Subscribe Gift International Renew Subscribe
Threat Level

DarkHotel: A Sophisticated New Hacking Attack Targets High-Profile Hotel Guests

hotel-wifi
Getty Images
The hotel guest probably never knew what hit him. When he tried to get online using his five-star hotel’s WiFi network, he got a pop-up alerting him to a new Adobe software update. When he clicked to accept the download, he got a malicious executable instead.
What he didn’t know was that the sophisticated attackers who targeted him had been lurking on the hotel’s network for days waiting for him to check in. They uploaded their malware to the hotel’s server days before his arrival, then deleted it from the hotel network days after he left.
That’s the conclusion reached by researchers at Kaspersky Lab and the third-party company that manages the WiFi network of the unidentified hotel where the guest stayed, located somewhere in Asia. Kaspersky says the attackers have been active for at least seven years, conducting surgical strikes against targeted guests at other luxury hotels in Asia as well as infecting victims via spear-phishing attacks and P2P networks.
Kaspersky researchers named the group DarkHotel, but they’re also known as Tapaoux by other security firms who have been separately tracking their spear-phishing and P2P attacks. The attackers have been active since at least 2007, using a combination of highly sophisticated methods and pedestrian techniques to ensnare victims, but the hotel hacks appear to be a new and daring development in a campaign aimed at high-value targets.
“Every day this is getting bigger and bigger,” says Costin Raiu, manager of Kaspersky’s Global Research and Analysis Team. “They’re doing more and more hotels.” The majority of the hotels that are hit are in Asia but some are in the U.S. as well. Kaspersky will not name the hotels but says they’ve been uncooperative in assisting with the investigation.

“This Is NSA-Level Infection Mechanism”

The attackers’ methods include the use of zero-day exploits to target executives in spear-phishing attacks as well as a kernel-mode keystroke logger to siphon data from victim machines. They also managed to crack weak digital signing keys to generate certificates for signing their malware, in order to make malicious files appear to be legitimate software.
“Obviously, we’re not dealing with an average actor,” says Raiu. “This is a top-class threat actor. Their ability to do the kernel-mode key logger is rare, the reverse engineering of the certificate, the leveraging of zero days—that puts them in a special category.”
“Their targeting is nuclear themed, but they also target the defense industry base in the U.S.”
Targets in the spear-phishing attacks include high-profile executives—among them a media executive from Asia—as well as government agencies and NGOs and U.S. executives. The primary targets, however, appear to be in North Korea, Japan, and India. “All nuclear nations in Asia,” Raiu notes. “Their targeting is nuclear themed, but they also target the defense industry base in the U.S. and important executives from around the world in all sectors having to do with economic development and investments.” Recently there has been a spike in the attacks against the U.S. defense industry.
The attackers seems to take a two-pronged approach—using the P2P campaign to infect as many victims as possible and then the spear-phishing and hotel attacks for surgically targeted attacks. In the P2P attacks thousands of victims are infected with botnet malware during the initial stage, but if the victim turns out to be interesting, the attackers go a step further to place a backdoor on the system to exfiltrate documents and data.
Until recently, the attackers had about 200 command-and-control servers set up to manage the operation. Kaspersky managed to sinkhole 26 of the command server domains and even gained access to some of the servers, where they found unprotected logs identifying thousands of infected systems. A lot of the machines in the attackers’ logs, however, turned out to be sandboxes set up by researchers to ensnare and study botnets, showing how indiscriminating the attackers were in their P2P campaign. The attackers shut down much of their command infrastructure in October, however, presumably after becoming aware that the Kaspersky researchers were tracking them
“As far as I can see there was an emergency shut down,” Raiu says. “I think there is a lot of panic over this.”

Signs Point to South Korea

That panic may be because the campaign shows signs of possibly emanating from an important U.S. ally: South Korea. Researchers point out that one variant of malware the attackers used was designed to shut down if it found itself on a machine whose codepage was set to Korean. The key logger the attackers used also has Korean characters inside and appears to have ties to a coder in South Korea. The sophisticated nature of the key logger as well as the attack on the RSA keys indicates that DarkHotel is likely a nation-state campaign—or at least a nation-state supported campaign. If true, this would make the attack against the U.S. defense industry awkward, to say the least.
