Hacker News new | ask | show | jobs
by bigiain 3005 days ago
Nice talk! I just 1.5x-ed thru the first ~30 mins.

I still think we're talking at cross purposes though - I'm not disputing Zeus works, I'm disputing that it's "super easy" to identify and then infect a machine attributable to "an intelligence official in another country".

I mean - if all I need to do is make a tcp connection - all I need is an <img> tag in a web page - the big problem is getting that webpage and/or RAT onto a GRU officer's work computer.

(And if you _do_ cover how to do that in the remaining bit of the talk, I'd love to know...)

1 comments

Don't you also have to somehow get the up-to-date list of IP Address to Employee Name (as seems to be the claim)?