Underground Tradecraft — What's the difference between an anti virus and a...

1.5M ratings
277k ratings

See, that’s what the app is perfect for.

Sounds perfect Wahhhh, I don’t wanna

What’s the difference between an anti virus and a botnet? The botnet is free.

This is a purely speculative post. I have no information or evidence that anyone is doing anything like this. I’d be surprised if they were, but I’d also be surprised if some intel agency didn’t try it.

A discussion on twitter reminded me of something I’d thought about before: what is the best possible cover for a digital espionage tool? - Anti virus.

You want a program that:

  • runs continuously
  • gets constant updates from a command and control server
  • scans every file on the system
  • sends frequent data to the command and control server
  • updates itself dynamically as required based on C&C commands
  • is completely integrated into the operating system to run at the highest privilege level
  • kills or prevents running security analysis tools (eg debuggers) to protect itself

An antivirus product is absolutely perfect for this. If I was an intelligence agency I would be looking to subvert an AV system and use that for my espionage tool.

Flame is lame! I’d rather be an antivirus. ;)