsoft published a Fitial statement in which he openly criticized the NSA and the CIA for “accumulation of [computer] vulnerabilities”. State intelligence agencies know about holes in computer systems, for example, the one used by Eternablue exploit, but store this information with them, not allowing vendors to release patches. But what if such a cyber weapon falls into the hands of criminals? “The same script in ordinary weapons is as if the US Army stole the Tomagavk missiles,” said Brad Smith, President of Microsoft. The Authenticity of Dampa The Shadow Brokers was later confirmed by the former Minister of Defense of the United States and the CIA Director Leon Panetta, who recognized in an interview in November 2017, that these leaks were caused by a huge Damage to our intelligence and cybernetic capabilities [...] When this happens, you have to start all over again. ”
Russian security guards turn into Russian hackers at night, but only with a full moon
So in whose hands did cyberspes get? The Shadow Brokers continued to publish leaks until April 2017. Каждое объявление сопровождалось текстом анархистского толка, например, утечка конца октября 2016 года содержала призыв “взламывать” президентские выборы в США или мешать им – “Может, люди не идут на работу, ищут местные места для голосования, протестуют, блокируют, мешают, ломают оборудование, рвут бюллетени?”. В другом сообщении авторы иронизируют: “Российские безопасники по ночам превращаются в российских хакеров, но только при полной луне”. Но корявый английский язык, намеки на связь с Россией, идеологизированное содержание этих сообщений могли быть умелой маскировкой. Примечательно, что финансовый вопрос как будто с каждым сообщением все меньше интересует хакеров – они готовы отдать инструменты едва ли не бесплатно.
В ноябре 2017 года газета New York Times рассказала , что продлившееся полтора года внутреннее расследование АНБ слива The Shadow Brokers (который охарактеризован как больший ущерб американской разведке, чем действия Сноудена) изначально разрабатывало две версии – внутреннюю утечку и внешнюю атаку, причем вероятнее всего со стороны России. Or both. В связи с расследованием были арестованы как минимум три сотрудника АНБ (один из них – тот самый, с чьего компьютера антивирус Касперского сгрузил секретные файлы).
Эдвард Сноуден выступает на конференции по кибербезопасности через видеосвязь
Но рассуждая о второй версии – внешней хакерской атаке, журналисты упоминают российскую компанию, которая “готовила отчет, который позволил поменяться с США местами [в направлении хакерских атак], (...) охотилась на шпионское ПО, установленное хакерами АНБ отчасти на основе ключевых слов и кодовых имен, озвученных в файлах мистера Сноудена и опубликованных журналистами”. Эта компания, разумеется, – "Лаборатория Касперского", а отчет – описание инструментов Equation Group, которое можно сравнить с досье кибернетических возможностей АНБ.
Жертва навета или жертва провала
Итак: "Лаборатория Касперского" год за годом изучает, анализирует, описывает “государственные” атаки – Stuxnet, Duqu, Flame, Gauss, Regin, за которыми, на что регулярно намекают отчеты компании, стоят спецслужбы США, Израиля и Великобритании. Некоторые из этих вирусов ЛК анализирует параллельно с другими крупными вендорами, как например со Stuxnet, наиболее подробный отчет о котором составила калифорнийская Symantec. Другими малварями, как с Flame, российский вендор занимается заметно обстоятельнее конкурентов. Наконец, ЛК полностью самостоятельно и первой в мире описывает самый мощный киберарсенал, принадлежащий Equation Group, а на самом деле, и в этом мало кто сомневается, киберподразделению АНБ (и, возможно, аналогичным структурам некоторых союзников США). В какой-то момент в руки компании попадает архив, содержащий некоторые исходные коды этих инструментов. И вот год спустя в интернете возникает таинственная группировка, называющая себя The Shadow Brokers, которая предлагает приобрести исходные коды малварей Equation Group (используя название, изобретенное ЛК).
Кто еще, кроме "Лаборатории Касперского", так давно и старательно соблюдал информацию об арсенале АНБ, кто имеет для этого технические возможности, чей еще антивирус способен “случайно” зацепить и загрузить на свой сервер секретные документы и исходные коды малварей? Предположение, что между The Shadow Brokers и "Лабораторией Касперского" можно поставить что-то вроде знака равенства, не выглядит таким уж диким.
