Showing posts with label Vault 7. Show all posts
Showing posts with label Vault 7. Show all posts

Thursday, June 8, 2017

Microsoft Warns Of ‘Orwellian Future’ As WikiLeaks Exposes Participation With Surveillance

Microsoft Warns Of ‘Orwellian Future’ As WikiLeaks Exposes Participation With Surveillance | orwellian | CIA Science & Technology Sleuth Journal Special Interests Surveillance Whistle Blowers


By: Alexa Erickson, Collective Evolution | 


Recently, an installment of WikiLeaks’ Vault7 documents came to light that exposed two CIA malware programs that specifically infect Microsoft computers with the purpose of carrying out tasks on infected computers, checking for scheduled events, and collecting data.


The revelation put Microsoft in the hot seat, with people speculating that the tech giant may have been aware that the CIA works with features specifically built into Microsoft computers to collect data and perform tasks.




Microsoft’s history would suggest the worst, from Edward Snowden’s 2013 leaks that revealed Microsoft had “collaborated closely with US intelligence services to allow users’ communications to be intercepted, including helping the National Security Agency to circumvent the company’s own encryption,” to the NSA bragging about their newly acquired ability to triple the amount of Skype video calls being collected through Prism just nine months after Microsoft bought Skype.


Microsoft’s CEO had an intriguing and controversial response to the new WikiLeaks documents. At the company’s 2017 Build conference, Microsoft CEO Satya Nadella warned the technology industry against creating a dystopian future, which authors including George Orwell and Aldous Huxley have predicted in the past.




“I’m an unrepentant tech optimist, there’s no question of that,” said Nadella. “But I’m also grounded. There are unintended consequences of technology.


“And it’s not that we can just use more technology to solve those problems, and technologies by themselves cannot solve these. But I do believe that it’s up to us to ensure that some of the more dystopian scenarios don’t come true.”



The main screen in the conference hall then lit up with Orwell’s 1984 and Huxley’s Brave New World.


“[Think about] what Orwell prophesied in 1984, where technology was being used to monitor, control, dictate,” said Nadella. “Or what Huxley imagined we may do by just distracting ourselves without any meaning or purpose.


“Neither of these futures is something that we want. So the question is: what are we going to do? Are there practical ways we can make progress?”


He urged the importance of people trusting in technology.



“I think it starts with us taking accountability. Taking accountability for the algorithms we create, the experiences that we create, and ensuring that there is more trust in technology with each day.”


“We want to think about people,” Nadella concluded. “But we also want to think about the institutions people build.”



While well-spoken, is it possible that Nadella’s words are empty, and merely just a diversion from the truth? Examining Microsoft’s history, and acknowledging how much the company has worked with the government, it seems possible Nadella is only trying to keep people from realizing Microsoft is, indeed, prepared for such an Orwellian future.

Friday, April 21, 2017

The U.S. Government Declares War on WikiLeaks’ Julian Assange

(ANTIMEDIA) The U.S. government is dramatically ratcheting up its rhetoric against whistleblowing news collective Wikileaks, announcing on Thursday that authorities are preparing new charges on which to arrest the group’s founder, Julian Assange. Assange has lived at the Ecuadorian embassy in London for the last four years in order to avoid extradition and arrest. Now, in the wake of Wikileaks’ controversial Vault 7 releases, which exposed thousands of documents detailing the CIA’s use of domestic and international cyberhacking tools, it appears the government is out for blood.





The Justice Department has sought charges against Assange for almost decade, since Wikileaks facilitated the release of files stolen by whistleblowers like Chelsea Manning. Tension between Wikileaks and U.S. intelligence agencies was further eroded during and after the 2016 presidential election, when U.S. authorities — citing no evidence — asserted Wikileaks had colluded with Russia to affect the outcome.



While Ecuador previously signaled it would not extradite Assange, new statements by CIA Director Mike Pompeo indicate the U.S. may believe it has a path towards arresting Assange, whose leaks have revealed countless state abuses of surveillance power. Recently, a joint investigation by the CIA and the FBI sought to identify the leaker of the Vault 7 files, which show, among other things, that the CIA is capable of surveilling U.S. citizens by hacking into their smart devices.



It’s time to call out WikiLeaks for what it really is: A non-state hostile intelligence service often abetted by state actors like Russia,” Pompeo said last week in a speech at the Center for Strategic and International Studies in Washington.







In a recent op-ed in the Washington Post, Assange repudiated claims made against Wikileaks.


“Quite simply, our motive is identical to that claimed by the New York Times and The Post — to publish newsworthy content. Consistent with the U.S. Constitution, we publish material that we can confirm to be true irrespective of whether sources came by that truth legally or have the right to release it to the media. And we strive to mitigate legitimate concerns, for example by using redaction to protect the identities of at-risk intelligence agents.”


Creative Commons / Anti-Media / Report a typo












Thursday, April 20, 2017

CIA Launches Manhunt for ‘Traitor’ Who Showed the World They Spy on EVERYONE

manhunt



CBS News first reported a manhunt inside the Central Intelligence Agency in search of the source who provided thousands of top secret documents to Wikileaks, published in its “Vault 7” — which revealed the clandestine agency’s hacking tools and surveillance practices.


“Sources familiar with the investigation say it is looking for an insider — either a CIA employee or contractor — who had physical access to the material,” CBS reported Wednesday evening. “The agency has not said publicly when the material was taken or how it was stolen.


“Much of the material was classified and stored in a highly secure section of the intelligence agency, but sources say hundreds of people would have had access to the material. Investigators are going through those names.”



Investigators surmise the source of the massive leak was either an agent of the CIA or a contractor with the agency — someone with physical access — rather than an outside hacker.


In a statement coinciding with the Vault 7 release, Wikileaks announced,


“The archive appears to have been circulated among former US government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive […]


“In a statement to WikiLeaks the source details policy questions that they say urgently need to be debated in public, including whether the CIA’s hacking capabilities exceed its mandated powers and the problem of public oversight of the agency. The source wishes to initiate a public debate about the security, creation, use, proliferation and democratic control of cyberweapons.”



Unnamed sources from inside the U.S. Intelligence Community told Reuters less than 24 hours after Wikileaks published the first selection of the damning cache of documents the agency had expected their public disclosure since 2016.


Officials from the CIA and FBI quickly reviewed the case and, within one day, initiated a joint investigation of the release — including the internal manhunt in question.


Wikileaks — itself, fraught by rumors of enemy State collusion and political opportunism — was lambasted by CIA Director Mike Pompeo, who also had choice words for the pro-transparency organization’s founder, Julian Assange, in his first public comments since taking that role:


“It is time to call out WikiLeaks for what it really is: A non-state hostile intelligence service often abetted by state actors like Russia.”


Wikileaks founder and editor Julian Assange — incidentally deemed a “demon” by Pompeo — responded to the wholly unproven accusation, stating,


“In fact, the reason Pompeo is launching this attack is because he understands we are exposing in this series all sorts of illegal actions by the CIA, so he’s trying to get ahead of the publicity curve and create a preemptive defense.”


Former CIA Deputy Director Mike Morell claimed within days of the Vault 7 disclosure it had to be an ‘inside job.’


“This data is not shared outside CIA,” Morell said. “It’s only inside CIA. It’s on CIA’s top secret network, which is not connected to any other network. So, this has to be an inside job.”


Investigators continue to pour over the hundreds of names of hundreds of contractors and agents who would have had physical access to the high-security area, urgently seeking the unknown person or persons who could have managed such a devastating theft of information.


Given the nature and scope of Wikileaks’ trove — estimated of greater impact than spying practices revealed by NSA whistleblower Edward Snowden — whoever was behind the breach is likely to become a transparency and anti-surveillance folk hero.


Thus far, the CIA has not commented on the ongoing probe — nor on the authenticity of documents in the Wikileaks trove.


Assange, in the same statement released in tandem with Vault 7, noted the content of the cache,


“The disclosure is also exceptional from a political, legal and forensic perspective.”


