Jump to content

Symantec discovers new spy software with stealth functionality

Symantec just announced the discovery of Regin, a new kind of spyware that uses Stealth technology to hide itself and what it's doing on infected machines. 

So far it has been found on ISP servers, but appears to be targeting companies, governments, research facilities, etc.  Apparently it's been active for a few years already.

 

Considering the complexity of the thing, this is designed at great expense by a government.  The question of course is which one. 

 

 

 

Source : Reuters UK

 

http://uk.reuters.com/article/2014/11/23/uk-symantec-malware-regin-idUKKCN0J70S920141123

 

Source 2 : deredactie.be (only in dutch unfortunately, but this was my first source)

 

http://deredactie.be/cm/vrtnieuws/binnenland/1.2157506

Link to comment
Share on other sites

Link to post
Share on other sites

Obfuscated malware is not a new thing, also, let me guess... it was either Russia or China, thats what they always say

Link to comment
Share on other sites

Link to post
Share on other sites

Um, this is news? We went over this in my client server systems and network security classes months ago. It's always been possible for malware to hide its actions when a scanner is getting close.

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

*cough* NSA *cough*

 

From the Reuters article : "The U.S. government and private cyber intelligence firms have said they suspect state-backed hackers in China or Russia may be responsible. "

 

Upon reading that, my first thought was : "If the story only broke today, how come the US are pointing fingers already?  Got something to hide?"

---

 

Um, this is news? We went over this in my client server systems and network security classes months ago. It's always been possible for malware to hide its actions when a scanner is getting close.

True, stealth spyware has been known to exist. However this is news indeed because they only just found this particular one and are still figuring out just what it does and where it's from.

Link to comment
Share on other sites

Link to post
Share on other sites

Wow Symantec did good for one instead of stupid norton

FANBOY OF: PowerColor, be quiet!, Transcend, G.Skill, Phanteks

FORMERLY FANBOY OF: A-Data, Corsair, Nvidia

DEVELOPING FANBOY OF: AMD (GPUS), Intel (CPUs), ASRock

Link to comment
Share on other sites

Link to post
Share on other sites

Extremetech also reported on it, and they drew their own conclusions.

http://www.extremetech.com/computing/194819-new-regin-malware-is-an-incredibly-sophisticated-spy-tool-possibly-developed-by-the-us-government

GCHQ have already been found snooping in Belgian telecom firms using much more amateuristic approaches, so it looks like the UK simply has no access to anything as advanced as Regin.

China and Russia would target the US first, so they most likely aren't involved either.

What other countries have both the capabilities and intentions to develop something like this and use it to spy on a massive scale?

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×