Correct me if I'm wrong, but I think what they're getting at is that they're expecting an evolution in malware because of this. i.e. your typical "stupid"/mass malware will slowly grow obsolete, maybe even drop off the map and be replaced with more intelligent forms of the same thing, using concepts from that of Flame or better.
So should malware authors all figure out what Flame (or other more advanced malware) is doing, and how to do it themselves, eventually current day AV _will_ be useless.
Current antivirus solutions can detect Flame, Duqu, Stuxnet, et al, they just need to know about them and/or what they do. That's the problem with blacklisting.
It's probably more helpful to think of these classes of malware as being "obscure" or "wide-spread" than "smart" or "stupid" (I apologize for my previous analogy.) "Advanced persistent threats" don't really exist on a higher plane than common, boring malware (although these have included some impressive payloads), they're just tailored toward something specific in most cases.
I think it's a logical impossibility that all malware should suddenly become as obscure as these were. The payload can certainly be shuffled around, but nothing stops AV from recognizing and stopping whatever mechanism decrypts and runs them. That doesn't, in any way, make AV a panacea--but that's the way it's always been.
Woah, thank for the explanation. You're right, and that makes sense. However I'm of the "anything is possible" mindset, so I do still have to wonder if signature matching is nearing its end. Though I admit, given what you've just clarified, it seems unlikely.
So should malware authors all figure out what Flame (or other more advanced malware) is doing, and how to do it themselves, eventually current day AV _will_ be useless.
No?