Friday, April 7, 2017

Wikileaks Newest #Vault7 Release Exposes How CIA Used Malware Stolen From ‘Russian Mafia’




(RT) WikiLeaks has released the fourth part of ‘Vault 7’, named ‘Grasshopper’, the latest in a series of leaks detailing alleged CIA hacking techniques. It details malicious software WikiLeaks claims was taken from “suspected Russian organized crime.”




The latest release consists of 27 documents WikiLeaks claims come from the CIA’s ‘Grasshopper framework’, a platform for building malware for use on Microsoft Windows operating systems.



In a statement from WikiLeaks, ‘Grasshopper’ was described as providing the CIA with the ability to build a customized implant which will behave differently, depending on the security capabilities of a computer.





According to WikiLeaks, Grasshopper performs “a pre-installation survey of the target device, assuring that the payload will only [be] installed if the target has the right configuration.”


This allows CIA operators to detect if a target device is running a specific version of Microsoft Windows or if an antivirus is running, according to the statement.




Grasshopper allows tools to be installed and run on a machine without detection using PSP avoidance, allowing it to avoid Personal Security Products such as ‘MS Security Essentials’, ‘Rising’, ‘Symantec Endpoint’ or ‘Kaspersky IS’.


One of the so-called persistence mechanisms, which allows malware to avoid detection and remain on a computer system indefinitely, is known as ‘Stolen Goods’.



READ MORE:  Breaking: Podesta Told Mills "Dump All Those Emails" on Day News of Clinton"s Private Email Server Broke



In the WikiLeaks release, it is credited to Umbrage, a group within the CIA’s Remote Development Branch (RDB) which was linked in the ‘Year Zero’ release to collecting stolen malware and using it to hide its own hacking fingerprints.


The components of the Stolen Goods mechanism were taken from a malware known as Carperb, “a suspected Russian organized crime rootkit,” alleges WikiLeaks.


Stolen Goods targets the boot sequence of a Windows machine, loading a driver onto the system that allows it to continue executing code when the boot process is finished.


WikiLeaks confirmed that the CIA did not merely copy and paste the suspected Russian malware but appropriated “[the] persistence method, and parts of the installer,” which were then modified to suit the CIA’s purposes.


The latest release came with an emblem containing a grasshopper and the words: “Look before you leap,” a possible reference to how the latest leaked tools would allow the CIA to prepare a machine for future hacking, without raising suspicion.


The rootkits can be installed and used as a ‘man on the inside’ who can allow more malicious software through undetected in future, if the CIA felt it necessary. If suspicions were raised on initial installation, they would know not to proceed with a more extensive operation.


Also detailed in the release are Buffalo and Bamboo, modules that hide malware inside DLL’s, a collection of shared libraries, on a Windows system.


The two modules operate in slightly different ways: Buffalo runs immediately on installation whereas Bamboo requires a reboot to function properly.


The goal of today’s release is to help users seeking to defend their systems against any existing compromised security systems, Wikileaks stated.



READ MORE:  CIA Files Reveal Decades of US Intel on Iran Came from Hundreds of CIA Psychics



Also detailed in the release is ScheduledTask, a component of ‘Grasshopper’ that allows it to utilize Windows Task Scheduler to schedule executables.


The component would allow the executables to automatically run at startup or logon, before killing it at the end of its duration. Included in ScheduledTask are commands that allow the executables names and description to be hidden.


The release is the fourth in a series called ‘Vault 7’ which WikiLeaks claims contains documents taken from within the CIA. Releases so far include ‘Zero Days’ which detailed the CIA’s hacking of Samsung smart TVs and ‘Marble’, which allowed the CIA to disguise their hacks and attribute them to someone else, including Russia.

Saturday, April 1, 2017

Vault 7: Wikileaks reveals CIA tool that makes their hack attacks appear to come from Russia


Tool may have been used to start Trump-Russian narrative






(INTELLIHUB) — In yet another stunning series of revelations, Wikileaks has published hundreds more CIA files that show that the secretive intelligence agency has tools that specifically allow them to disguise their own hacking attacks in order to make them appear to come from multiple different foreign nations.


The release, which includes 676 source code files for the CIA’s secret anti-forensic Marble Framwork, confirms previous reports that the agency is able to carry out hack attacks and then pin the blame on other countries such as Russia, China, Iran, and North Korea.


“Marble is used to hamper forensic investigators and anti-virus companies from attributing viruses, trojans and hacking attacks to the CIA,” Wikileaks wrote in a release accompanying the files.


“Marble does this by hiding (“obfuscating”) text fragments used in CIA malware from visual inspection. This is the digital equivallent of a specalized CIA tool to place covers over the english language text on U.S. produced weapons systems before giving them to insurgents secretly backed by the CIA.”


Amazingly, the release from Wikileaks also claims that the source code files could allow investigators to attribute previous hacks to the CIA that had been reported to come from other actors. (Russian Federation?!)


“The Marble source code also includes a deobfuscator to reverse CIA text obfuscation. Combined with the revealed obfuscation techniques, a pattern or signature emerges which can assist forensic investigators attribute previous hacking attacks and viruses to the CIA. Marble was in use at the CIA during 2016.”


The news is especially relevant when you consider the fact that elements within the intelligence community, with help from the mainstream media, continue to claim that there is evidence of a connection between Trump and the Russians. Remember, this allegation was first put forward after deep state operatives claimed that Wikileaks received the DNC hacked emails from Russia.


This recent release of key CIA files follows a previous Vault 7 release that also revealed intelligence community tools that allow them to “misdirect attribution” of a hack.


“Among the startling revelations coming out through the Wikileaks “Vault 7” release is the shocking fact that the CIA has the ability to “misdirect attribution” of a hack, effectively making it look as if a country such as Russian was the culprit when in reality it was forces within the Central Intelligence Agency itself,” Intellihub News reported.


“According to the Wikileaks documents, a group within the CIA’s Remote Devices Branch, code-named UMBRAGE, collects and maintains a massive library of attack techniques stolen from other countries, including the Russian Federation.”


At this point it is clear that the same agency that has had a hand in directly targeting the Trump Administration also has the ability to conduct “cyber false flags” in which one party is blamed for a hack that the deep state itself actually carried out.


Further Reading:


Alex Thomas is an opinion journalist and editor for Intellihub News. He was a founding member of what later became Intellihub.com and an integral part of the team that destroyed the mainstream media blockade on Bilderberg in 2012. You can contact him here.

Featured Image: Global Panorama/Flickr

©2017. INTELLIHUB.COM. All Rights Reserved.




Monday, March 13, 2017

Wikileaks Dismantles False BuzzFeed Article in One Tweet

Last week, Wikileaks dumped what seems to be authentic CIA documents which revealed, among other things, that the spy agency has a way of hacking into smart TV’s in order to spy on targeted persons of interest. The data dump, known as the Vault 7 release, also showed the CIA has the ability to hack into Apple phones as well. While the conjugation of the verb is apparently incorrect, when Buzzfeed News recently posted a tweet with an attached story which stated Apple had patched its IOS vulnerabilities described in Vault 7, Wikileaks responded with a tweet of its own.




The agency, committed to forcing governments to operate with transparency, called Buzzfeed “fakenews” and stated Apple had not been able to patch those weaknesses in its operating system.





In Buzzfeed’s own article Apple states: “…our initial analysis indicates that many of the issues leaked today were already patched in the latest iOS…” — not all the issues, as Buzzfeed implied.


At one point, the FBI admitted it had not developed the capability to get into the Apple IOS. Readers may recall James Comey had actually petitioned Congress to force Apple to cooperate with the FBI and help the investigative bureau unlock one of the San Bernardino terrorist’s iPhones. Then, abruptly, Comey withdrew his request to mandate Apple to cooperate. As a result, those who were following the story began to speculate the FBI had found another way to get inside the phone.



READ MORE:  Islamic Cleric Kidnapped by CIA, Defends Convicted Agents -- Calls them "Scapegoats" for the US Elite



With the Wikileaks data dump last week, the world now knows that Apple’s proprietary operating system is vulnerable to attack, and there’s nothing anyone can do about it. For years, iPhone and Apple users have been under the impression their operating system was not vulnerable to attack from viruses, spyware, or malware. And for decades now, there’ve been very few issues to cause concern or alarm. But that all changed last week with the revelation the government can penetrate their defenses at will.



