# Librarian Likho — an APT group combining cyberespionage and financial motivation Alexey Shulmin · Kaspersky MOSCOW FORENSICS DAY ’25 · Day 2 — Friday, 12 September 2025: information security day · Scheduled 11:40–12:10 · In the recording 04:50:31–05:28:02 Talk transcript · https://2025.moscow-forensics-day.workers.dev/en/transcript/12-shulmin Summary: https://2025.moscow-forensics-day.workers.dev/en/summary/12-shulmin · Slides: https://2025.moscow-forensics-day.workers.dev/en/slides/11-shulmin-librarian-likho · Watch from 04:50:31: https://youtu.be/4V7Wez3L_58?t=17431 --- ## Moderator's introduction Overall, our next story will be like, well, when our next speaker pitched it to me, it will be, as I understand it, something like a real little cyber-detective story, probably, because, all in all, it's got everything. So we've got greed for profit there, and espionage as well, a proper decent little action flick. So, how APT groups operate — Alexey Shulmin will tell us that. Let's give him a round of applause. I'm sure it's going to be super hot. Right, here you go: the clicker, the microphone. ## Talk and Q&A Check, check, check. Hi everyone, hello, hello, dear attendees, dear colleagues. My name is Lyosha, I'm from Kaspersky, a malware expert in the Advanced Threat Research Department. And today I'm here to tell you about one group whose activity we investigated. I think it'll be interesting, because it's, you know, on the one hand fairly ordinary, on the other hand it has some unique features of its own, which I'll tell you about today. So, let's go. The group is called Librarian Likho. Originally it was called Librarian Ghouls. We assigned it to the Ghouls cluster because we considered it cybercrime. But actually we later renamed it Librarian Likho, because we realized that the main motivation is, after all, cyber espionage, and the financial motivation is secondary for this group. Look, I'd like my talk to be fairly lively, so if there are any questions or remarks, please speak up, we'll discuss. I'll add some details, throw in some more things. I hope it'll be lively and interesting enough. So, let's go. Actually, what I'm going to tell you is a small part of our big research report. It came out very recently. We worked all summer; there was a big team of authors who worked on this research. It's presented here, it's called "Notes of a Digital Auditor". It's no marketing bullshit, there's none in there, don't even hope; it's technical meat, roughly 330 pages. Here's the QR code, please grab it, it's free, read it. We looked at three threat clusters there; it's about Ukrainian groups operating against Russia first and foremost. We split them into three clusters. The first cluster is hacktivists, those who break things just for the sake of breaking them, to get some message across to their public. The second cluster is cyber espionage, the APT groups; their main goal is to get some data, find something out, hunt for some know-how and so on. And the third group is everyone else. Lots of meat, lots of interesting technical meat, and reading this work will, overall, let you form a picture of how the adversary operates, what main techniques, tactics and procedures they use, and, generally, how to defend against it. Because the main goal of Threat Intelligence, one of the main goals of Threat Intelligence, is to know your enemy. We need to know who's attacking us, we need to know how to fight it off. So please, download the report, it's out digitally as a PDF, it's free. It's available in English too; if our customers speak English, it can be requested. And please, have a look. Besides that, besides just the description, our report also comes with interesting diagrams, graphs built in Obsidian, which you can load, look at, click through with the mouse and move around. Tons of IOCs there, the whole infrastructure, well, the part of the infrastructure that we found, so you know what to ban, so you know which IOCs to pull into your infrastructure and block, or conversely, to search for them, in case it's already happened and you're unaware. So, now let's go, to what we're actually talking about today. It's Librarian APT, Librarian Likho APT, it's an APT, also known as Librarian Ghouls, that's how we attributed it before; our colleagues from other vendors call it either Rare Wolf or Rezet; I'll say a bit more about why. Let's take a look at what it is. It's actually an APT performing the classic role, the classic function of any APT: stealing data. There's a sponsor behind it, no doubt, an APT, i.e. some large agency stands behind this APT's development. It's state-sponsored, so we can assume the developers have essentially unlimited resources, because, you see, however big the company countering them is, if it's a commercial vendor, the resources are still limited. When it's special tooling used by intelligence services, of course, the resources there are essentially limitless, because the stakes are very high. The main task is cyber espionage. But then again, why not steal money