Skip to content
July 20, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • Former NSA hacker to expose how to subvert the Kaspersky Lab antivirus and turn it into a powerful search tool for classified documents
  • Cyber Security

Former NSA hacker to expose how to subvert the Kaspersky Lab antivirus and turn it into a powerful search tool for classified documents

Do Son January 4, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

According to Kaspersky’s case, security software can be used by intelligence agencies as a formidable spy tool. Patrick Wardle, chief research officer at Digita Security, and former NSA hacker confirmed this by subverting Kaspersky Lab antivirus software and turning it into a powerful confidential document search tool.

In an interview with The New York Times, Patrick Wardle said: “Antivirus products are the first choice for fighting malicious code.” Ironically, however, these products have much in common with advanced cyber espionage tools. “From a technical point of view, if an anti-virus maker can for some reason, such as being forced, hacked, etc., create a signature that marks a confidential file?

Last December, U.S. President Trump signed a bill banning the use of Kaspersky Lab products and services in federal agencies. According to a leaked top-secret report by Edward J. Snowden, the NSA has targeted anti-virus software (Checkpoint and Avast) since at least 2008 to gather sensitive information stored on the target machines.

Wardle reverse-engineered Kaspersky Lab antivirus software to explore the possibility of using it for intelligence purposes. The goal is to be able to write a signature that will detect confidential documents. Wardle found the code to be very complex. Unlike traditional antivirus software, Kaspersky’s malware signatures are easy to update. Researchers think this feature can be tuned to automatically scan victims’ machines and steal confidential documents.

“Modern anti-virus products are very complex software and Kaspersky is probably the most complicated one, so getting just a sound understanding of its signatures and scanning logic is a challenging task.” Kaspersky’s anti-virus The engine periodically checks for and automatically installs any new signatures. When a new signature is available, the signature will be downloaded by the Kaspersky update server’s kav daemon.

Antivirus scan may be used for cyber espionage

Wardle said officials often classified top secret documents and “TS / SCI” (“Top Secret / Sensitive Area Information”) and Wardle added a rule to Kaspersky’s antivirus program to mark any document containing “TS / SCI “document. To test the new rules, researchers edited a file on his computer containing the text of the Winnie the Pooh children’s book series with the addition of the “TS / SC” tag. Once the document is saved on his machine, Kaspersky Anti-Virus marks and quarantines the document.

The next phase of the Wardle test was to find out how to manage the marked documents, but the anti-virus software sent the data back to the company for further analysis to find it normal.

However, Kaspersky said in a statement that Wardle’s research is not correct because Kaspersky Lab can not provide specific signatures or updates to specific users in a certain secret manner, and all signatures are always made public to all users And updates are digitally signed and can not be further forged.

However, Wardle’s research shows that hacker vendors’ platforms can use anti-virus software as a search tool.

The experts concluded, “However, if a malicious or conscious insider inside any antivirus company can strategically deploy such a signature, then whenever possible, anything that is forced or willing to cooperate with a powerful agency like the government Antivirus companies are equally able to quietly use their products to detect and utilize any files of interest. ”

For details, please read All Your Docs Are Belong To Us

Source: SecurityAffairs

Related coverage

  • Fake CEO, Real Hack: North Korea Uses AI Deepfakes to Steal Crypto
  • Beware of Word: Remcos RAT Lurks in Malicious Documents
  • New Phishing Campaigns from Scattered Spider Target Finance and Insurance Industries
  • Poloniex Crypto Exchange Hacked, Over $100 Million Stolen
  • The DarkGate Deception: How Microsoft Teams Became a Phishing Playground
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Former NSA hacker kaspersky

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
  • CVE-2026-53362
    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-46242CVSS 7.8
    In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-56155CVSS 7.8
    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate...
    CISA KEV📅 Added to KEV: Jul 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-12701CVSS 9.0
    A path traversal vulnerability was found in pulpcore. The relative_path_validator function only...
  • CVE-2026-64620CVSS 9.8
    FreeRDP before 3.28.0 (affected
  • CVE-2026-16242CVSS 9.4
    A flaw was found in the Konnectivity proxy-server configuration for hosted control...
  • CVE-2026-16235CVSS 9.8
    Crypt::Password versions through 0.28 for Perl generate insecure random values for salts....
  • CVE-2026-13147CVSS 9.1
    The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL...
  • CVE-2026-44359CVSS 10.0
    Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23,...
  • CVE-2026-64162CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: idpf: fix...
  • CVE-2026-64160CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: netfs: Fix...
  • CVE-2026-64150CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner:...
  • CVE-2026-64142CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ksmbd: close...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.