Thanks for the link to that report, Polyphony. I had glanced over the news about this earlier in the week but haven't had time to read up on it much, and I just read the report.
Pretty fucking insane. With the technological links to stuxnet, and this appearing to be the precursor to stuxnet, as well as the GROK keylogger as mentioned here,
http://www.itnews.com.au/News/374987,nsa-spreads-malware-on-an-industrial-scale.aspxIt's obviously the NSA. Perhaps also in partnership with the GCHQ.
What's interesting is on page 25 of the report in discussing the PHP vbulletin exploit, it states that visitors from Jordan, Turkey, and Egypt were not infected. However, if you look at page 20 of the report, the United States is listed as being a country where victims were exploited. How nice of the NSA to extend a courtesy to people within the borders of Jordan, Turkey, and Egypt that they didn't extend to people within the United States.
This is yet another example of how truly pervasive the exploitation and surveillance is that the NSA and its nation state partners is doing. They need to be severely defunded, but that will never happen.
I wonder what sorts of data would signal an infectee as interesting?
Finally, what a great job by Kaspersky, not only in uncovering this, but actually heuristically blocking a nation state infection. I think I'm going to give them some money right now and buy their product.