too, if the opportunity is there. I'll show you how these guys operate, what they do. These guys hit Russia, the Republic of Belarus, Kazakhstan. Mostly they hit industrial enterprises, to steal from them. Also, research institutes, design bureaus, so-called think tanks and universities get hit too, as we noted. Big universities at that, national ones and so on, too. The developers follow the KISS principle, Keep It Simple, Stupid, because they don't want to overcomplicate. Actually, there may be two reasons here. First reason: we don't want to overcomplicate because we've got clumsy paws and can't write proper code. Second reason: we won't overcomplicate because, here, have some legitimate tools, now try to detect them, it'll be hard for you. Well, they think it'll be hard for us; in fact, we've seen all sorts of things, and so we've already adapted to everything; we'll detect legitimate tools if they're used in an illegitimate way. This is how they hand out their little gifts. Look, this is a real example of a spear-phishing email that they use as the initial vector. Here's what arrives; the sender may be real or may be spoofed, they can first compromise someone and then send it in their name, or simply spoof who the email really came from. Some little attachment. Every time I speak at conferences, which happens quite often, every time I say: security awareness, security awareness, and once again security awareness. Unfortunately, it's 2025 outside, and in this room too, by the way. And people still run.pdf.exe attachments. You understand? It's funny, but they run them. They run them. It's actually a big problem, I don't know what to do about it. I'm now investigating another threat, which, due to certain internal processes of ours, I'll talk about a bit later, because first we'll release the report, then an article, then I'll talk about it at conferences. So there I observe, for example, the attacker sending a command to their implant to upload a file from the user; they want to steal a file from the user. So they grab a file from the user's desktop called "logins and passwords.xlsx". Employee logins and passwords.xlsx. 2025, right — if you don't kill people for this, then what do you kill them for? I mean, where's the security awareness, where's at least some minimal knowledge of what's supposed to happen? And these aren't some small outfits, these are quite large, large victims. But, to be fair, I've also seen cases where victims fend off such attacks quite successfully, respond quite successfully, and, all in all, the attackers don't get very far. So this is what arrives, and unfortunately they open, open the attached archive. I just gave you an example I found, an example of such spear phishing I found, but we'll look at a slightly different gift of theirs. We'll look at this archive they hand out. Let me go to the next slide. Ah, here. Right, I don't have a laser pointer here. Okay, look. So a RAR archive arrives as the attachment, named like this: "payment order", then 2N. That's the original spelling, I'll leave it. By the way, mistakes like these make it pretty easy to figure out who might be behind this group. Later I'll show you a few more interesting artifacts we found during the investigation — you may draw some conclusions of your own too. Inside is a file with the.scr extension. That's the screensaver extension, for screen savers, but in fact it's a perfectly ordinary MZ/PE, which, if launched via ShellExecute, runs like a regular executable. So it's a regular executable file. Well, maybe they swapped the icon, maybe not, it doesn't matter anymore. But anyway, users, unfortunately, run it. What's inside? Inside we have a classic MZ/PE built with Smart Install Maker. Smart Install Maker is a fairly simple utility, you can unpack it yourselves, there are free unpackers, or you can knock one together in Python, it's literally a few lines, because it's incredibly simple. Inside there are three little files. data.cab is a cabinet file containing the main payload of this archive. installer.config is the installer's configuration file, which specifies what to actually do during installation of this self-extracting archive. And runtime.cab, that's some cab, I have no idea what it's for, it has nothing in it but 36 bytes of headers. The embedded cab file data.cab contains the following files. First, it contains this PDF here — and the PDF, by the way, is genuine. It's a decoy, well, sort of a decoy, let me call it not a decoy but a red herring. That is, it's not a lure file, because by the time the user sees it, everything has already happened. It's more of a dummy file. It's a dummy file that has to be shown to the user so they calm down, that everything's fine, that it really was a PDF they opened. The PDF gets dropped over here. The legitimate executable is the curl utility. Just in case there's no curl on the system, we bring our own. And, look, a malicious LNK file. Simple as that. That's the payload. You'd think, what's there to detect here? Well, the malicious LNK