According to Wikileaks, there are 14 exploits the CIA can and does use to gain access to IOS data. The hacking tools have eclectic names as well. Three are named Sal, Rhino, and Ironic, and the archive demonstrates the CIA was in the business of paying certain entities for the rights to the program and its uses.


Even Wired reiterated what Buzzfeed stated, that the company (Apple) had fixed the problems which the world’s most powerful spy agency exploited.




In the iOS documents: the security issues detailed are all given codenames, such as the Elderpiggy, Juggernaut, and Winterspy. Listed in the details are the types of exploit (e.g. API); the types of access the code run (kernel and remote exploits are featured); what version of iOS the flaw works for; descriptions of the issues; and who it was found by (GCHQ, the NSA, and more are featured). Apple has since said the flaws highlighted in the documents had already been fixed in past patches.



The government’s spin machine was in full force over the weekend, with the former CIA deputy director, Mike Morrell, calling it an “inside job” and said Americans should, “be proud that their intelligence agency has developed these capabilities to collect intelligence on our adversaries who are trying to undermine our security and in some cases kill Americans. So I think that is how the average American should think about it.” He also said earlier that Americans shouldn’t be worried about the CIA’s hacking operations, saying they’re not permitted to target American nationals.



READ MORE:  Polarize & Conquer - How the Paris Attacks Benefit ISIS and the Western Military Industrial Complex



Well, Mr. Morrell, if that’s your real name, and if you’re no longer with the agency, it makes no difference to any free thinker. We don’t want any intelligence agency operative, former or not, telling us how we should think, especially one which is a part of an intelligence community which has reportedly been known to spy on all Americans.

Sunday, March 12, 2017

16-Year Congressman Says CIA Leaks Prove USA Rapidly “Moving Toward Totalitarianism”

Democratic Congressman Dennis Kucinich recently published a searing critique of the federal government’s spying powers in light of Wikileaks data releases that allege various vulnerabilities inside the CIA, as well as the agency’s capabilities to pursue surveillance of Americans with impunity. For a great number of years, Kucinich has stressed the importance of privacy and the consequences of federal overreach and was one of relatively few in Congress to stand up against legislation including the Patriot Act that has led to widespread spying with scarce oversight.


“If Tuesday’s WikiLeaks document dump is authentic, as it appears to be, then the agency left open electronic gateways that make all Americans vulnerable to spying, eavesdropping and technological manipulation that could bring genuine harm,” Kucinich wrote.



“It is bad enough that the government spies on its own people. It is equally bad that the CIA, through its incompetence, has opened the cyberdoor to anyone with the technological skills and connections to spy on anyone else,” he said.


“The constant erosion of privacy at the hands of the government and corporations has annihilated the concept of a “right to privacy,” which is embedded in the rationale of the First, Third, Fourth, Ninth and Fourteenth Amendments to the U.S. Constitution.


“It is becoming increasingly clear that we are sliding down the slippery slope toward totalitarianism, where private lives do not exist.”


Kucinich went on to warn that “We have crossed the threshold of a cowardly new world, and it’s time we tell the government and the corporations who have intruded to stop it.”



Unfortunately, voices of dissent such as Kucinich are much harder to find than reports that gloss over or dismiss the revelations shared by Wikileaks. In the wake of last week’s Wikileaks bombshell unveiling of “Vault 7” – the leak of an expansive and unsettling collection of documents that detail just how intrusive the CIA has become – the mainstream media’s collective reaction has been nearly as telling as the documents themselves. Rather than providing an objective look at the data within the leak itself, a number major news outlets have predictably opted to echo one another and focus instead almost entirely on their distaste for Wikileaks and its founder, Julian Assange.



READ MORE:  BREAKING: Assange Releases SMS Records Showing He Was Framed by Police in Rape Cases



A plethora of popular news articles over the last few days show passive yet unified rejection of the information’s legitimacy. The Washington Post wasted little time in attempting to minimize Wikileaks’ credibility, as well as questioning whether the Vault 7 leak has Russian ties. The Post claimed the release of documents “shifts the narrative away from the hacking of the DNC and Russia’s relationship with Trump” and suggesting that people should “consider where the information came from and the lack of credibility WikiLeaks has as a news source.” NBC’s Today similarly indicated a potential connection between Russia and the documents, although posed as a question.


However, as we’ve pointed out in the past, WikiLeaks has never released anything that was not entirely genuine and verifiable.


Fortune summarized the leak as a collection of “misinformation” and accused Wikileaks of  serving as “a well-oiled machine of information warfare, sowing panic, fear, and paranoia among the populace.”A Forbes article, titled “WikiLeaks Vault 7 CIA Dump Offers Nothing But Old News,” seeks to reassure the reader that “the overwhelming majority of us aren’t likely to be targeted by the CIA.”



A Foreign Policy post, titled “Wikileaks Has Joined the Trump Administration,” described Wikileaks as an “anti-American group” that “has become the preferred intelligence service for a conspiracy-addled White House.” This article centered around a possible Trump-Wikileaks kinship, noting that the president may be keeping quiet about the Vault 7 leaks because he could “benefit from” them.


However, beneath the surface of Vault 7 reports that seek to obfuscate the data, summaries, and analyses that expose the CIA’s troubling hacking capabilities are able to be found and are vital to bringing these disconcerting but crucial topics to light.



READ MORE:  Newly Declassified Govt Docs Reveal Operation Mockingbird is Alive and Well



The Independent published a straightforward explanation of the Vault 7 leak as well as steps that can be taken to protect some personal data. The article also points out how Apple’s response to the leaks serve as an admission of sorts regarding vulnerabilities exploited by the CIA: “While our initial analysis indicates that many of the issues leaked today were already patched in the latest iOS, we will continue work to rapidly address any identified vulnerabilities.”


In addition, Edward Snowden publicly recognized the authenticity and implications of the information released through Vault 7. “Evidence mounts showing CIA & FBI knew about catastrophic weaknesses in the most-used smartphones in America, but kept them open — to spy,” he noted in one tweet. In another, he declared that the leaks are “first public evidence USG secretly paying to keep US software unsafe.”



It’s important to note that Wikileaks dumped a massive amount of data at once in its Vault 7 release, and proper, thorough analysis of this information is critical. When troves of documents are unleashed so quickly, it is possible for some parts of information to be initially overstated or misunderstood. But for the media to uniformly proclaim that all is settled- that the leaks are nothing but old news, insignificant bits of data not worthy of concern, or a nefarious disinformation campaign- is a disservice to the public.

Thursday, March 9, 2017

F.B.I. investigates C.I.A. leaks

(INTELLIHUB) — The F.B.I. is investigating thousands of C.I.A. personnel and contractors to ascertain where the Vault 7 leaks came from.


Wikileaks’ founder Julian Assange held a live press conference Thursday and said that more leaks are on the way.


The Vault 7 release contains only 1% of the information garnered from the C.I.A. by Wikileaks in total.


©2017. INTELLIHUB.COM. All Rights Reserved.






Comment Policy: Threats of violence, foul language, bullying, and spam will not be tolerated and may be flagged.

When Whistleblowers Tell the Truth They’re Traitors. When Government Lies It’s Politics




(ANTIMEDIA) Immediately after Wikileaks released thousands of documents revealing the extent of CIA surveillance and hacking practices, the government was calling for an investigation — not into why the CIA has amassed so much power, but rather, into who exposed their invasive policies.




We"re revolutionizing the news industry, but we need your help! Click here to get started.




A federal criminal investigation is being opened into WikiLeaks’ publication of documents detailing alleged CIA hacking operations, several US officials,reportedly told CNN.





According to USA Today:


The inquiry, the official said, will seek to determine whether the disclosure represented a breach from the outside or a leak from inside the organization. A separate review will attempt to assess the damage caused by such a disclosure, the official said.”


