Security firm Kaspersky Lab today published a report detailing its version of how the NSA files were stolen.
It should be noted that US authorities had been investigating Kaspersky for suspected ties to the Russian government for many months, but nothing had become known in the first months of the year.
This fall, however, reports from the Wall Street Journal and the New York Times revealed to the public that the US government suspected that Russian FSB agents used Kaspersky's antivirus as an interactive spying machine to scan all of their service's computers.
The two media outlets reported that the NSA employee's files were also leaked in this way, and ended up in the hands of the Russian government. The specific data leak was unknown until then.
Kaspersky Lab: our software works as designed
Kaspersky denied all charges from the beginning and, especially after the publications by the two major media outlets, promised to investigate what exactly happened.
The preliminary findings of this investigation were published today. In the report, Kaspersky Lab admits that it did indeed collect secret NSA files, but did not do so intentionally, as reported by US media.
The company said the data collection process was automatic, as the files were hacking tools that were identified with signatures associated with malware. The company believed they belonged to a cyber-espionage group it was investigating at the time.
This incident occurred in 2014, and Kaspersky published a report on the group in 2015 (PDF). The group's name in the company's report was Equation Group, and most security experts admitted that it was connected to the NSA's government operations division.
The CEO ordered the destruction of the files
Kaspersky Lab did not know where the computer from which the Equation Group malware files originated came from, but says the user was using the company's antivirus and had enabled "automatic submission of new samples and unknown malware."
The company says that the files collected by this user “were new, unknown, and contained malware variants used by the Equation Group.”.
Because it was new malware, an analyst reviewed the collected data to verify and classify it. The company says that employee reported the files to the company's CEO, Eugene Kaspersky, after realizing they contained the source code for NSA tools.
Eugene Kaspersky ordered the files deleted. The company did not give a reason why its CEO made this decision, but clarified that it did not share the files with any third parties.
The “bulletproof” NSA was infected by a backdoor
The findings of this report come to confirm unofficial theories circulating in the infosec community about what really happened.
Most experts suspected that Kaspersky Antivirus was doing nothing but its job after a careless NSA employee took hacking tools from the NSA network and took them to his home for unknown reasons.
Additionally, Kaspersky Lab reported something that will shake up the US intelligence community. The company said it had seen telemetry data from the NSA employee's computer.
As the Russian company stated, the NSA agent was also infected with some malware.
Kaspersky claims that the agent used a keygen to install a pirated version of Microsoft Office. As is usually the case with Office keygens (there is no keygen for Office), the file contained malware, (the backdoor trojan Win32.Mokes.hvl).
What Kaspersky is trying to say by mentioning this detail in its publication is that some random crook was also able to gain access to the same computer that hosted the NSA hacking tools.
Overall, Kaspersky's publication provides all the nitty-gritty technical details, painting an incredible story about the events that led American officials to ban the company's software from US computers.
Let's see if the US issues a similar technical report. All the reports we have from the US about Kaspersky to date are reportedly only from anonymous sources.
Of course, Kaspersky is not necessarily innocent, as it has previously stated to the US government that it can use its AV product as a tool to help apprehend suspected terrorists.