file, okay, fine, that can be detected. Everything else is perfectly legitimate. An innocent PDF you can't do anything with, it's legitimate, no evil in it. And curl — you could detect it, but that's shooting yourself in the foot. Apparently that's what the attackers are counting on. Moving on. Here's the PDF, here's the payment slip. A whole 600 rubles for life or health insurance against accidents, I think. See, against workplace accidents, we even insured someone for 600 rubles. Impressive. Well, the payment slip is real, they found it somewhere, stuck it in here as a sample, as some kind of dummy to show the user. The user sees all this and thinks, what a good boy I am, I opened the right email, I don't need it, actually I'll just send it to spam. But it's too late to flail. What happens next? Next, the install config contains commands that are executed during, as I already told you, during installation of this implant into the system. First we add a whole heap of stuff to the registry. Very noisy, very noisily a bunch of keys are added in order to install a utility called 4t Tray Minimizer. From this developer here, 4t-niagara.com. It's a very interesting developer. Look, it positions itself as a company located in Great Britain, as a developer located over there in the United Kingdom. See, it's even been assigned an English VAT payer number, a VAT number, see, in the top right corner. A thoroughly English developer through and through. But I didn't put that image in here, because these days, you know, say the wrong thing and you'll hurt someone's feelings or discredit somebody. But you can go to this wonderful site and look at what's in the header. In the header there's a motto, well, not a motto, a slogan that instantly gives away the real developers of this real software, who think they're in British jurisdiction and everything's fine for them. So of course this is no British developer, seriously, no, not British. Not British in the slightest, it seems to me, but these comrades keep using it. Well, okay, fine, we'll take their word for it. What happens next? Next, a command file, a batch file, is created: rezet.cmd. And that's where, by the way, the name used by our colleagues from other vendors comes from. Commands get written into it like this. Wonderful — how do we do a pause if we can't do a pause properly? We do a pause by pinging localhost, of course, as tradition dictates. And we self-delete via the batch file. When we can't delete ourselves properly, this is what we do. Right. The main stealth trick, of course, is that the directory C:\Intel, where the attackers drop their malicious toolkit, gets the system and hidden attributes slapped on, I don't know. Actually, to my mind, that gives them away, because, for instance, I have display of hidden system directories enabled by default, and when I see an Intel directory in the root of drive C that's system and hidden, I'm going to have some questions. I'll definitely go look at what's inside it and what's being hidden from me. Well, maybe other users have it set up differently, I don't know. Yes, so much for stealth. We'll be tracking this stealth throughout all the work, all the activity of this group. You'll see, they used it a few more times. I'll point it out too. I always get a certain pleasure from finding artifacts like these and chuckling a bit under my breath when analyzing yet another threat whose authors considered themselves very clever. But unfortunately, yes, unfortunately, it is what it is, either they don't bother, most likely they just don't bother, because why would they, it works as it is, why do anything complicated. Actually, look, as an analyst who's used to complex binary implants, I miss it — give me back my, not 2007, but 2017, when there were all sorts of leaks, Snowden and so on, when there were zero-days, when there was the wonderful MS17-010, when all of that had to be researched, when there was kernel code, when it was beautiful — and now what, APTs on batch files. And it's not the first batch-file APT. I've already talked about another APT on batch files. And the worst part, you see, is that it works. It damn well works. Users launch PDF.exe. We keep logins and passwords in plain text on the desktop. And that wasn't deception. A user really put it there like that. I don't know, just publish it then. Upload it to some cloud somewhere and post the link publicly. Come on, guys, at least something, at least somehow. No, no, no. People don't think about it. The operators use several legitimate utilities, they're listed here. Let me tell you a bit about them. First of all, there's what's called driver.exe. driver.exe is no driver at all, of course. What did the attackers do? They took RAR, an ancient version, 3.8, I even found the executables and did a binary comparison. They stripped out all the text strings that get printed to the console, since these are console utilities. They just went and overwrote them with zeros. So the string, well, the string reference is in the code, it didn't go