Raiu says the key logger, a kernel-mode logger, is the best written and most sophisticated logger he’s seen in his years as a security researcher. Kernel-mode malware is rare and difficult to pull off. Operating at the core of the machine rather than the user level where most software applications run, allows the malware to better bypass antivirus scanners and other detection systems. But kernel-mode malware requires a skillful touch since it can easily crash a system if not well-designed.
“You have to be very skilled in kernel-level development and this is already quite a rare skillset,” says Vitaly Kamluk, principal security researcher at Kaspersky Lab. “Then you have to make it very stable…. It must be very stable and very well tested.”
There’s no logical reason to use a kernel-level keylogger says Raiu since it’s so easy to write key loggers that hook the Windows API using about four lines of code. “But these guys prefer to do a kernel-level keylogger, which is about 300 kilobytes in size—the driver for the key logger—which is pretty crazy and very unusual. So the guy who did it is super confident in his coding skills. He knows that his code is top-notch.”
The logger, which was created in 2007, appears to have been written by someone who goes by the name “Chpie”—a name that appears in source code for the logger. Chpie is the name used by a South Korean coder who is known to have created another kernel-level key logger that Raiu says appears to be an earlier version of this one. The key logger in the DarkHotel attack uses some of the same source code but is more sophisticated, as if it’s an upgraded version of the earlier keylogger.
Aside from the sophisticated key logger, the attacker’s use of digital certificates to sign their malware also points to a nation-state or nation-state supported actor. The attackers found that a certificate authority belonging to the Malaysian government as well as Deutsche Telekom were using weak 512-bit signing keys. The small key size allowed the attackers, with a little super-computing power, to factor the 512-bit RSA keys (essentially re-engineer them) to generate their own digital certificates to sign their malware.
“You very rarely, if ever, see such techniques used by APT (advanced persistent threat) groups,” Raiu says. “Nobody else as far as we know has managed to do something similar, despite the fact that these certificates existed for some time…. This is [an] NSA-level infection mechanism.”
These sophisticated elements of the attack are important, but the most intriguing part of the DarkHotel campaign is the hotel operation.

Unravelling the Mystery of DarkHotel

The Kaspersky researchers first became aware of the hotel attacks last January when they got reports through their automated system about a cluster of customer infections. They traced the infections to the networks of a couple of hotels in Asia. Kamluk traveled to the hotels to see if he could determine how guests were being infected, but nothing happened to his machine. The hotels proved to be of no help when Kamluk told them what was happening to guests. But during his stay, he noticed that both hotels used the same third-party firm to manage its guest WiFi.
Some hotels own and operate their network infrastructure; others use a managed services firm. The company managing the WiFi network of the two hotels Kamluk visited wishes to remain anonymous, but it was an unusually willing partner in getting to the bottom of the attacks. It acted quickly to provide Kaspersky with server images and logs to track down the attackers.
Although the attackers left very few traces, “There were certain command lines which should not have been there in the hotel system,” a senior executive with the managed-services company says.
In one case, the researchers found a reference to a malicious Windows executable in the directory of a Unix server. The file itself was long gone, but a reference pointing to its former existence remained. “[T]there was a file-deletion record and a timestamp of when it happened,” says Kamluk. Judging from traces left behind, the attackers had operated outside normal business hours to place their malware on the hotel system and infect guests.
“They started early in the morning before the hotel staff would arrive to the office and then after they leave the office they were also distributing the malware then,” says the senior executive. “This is not just something that happened yesterday. These are people who have been taking their time. They’ve been trying to access networks over the last years.”
It’s unclear how many other hotels they’ve attacked, but it appears the hackers cherry-pick their targets, only hitting hotels where they know their victims will be staying.
When victims attempt to connect to the WiFi network, they get a pop-up alert telling them their Adobe Flash player needs an update and offering them a file, digitally signed to make it look authentic, to download. If the victims accept they download, they get a Trojan delivered instead. Crucially, the alerts pop up before guests actually get onto the WiFi network, so even if they abandon their plan to get online, they are infected the moment they hit “accept.” The malware doesn’t then immediately go to work. Instead it sits quietly for six months before waking up and calling home to a command-and-control server. Raiu says this is likely meant to circumvent the watchful eyes of IT departments who would be on the lookout for suspicious behavior immediately after an executive returned from a trip to Asia.