Even Democratic representative Ted Lieu, who has been urging whistleblowers to come forward to expose wrongdoing within the Trump administration, has turned his focus away from what the documents exposed and toward determining how it could have possibly happened.







I am deeply disturbed by the allegation that the CIA lost its arsenal of hacking tools,” he said while calling for an investigation. “The ramifications could be devastating. I am calling for an immediate congressional investigation. We need to know if the CIA lost control of its hacking tools, who may have those tools, and how do we now protect the privacy of Americans.”


According to Lieu’s statements, the problem isn’t necessarily that the CIA is spying on Americans and invading innocent people’s technology without consent. It’s that the CIA mishandled their spying tools, and in doing so, endangered Americans’ privacy by exposing the tools to presumably ‘bad actors.’ The problem isn’t the corrupt agency violating basic privacy rights, but that they weren’t skillful enough to keep their corruption under wraps.


So goes the familiar whistleblower narrative in the United States. Whistleblowers step forward to expose wrongdoing on the part of government — something the government claims to support — and immediately, establishment institutions and the media bend the conversation away from the wrongdoing in order to focus on the unlawful release of secrets.


Putting aside the fact that, according to popular American mythology breaking the law is a patriotic duty, the government and politicians’ reactions are both hypocritical and habitual.


When Chelsea Manning revealed damning evidence of U.S. war crimes in Iraq, including soldiers directly targeting Reuters news staff, the response was not to investigate who allowed those crimes (in fact, a later Pentagon manual went on to describe instances in which it’s permissible to kill journalists; that version was later retracted after outcry from reporters). Rather, Manning was subject to a military tribunal and issued multiple life sentences, a cruel and unusual punishment reversed only in President Obama’s last days in office amid his attempts to salvage his abysmal human rights, transparency, and whistleblower record.


When Edward Snowden revealed the extent of the NSA’s warrantless mass surveillance of American citizens and millions of others around the world, the government’s response was not to investigate why those programs existed in the first place. Rather, they thrashed and flailed around the world, ordering the plane of Bolivian President Evo Morales to be grounded in the hopes of catching the whistleblower. Congress later passed the deceptive “USA Freedom Act,” which codified continued surveillance.


Edward Snowden remains in exile, and establishment politicians repeatedly call him a traitor for exposing the crimes of his government. Some, including Trump’s CIA Director Mike Pompeo, have called for his execution. Mass surveillance continues, and the president himself is seeking to retain those powers as he condemns former President Obama for allegedly spying on him.


And so on and so forth. The same was true for John Kiriakou, Thomas Drake, William Binney, and Jeffrey Sterling. The government is exposed for wrongdoing, and rather than prove themselves to be representatives of the people by remedying those transgressions, they point fingers and divert, all the while refusing to relinquish the unjust power any given agency is exposed for having.


Many people are already aware that the government does little to actually serve them (Americans’ trust in political leaders and government, in general, is abysmally low). Rather, government agents and agencies operate to advance and concentrate their own interests and power. This is why penalties against killing government employees are more stringent than killing civilians. It is why stealing from the government is perceived as more outrageous to the State than stealing from a civilian. The government considers “crimes” committed against itself to carry the utmost offense, yet often fails to deliver justice to the people who provide their financial foundation.


As a result, the State does not even try to show remorse for its violative policies, even when they are exposed and splattered across social media for the world to see. Instead, with the help of corporate media, the debate is shifted to whether or not WikiLeaks is a criminal organization, or whether or not Edward Snowden is a traitor.


As White House Press Secretary Sean Spicer said of the leaks:


“This is the kind of disclosure that undermines our country, our security. This alleged leak should concern every American for its impact on national security. … Anybody who leaks classified information will be held accountable to the maximum extent of the law.”


Meanwhile, we’re supposed to accept the government’s investigation of itself, which (surprise!) usually finds little or no wrongdoing on their own behalf and often consolidates and extends the very same power whistleblowers exposed in the first place.


Creative Commons / Anti-Media / Report a typo

Wednesday, March 8, 2017

“Vault 7” release is a game changer — here’s why!




(INTELLIHUB) — The recent Wikileaks release of “Vault 7 Part 1” is a game changer that’s sure to balance the playing field.


The C.I.A.’s Center for Cyber Intelligence has been forced to deal with the repercussions of their secrets being made public and has gone on a public propaganda campaign to contain the damage.


The proverbial carnage came after the C.I.A.’s prized “cyber-spying toolkit” was leaked into the public domain creating government distrust.


Documents contained within the dump prove that the C.I.A. has the capability to hack into smartphones and T.V.s and may even be using it to surveil U.S. persons of interest.


Fox News reports:



Among revelations still emerging from the shocking disclosure is an alleged CIA program named “Weeping Angel,” in which Samsung brand “smart” televisions were apparently being used as recording devices. “Weeping Angel places the target TV in a “Fake-Off” mode, so that the owner falsely believes the TV is off when it is on,” WikiLeaks claims. “In ‘Fake-Off’ mode the TV operates as a bug, recording conversations in the room and sending them over the Internet to a covert CIA server.”



This is what radio talk show host Alex Jones has been warning everyone about for years when he’s said we all live in a “police state.”


The recent leak serves as the proof.


With this technology in the public sector, there is no telling how this will all turn out as the script can now be flipped if you know what I’m saying. The technology is a dual-edged sword and Vault 7 was a game changer.


With that being said, I tip my hat to Wikileaks.



Featured Image: frankieleon/Flickr

©2017. INTELLIHUB.COM. All Rights Reserved.







Comment Policy: Threats of violence, foul language, bullying, and spam will not be tolerated and may be flagged.


Feds Begin Hunt for WikiLeaks’ Snowden 2.0




(ZHEA federal criminal investigation is being opened into WikiLeaks’ publication of documents detailing alleged CIA hacking operations, CNN reported as both the FBI and CIA are coordinating their hunt for the mysterious whistleblower inside the CIA, who has already been dubbed Snowden 2.0.




We"re revolutionizing the news industry, but we need your help! Click here to get started.




The criminal probe will look into how the documents came into WikiLeaks’ possession and whether they might have been leaked by an employee or contractor. The CIA is also trying to determine if there are other unpublished documents WikiLeaks may have. Incidentally, the answer to that is yes as the whistleblowing organization revealed earlier in the day on its twitter feed.














The documents published so far are genuine, officials confirmed to CNN, which adds that one of the biggest concerns for the federal government is if WikiLeaks publishes critical computer code on how operations are conducted, as other hackers could take that code and cause havoc overseas. Of course, if the CIA had not left its code open and accessibly by outside interlopers, making hacking simple – as Edward Snowden explained – that would not be a concern.


Still, the attacks listed in the Wikileaks documents largely require physical access to devices. Even if code was released, a hacker would need to physically tamper with a smart television to infect it with the CIA’s purported malware.


The officials emphasized any intelligence collection using the types of operations described in the documents is legal intelligence collection against overseas targets. The officials also cautioned some of the material describes programs still under development by the intelligence community.


Rep. Ted Lieu (D-Calif.) immediately called for a Congressional investigation upon the documents’ release. “I am deeply disturbed by the allegation that the CIA lost its arsenal of hacking tools. The ramifications could be devastating.” It appears that his wish has been granted.


By Tyler Durden / Republished with permission / Zero Hedge / Report a typo / Image: WikiLeaks Truck

Tuesday, March 7, 2017

WikiLeaks Unveils ‘Vault 7’: “The Largest Ever Publication Of Confidential CIA Documents”



WikiLeaks Unveils ‘Vault 7’: “The Largest Ever Publication Of Confidential CIA Documents”







BREAKING: WikiLeaks’ Vault 7 Shows How CIA Spies on Your TV, Phone, PC, Mac, and More

Only moments ago, WikiLeaks released what it claims to be the largest ever release of confidential documents on the CIA. This dump comes on the heels of a preview that the Free Thought Project reported on last month, in which WikiLeaks released documents showing the CIA’s role in interfering with French elections. This dump, however, is the apparent motherload, which the transparency organization allegedly obtained from the CIA’s Center for Cyber Intelligence in Langley. It involves a massive cache of data ranging from the years 2013-2016.