anywhere, but the string itself is zeroed. As a result we have a RAR that works but prints nothing to the console. It understands the same switches, works, does its thing, but the console is quiet. That's how they dissected it. The next utility is blat.exe. Yes, blat, not the swear word, it's a legitimate utility. A legitimate utility designed for sending emails. They use it because that's how their exfiltration is set up. These folks do their exfiltration via email. They gather all sorts of stuff and send themselves a little email with findings they've harvested. Disguised as svchost we have AnyDesk, which they use actively. I'll tell you and show you how later. By the way, during the initial analysis we didn't pay much attention to AnyDesk, and it turned out to be, basically, the core of the whole attack, which they use actively later on. The same 4t Tray Minimizer is used. Well, you've got to hide the window somehow, and we can't, or we don't want to build binary implants, so we drag it along. A script is used, I'll talk about it a bit later, wol.ps1. And the Defender Control utility is used. It's a free utility designed for manipulating Defender. In particular, these folks use it to disable that very Defender. Well, you see, these folks are all thumbs, because fixing a few keys in the registry and stopping a service is just too hard. Yes, it's too hard, you have to drag in a third-party utility and use that. Well, whatever they want. So, remember the secrecy, right? So our driver.exe, which is our RAR, is used for unpacking and packing with this wonderful password. You can see it on the slide. The password, by the way, is unique. In this respect the password is a find, because our hands aren't idle either. I took this password, combed the archives, dug well through everything we have. What do you think? The group's traces go back, the traces of this password, let's say, and it's unique, go way back to 2010. So these folks have been operating for a long time and fairly successfully. Each of you, think about that for yourselves. I put forward the hypothesis that a password is a rather sensitive thing, and they stick with a user for a long time, for many years. A person sets a password once, then modifies it somehow, but the core stays the same, the password gets reused, and unfortunately that's a disease. So here we have one and the same password, which is a rather interesting IOC, that they've carried through the years. They dump everything they need into C:\Intel, then launch trace.lnk, which they also brought in the archive, and it runs inside 4t Tray Minimizer. Moving on. Why do the attackers need this utility? Well, it's simple, they're all thumbs, they can't properly hide an icon or hide a window, so they carry around either 4t Tray Minimizer or one more utility, which I'll get to a bit later, they carry it with them and use it to hide their windows. Just to somehow avoid drawing extra attention from the user, though they really blow their cover everywhere. Well, apparently they're counting on those same users who launch.pdf.exe. Now look at what rezet.cmd does next. Next it installs AnyDesk on the computer in installation mode, after which it sets the password qwerty1234566 on it, so as to get access to the host without a permission prompt. So, using this password, the attacker just connects to the machine, no window is shown to the user, the user sees nothing, the attacker just connects and does what they want. Here's our Defender Control, see, it looks like this, it's pretty primitive, a whole three switches. The attackers call it with the D switch to turn Windows Defender off. As if protection ends with Windows Defender, but no. Next, look, we call the powercfg utility 6 times to make sure the PC won't sleep, stays available, to adjust its power settings. Again, we're all thumbs, we can't do it through the registry, so we'll go this way instead. Well okay, fine. Next, again with schtasks, because again we don't touch the registry, right. A command is created, sorry, a task, a task is created called shutdown at 5 a.m. So, shut down at 5 in the morning. The name says it all, it's clear what it does. The task is needed to power off the victim every day at 5 a.m. Why 5 a.m., I'll explain a bit later. It's a rather interesting technique. It's, you know, an APT that lives by night. What happens next? Next, finally, remember, wol.ps1 was extracted. Yes, now it's time to run it. It runs these commands, look at what's happening here. Here Edge gets launched. At least, a task is created to launch it, called WakeUpAndLaunchEdge. When I first saw this, I got tense, because, well, why would an attacker launch Edge, right? What's the point? I went to look. I thought, okay, they replaced Edge. Patched it, swapped it, something sits there instead of Edge, some little gift. No, you know, Edge turned out to be genuine. A perfectly original binary with a valid MS digital signature, everything's fine there. The real Edge. So here's a task that launches the real Edge. What do you think, take