Эксперт по кибероружию и бывший хакер Андрей Споров уверен, что между ними во всяком случае существует связь, то есть The Shadow Brokers выставили на продажу файлы, доставшиеся им напрямую или опосредованно, например, через российские спецслужбы, от "Лаборатории Касперского". “Это мое субъективное профессиональное экспертное мнение. Я говорил про SB, когда никто в СМИ не говорил, что ЛК получила что-то, имеющее отношение к Equation. Для меня просто было очевидно сочетание всех фактов. Я никогда не верил в то, что SB видит своими целями какие-то продажи и т. п. Для меня это так же было очевидно, что это "увод в сторону", цель не в этом”, – объясняет Споров.
При этом все случившееся – от интереса Касперского к Equation Group через дамп The Shadow Brokers и к проблемам американского бизнеса ЛК эксперт называет провалом российских спецслужб. Споров рассуждает о том, что могло произойти на самом деле: компания могла передать силовикам попавшее к ней импортное кибероружие в качестве оперативных материалов, то есть для изучения и внутренней работы, но не для публичного использования или тем более публикации. Спецслужбы же из собственных политических соображений могли организовать слив информации через выдуманную группировку The Shadow Brokers и тем самым, во-первых, раскрыли свой источник и методы получения информации, во-вторых, походя, разрушили зарубежный бизнес одного из самых успешных российских несырьевых экспортеров, а в-третьих, сделали российский софт на много лет вперед токсичным, как и многое, что происходит из страны “водки, медведей и КГБ”.
В лобби "Лаборатории Касперского"
В том, что The Shadow Brokers слили файлы, полученные Касперским, уверен и украинский эксперт по кибербезопасности Шон Таунсенд . Он напоминает о порядке событий, описанном в начале этой главы: интерес ЛК к Equation Group, признанная компанией загрузка исходных файлов инструментов АНБ и – спустя год, как раз вскоре после обвинений в адрес России во взломе серверов комитета Демократической партии США, – появление инструментов АНБ на открытом рынке. “С моей точки зрения, не так уж важно, кто именно стоит за TSB, – это мог быть сотрудник Касперского, сам Касперский или к примеру ФСБ. Касперский мог отдать информацию чекистам, а реализовать ее (не в техническом, а в политическом плане) могла другая спецслужба, даже не понимая, что при этом случится с ЛК”, – рассуждает Таунсенд.
Может быть, Касперский передал ФСБ секретные файлы АНБ из патриотизма – чтобы помочь защитить страну от угрозы извне? Евгений Касперский категорически отрицает, что в принципе мог иметь такую мотивацию. “Если мы получим образец наступательного кибероружия, то мы тут же разработаем способ защиты наших пользователей и распространим его через обновления, – заявил он Радио Свобода. – Я неоднократно подчеркивал, что как частная компания мы не имеем никаких политических связей с каким бы то ни было правительством. Мы гордимся своим партнерством в сфере борьбы с киберпреступностью с властями разных стран и международными правоохранительными организациями, включая Интерпол, Европол и ООН. Повторюсь, мы сотрудничаем исключительно с борцами с киберпреступностью”.
В убедительно выглядящих описаниях того, как могла выглядеть связь ЛК и The Shadow Brokers, не хватает одного – доказательств. Евгений Касперский настаивает, что стер попавший в компанию секретный архив, и утверждает, дамп The Shadow Brokers в любом случае состоит из других файлов: “Насколько мы можем судить по телеметрии, это были разные архивы”, – утверждает он.
Независимый американский специалист Николас Вивер отмечает, что в версии о существовании связи между ЛК и сливом SB есть нестыковки: “The Shadow Brokers выложили четыре транша данных. Два из них были точно украдены с отладочных серверов под Linux, через которые аналитики из АНБ атакуют свои цели, еще один очевидно был с рабочей Windows-системы аналитика, и еще там был один набор инструментов под Windows неизвестного происхождения (возможно, с той же рабочей станции), – рассуждает Вивер. – К тому же тайминг не совпадает. Словом, есть НОЛЬ улик, что Касперский связан с The Shadow Brokers и много улик, доказывающих противоположное”.
В окончательном отчете о загрузке секретного архива в 2014 году специалисты Касперского делают особый упор на то, что американский компьютер, с которого файлы попали в сеть Касперского, был заражен более чем сотней вирусов, в том числе бэкдором Mokes, связанным с китайской хакерской группой (в начале 2010-х его предлагали приобрести в российском киберподполье, замечают авторы документа), и все это является прямым намеком на то, что секретная информация из того же архива могла оказаться не только у Касперского и именно от третьей стороны попасть в руки The Shadow Brokers.