Inside this data, according to WikiLeaks, are the tools the CIA has been using for years to wreak digital havoc on the world. According to the release:



Recently, the CIA lost control of the majority of its hacking arsenal including malware, viruses, trojans, weaponized “zero day” exploits, malware remote control systems and associated documentation. This extraordinary collection, which amounts to more than several hundred million lines of code, gives its possessor the entire hacking capacity of the CIA. The archive appears to have been circulated among former U.S. government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive.



WikiLeaks notes that this is only the first part of a series they are calling “Year Zero,” which is comprised of 8,761 documents and files from an isolation high-security network situated inside the CIA’s Center for Cyber Intelligence in Langley, Virgina.


“Year Zero,” according to WikiLeaks, introduces the scope and direction of the CIA’s global covert hacking program, its malware arsenal and dozens of “zero day” weaponized exploits against a wide range of U.S. and European company products, include Apple’s iPhone, Google’s Android and Microsoft’s Windows and even Samsung TVs, which are turned into covert microphones.


This leak exposes the massive hacking powerhouse the CIA has become in the last decade — surpassing even that of the NSA.



Since 2001 the CIA has gained political and budgetary preeminence over the U.S. National Security Agency (NSA). The CIA found itself building not just its now infamous drone fleet, but a very different type of covert, globe-spanning force — its own substantial fleet of hackers. The agency’s hacking division freed it from having to disclose its often controversial operations to the NSA (its primary bureaucratic rival) in order to draw on the NSA’s hacking capacities.






What is also notable about this leak is the fact that it reveals another Snowden-type whistleblower within the massive spying apparatus. This time, however, knowing how the US treats whistleblowers, the source has chosen to remain anonymous.



READ MORE:  Wikileaks Releases Smoking Gun Email Proving Once and For All Clinton is Lying Through Her Teeth



In a statement to WikiLeaks, “the source details policy questions that they say urgently need to be debated in public, including whether the CIA’s hacking capabilities exceed its mandated powers and the problem of public oversight of the agency. The source wishes to initiate a public debate about the security, creation, use, proliferation and democratic control of cyberweapons.”


Cyber weapons pose a massive threat to the entire world’s infrastructure as they can be used by anyone from rival states, cyber mafias, and even teenage hackers.


According to Julian Assange, “There is an extreme proliferation risk in the development of cyber ‘weapons’. Comparisons can be drawn between the uncontrolled proliferation of such ‘weapons’, which results from the inability to contain them combined with their high market value, and the global arms trade. But the significance of ‘Year Zero’ goes well beyond the choice between cyberwar and cyberpeace. The disclosure is also exceptional from a political, legal and forensic perspective.”


Noting the severe implications of releasing these hacking tools publicly, WikiLeaks will avoid distributing the ‘armed’ version of the cyber weapons “until a consensus emerges on the technical and political nature of the CIA’s program and how such ‘weapons’ should analyzed, disarmed and published.”


To quantify the sheer size and scope of Vault 7, WikiLeaks notes that just part 1 “already eclipses the total number of pages published over the first three years of the Edward Snowden NSA leaks.”


One of the most ominous techniques profiled by WikiLeaks in Vault 7 is “Weeping Angel,” developed by the CIA’s Embedded Devices Branch (EDB) — a cyber weapon that infests smart TV’s and transforms them into microphones.


As WikiLeaks reports, after infestation, Weeping Angel places the target TV in a ‘Fake-Off’ mode, so that the owner falsely believes the TV is off when it is on. In ‘Fake-Off’ mode the TV operates as a bug, recording conversations in the room and sending them over the Internet to a covert CIA server.


Upon news of ‘Weeping Angel,’ Kim Dotcom chimed in, noting that it is not just TV’s the CIA can control to spy on you.






It gets far worse. According to WikiLeaks:



The CIA’s Mobile Devices Branch (MDB) developed numerous attacks to remotely hack and control popular smart phones. Infected phones can be instructed to send the CIA the user’s geolocation, audio and text communications as well as covertly activate the phone’s camera and microphone.



Despite iPhone’s minority share (14.5%) of the global smart phone market in 2016, a specialized unit in the CIA’s Mobile Development Branch produces malware to infest, control and exfiltrate data from iPhones and other Apple products running iOS, such as iPads. CIA’s arsenal includes numerous local and remote “zero days” developed by CIA or obtained from GCHQ, NSA, FBI or purchased from cyber arms contractors such as Baitshop. The disproportionate focus on iOS may be explained by the popularity of the iPhone among social, political, diplomatic and business elites.




A similar unit targets Google’s Android which is used to run the majority of the world’s smart phones (~85%) including Samsung, HTC and Sony. 1.15 billion Android powered phones were sold last year. “Year Zero” shows that as of 2016 the CIA had 24 “weaponized” Android “zero days” which it has developed itself and obtained from GCHQ, NSA and cyber arms contractors.



These techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram, Wiebo, Confide and Cloackman by hacking the “smart” phones that they run on and collecting audio and message traffic before encryption is applied.


CIA malware targets Windows, OSx, Linux, routers



The CIA also runs a very substantial effort to infect and control Microsoft Windows users with its malware. This includes multiple local and remote weaponized “zero days”, air gap jumping viruses such as “Hammer Drill” which infects software distributed on CD/DVDs, infectors for removable media such as USBs, systems to hide data in images or in covert disk areas ( “Brutal Kangaroo”) and to keep its malware infestations going.




Many of these infection efforts are pulled together by the CIA’s Automated Implant Branch (AIB), which has developed several attack systems for automated infestation and control of CIA malware, such as “Assassin” and “Medusa”.



Attacks against Internet infrastructure and webservers are developed by the CIA’s Network Devices Branch (NDB).





READ MORE:  Declassified Docs Show CIA Not Only Attended But Spied on Bilderberg for Years



WikiLeaks put the world on notice with the news of the encrypted torrent file Vault 7 last night, and, at 8:06 am EST, they tweeted out the key to unlock it.




Assange was planning a press conference to go over the data dump this morning. However, shortly before it was supposed to begin, they announced the Facebook and Periscope streams were under attack.




As for why WikiLeaks chose to release this information now, they explain:




WikiLeaks published as soon as its verification and analysis were ready.


In Febuary the Trump administration has issued an Executive Order calling for a “Cyberwar” review to be prepared within 30 days.


While the review increases the timeliness and relevance of the publication it did not play a role in setting the publication date.



Finally, WikiLeaks leaves the rest of the data mining up to the public.



WikiLeaks has intentionally not written up hundreds of impactful stories to encourage others to find them and so create expertise in the area for subsequent parts in the series. They’re there. Look. Those who demonstrate journalistic excellence may be considered for early access to future parts.



The Free Thought Project is one of those outlets that will be bringing you our analysis of important information we find within these leaks. We will keep you updated as this, the largest leak in US history, unfolds.



Matt Agorist is an honorably discharged veteran of the USMC and former intelligence operator directly tasked by the NSA. This prior experience gives him unique insight into the world of government corruption and the American police state. Agorist has been an independent journalist for over a decade and has been featured on mainstream networks around the world. Agorist is also the Editor at Large at the Free Thought Project. , Steemit, and now on Facebook.

Wikileaks unveils ‘Vault 7’: “The largest ever publication of confidential documents on the CIA”

Last night Wikileaks announced that it has released an encrypted torrent file which reportedly contains information on the mysterious “Vault 7”, and which we now know is the biggest “collection of material about CIA activities obtained by WikiLeaks.publication in history.” It can be downloaded now at the following URL, and accessed using the password “SplinterItIntoAThousandPiecesAndScatterItIntoTheWinds”


Wikileaks had previously announced that it would hold an 8am Eastern press conference, as part of the unveiling.




However, there appeared to have been some complications, with Wikileaks tweeting that “the press conference is under attack: Facebook+Periscope video used by WikiLeaks’ editor Julian Assange have been attacked. Activating contingency plans”




Wikileaks then announced that “As Mr. Assange’s Perscipe+Facebook video stream links are under attack his video press conference will be rescheduled.”