a guess, why do the attackers need this task? Just guess. Actually it's all simple here. It's just there to wake the computer up. The computer wakes up at 1 a.m. and shuts down at 5. See how elegant it is, right? So they infected the victim, turned the PC on at night, the PC doesn't hibernate, the PC won't sleep, they worked till 5 a.m., siphoned off all they needed, the PC shut down at 5. The victim comes in the morning, boots the PC, as if all's fine, nothing happened. So, yes, and the attacker has 4 hours, enough to scoop up absolutely everything. I have no idea why they even persist on the PC, because in 4 hours you can siphon it all off. You can make proper images there, since nobody restricts you, but if the SOC isn't watching 24/7, you don't have to limit yourself on the volume exfiltrated and can siphon off absolutely everything somewhere, like to some cloud. Let's move on. What happens next? Next our batch file deletes, in fact, curl, the curl installer, the AnyDesk installer, because they're no longer needed, trace.rar is deleted too, because it's no longer needed. We put the utility, Tray Minimizer, in the system, it's running. Next, environment variables get configured so that the blat.exe utility can do its job, so that data can be exfiltrated over email. Then the classics: registry hives are simply dumped, reg.exe is used to dump SYSTEM and SAM. I don't know, if this got past the SOC, no idea where the SOC's looking. That's not just blinders on, those blinders cover the eyes completely. You know, like covering your eyes with your ears out of shame, because to miss something like this, I don't know what you'd have to do. What do these comrades do next? Next they figured, we already stole everything we were interested in, now let's steal some money. Look, I wrote "redacted" here, yes, I actually cut it out, but here was that same password they use, the one that was on several slides earlier. They just go through and gather into a file with the telling name wallet.rar everything they find that's related to electronic money. They'll pull out all they find, all they can reach. That's their appetite so far. And they'll grab the SAM and SYSTEM backups too, just in case. All of this gets sent to the attackers. Think they'll stop there? No, they won't stop there. They'll also plant a miner in the system. Utilization at 110-146%, so to speak. They download a miner, which, by the way, is legitimate, XMRig, but the pool is malicious, the controller is malicious, they just dragged in miners, now they also want the idle machine, while there's still Lyuda the secretary using the computer at 10 percent, give us the other 90, we'll put a miner on the other 90. So, I don't know why they do it this way, I don't know, seems they fear nothing, because not noticing a miner, well, again, it takes, again, blinders on the eyes, not noticing that the computer clearly doesn't belong to you anymore, that most of its resources are going to mining some Monero or something like that. So, where's the money? Where's the money? The money's gone, all of it, all stolen. And not only did they steal it, they also mined some on top. Look, on top of that, I've seen a lot of implants, several dozen, maybe even hundreds, that I took apart while researching, while writing the report and articles, and now preparing for conferences, they use different ones, meaning they change, they don't stand still, they evolve, try all kinds of utilities, I've only talked about one specific implant, but among other things, they, you see, they also use ngrok, they may drag in the WebBrowser PassView tool, yes, they use Mipko Professional Keylogger, by the way, Mipko Professional Keylogger is quite a DLP system, but in plain terms, spyware, yes, which, among other things, records keystrokes, but the curious thing here is that MPK, Mipko Professional Keylogger, is, generally speaking, made in Russia. As I recall, it's developed in the city of Pskov, but its interface supports many languages, and in the distribution I found in the implant that I was researching, for some reason, had language settings for Ukrainian. Well, apparently, maybe attackers somehow prefer it. That's a hypothesis, of course, but that's what these guys leave behind when they get in. So, I think that covers it all here. Yes, seems that's all. And these comrades, too. At first they only hit one computer, took all they wanted from it, and left. After that, this isn't in the presentation, I'll just tell you. They used all sorts of batch files, again, for moving over SMB, for lateral movement they moved around inside the organization, hopped to other computers, scooped it all out and, basically, left the same way. Yes, no idea why they used no binary implants in the attack. I assume the operators will watch the stream or the recording either way. Guys, make something binary already, it'd be interesting to see, I'm wasting away, my brain's atrophying reading batch files. We need something interesting, some 0-day or something original like that, because this