At some of the hotels, only a few victims appear to have been targeted. But on other systems, it appears the attackers targeted a delegation of visitors; in that instance, evidence shows they tried to hit every device attempting to get online during a specific period of time.
“Seems like some event occurred or maybe some delegation visited the hotel and stayed there for a few days and they tried to hit as many members of the delegation as possible,” Raiu says. He thinks the victims were ones the attackers couldn’t reach through ordinary spearphishing attacks—perhaps because their work networks were carefully protected.
Kaspersky still doesn’t know how the attackers get onto the hotel servers. They don’t live on the servers the way criminal hackers do—that is, maintain backdoor access to the servers to gain re-entry over an extended period of time. The DarkHotel attackers come in, do their deed, then erase all evidence and leave. But in the logs, the researchers found no backdoors on the systems, so either the attackers never used them or successfully erased any evidence of them. Or they had an insider who helped them pull off the attacks.
The researchers don’t know exactly who the attackers were targeting in the identified hotel attacks. Guests logging onto WiFi often have to enter their last name and room number in the WiFi login page, but neither Kaspersky, nor the company that maintained the WiFi network, had access to the guest information. Reports that come into Kaspersky’s automated reporting system from customers are anonymous, so Kaspersky is seldom able to identify a victim beyond an IP address.
The number of hotels that have been hit is also unknown. So far the researchers have found fewer than a dozen hotels with infection indicators. “Maybe there are some hotels that … use to be infected and we just cannot learn about that because there are no traces,” the network-management executive says.
The company worked with Kaspersky to scour all of the hotel servers it manages for any traces of malware and are “fairly confident that the malware doesn’t sit on any hotel server today.” But that is just one network-management company. Presumably, the DarkHotel operation is still active on other networks.
Safeguarding against such an attack can be difficult for hotel guests. The best defense is to double check update alerts that pop up on your computer during a stay in a hotel. Go to the software vendor’s site directly to see if an update has been posted and download it directly from there. Though, of course, this won’t help if the attackers are able to redirect your machine to a malicious download site.
We were unable to load Disqus. If you are a moderator please see our troubleshooting guide.
Avatar
Join the discussion…

  • in this conversation
⬇ Drag and drop your images here to upload them.
Sign in with
or register with Disqus
?

Disqus is a conversation network

  • Disqus never moderates or censors. The rules on this community are its own.
  • Your email is safe with us. It's only used for moderation and optional notifications.
  • Don't be a jerk or do anything illegal. Everything is easier that way.
Be the first to comment.
  • Howard Treesong 4 days ago
    "Hi, I'm a process on a server you don't know. Can I install some files on your computer?"
    No. The answer is no. Never.
    I find all stories about problems with computers and malware a bit odd, seeing as how at some level the user has to cooperate. This user does not cooperate. This user trusts no one, for any reason, ever.
    I don't know what strangled-by-his-own-umbilical-cord idiot came up with the idea of 'trusted certificates'. What is going to be the first vector for any attack? That which the user ostensibly [has to] trust[s]. Do these characters have no idea what words mean? It's all a meme now, it no longer matters?
    Who can you truly trust in life? Very few people. Who can you trust online? Absolutely nobody. Is this something people are really too dumb to learn or will the lesson sink in at some point?
      see more
      • RationalCenter > Howard Treesong 4 days ago
        The point of the article is that the site was able to successfully masquerade as a trustworthy site. This is not an example of clueless users, it's an example of a very sophisticated attack that would work on the vast majority of computer users, even many experienced ones.
        Our entire technology ecosystem is predicated on constant updates - Windows, Adobe, even Kaspersky need updates on an almost daily basis, many just for security reasons. You can't tell people that they have to keep their computers updated to be safe, and then call them stupid for installing an update that by all appearances is from a trusted source. That's a system issue, not a user issue.
          see more
          • Howard Treesong > RationalCenter 3 days ago
            "masquerade as a trustworthy site".
            Hello? *knock knock* is there anyone alive in there?
            There are -no- trustworthy sites. Such a thing does not exist on this planet. Read the words. 'trusted sites'. There are sites the traffic of which you begrudgingly have to accept. That does not mean I trust them. That is never what it means. I do not trust them, I have not trusted them before and I will never trust them hereafter. The concept of 'trust' is something entirely different than the need to accept traffic from the site. Entire national security departments are filled with people chuckling at the notion of users 'trusting' sites.
