Hello,

We noticed you're browsing in private or incognito mode.

To continue reading this article, please exit incognito mode or log in.

Not an Insider? Subscribe now for unlimited access to online articles.

Tom Simonite

A View from Tom Simonite

A Cyber "Warhead" With an Unknown Target

The Gauss malware uncovered last week features a mystery payload.

  • August 14, 2012

The Gauss malware described last week that targets Lebanese bank accounts still has one secret to divulge - the purpose of its “encrypted warhead” known as Godel. That’s the term used by researchers at Kaspersky, the computer security firm that described Gauss last week, for a part of the malware programmed to decrypt only when it lands on exactly the right computer system. What Godel does under those conditions is unknown, and today, Kaspersky laid out what it knows about Godel and asked for help determining its purpose.

Mystery weapon: some of the inner workings of the Gauss malware. Credit: Kaspersky

[T]oday we are presenting all the available information about the payload in the hope that someone can find a solution and unlock its secrets. We are asking anyone interested in cryptology and mathematics to join us in solving the mystery and extracting the hidden payload.

Kaspersky says Gauss is related to government-sponsored cyberweapons Stuxnet and Flame, and the company’s researchers and some other experts believe Gauss was also created by a nation state. Godel can only be decrypted with a key built using information drawn from the computer it has infected, specifically information about programs installed on the system. Until someone figures out exactly what Godel’s looking for, it’s impossible to know what it will do when activated. Kaspersky’s researchers are considering the possibility that it is intended to attack SCADA - industrial control - systems, like those in use by the Iranian nuclear program disrupted by Stuxnet:

The resource section is big enough to contain a Stuxnet-like SCADA targeted attack code and all the precautions used by the authors indicate that the target is indeed high profile.

Cut off? Read unlimited articles today.

Become an Insider
Already an Insider? Log in.

Uh oh–you've read all of your free articles for this month.

Insider Premium
$179.95/yr US PRICE

More from Intelligent Machines

Artificial intelligence and robots are transforming how we work and live.

Want more award-winning journalism? Subscribe to Insider Premium.
  • Insider Premium {! insider.prices.premium !}*

    {! insider.display.menuOptionsLabel !}

    Our award winning magazine, unlimited access to our story archive, special discounts to MIT Technology Review Events, and exclusive content.

    See details+

    What's Included

    Bimonthly magazine delivery and unlimited 24/7 access to MIT Technology Review’s website

    The Download: our daily newsletter of what's important in technology and innovation

    Access to the magazine PDF archive—thousands of articles going back to 1899 at your fingertips

    Special discounts to select partner offerings

    Discount to MIT Technology Review events

    Ad-free web experience

    First Look: exclusive early access to important stories, before they’re available to anyone else

    Insider Conversations: listen in on in-depth calls between our editors and today’s thought leaders

/
You've read all of your free articles this month. This is your last free article this month. You've read of free articles this month. or  for unlimited online access.