CIA Implant: Green Lambert for OS X

(objective-see.com)

118 points | by jbegley 934 days ago

4 comments

  • dontbenebby 934 days ago
    Stupid question, but if I wanted to recreate Runa's analysis to learn these tools, where do I go to get it?

    I clicked over to Wikileaks + Kapersky's post, interested in possibly writing a small shell script to automate running some of these commands on a given file as a weekend project, but it'd be hard to test such a tool w/o the original binary.

    (Maybe it's just been a long day and I'm missing a plainly labeled link, and if so, I apologize for not RTFMing hard enough :) )

  • saagarjha 934 days ago
    > But which version of OS X does the implant need? We know that it’s a 32-bit executable, and the latest macOS is 64-bit only. We can narrow this down further by looking at symbols using nm.

    Not sure if it was useful in this case, but usually you can find this information in the Mach-O header.

  • sneeeeeed 934 days ago
    Sounds like this could have been an interesting story. Sadly there was one of those insufferable pop up email harvesting nag attempts and I instinctively closed the tab. I just can’t bring myself to reopen it.
    • junon 934 days ago
      These sorts of comments are discouraged on HN as per the guidelines. Link at the bottom of the page.
      • pocw 934 days ago
        I also find this unreadable but for a different reason. I'm on mobile and it's rendering unreadably small. On the one hand maybe I should put more time into my setup. On the other hand maybe we, the target audience of this sort of content should comment when the format is unusable. If your power users find mailing list popups annoying to the point they go elsewhere don't you want to know? Isn't a comment on hacker news a great way for someone to learn what their readers like or don't like?
        • oriki 934 days ago
          Like the guidelines say:

          > Please don't complain about website formatting, back-button breakage, and similar annoyances. They're too common to be interesting. Exception: when the author is present. Then friendly feedback might be helpful.

          If the author isn't actually present (which, as far as I can tell, they are not) it just clutters up the comments. There's no actual discussion happening here, just a lot of "wow i sure don't like this thing [website] does" and that doesn't provide very much value at all.

        • atok1 934 days ago
          I'd say this is very thoughtful and rational, and if I was the owner of the site in question, I would be thankful for poweruser comments.
    • photochemsyn 934 days ago
      NoScript on Firefox solves that problem. Yes it breaks a lot of pages, but then you get to fiddle about allowing and banning different scripts to see what's doing what. Probably not for everyone but I like the educational value.

      [Edit] So that pop-up is coming from mailchimp_com, which is called by list-manage_com, which in turn is called by s3amazonaws_com. So blocking that last one is all you need.

      In fact this is quite a great web site, as it displays all its content even if you completely disable all scripts.

    • simion314 934 days ago
      Works great with JS off. For power user I suggest a browser that let's you easily whitelist JS for the websites you need.(I use Vivaldi)
    • devwastaken 934 days ago
      I can't read it on mobile because the site fails to add a basic viewport meta tag.
    • amatecha 934 days ago
      FWIW I am browsing with Firefox with "Strict" privacy settings and didn't get any popup.
    • jcun4128 934 days ago
      It's funny I won't accept those "cookies" so I've gotten used to part of SO's screen real estate being taken. Or on a Ubuntu page I do F12/kill the popup... can put that in some kind of extension but ehh...
      • dreamcompiler 934 days ago
        Kill Sticky bookmarklet is your friend.

        https://alisdair.mcdiarmid.org/kill-sticky-headers/

        • leephillips 934 days ago
          Since I was invoking this on nearly every page I made it automatic: https://lee-phillips.org/nomorecookiewarnings/
          • occoder 933 days ago
            Thank you so much!

            Just like you, I don't want to interact with cookie warnings at all so they have been annoying me to no end.

            I even tried writing my own bookmarklet to hide them by setting "display: none" on these elements. But it sometimes fails on Stackoverflow sites, and I didn't look into it further.

            This is just what I need, thanks again!

            • leephillips 933 days ago
              I'm glad you found this useful. But it doesn't work on every site nor on every cookie warning. On some of those sites you can get rid of it by switching off javascript.
    • throaway46546 934 days ago
      uBlock Orgin
      • Xavdidtheshadow 934 days ago
        Is there a rule to block modals like this? I can add site-specific things, but I can't seem to find anything that blocks all overlays.
        • throaway46546 934 days ago
          You want to enable the "annoyance" lists. In this case it was caught by "Fanboy's Annoyance List" for me.
    • unstatusthequo 934 days ago
      The developer is pretty well respected. Click the X on the newsletter and there is great content.
    • dalrympm 934 days ago
      I had the exact same reaction. Do we have a tl;dr equivalent for these things?

      pu;dr ?

  • amatecha 934 days ago
    Where is it asserted/confirmed that Longhorn == CIA? I don't see it mentioned in the article nor the linked articles (not that I searched exhaustively).