            Seriously, do people no longer care about what words mean?
              see more
              • Unlo4 > Howard Treesong 3 days ago
                You keep using that word. I don't think it means what you think it means (in an IT context).
                  see more
                • foobar > Howard Treesong 7 hours ago
                  I don't think you understand what you're talking about. Do you use Windows? Mac? Linux? You're trusting their makers. A browser? You're trusting the people who made that too. You cannot use a damn computer without trust. Well, here you are -- you've entered a password to make this post, and in doing so, you've trusted the computer, operating system, browser, etc... Accepting a signed update is no different.
                  I don't care if you don't trust the people on the internet; you trust the software you are using, which is what we're talking about here. The malware in question was signed so that it would be trusted, so you cannot ridicule those who are accepting a trusted update.
                    see more
                    • Howard Treesong > foobar 3 hours ago
                      Somebody once ran your head into a steel bulkhead and they kept on doing that for half an hour straight until your face looked like raw beef or something.
                      Using something does not of and by itself imply that it is trusted. I do all the things you say, it is not as if I do not download apps, update them or use passwords. I do those things that the systems allows or builds an interface for, it does not mean, not by a long shot, that I trust these things.
                      I have over 45 dictionaries, 30 of which are in English. Do you want me to send you a copy so that you can look up what the definition of trust is?
                        see more
                      • avguy > Howard Treesong 2 days ago
                        You say "accept traffic" from sites, which seems to be another way of saying you download and install executable code/updates from some sites, if begrudgingly because nothing online is truly safe. Regardless of how you personally feel in your brain, you are saying by your actions that you TRUST those sites by allowing them to execute code on your computer, just like most of the computing public. Do you take any other measures before or after "accepting traffic" that the rest of the public does not?
                        Actions matter much more than thoughts, and I think you're getting hung up on a word and missing the big picture, no?
                          see more
                          • Howard Treesong > avguy 2 days ago
                            I say 'accept traffic' I do not say 'trust' and I do so for a very real reason. I can accept something without trusting it.
                            To wit: I 'accepted' traffic from an application that updated to a new version. This was right after that company was taken over by a new crew. The product had up to that point performed to specification. After the update, which was mandatory if I wanted to keep using the service, the update destroyed two databases that were totally unrelated to the application.
                            I do not trust any content that comes in from any direction across the internet or a volume that I have not populated myself. I'll say again: I begrudgingly accept incoming traffic. I never, not a single time, trust anything that reaches me over the internet and other people get no access to my computer for any reason.
                              see more
                              • avguy > Howard Treesong 2 days ago
                                It's not just "traffic", it is executable code that performs operations on your computer. When I need an update to a piece of software or need to install software in the first place, I perform my due diligence and, not being able to view the source code in many cases, I have to place TRUST in the provider that the code will not do anything bad, because I don't have a way to verify. Even further, there is plenty of source code out there that I wouldn't be able to understand even if I did review it and compile it myself (and I have to trust the compiler anyway).
                                When you require an update to a piece of software, you download and install it, without reviewing source code or anything like that, yet you claim that you don't trust that code. If that is truly the case, then why the hell are you installing it? It's not *required*, as there is plenty of open source software out there and you are of course free to write your own - see "if I wanted to keep using that service" - why do you use a service that you don't trust? Do you trust that the guy who serviced the brakes on your car did so competently? Or is that just "accepting traffic" that is required to keep the car operational, and you don't trust the work but drive the car anyway? Your argument is ludicrous.
                                Back on topic, I'm assuming that a non-expert is not familiar with code review/diffs, checksums, package management, and compiling. Is there a better way than signed certificates to indicate to a non-expert that the software he is about to install came from the provider that he thinks it's coming from (which he trusts based on the parameters above)?
                                  see more
                                  • Howard Treesong > avguy a day ago
                                    You seem to have an unbelievably hard time accepting the fact that one can at once use something without trusting it.
                                    "Do you trust that the guy who serviced the brakes on your car did so competently?" Have you truly not heard about car manufacturers who willingly and knowingly introduced vehicles on the market of which they were fully aware that they contained design flaws that were guaranteed to result in accidents and/or deaths and that they weighed the cost of recalling and repairing them against the cost of any resulting law suits? Do you really stumble through this world in a narcotics-induced pink cloud of never-ending happiness?