isn't very interesting in terms of analysis, because it's all written already, you're just reading off the page. Yes, we went looking at these wonderful guys' infrastructure, what they've got there, what domains they use. They use quite a lot of domains and servers to carry out their activities. And among other things, we found this wonderful one, look here, Yes, we're invited to sign in to a Mail.ru account. Very similar. I even compared them at the time. I opened the real Mail.ru next to it and compared them. An exact match. I blacked out a bit here, just in case. Yes, they even offer sign-in via Gosuslugi. Please pay attention to the address bar. We've got login.php there, you see? So in the attackers' minds, Mail.ru runs on standard, stock PHP. Well, guys, fine, okay, let it be so. Please pay attention to the domain name. Let me highlight it. users-mail.ru. So they don't bother at all, and that's fine. And they think this'll fly, but judging by what they've done, and by the fact they have real scripts there that grab all of it from users, the creds the user enters, it actually works. How this is used against users, sadly, I haven't had the pleasure of observing, but at least it's there in their infrastructure. And with medium confidence we can assume it. They probably used it somehow, probably made it for something, since I don't think they worked for nothing. But apart from all that, apart from all else, the guys really don't bother much. You know, it's like back in the 2000s, when people talked about games, a joke went: "translated by the best programmers". It's the same here, you know: "site administered by the best C developers". Roughly the same thing, because the site has directory listing wide open. You open it up, just the bare domain as it is, the bare site as it is, that's it, all this happiness is here, please, download the whole toolkit, ready to go. Well, for simplicity, apparently, so as not to bother, it's convenient to poke around the file system, take a look, we just open 127.0.0.1, and that's it, we see everything. And we've also got a wonderful thing hanging here, phpMyAdmin, right there, since they need to administer all this somehow, I don't know, either to bolt on a CMS or keep a database there. Well, anyway, we've got phpMyAdmin, which speaks to us in Russian by default, yes. So that's the kind of evidence the guys behind this attack left about themselves. They've been operating quite a while, several years. They don't bother, they don't make binary implants, they stick to batch files. And, all in all, judging by the fact that people still run.pdf.exe, unfortunately, they do get some kind of result. I would really like the situation to change. But you understand, for our part, we'll do all we can. We detect, and we detect well. We detect actively, we detect proactively. If you read the darknet, yes, go read it. I won't advertise our product or company right now, you already know we're cool, but I'll just tell you about a few funny cases. Read the darknet, the wailing begins. Guys, someone kill Kaspersky's detection, I can't, I can't, I keep getting detected. I'll give you 3000 USDT or something along those lines to get the detection off me. And I know the one who made that detection. And I know how well it's made, and that it can't be evaded quickly. So on our side we'll do everything we can, we're here to protect the world, we save the world, that's the mission our CEO has set, and that's how we work. But we're not everywhere. Not all are our clients. Some we won't cover, some simply don't use us, some don't use anything at all. And without a proper, adequate level of security awareness, nothing will change. They've been getting what they want, and they still are. And, unfortunately, it goes on and on and on. And at the last conference I spoke at, I think, I said that spear phishing now delivers about 80% of threats. Not at all. You know, I think spear phishing now delivers something like 90-95% of threats. And it's hard to do anything about it. They resort to all sorts of tricks, they send an archive, for example, an encrypted, password-protected one. They put the password in the email body. But, to be fair, a decent solution, again, not plugging anyone, yes, they can pick those passwords out, plug them in, guess them, etc. They go further, they've stopped sending passwords in the email body. They email the password-protected archive so it flies past all defense layers. And the password for that archive, for example, they send some other way, some other, I don't know, some other, through some other channel. But that, too, is basically easy to detect with modern solutions. Usually in those cases the attachment is simply cut out, and in its place they put a link to the solution's web interface, where you enter that very password. After that the solution checks it, and then the solution says whether it can be handed to the user or not. We'll soon have this functionality implemented too. So on our side we're doing everything we can, but the vendor's efforts