HomeinetHow did they manage to breach Kaspersky Lab?

How did they manage to breach Kaspersky Lab?

The state-sponsored malware used to hack into Russian security firm Kaspersky Lab used a digital certificate that had been stolen from one of the world's leading electronics manufacturers: Foxconn.

The Taiwanese company manufactures hardware for most major technology companies, such as Apple, Dell, Google, and Microsoft.

No one can say for sure why the attackers used digital certificates from Taiwanese companies, but they may have done so intentionally, trying to create false impressions that the attacks are being carried out from China, says Costin Raiu, director of Kaspersky Lab's Global Research and Analysis Team.Kaspersky Lab Foxconn Kaspersky Lab

Digital certificates are like passports that software developers use to sign and validate their code.
To hide malware behind a legitimate digital certificate, someone would first have to steal it by hacking the company that uses it.

The attack on Kaspersky Lab, with malware dubbed Duqu 2.0, is believed to have been carried out by the same hackers responsible for the previous Duqu attacks revealed in 2011.
Many also believe that the same hackers played a major role in the spread of Stuxnet, a digital weapon used to attack Iran's nuclear program.

While Stuxnet was likely created jointly by US and Israeli teams, many researchers believe that Israel developed Duqu 1.0 and Duqu 2.0 on its own.

In all of the Stuxnet, Duqu 1.0, and Duqu 2.0 attacks, the attackers used digital certificates from Taiwan-based companies.

Two digital certificates were used by Stuxnet. One was from RealTek Semiconductor and the other from JMicron. Both companies are located in the Hsinchu Science and Industrial Park in Hsinchu City, Taiwan.
Duqu 1.0 used a digital certificate from C-Media Electronics, a digital audio chip manufacturer located in Taipei, Taiwan.

The fourth digital certificate was stolen from Foxconn, which is headquartered in Tucheng, New Taipei City, Taiwan and is located about 40 miles away from RealTek and JMicron.

The fact that the attackers appear to have used a different certificate in each attack suggests they have a fairly large stockpile of stolen certs, which "is definitely concerning," Raiu says.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS