• ikidd@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    8 months ago

    Well, it doesn’t invalidate the analysis.

    This was a sophisticated attack happening over 2 years, from knowing the current maintainer was emotionally vulnerable to the structure of using the build system to introduce the patched code to Linux distro repos.

    I’m guessing Kaspersky will come to the same conclusions many others have; that this was a state actor or similiarly well heeled group.

    • Xavienth@lemmygrad.ml
      link
      fedilink
      arrow-up
      2
      ·
      8 months ago

      First time I’ve seen somebody acknowledge that it’s not just nation states with such capabilities. There are some huge organized crime syndicates.