alone, which aren't everywhere, aren't enough. First of all TI, first of all security awareness. We need to know who we're up against in order to counter them successfully. And on that positive note, I'll probably wrap up. Thank you very much. I'll be happy to chat and answer questions. Go ahead. Awesome. Okay, I see hands, I see them. Good afternoon. Tell me, do you understand why they do it with batch files, or not? And with implants. Look, as I said, yes, I have two hypotheses. Maybe they should even be merged into one. First, they've got paws, so to speak: hard to write binary implants. Second, it's hard to detect. Hard to detect, well, supposedly, they think it's hard to detect. Actually, you know, they didn't invent this, and this technique's over a year old, over five years old, over a decade old, even. We've all seen it many times, and we're very good at detecting it. And if they think that by using a legitimate operating system mechanism, especially PowerShell, by the way, which they also love, it's their great hope. And using PowerShell, I have no idea what they're thinking. After AMSI came along, PowerShell, well, I don't know, well, fine, you might as well hand us your code directly, we'll detect it. And the second question. Isn't Kaspersky Lab, actually, planning to make a lightweight solution to detect this stuff, with Astra, for example? Not a full-blown antivirus, but something very stripped-down that we could deploy alongside Russian solutions. Like Microsoft: here, have an antivirus. Well, look, I'm not a product manager, I'm a techie, so I really can't commit to which products will be made. Yes, but there is, for example, KFA, you know, yes, Kaspersky Free Antivirus, great, please use it. There are trial versions of our products, please install them. If something's already happened, of course, you need to get protected. We provide the full range of both services and products for protecting the information world, the digital world. We can cover basically anything. We can help with everything. Please, come to us, we'll do it. And on top of that, we really do care about what we do, we put our heart into it. We're all into it, there are no random people here. We're all professionals who are engaged, who are ambitious, who are interested in growing their expertise. And so all the new stuff the attackers roll out, we see it, often we see it even before the attackers can start using it. That happens too, and then they're very surprised. How come? They haven't even used it yet, haven't even delivered it to victims, and Kaspersky somehow already detected it. How does that happen? I don't know how. Somehow. Somehow. They're generally pretty naive people, they use services like VirusTotal, well, not VirusTotal, of course, but similar ones, to check that their little creation isn't detected by anyone or anything. Now I'll finish it and send it out to users. And when they see it's supposedly undetected by anyone or anything, they send it out to users hoping that's really the case, that we have no other engines. We won't disappoint them. We do, of course, have our own technologies. You see, it's a cat-and-mouse game that will never end. We catch them, they run, we catch them, they run again. All of this, of course, has to end not with technical, not only with technical means of countering them. I always talk about this, and I'll probably tell it again now. When we watch the evolution of a fellow who has decided to try a black hat on, try it on, put it on, not for himself, on himself, whatever. Here's what we observe. For a while at first he's terrified. He fears they'll come for him, that tomorrow at 6 a.m. they break his door in, put him face down on the floor, and it all begins. And then time passes, weeks, months, maybe years, and nothing happens, and nobody breaks down his door, and nobody puts him face down. And he figures everything's fine, that's it, he can keep blackhatting, keep working. Some, the especially reckless ones, start working against Russia while in Russia. It all ends exactly the way they feared. Work the RU, and they come for you at dawn. That's how it goes. But, sadly, these fellows don't stop doing it. Well, as they wish. They all hope for Art. 272, 273, 274, but it's not always so. Sometimes it turns out a little differently and get very, very long sentences. — — More questions, please. Alexey, hello. Thanks for the talk, very interesting. But, unfortunately, nothing was said about the victim computer. What system was on it, was there any protection, and why didn't it work. Because usually, if it's Windows and Defender is there, it should always trigger on a BAT file and on a PowerShell script. Well, if it's up to date, of course. Thank you. Thanks for the question. Actually, it needs splitting into sub-questions. I'll do just that and answer them one by one. First, we don't see everything. Let's start there. It's not because we're blind, but because part of the data is simply cut out. You know, we're bound by regulators' requirements, bound by all