                                    Have you not heard about the fact that national security agencies deliberately weakened security protocols so that they would have easy/easier access to systems and data? Does the name Edward Snowden mean anything to you at all?
                                    All my use of systems is only and exclusively a balancing act between my perceived use of them and the implied risk of using them. I manifestly DO NOT trust any entity, any signer of certificates. Have you not read this piece? It is specifically about forging certificates to gain access to systems. That which is implicitly trusted is THE FIRST attack vector of anyone with nefarious purposes. No I do not trust these things and I never will and that is not because I wear a tinfoil hat or because I suffer from paranoia, it is because that is the world we live in.
                                    My argument is useless because all the idiots who leave their computers on taxi seats or in trains, or get robbed, who have a copy of a database that contains my data, were all very trustworthy if not a little forgetful/unlucky. Our dear Chinese friends are so known for ripping all data off of electronic devices that corporations have protocols for how to handle electronic devices when they go to China on business travel. That is how ridiculous my argument is.
                                      see more
                            • Sergio Ortiz > Howard Treesong 4 days ago
                              So you're saying you don't download updates for your operating system then? Or for your antivirus? Because if you do, then you're trusting someone somewhere online.
                                see more
                              • Andy H > Howard Treesong 4 days ago
                                "Is this something people are really too dumb to learn or will the lesson sink in at some point?"
                                I think we both know the unfortunate answer to that question. Some users just shut off their brains when it's anything computer related and others refuse to take even basic precautions because it's just too inconvenient. Somehow they don't understand that "it shouldn't work that way", "it should know what I want/mean" and "they shouldn't be able to do that" are fine sentiments but utterly meaningless in the real world.
                                  see more
                                  • moleculethecat > Howard Treesong 4 days ago
                                    Well said. I NEVER download and install software from a server I don't know and/or trust.
                                      see more
                                  • Justicer23 4 days ago
                                    Hmmmm... Rats at night,.....Ghosts at daylight!!! Insider Job? Negative... -> Many Hotels!...
                                    Outsider? With the ability to deep intrusion every night and purging their bread crumbs till morning!!!... -> NotSuchAgency skills!!!
                                      see more
                                      • YaPiDo 4 days ago
                                        "The best defense" is to insist on a MicroSoft product that stops stuff like this. Instead they keep messing with the GUI and the Start Button.
                                          see more
                                        • bogorad 4 days ago
                                          Kasperski! Stopped reading right there. These pitiful fear-mongers will say anything to cheat you out of your money.
                                            see more
                                            • slave138 > bogorad 4 days ago
                                              Maybe next time you should try reading a little more then. If you had, you might have realized that your whine makes no sense at all in the context of this article.
                                              If they were trying to scare people out of their money, why would they admit they don't know who exactly is doing it, where (other than a few examples they could find) it has been done, or how to stop it from happening again?
                                              Their software obviously wasn't stopping it because they received the reports of suspicious activity from users who were already infected.
                                                see more
                                                • bogorad > slave138 4 days ago
                                                  Oh, this one's easy - they just want to keep paranoia in people's minds as strong as possible. I knew a guy from Elya-Shim (google it!) who told me that most viruses were written by them. Big surprise it goes on.
                                                    see more
                                                    • slave138 > bogorad 4 days ago
                                                      I know a guy from McAfee who told me most viruses were written by Norton. I know a guy from Norton who told me most viruses were written by Memco. I know a guy from Memco who told me that Elyashim wrote most of the viruses but blames Kaspersky for doing it. I know a guy from Kaspersky who doesn't say much of anything because he's always drunk.
                                                      Similar rumors have been going around the antivirus industry for just about as long as the industry has been around. None of which has ever been proven. They always have the earmarks common to urban legends and chain email B.S.
                                                      Don't you think if Elyashim (or any other AV company) had proof that one of their competitors was writing viruses to drum up business, they would expose them properly rather than starting a friend-of-a-friend whisper campaign?
                                                        see more
                                                    • Unlo4 > bogorad 3 days ago
                                                      So... this is all a big lie?
                                                        see more
                                                      • Rick Fictus 4 days ago
                                                        Users should not have permission to update software, period. If you want to do any updates, you should have to log out, log in as an administrator, and do it there. Yes, I'm aware of how sudo works, but complete separation of the accounts, with lockdown of the administrator account as far as install vectors, is the only way to go.
