Are you planning to send malware to the US? The US military will take it, reprogram it and send it back to you, warned Major General Vincent Stewart of the US Defense Intelligence Agency last week.
“Once we isolate the malware, we will reprogram it and prepare it to use against the adversary who tried to use it against us.”
Stewart spoke at the Department of Defense Intelligence Systems Global Conference , which was attended by intelligence commanders from several countries (the United States, Canada, and the United Kingdom).
Participants also included the FBI, CIA, National Security Agency (NSA), National Geospatial-Intelligence Agency, and National Intelligence Service, along with Microsoft, Xerox, NFL, FireEye, and DataRobot.
The meeting focused on the increasing and international nature of cyberattacks. US Navy Commander William Marks explained why the cybersecurity conversation is important to them:
“Threats are no longer limited by international borders, economics, or military power. They have no borders, age limits, language barriers, or identity. The threat could come from a large nation-state, from a 12-year-old, or from a small isolated country.
Janice Glover-Jones, head of the DIA's information service, added:
“In the past, we have been inward-looking, focusing on improving our internal processes, business practices, and integration. Today, we look outward, and directly at the threat. The adversary is moving faster than ever, and we must continue to stay one step ahead.”
Of course, there are many concerns about the upcoming US strategy of retooling malware and sending it back to attackers.
Sophisticated attacks make it even more difficult to determine the origin.
What if the malware returned by the US intelligence services was received by a child who was simply experimenting with his computer?
What if the US sends malware to people who don't know their computers are part of a botnet?
