Categories: SecurityWorkspace

Symantec Denies Hackers Have Norton Source Code

A hacking group known as the Lords of Dharmaraja claims to have acquired source code for Symantec’s Norton Antivirus software and is threatening to release it.

The group posted an Adobe document which supposedly contained a glimpse of the code, but Symantec denied that any source code was disclosed and said it was continuing to investigate.

Lords of Dharmaraja

Symantec said that the post made on Pastebin was simply an old document that described how the software worked and insisted that its own servers had not been breached.

“We take each and every claim very seriously and have a process in place for investigating each incident,” said Symantec spokesman Cris Paden. “To date, we have not detected any inordinate or suspicious rates of traffic or activity going in or out of our networks.”

The company added in a Facebook post, “The code involved is four and five years old. This does not affect Symantec’s Norton products for our consumer customers. Symantec’s own network was not breached, but rather that of a third party entity.”

The Lords of Dharmaraja, who haven’t claimed responsibility for hacking before, maintain that they discovered the information on India’s military computer network, along with those of a “dozen software companies” which have signed agreements to share code with Indian intelligence agencies.

‘Trophy Hack’

However senior technology consultant at Sophos Graham Cluely has dismissed the group’s actions as a “trophy scalp” designed to generate publicity.

“It’s important to underline that there is presently no reason to believe that Symantec’s own servers have been breached,” commented Cluely. “Instead, it appears that the data leak may have occurred on Indian government servers – and the implication is that Symantec, and perhaps other software companies, may have been required to supply their source code to the Indian authorities.”

“It’s hard not to feel sympathy for Symantec – who appear to have been caught in the crossfire between a hacking gang and the Indian authorities,” he added.

Paul Vlissidis, technical director at NGS Secure, says that the incident has highlighted the dangers of sharing information with third parties.

“Third party suppliers can be an attractive way for cyber criminals to gain access to data and networks that would otherwise beyond their reach,” he said. “As a security firm no doubt Symantec has extremely sophisticated systems in place to protect its data. But a huge range of external suppliers, from marketing to accountants to legal firms, can all be potential vulnerabilities.”

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Google, DOJ Closing Arguments Clash Over Search ‘Monopoly’

Google clashes with US Justice Department in closing arguments as government argues Google used illegal…

3 hours ago

Stanford AI Scientist Working On ‘Spatial Intelligence’ Start-Up

Prominent Stanford University AI scientist Fei-Fei Li reportedly completes funding round for start-up based on…

4 hours ago

Apple Shares Surge Ahead Of New AI Hardware Launches

Apple shares surge on optimism that new AI-focused hardware launches will drive renewed sales, starting…

4 hours ago

Biden Vetoes Republican Measure In Row Over Contractors’ Unions

Biden vetoes Republican-backed measure amidst dispute over 'joint employer' status for contract workers, affecting tech…

5 hours ago

Lawyers Say Strict Child Controls In China Show TikTok Could Do Better

Lawyers in US social media addiction action say strict controls on Douyin in China show…

5 hours ago

London Black Cabs Sue Uber In Latest Legal Tangle

More than 10,000 London black cab drivers sue Uber claiming company acted illegally to obtain…

6 hours ago