                                                          see more
                                                          • FistOfReason > Rick Fictus 4 days ago
                                                            Interesting how that's how OSX is configured by default. Plus, even if the user has permissions, the file must be set to executable before it can run. Yay POSIX!
                                                              see more
                                                              • slave138 > FistOfReason 4 days ago
                                                                Interesting that OSX (with default configurations) still manages to be compromised each year at the Pwn2Own competition.
                                                                  see more
                                                                  • FistOfReason > slave138 3 days ago
                                                                    It takes a team of attackers to compromise OSX, yet Windows can be compromised be any third rate script kiddie.
                                                                      see more
                                                                      • slave138 > FistOfReason 3 days ago
                                                                        Even third-rate script kiddies know that there's nothing worth stealing from an OSX machine. Crappy indie films and emo hipster poetry just isn't worth a scripted attack. Also, this article is about a "team of hackers".
                                                                        Funny that as soon as there's something worth grabbing (celeb photos), the iCloud was compromised pretty quickly by 3rd rate script kiddies. It should also be noted that Apple put out a warning today about the exact same kind of vulnerability described here affecting iOS devices - You know, their only product with widespread usage?
                                                                          see more
                                                                          • FistOfReason > slave138 3 days ago
                                                                            HAHA!! You kids crack me up, no wonder nobody takes you seriously. Actually iCloud was penetrated with a device meant for law enforcement, but I'm sure you know that since you have such exteneive experience. Plus, OMac users tend to have higher incomes; thus proving to be very tempting targets. But keep believing what your MCSE tells you.
                                                                              see more
                                                                              • slave138 > FistOfReason 3 days ago
                                                                                To quote your earlier post: Wrong.
                                                                                iCloud was hacked by people on 4chan using phishing and brute force methods to obtain account passwords. It had nothing to do with the law enforcement devices.
                                                                                Where do you dream up your extensive levels of complete B.S.?
                                                                                As for incomes and OS usage: It's one of those misleading statistics that get passed around like it means something significant. Yes, OSX users tend to have higher incomes than the average Windows user, but there are a lot more wealthy people using Windows than OSX.
                                                                                OSX is used by less than 10% the consumer market. Assuming Windows is limited to only 60% of the market, that still means there are likely a lot more wealthy users on Windows than OSX. This is also not surprising since OSX systems tend to cost significantly more than Windows systems. It only goes to figure that their userbase will have more wealthy users.
                                                                                As for iOS: it did manage to capture a significant userbase with a higher average income. Which is precisely why it is being successfully targeted.
                                                                                  see more
                                                                                  • FistOfReason > slave138 3 days ago
                                                                                    Wrong, completely. You must enjoy being abused! No, iCloud was hacked by this:
                                                                                    http://www.wired.com/2014/09/e...
                                                                                    Without the device the hack wouldn't work. "none of the cases we have investigated has
                                                                                    resulted from any breach in any of Apple’s systems including iCloud or
                                                                                    Find my iPhone." Plus you seem to forget DropBox accounts were hacked too.
                                                                                    Wealthy people don't use $200 Acers. I work for a Mercedes & BMW dealer, just about all of our customers come in here with Macbooks.
                                                                                    Sorry kiddo you're wrong, quit while you're behind. As for market share, didn't GM have 90% of the car market for the world? Then Toyota came in at 10%. Then 15%. The biggest sector for Mac's growth? The enterprise! w00t!
                                                                                    Having said that, OSX should be targeted more because people want to rob the house on the hill, not the crackhouse next to ehe tracks. (Windows=house on the tracks, OSX=house in the hill, for clarification).
                                                                                    As for iOS being "successfully" targeted, you call this successful?
                                                                                    http://www.businessinsider.com...
                                                                                    How long was Wirelurker a threat? A week? In China?
                                                                                    Don't be butthurt by Apple's superiority, just accept it and move on with life.
                                                                                      see more
                                                                                      • avguy > FistOfReason 2 days ago
                                                                                        I really don't get the fanboyism on either side. "Apple's superiority" can be shot down in minutes by an incompetent user misconfiguring it or installing malware (yes, some malware actually targets Apple). I have seen people open up an OSX terminal and paste in commands from some random website, not knowing at all what it means, in an attempt to change a setting or install a program.