In a separate tweet, Wikileaks has just released the passphrase to decrypt the torrent file: RELEASE: CIA Vault 7 Year Zero decryption passphrase:


SplinterItIntoAThousandPiecesAndScatterItIntoTheWinds




As a result, since Assange appears to have been unable to launch his previously scheduled press conference, he has gone ahead and issued the press release on Vault 7 Part 1 “Year Zero, which is titled: Inside the CIA’s global hacking force:


Press Release


Vault 7: CIA Hacking Tools Revealed


Today, Tuesday 7 March 2017, WikiLeaks begins its new series of leaks on the U.S. Central Intelligence Agency. Code-named “Vault 7” by WikiLeaks, it is the largest ever publication of confidential documents on the agency.


The first full part of the series, “Year Zero”, comprises 8,761 documents and files from an isolated, high-security network situated inside the CIA’s Center for Cyber Intelligence in Langley, Virgina. It follows an introductory disclosure last month of CIA targeting French political parties and candidates in the lead up to the 2012 presidential election.


Recently, the CIA lost control of the majority of its hacking arsenal including malware, viruses, trojans, weaponized “zero day” exploits, malware remote control systems and associated documentation. This extraordinary collection, which amounts to more than several hundred million lines of code, gives its possessor the entire hacking capacity of the CIA. The archive appears to have been circulated among former U.S. government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive.


“Year Zero” introduces the scope and direction of the CIA’s global covert hacking program, its malware arsenal and dozens of “zero day” weaponized exploits against a wide range of U.S. and European company products, include Apple’s iPhone, Google’s Android and Microsoft’s Windows and even Samsung TVs, which are turned into covert microphones.


Since 2001 the CIA has gained political and budgetary preeminence over the U.S. National Security Agency (NSA). The CIA found itself building not just its now infamous drone fleet, but a very different type of covert, globe-spanning force — its own substantial fleet of hackers. The agency’s hacking division freed it from having to disclose its often controversial operations to the NSA (its primary bureaucratic rival) in order to draw on the NSA’s hacking capacities.


By the end of 2016, the CIA’s hacking division, which formally falls under the agency’s Center for Cyber Intelligence (CCI), had over 5000 registered users and had produced more than a thousand hacking systems, trojans, viruses, and other “weaponized” malware. Such is the scale of the CIA’s undertaking that by 2016, its hackers had utilized more code than that used to run Facebook. The CIA had created, in effect, its “own NSA” with even less accountability and without publicly answering the question as to whether such a massive budgetary spend on duplicating the capacities of a rival agency could be justified.


In a statement to WikiLeaks the source details policy questions that they say urgently need to be debated in public, including whether the CIA’s hacking capabilities exceed its mandated powers and the problem of public oversight of the agency. The source wishes to initiate a public debate about the security, creation, use, proliferation and democratic control of cyberweapons.


Once a single cyber ‘weapon’ is ‘loose’ it can spread around the world in seconds, to be used by rival states, cyber mafia and teenage hackers alike.


Julian Assange, WikiLeaks editor stated that “There is an extreme proliferation risk in the development of cyber ‘weapons’. Comparisons can be drawn between the uncontrolled proliferation of such ‘weapons’, which results from the inability to contain them combined with their high market value, and the global arms trade. But the significance of “Year Zero” goes well beyond the choice between cyberwar and cyberpeace. The disclosure is also exceptional from a political, legal and forensic perspective.”


Wikileaks has carefully reviewed the “Year Zero” disclosure and published substantive CIA documentation while avoiding the distribution of ‘armed’ cyberweapons until a consensus emerges on the technical and political nature of the CIA’s program and how such ‘weapons’ should analyzed, disarmed and published.


Wikileaks has also decided to redact and anonymise some identifying information in “Year Zero” for in depth analysis. These redactions include ten of thousands of CIA targets and attack machines throughout Latin America, Europe and the United States. While we are aware of the imperfect results of any approach chosen, we remain committed to our publishing model and note that the quantity of published pages in “Vault 7” part one (“Year Zero”) already eclipses the total number of pages published over the first three years of the Edward Snowden NSA leaks.


* * *


Analysis


CIA malware targets iPhone, Android, smart TVs


CIA malware and hacking tools are built by EDG (Engineering Development Group), a software development group within CCI (Center for Cyber Intelligence), a department belonging to the CIA’s DDI (Directorate for Digital Innovation). The DDI is one of the five major directorates of the CIA (see this organizational chart of the CIA for more details).


The EDG is responsible for the development, testing and operational support of all backdoors, exploits, malicious payloads, trojans, viruses and any other kind of malware used by the CIA in its covert operations world-wide.


The increasing sophistication of surveillance techniques has drawn comparisons with George Orwell’s 1984, but “Weeping Angel”, developed by the CIA’s Embedded Devices Branch (EDB), which infests smart TVs, transforming them into covert microphones, is surely its most emblematic realization.


The attack against Samsung smart TVs was developed in cooperation with the United Kingdom’s MI5/BTSS. After infestation, Weeping Angel places the target TV in a ‘Fake-Off’ mode, so that the owner falsely believes the TV is off when it is on. In ‘Fake-Off’ mode the TV operates as a bug, recording conversations in the room and sending them over the Internet to a covert CIA server.


As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations.


The CIA’s Mobile Devices Branch (MDB) developed numerous attacks to remotely hack and control popular smart phones. Infected phones can be instructed to send the CIA the user’s geolocation, audio and text communications as well as covertly activate the phone’s camera and microphone.


Despite iPhone’s minority share (14.5%) of the global smart phone market in 2016, a specialized unit in the CIA’s Mobile Development Branch produces malware to infest, control and exfiltrate data from iPhones and other Apple products running iOS, such as iPads. CIA’s arsenal includes numerous local and remote “zero days” developed by CIA or obtained from GCHQ, NSA, FBI or purchased from cyber arms contractors such as Baitshop. The disproportionate focus on iOS may be explained by the popularity of the iPhone among social, political, diplomatic and business elites.


A similar unit targets Google’s Android which is used to run the majority of the world’s smart phones (~85%) including Samsung, HTC and Sony. 1.15 billion Android powered phones were sold last year. “Year Zero” shows that as of 2016 the CIA had 24 “weaponized” Android “zero days” which it has developed itself and obtained from GCHQ, NSA and cyber arms contractors.


These techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram, Wiebo, Confide and Cloackman by hacking the “smart” phones that they run on and collecting audio and message traffic before encryption is applied.


CIA malware targets Windows, OSx, Linux, routers


The CIA also runs a very substantial effort to infect and control Microsoft Windows users with its malware. This includes multiple local and remote weaponized “zero days”, air gap jumping viruses such as “Hammer Drill” which infects software distributed on CD/DVDs, infectors for removable media such as USBs, systems to hide data in images or in covert disk areas ( “Brutal Kangaroo”) and to keep its malware infestations going.


Many of these infection efforts are pulled together by the CIA’s Automated Implant Branch (AIB), which has developed several attack systems for automated infestation and control of CIA malware, such as “Assassin” and “Medusa”.


Attacks against Internet infrastructure and web servers are developed by the CIA’s Network Devices Branch (NDB).


The CIA has developed automated multi-platform malware attack and control systems covering Windows, Mac OS X, Solaris, Linux and more, such as EDB’s “HIVE” and the related “Cutthroat” and “Swindle” tools, which are described in the examples section below.


CIA ‘hoarded’ vulnerabilities (“zero days”)


In the wake of Edward Snowden’s leaks about the NSA, the U.S. technology industry secured a commitment from the Obama administration that the executive would disclose on an ongoing basis — rather than hoard — serious vulnerabilities, exploits, bugs or “zero days” to Apple, Google, Microsoft, and other US-based manufacturers.


Serious vulnerabilities not disclosed to the manufacturers places huge swathes of the population and critical infrastructure at risk to foreign intelligence or cyber criminals who independently discover or hear rumors of the vulnerability. If the CIA can discover such vulnerabilities so can others.