Toxicity
В мае – июне 2017 года издание The Insider опубликовало несколько материалов о взломе почты президента Франции Эммануэля Макрона. В частности, журналисты рассказали о том, что один из взломщиков косвенно связан с Центром специальных разработок Минобороны России. Об этом же достаточно новом подразделении российской армии писало и издание Meduza в материале, описывающем, из каких частей могут состоять российские кибервойска или пресловутые “российские государственные хакеры”. Центр специальных разработок активно нанимает программистов и специалистов в криптографии. Чтобы привлечь талантливых студентов, эта любопытная организация даже регулярно поддерживает соревнования CFT (Capture The Flag) – популярную в России командную игру для white hats, то есть хакеров, которые занимаются не атаками, а защитами от них. Другим активным участником CFT-движения является "Лаборатория Касперского".
Следует ли из этого, что Касперский связан и с армейскими хакерами? Нет, но очевидно, что крупнейшая в стране компания, занимающаяся кибербезопасностью, регулярно сталкивается с соответствующими подразделениями в разведке, полиции и Министерстве обороны. В конце концов, кадров соответствующей квалификации в стране не настолько много, чтобы эти структуры не боролись за одни и те же таланты, не знали друг друга по конференциям, не были однокашниками, не перетекали между одними и теми же организациями.
Вход в здание ФСБ после акции Павленского
Яркий пример – бывший сотрудник подразделения по борьбе с киберпреступностью (управления “К”) ГУВД Москвы майор Руслан Стоянов, в 2012 году ставший главой отдела расследований "Лаборатории Касперского". МВД и ФСБ привлекали подразделение Стоянова к поиску и задержанию группировки хакеров, создавшей вирус Lurk. С его помощью со счетов пользователей в России и странах бывшего СНГ была похищена астрономическая сумма. В конце весны 2016 года правоохранители с удовлетворением отчитались о задержании преступников. А через полгода Стоянова, а также сотрудников Центра информационной безопасности (ЦИБ) ФСБ России Сергея Михайлова и Дмитрия Докучаева арестовали по обвинению в госизмене – по данным Reuters, “фигуранты дела передавали секретные данные американской компании Verisign и другим коммерческим организациям, которые в свою очередь передавали эти данные спецслужбам США”. Кстати, не задержание ли группировки Lurk, к которому привлекли "Лабораторию Касперского", имели в виду авторы расследования в Bloomberg?
Еще одна публичная связь между ЛК и спецслужбами – центр реагирования на инциденты в сфере информационной безопасности (CERT), который создается "Лабораторией Касперского" для отражения атак на ключевые объекты российской инфраструктуры, такие как атомные электростанции, предприятия ядерно-топливного, нефтегазового и энергетического комплексов. Вероятно, этот центр будет работать в связке или как часть системы "ГосСопка" (системы обнаружения, предупреждения и ликвидации последствий компьютерных атак на информационные ресурсы), создание которой в январе 2013 года Владимир Путин поручил ФСБ. Комментируя эту работу, Евгений Касперский заявил: “Мы вовлечены в экспертную работу и используем все возможности сотрудничества для борьбы с вредоносным кодом и хакерами. При этом мы всегда действуем как независимая коммерческая компания, не ангажированная госструктурами”. Кстати, не об этой ли системе защиты от хакерских атак, которой ЛК занимается по “большой просьбе с Лубянки”, идет речь в материале Bloomberg?
Evgeny Kaspersky
Мы сотрудничаем только с теми спецслужбами, которые борются с преступниками. Dot
“Мы сотрудничаем с российскими спецслужбами в той же мере, что и с любыми другими международными правоохранительными организациями. Наше взаимодействие строится исключительно на совместном расследовании киберпреступлений. Точка. Мы сотрудничаем только с теми спецслужбами, которые борются с преступниками” – так выглядит стейтмент Евгения Касперского по поводу подозрений о связи его компании с ФСБ (отдельно он подчеркнул, что истории о “группе Чикунова” в ЛК – “бред и неправда”). Можно ли было увязнуть коготком, а всей птичке не пропасть – и ограничиться совместным походом в баню, поимкой преступников и работой над большой оборонительной системой? Неизвестно, но крестовый поход Касперского против “государственных” вирусных атак не мог не заинтересовать российские спецслужбы и не стать раздражителем для американских. Теперь "Лаборатория Касперского" декларирует принцип прозрачности и готова открыть код своих продуктов, чтобы все убедились – они не занимаются поиском по ключевому сочетанию “top secret”. Основатель компании рвется свидетельствовать перед Сенатом США. Но уже, вероятно, поздно – чекистская токсичность, все сильнее поражающая Россию, перекинулась и на “Лабораторию Касперского”, словно какой-нибудь компьютерный вирус.
Первую часть расследования читайте здесь .