Go back

25 March 2022 Paddy McGuinness

Should you keep using Kaspersky? As some governments warn antivirus could be ‘dangerous’, experts are silent

European governments have warned that Kaspersky could potentially be used by the Russian government to hack websites. But as official warnings increase, experts have mostly chosen to remain silent on whether it is safe to keep using the anti-virus company’s products.

Franco Gabrielli, the Italian state undersecretary for security, said last week that the government was working to replace Kaspersky software that state organisations used.

Italy’s cybersecurity agency said there is no evidence that Russian products have been compromised since the invasion of Ukraine on 24 February, but that anti-virus software could be particularly sensitive because of their “high level of invasiveness”.

The German cyber security agency has also claimed that Kaspersky’s anti-virus software could pose a serious risk if it is used by Russian government agents to hack IT systems.

“A Russian IT manufacturer can carry out offensive operations itself, be forced to attack target systems against its will, or be spied on without its knowledge as a victim of a cyber operation, or be misused as a tool for attacks against its own customers,” BSI reportedly said.

“We have received the request from the Italian DPA (GPDP) and are ready to communicate with the agency on any questions or concerns they may have”, Kaspersky said in a comment. It also released a lengthy statement to “address its and other regulators’ concerns”.

Kaspersky offers a range of software including antiviruses, VPNs, ad-blocking, anti-phishing, and more.

Antivirus software generally scans programs and files as they enter the computer, or scans software already on the device.

Kaspersky’s chief executive, Eugene Kaspersky, formerly worked for the Russian military and was educated at a KGB-sponsored technical comments, but the company has denied that it has direct ties with the Russian government.

The Department of Homeland Security issued an order in 2017 that Kaspersky products cannot be used within the US civilian federal government because of “[concerns] about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks.”

One month later, it was alleged that hackers working for the Russian government used Kaspersky software to steal classified material from an National Security Agency contractor, and it was alleged that Russian intelligence used the software to scan computers worldwide.

Kaspersky said the reports were “baseless paranoia” and a “witch hunt”, later stating that it had detected samples and source code from the Equation Group, a threat actor suspected of being connected to the Tailored Access Operations (TAO) unit of the National Security Agency.

With this controversial history, it remains unclear whether the Russian government could or would use Kaspersky software to launch attacks.

“Cyber security firms such as Kaspersky are trusted to have a presence on or around client networks and to process client data. They would therefore be aware of weak points that clients were trying to protect, legacy systems and known vulnerabilities. They open a door into a network, and highlight the best options for disruptive effect”, Paddy McGuinness of cybcersecurity company Venari Security told The Independent.

“This could be done with or without Kaspersky’s knowledge, which either way creates potential risks. If Kaspersky isn’t informed, then it may well intervene when it sees something unexpected. If Kaspersky is informed it increases the risk that an employee will publicise or obstruct it. For example, the Russian Ransomware group Conti was recently torn open in this way.”

Cyber security may become a means to attack, Mr McGuinness also said. Encrypted channels can protect attackers’ command and control technology, and the cloud “invites hard to spot zero day exploits.”

Other cyber experts contacted by The Independent refused to comment on the situation.

Article by Adam Smith, The Independent

Get the Measure

  • 23 May 2022 Hiten Mistry

    Encrypted data is good for you

    Almost all data is encrypted from end to end. That’s a good thing. Venari Security is here to make today’s encrypted world more secure and compliant. Some...

  • 20 May 2022 Simon Mullis

    Long-term operational resilience includes security planning

    With today’s greater connectivity between companies, there’s an increasing disconnect between what we need to know, and what we do know. Scenario planning...

  • 18 May 2022 Chanj Grewal

    Venari Security Townhall

    It was great to see the full Venari Security team yesterday at our monthly Town Hall meeting. These sessions are a priceless way of bringing everyone...

View more

Reassurance Can Replace Uncertainty

Once established, any deviation can be quickly identified, and the appropriate action taken for the containment of incidents.

Positive, long-term security can replace a reactive, unstable environment.

See how