The U.S. government’s commitment to the Vulnerabilities Equities Process came after significant lobbying by US technology companies, who risk losing their share of the global market over real and perceived hidden vulnerabilities. The government stated that it would disclose all pervasive vulnerabilities discovered after 2010 on an ongoing basis.


“Year Zero” documents show that the CIA breached the Obama administration’s commitments. Many of the vulnerabilities used in the CIA’s cyber arsenal are pervasive and some may already have been found by rival intelligence agencies or cyber criminals.


As an example, specific CIA malware revealed in “Year Zero” is able to penetrate, infest and control both the Android phone and iPhone software that runs or has run presidential Twitter accounts. The CIA attacks this software by using undisclosed security vulnerabilities (“zero days”) possessed by the CIA but if the CIA can hack these phones then so can everyone else who has obtained or discovered the vulnerability. As long as the CIA keeps these vulnerabilities concealed from Apple and Google (who make the phones) they will not be fixed, and the phones will remain hackable.


The same vulnerabilities exist for the population at large, including the U.S. Cabinet, Congress, top CEOs, system administrators, security officers and engineers. By hiding these security flaws from manufacturers like Apple and Google the CIA ensures that it can hack everyone &mdsh; at the expense of leaving everyone hackable.


‘Cyberwar’ programs are a serious proliferation risk


Cyber ‘weapons’ are not possible to keep under effective control.


While nuclear proliferation has been restrained by the enormous costs and visible infrastructure involved in assembling enough fissile material to produce a critical nuclear mass, cyber ‘weapons’, once developed, are very hard to retain.


Cyber ‘weapons’ are in fact just computer programs which can be pirated like any other. Since they are entirely comprised of information they can be copied quickly with no marginal cost.


Securing such ‘weapons’ is particularly difficult since the same people who develop and use them have the skills to exfiltrate copies without leaving traces — sometimes by using the very same ‘weapons’ against the organizations that contain them. There are substantial price incentives for government hackers and consultants to obtain copies since there is a global “vulnerability market” that will pay hundreds of thousands to millions of dollars for copies of such ‘weapons’. Similarly, contractors and companies who obtain such ‘weapons’ sometimes use them for their own purposes, obtaining advantage over their competitors in selling ‘hacking’ services.


Over the last three years the United States intelligence sector, which consists of government agencies such as the CIA and NSA and their contractors, such as Booze Allan Hamilton, has been subject to unprecedented series of data exfiltrations by its own workers.


A number of intelligence community members not yet publicly named have been arrested or subject to federal criminal investigations in separate incidents.


Most visibly, on February 8, 2017 a U.S. federal grand jury indicted Harold T. Martin III with 20 counts of mishandling classified information. The Department of Justice alleged that it seized some 50,000 gigabytes of information from Harold T. Martin III that he had obtained from classified programs at NSA and CIA, including the source code for numerous hacking tools.


Once a single cyber ‘weapon’ is ‘loose’ it can spread around the world in seconds, to be used by peer states, cyber mafia and teenage hackers alike.


U.S. Consulate in Frankfurt is a covert CIA hacker base


In addition to its operations in Langley, Virginia the CIA also uses the U.S. consulate in Frankfurt as a covert base for its hackers covering Europe, the Middle East and Africa.


CIA hackers operating out of the Frankfurt consulate ( “Center for Cyber Intelligence Europe” or CCIE) are given diplomatic (“black”) passports and State Department cover. The instructions for incoming CIA hackers make Germany’s counter-intelligence efforts appear inconsequential: “Breeze through German Customs because you have your cover-for-action story down pat, and all they did was stamp your passport”


Your Cover Story (for this trip)
Q: Why are you here?
A: Supporting technical consultations at the Consulate.


Two earlier WikiLeaks publications give further detail on CIA approaches to customs and secondary screening procedures.


Once in Frankfurt CIA hackers can travel without further border checks to the 25 European countries that are part of the Shengen open border area — including France, Italy and Switzerland.


A number of the CIA’s electronic attack methods are designed for physical proximity. These attack methods are able to penetrate high security networks that are disconnected from the internet, such as police record database. In these cases, a CIA officer, agent or allied intelligence officer acting under instructions, physically infiltrates the targeted workplace. The attacker is provided with a USB containing malware developed for the CIA for this purpose, which is inserted into the targeted computer. The attacker then infects and exfiltrates data to removable media. For example, the CIA attack system Fine Dining, provides 24 decoy applications for CIA spies to use. To witnesses, the spy appears to be running a program showing videos (e.g VLC), presenting slides (Prezi), playing a computer game (Breakout2, 2048) or even running a fake virus scanner (Kaspersky, McAfee, Sophos). But while the decoy application is on the screen, the underlaying system is automatically infected and ransacked.


How the CIA dramatically increased proliferation risks


In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of “Vault 7” — the CIA’s weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse.


The CIA made these systems unclassified.


Why the CIA chose to make its cyberarsenal unclassified reveals how concepts developed for military use do not easily crossover to the ‘battlefield’ of cyber ‘war’.


To attack its targets, the CIA usually requires that its implants communicate with their control programs over the internet. If CIA implants, Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently, the CIA has secretly made most of its cyber spying/war code unclassified. The U.S. government is not able to assert copyright either, due to restrictions in the U.S. Constitution. This means that cyber ‘arms’ manufactures and computer hackers can freely “pirate” these ‘weapons’ if they are obtained. The CIA has primarily had to rely on obfuscation to protect its malware secrets.


Conventional weapons such as missiles may be fired at the enemy (i.e into an unsecured area). Proximity to or impact with the target detonates the ordnance including its classified parts. Hence military personnel do not violate classification rules by firing ordnance with classified parts. Ordnance will likely explode. If it does not, that is not the operator’s intent.


Over the last decade U.S. hacking operations have been increasingly dressed up in military jargon to tap into Department of Defense funding streams. For instance, attempted “malware injections” (commercial jargon) or “implant drops” (NSA jargon) are being called “fires” as if a weapon was being fired. However the analogy is questionable.


Unlike bullets, bombs or missiles, most CIA malware is designed to live for days or even years after it has reached its ‘target’. CIA malware does not “explode on impact” but rather permanently infests its target. In order to infect target’s device, copies of the malware must be placed on the target’s devices, giving physical possession of the malware to the target. To exfiltrate data back to the CIA or to await further instructions the malware must communicate with CIA Command & Control (C2) systems placed on internet connected servers. But such servers are typically not approved to hold classified information, so CIA command and control systems are also made unclassified.


A successful ‘attack’ on a target’s computer system is more like a series of complex stock maneuvers in a hostile take-over bid or the careful planting of rumors in order to gain control over an organization’s leadership rather than the firing of a weapons system. If there is a military analogy to be made, the infestation of a target is perhaps akin to the execution of a whole series of military maneuvers against the target’s territory including observation, infiltration, occupation and exploitation.


Evading forensics and anti-virus


A series of standards lay out CIA malware infestation patterns which are likely to assist forensic crime scene investigators as well as Apple, Microsoft, Google, Samsung, Nokia, Blackberry, Siemens and anti-virus companies attribute and defend against attacks.


“Tradecraft DO’s and DON’Ts” contains CIA rules on how its malware should be written to avoid fingerprints implicating the “CIA, US government, or its witting partner companies” in “forensic review”. Similar secret standards cover the use of encryption to hide CIA hacker and malware communication (pdf), describing targets & exfiltrated data (pdf) as well as executing payloads (pdf) and persisting (pdf) in the target’s machines over time.


CIA hackers developed successful attacks against most well known anti-virus programs. These are documented in AV defeats, Personal Security Products, Detecting and defeating PSPs and PSP/Debugger/RE Avoidance. For example, Comodo was defeated by CIA malware placing itself in the Window’s “Recycle Bin”. While Comodo 6.x has a “Gaping Hole of DOOM”.


CIA hackers discussed what the NSA’s “Equation Group” hackers did wrong and how the CIA’s malware makers could avoid similar exposure.


