What’s the difference between an anti virus and a botnet? The botnet is free.
This is a purely speculative post. I have no information or evidence that anyone is doing anything like this. I’d be surprised if they were, but I’d also be surprised if some intel agency didn’t try it.
A discussion on twitter reminded me of something I’d thought about before: what is the best possible cover for a digital espionage tool? - Anti virus.
You want a program that:
- runs continuously
- gets constant updates from a command and control server
- scans every file on the system
- sends frequent data to the command and control server
- updates itself dynamically as required based on C&C commands
- is completely integrated into the operating system to run at the highest privilege level
- kills or prevents running security analysis tools (eg debuggers) to protect itself
An antivirus product is absolutely perfect for this. If I was an intelligence agency I would be looking to subvert an AV system and use that for my espionage tool.
Flame is lame! I’d rather be an antivirus. ;)