A Moscow-based cybersecurity firm called Kaspersky Lab has admitted it got a hold of hacking tools linked to the NSA. But it insists the tools were obtained without malicious intent and Netherlandsnot provided to the Russian government.
The Russian government did, however, wind up in possession of those tools, which include information about how the U.S. defends against cyberattacks, as well as how they penetrate foreign computer networks. Reportedly, this all came from a hapless NSA contractor. The question is whether Kaspersky was involved and, if so, to what extent — knowingly or unknowingly.
SEE ALSO: Obama tried to warn Zuckerberg about fake newsKaspersky Lab's relationship with the United States is rife with suspicion. The Department of Homeland Security ordered federal agencies to remove the lab's widely used antivirus software in September, writing in a statement that DHS was "concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks. The risk that the Russian government, whether acting on its own or in collaboration with Kaspersky, could capitalize on access provided by Kaspersky products to compromise federal information and information systems directly implicates U.S. national security."
But, as Wiredwrote on Wednesday, the U.S. hasn't provided evidence to back up its claims, leaving observers to hash out what to believe, and forcing Kaspersky customers to decide whether to ditch the software due to suspicion alone.
All this brings us back to why it's important to figure out Kaspersky's relationship to the stolen NSA tools, which, according to The Wall Street Journal, contained information about tactics the NSA uses to break into computer networks in other nations.
Kaspersky's version of events begins on Sept. 11, 2014, when, as explained in a blog post from the company on Wednesday, their antivirus software discovered "Equation malware" on a user's computer. "Equation malware" is thought to be associated with the NSA.
That user — reportedly an NSA contractor who had information about the agency's hacking tools on his personal computer — then deactivated the software for several weeks. During that time, the user evidently pirated a malware-ridden version of Microsoft Office. Upon reactivating the software, Kaspersky caught the obvious malware along with something it didn't recognize, described in the blog post as malware of "new and unknown variants," linked to that same supposed NSA malware.
Acting according to its security settings, the software sent this new malware to Kaspersky Lab HQ for further processing. A Kaspersky analyst discovered the NSA malware and "reported the incident to the CEO," Eugene Kaspersky, at which point "the archive was deleted from all our systems. The archive was not shared with any third parties."
If this is true, then several things seem possible.
The more generic malware contracted by the hapless NSA contractor when he pirated Microsoft Office reportedly contained a "backdoor" that could have allowed unknown actors to waltz into his computer and take what they wanted during the few weeks the contractor had switched off Kaspersky's antivirus software. If this is the case, then Kaspersky might be free of blame.
Of course, if Kaspersky's software is (knowingly or unknowingly) compromised, then Russian hackers might have been notified about the NSA information as soon as the antivirus software picked up on those "new and unknown variants." From there, hackers associated with the Russian government could have repeatedly targeted the NSA contractor to extract as much information as possible.
This wouldn't necessarily mean Kaspersky Lab is an active partner of the Kremlin, but, as cryptography expert Matthew Green tweeted in early October, it wouldn't be a good look for a cybersecurity firm.
This Tweet is currently unavailable. It might be loading or has been removed.
Not quite sure how that’s qualitatively different from the point of view of Kaspersky customers. But I guess it’s something.
— Matthew Green (@matthew_d_green) October 5, 2017
It's also, of course, possible that Kaspersky isn't telling the truth.
This Tweet is currently unavailable. It might be loading or has been removed.
Or, as Eugene Kaspersky implied was possible earlier this month (according to The Guardian), maybe Russian hackers hacked Kaspersky Lab.
As for the NSA contractor, the article from The Wall Street Journalthat broke the story didn't name him. He reportedly wasn't trying to help the Russian government or any other foreign body, but might've brought his work home to get more done — even though he knew it's possibly against the law to put NSA materials on a personal computer.
Topics Cybersecurity
Nope, your Android phone's secretly tracking your locationIHOP will deliver hot pancakes to your door because the future is now$30 million worth of Tether stolen in latest crypto heistFord shows off new hybrid police cars that can go 21 mph on electricity aloneDoneGood's new website gives your holiday shopping a social good boostNope, your Android phone's secretly tracking your locationThis adorable Google Doodle is an ode to kimchiAl Franken's female 'SNL' colleagues write open letter defending himOutlander episode 10 traps Claire on a typhoid ship while Jamie unravelsAngry 'Justice League' fans petition for Zack Snyder's cutDon't believe that 'Aretha Franklin is dead' tweetTwitter user trolls ‘Breitbart’ in one genius moveResearchers show that water didn't carve these dark flows on MarsCher nails the net neutrality debate in one excellent tweet'The Last Jedi' is a timely look at how women leaders are mistrustedAngry tweets pour in after Trump ends protected status for HaitiansFormer Han Solo movie directors Chris Miller, Phil Lord discuss firingAustralia is exploiting working backpackers, according to new studyIHOP will deliver hot pancakes to your door because the future is nowAngry tweets pour in after Trump ends protected status for Haitians Hinge launches voice notes and voice prompts Subtitles are the future. Sorry, caption haters. James Michael Tyler, beloved Central Perk manager Gunther on 'Friends', is dead at 59 Tesla's new feature turns your car into a security camera with remote access No, Stormy Daniels' lawyer didn't say he has Trump dick pics 'Game of Thrones' cosplay photoshoot turned into the cutest proposal SZA's mom has some words of wisdom for coping with stress and hello to our new mentor 11 best tweets of the week, including lunch meats, the Oregon Trail, and beans How 'Dune' the movie differs from the book Everything coming to Amazon Prime Video in November Google will finally give meeting hosts the power of making people shut up HHS removes key lesbian and bisexual women's health info from site Sudan, the world's last northern white rhino, dies aged 45 Hertz orders 100,000 Teslas to build the largest EV rental fleet in the U.S. 5 damning revelations from the Facebook Papers Cynthia Nixon tweets witty response to 'unqualified lesbian' barb 'Doom Patrol's Madame Rouge is the mystery that keeps on giving HBO Max’s ‘Love Life’ justifies its existence in Season 2 Ivanka Trump doing 'science' inspired a Photoshop battle for the ages So, you're worried about your boob(s)