Examples


The CIA’s Engineering Development Group (EDG) management system contains around 500 different projects (only some of which are documented by “Year Zero”) each with their own sub-projects, malware and hacker tools.


The majority of these projects relate to tools that are used for penetration, infestation (“implanting”), control, and exfiltration.


Another branch of development focuses on the development and operation of Listening Posts (LP) and Command and Control (C2) systems used to communicate with and control CIA implants; special projects are used to target specific hardware from routers to smart TVs.


Some example projects are described below, but see the table of contents for the full list of projects described by WikiLeaks’ “Year Zero”.


UMBRAGE


The CIA’s hand crafted hacking techniques pose a problem for the agency. Each technique it has created forms a “fingerprint” that can be used by forensic investigators to attribute multiple different attacks to the same entity.


This is analogous to finding the same distinctive knife wound on multiple separate murder victims. The unique wounding style creates suspicion that a single murderer is responsible. As soon one murder in the set is solved then the other murders also find likely attribution.


The CIA’s Remote Devices Branch‘s UMBRAGE group collects and maintains a substantial library of attack techniques ‘stolen’ from malware produced in other states including the Russian Federation.


With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the “fingerprints” of the groups that the attack techniques were stolen from.


UMBRAGE components cover keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.


Fine Dining


Fine Dining comes with a standardized questionnaire i.e menu that CIA case officers fill out. The questionnaire is used by the agency’s OSB (Operational Support Branch) to transform the requests of case officers into technical requirements for hacking attacks (typically “exfiltrating” information from computer systems) for specific operations. The questionnaire allows the OSB to identify how to adapt existing tools for the operation, and communicate this to CIA malware configuration staff. The OSB functions as the interface between CIA operational staff and the relevant technical support staff.


Among the list of possible targets of the collection are ‘Asset’, ‘Liason Asset’, ‘System Administrator’, ‘Foreign Information Operations’, ‘Foreign Intelligence Agencies’ and ‘Foreign Government Entities’. Notably absent is any reference to extremists or transnational criminals. The ‘Case Officer’ is also asked to specify the environment of the target like the type of computer, operating system used, Internet connectivity and installed anti-virus utilities (PSPs) as well as a list of file types to be exfiltrated like Office documents, audio, video, images or custom file types. The ‘menu’ also asks for information if recurring access to the target is possible and how long unobserved access to the computer can be maintained. This information is used by the CIA’s ‘JQJIMPROVISE’ software (see below) to configure a set of CIA malware suited to the specific needs of an operation.


Improvise (JQJIMPROVISE)


‘Improvise’ is a toolset for configuration, post-processing, payload setup and execution vector selection for survey/exfiltration tools supporting all major operating systems like Windows (Bartender), MacOS (JukeBox) and Linux (DanceFloor). Its configuration utilities like Margarita allows the NOC (Network Operation Center) to customize tools based on requirements from ‘Fine Dining’ questionairies.


HIVE


HIVE is a multi-platform CIA malware suite and its associated control software. The project provides customizable implants for Windows, Solaris, MikroTik (used in internet routers) and Linux platforms and a Listening Post (LP)/Command and Control (C2) infrastructure to communicate with these implants.


The implants are configured to communicate via HTTPS with the webserver of a cover domain; each operation utilizing these implants has a separate cover domain and the infrastructure can handle any number of cover domains.


Each cover domain resolves to an IP address that is located at a commercial VPS (Virtual Private Server) provider. The public-facing server forwards all incoming traffic via a VPN to a ‘Blot’ server that handles actual connection requests from clients. It is setup for optional SSL client authentication: if a client sends a valid client certificate (only implants can do that), the connection is forwarded to the ‘Honeycomb’ toolserver that communicates with the implant; if a valid certificate is missing (which is the case if someone tries to open the cover domain website by accident), the traffic is forwarded to a cover server that delivers an unsuspicious looking website.


The Honeycomb toolserver receives exfiltrated information from the implant; an operator can also task the implant to execute jobs on the target computer, so the toolserver acts as a C2 (command and control) server for the implant.


Similar functionality (though limited to Windows) is provided by the RickBobby project.


See the classified user and developer guides for HIVE.


* * *


FREQUENTLY ASKED QUESTIONS


Why now?


WikiLeaks published as soon as its verification and analysis were ready.


In Febuary the Trump administration has issued an Executive Order calling for a “Cyberwar” review to be prepared within 30 days.


While the review increases the timeliness and relevance of the publication it did not play a role in setting the publication date.


Redactions


Names, email addresses and external IP addresses have been redacted in the released pages (70,875 redactions in total) until further analysis is complete.


  1. Over-redaction: Some items may have been redacted that are not employees, contractors, targets or otherwise related to the agency, but are, for example, authors of documentation for otherwise public projects that are used by the agency.

  2. Identity vs. person: the redacted names are replaced by user IDs (numbers) to allow readers to assign multiple pages to a single author. Given the redaction process used a single person may be represented by more than one assigned identifier but no identifier refers to more than one real person.

  3. Archive attachments (zip, tar.gz, …) are replaced with a PDF listing all the file names in the archive. As the archive content is assessed it may be made available; until then the archive is redacted.

  4. Attachments with other binary content are replaced by a hex dump of the content to prevent accidental invocation of binaries that may have been infected with weaponized CIA malware. As the content is assessed it may be made available; until then the content is redacted.

  5. The tens of thousands of routable IP addresses references (including more than 22 thousand within the United States) that correspond to possible targets, CIA covert listening post servers, intermediary and test systems, are redacted for further exclusive investigation.

  6. Binary files of non-public origin are only available as dumps to prevent accidental invocation of CIA malware infected binaries.

Organizational Chart


The organizational chart corresponds to the material published by WikiLeaks so far.


Since the organizational structure of the CIA below the level of Directorates is not public, the placement of the EDG and its branches within the org chart of the agency is reconstructed from information contained in the documents released so far. It is intended to be used as a rough outline of the internal organization; please be aware that the reconstructed org chart is incomplete and that internal reorganizations occur frequently.


Wiki pages


“Year Zero” contains 7818 web pages with 943 attachments from the internal development groupware. The software used for this purpose is called Confluence, a proprietary software from Atlassian. Webpages in this system (like in Wikipedia) have a version history that can provide interesting insights on how a document evolved over time; the 7818 documents include these page histories for 1136 latest versions.


The order of named pages within each level is determined by date (oldest first). Page content is not present if it was originally dynamically created by the Confluence software (as indicated on the re-constructed page).


What time period is covered?


The years 2013 to 2016. The sort order of the pages within each level is determined by date (oldest first).


WikiLeaks has obtained the CIA’s creation/last modification date for each page but these do not yet appear for technical reasons. Usually the date can be discerned or approximated from the content and the page order. If it is critical to know the exact time/date contact WikiLeaks.


What is “Vault 7”


“Vault 7” is a substantial collection of material about CIA activities obtained by WikiLeaks.


When was each part of “Vault 7” obtained?


Part one was obtained recently and covers through 2016. Details on the other parts will be available at the time of publication.


Is each part of “Vault 7” from a different source?


Details on the other parts will be available at the time of publication.


What is the total size of “Vault 7”?


The series is the largest intelligence publication in history.


How did WikiLeaks obtain each part of “Vault 7”?


Sources trust WikiLeaks to not reveal information that might help identify them.


Isn’t WikiLeaks worried that the CIA will act against its staff to stop the series?


No. That would be certainly counter-productive.


Has WikiLeaks already ‘mined’ all the best stories?


No. WikiLeaks has intentionally not written up hundreds of impactful stories to encourage others to find them and so create expertise in the area for subsequent parts in the series. They’re there. Look. Those who demonstrate journalistic excellence may be considered for early access to future parts.


Won’t other journalists find all the best stories before me?


Unlikely. There are very considerably more stories than there are journalists or academics who are in a position to write them.


Via ZeroHedge







Comment Policy: Threats of violence, foul language, bullying, and spam will not be tolerated and may be flagged.