the GDPR stuff and so on. So quite often, as a rule, we don't know who the victim is, who's there. We just see anonymized information and nothing more. We have nothing that would let us attribute it to a specific victim. We just see what's happening, we see the facts, but don't know who it is. And that's how it should be. And for that we've built a special system, a mechanism, so that all this data simply never reaches us. It's all in our KSN agreement, you can read it. Secondly, who told you, where did you get the idea that it wasn't detected? Maybe it actually was detected. Well, I mean, look, most often, when we start studying some story, some statistics, it all started with some detection, with some activity that looked strange to our products. You know, something's going on, and our product goes into suspicious-dog mode, squints like this: something's off, need to take a look. These are fairly complex technologies, I probably can't even recall them all from memory now, but it goes as far as, depending on the conditions the binary runs in, for example, our emulation level changes, we can emulate deeply, or we can emulate not very deeply, because deep emulation costs resources, on the one hand, but on the other hand, deep emulation lets you pull out what's hidden under five layers of crypter, in other cases we don't emulate very deeply. But if we're seeing a fairly detailed picture, as a rule, it means something happened, there was a detection. Of course, we protect against all this, no doubt about it, don't even think about that, we simply have strict protocols. Look, before I can release a report or publish an article, or talk at a conference, I must check that every single one, absolutely all the implants that were found, are all detected, and detected well. But that's also a catch-up strategy, which in itself is a bit flawed, because when you're catching up, you'll always be catching up, you'll never get ahead, and we're trying to get rid of that flawed strategy and not use it, not run our strategy reactively. That is, our job is to cover users, to protect them from threats that haven't come yet, haven't happened yet. I'll give you a simple example. One of the common threats is, for example, ransomware. You all know it. When they encrypt data, then extort a ransom to decrypt it. Our products implement a proactive detection system, where the product just watches what's happening in the system. If it sees that one file in the system was changed, its name changed, a second file changed, its name changed, entropy went up, say, a third, fourth, fifth, after that the product says: OK, that's enough. I don't know this threat, but I think it's a threat. It'll kill the threat, roll back all the other files, the ones that got encrypted, restore them, and for the user it'll be completely transparent, if, for example, it's KES. The user won't notice a thing, the ransomware is just shot down on takeoff, everything it damaged will be restored, and the user just keeps working as before. So we protect, and we even try not to bother the user unnecessarily. Often the user doesn't even know what happened to them, and we already protected them, covered them, all fine. So we protect, we protect. As for Defender, you saw, they turn it off in this attack. If the attackers have enough privileges, they'll just switch it off, and that's it. That's one side. On the other, well, what are they doing? They install stuff via batch file. Install via batch file. Then start collecting. Well, they copy files. You'll agree, a file copy request can't be detected. That's legitimate activity. More questions, please. Hello. I wanted to ask, couldn't this thing, their stupidity with the password, be pushed further? Like, send a request to the social networks, say, VKontakte, to their archive, to check which user had that password. Or Mail.ru. Look, did I understand you correctly? You're suggesting doing OSINT on what? No, no, making an official request to Mail.ru or VKontakte, so they check which user once had that password. Well, look, I have no idea whether that's possible or not, because I don't talk to the colleagues who provide such social services, but it's not our job, we don't do that, I mean, we don't investigate incidents of that kind. That is, we have incident response, but we're not a government agency, we're a commercial company. Our job is to protect, we protect users. On the one hand, it's our mission, that's how we work. On the other hand, sometimes it's a bit, you know, oh, right now I'd..., right now I'd... — no, you can't, we protect. We don't attack, we protect. And even when you see some vulnerabilities in the attacker's infrastructure or something else that could be used to your advantage, we don't do it, because we're about Defensive, we're not about Offensive, we're about Defensive. Got it, thank you. — — Colleagues, I know many questions remain, but Alexey is staying with us at the venue, and we need to move on. Let's give Alexey a round of applause. Thank you very much. That was great.