                                                                                        That's not Apple's fault, of course - my point is that people are stupid in general, and more stupid people globally run Windows - if your figures are correct and consistent, that could change to OSX as they gain market share, and other people will blather on about the superiority of Windows. Today, a default OSX configuration puts a few more barriers between the user and certain doom than a default Windows configuration. Further, many programs written for Windows make no attempt to use the built-in UAC mechanisms, which conditions users to always blindly click "yes, allow, jesus tapdancing christ just open" and a poorly written OSX program (of which there are many) require users to enter an admin password during normal use.
                                                                                        This is not a problem inherent to some security flaw in either OS, but in the way that the public is being trained to use and maintain software written by third parties.
                                                                                          see more
                                                                                        • slave138 > FistOfReason 3 days ago
                                                                                          How cute - you thought you actually had an argument this time, but alas, it was not to be...
                                                                                          The "device" you describe is not the one typically described as used by law enforcement to download phones during police stops, but is instead, a program (you know, like a script) which can be used to obtain more content from iCloud by impersonating the owner's mobile device. They used another script called iBrute to get access to the accounts but this program allowed them to get more.
                                                                                          So, using scripts (the one from Elcomsoft and iBrute) they were able to access iCloud user data. That would make them script kiddies in the traditional sense that they use software someone else wrote to "hack" a system.
                                                                                          I don't give two steamers where you work. You are just confirming what I already said. OSX actually only has around 7-8% of the marketshare for laptops and desktops as of last month. The only Windows OS released this century with less marketshare was Vista.
                                                                                          So for every 100 computers is use, 8 of them are running OSX. Not everyone using OSX is rich, but the percentage is higher. If 3 rich people (say $100+k/year) buy OSX for every hundred computers made, you could say almost half of all OSX users are rich - which sounds impressive.
                                                                                          Then consider that 86 out of the hundred are using Windows machines. If they have twice the number rich people (6) buy their computers, that would mean that a little under 7% of their users are rich - even though twice as many are using their systems. If you are just looking at the percentage of rich people using an OS, OSX looks like a good target until you realize it is a very small pool.
                                                                                          Yes, if you only wanted to target a couple users and wanted to increase your odds of a good payout, going after OSX would make sense. If, on the other hand, you realize that you can operate in bulk an improve your overall haul, it makes a lot more sense to focus on the system that is nearly everywhere.
                                                                                          Quantity will beat out quality almost every time, because even if you manage to hit the handful of wealthy OSX users, you have to hope that they can be tricked into running the exploit.
                                                                                          Your House-on-the-Hill analogy is just as weak as the rest of your points. It assumes that all the valuable property is held by OSX users on the hill. Sure, they could rob the 3 houses with ABC security. Or they could go after the 6 houses with XYZ security. The twist: Going after XYZ also allows them to clean out 80 other houses of varying degrees of wealth, while ABC only lets them get 4 more.
                                                                                          It's funny how iOS exploits are considered minor (by you) because it was only around for a week or so (that they know of). It exploits the same weakness as the one in this article - tricking someone into installing malware disguised as an update. If you read the details, they just blocked the apps that were being used to infect the phones. Sounds like a bandage rather than a fix.
                                                                                          Wirelurker was only one implementation of the flaw and the hole doesn't appear to be filled:
                                                                                          http://www.cnet.com/news/apple...
                                                                                          Don't worry, Apple will keep putting out fashionable commercials to make you feel like you're not getting ripped-off by buying subpar products at luxury prices.
                                                                                            see more
                                                                          • FistOfReason 4 days ago
                                                                            Figures, this awesome malware runs on... WINDOWS! What a surprise! Sometimes I click on something I know is hostile and Safari downloads an EXE file. What an absolute joke!
                                                                              see more
                                                                            Nothing for you here ... yet. But as you comment with Disqus and follow other Disqus users, you will start to receive notifications here, as well as a personalized feed of activity by you and the people you follow. So get out there and participate in some discussions!
                                                                            WIRED.com © 2014 Condé Nast. All rights reserved. Use of this Site constitutes acceptance of our User Agreement (effective 01/02/2014) and Privacy Policy (effective 01/02/2014). Your California Privacy Rights.
                                                                            The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Condé Nast.
                                                                             
                                                                            0%
                                                                            10%
                                                                            20%
                                                                            30%
                                                                            40%
                                                                            50%
                                                                            60%
                                                                            70%
                                                                            80%
                                                                            90%
                                                                            100%