WikiLeaks Dump Reveals CIA Malware That Can Sabotage User Software (bleepingcomputer.com)
An anonymous reader writes: "While the world was busy dealing with the WannaCry ransomware outbreak, last Friday, about the time when we were first seeing a surge in WannaCry attacks, WikiLeaks dumped new files part of the Vault 7 series," reports BleepingComputer. This time, the organization dumped user manuals for two hacking tools named AfterMidnight and Assassin. Both are malware frameworks, but of the two, the most interesting is AfterMidnight -- a backdoor trojan for stealing data from infected PCs. According to its leaked manual, AfterMidnight contains a module to "subvert" user software by killing processes and delaying the execution of user software. Examples in this manual show CIA operatives how to kill browsers every 30 seconds to keep targets focused on their work, how to delay the execution of PowerPoint software with 30 seconds just to mess with their targets, or how to lock up 50% of PC resources whenever the user starts certain software. Basically, the CIA created nagware.
how to lock up 50% of PC resources whenever the user starts certain software
Isn't that just windows updates?
Do you not think the other agencies don't have access to such tools and information already? Exploits are sold and distributed in the darkweb on a daily basis, you can even these days buy malware as a service. It's a highly advanced, highly lucrative industry with professionals at work on all sides. And not all the players are state actors, plenty of them have commercial interests in mind and these people don't care who's buying.
Now, someone else said it well in a recent story about WannaCry: the lesson of this story is not just 'guard your weapons better' but also 'make better armor'
Putting these exploits out there allows for people to defend themselves against them. Following the mentality of 'well let's just not tell anyone of this exploit we found and no $BAD GUYS will ever find it" is arrogant and stupid because there are billions of dollars involved in the industry of seeking out and taking advantage of these exploits. There are millions of people across the planet right now working for criminal enterprises whose day-to-day job it is to seek these security holes out, with or without sites like WikiLeaks.
I personally think the whole tactic of not informing companies of serious security flaws in their products in the hopes of one day being able to use said exploits to target $BAD GUYS, is incredibly stupid and shortsighted because it simultaneously puts EVERYONE running these systems in the US/west at risk of being attacked by whoever else has found the same exploit. It's literally the same as finding out a vaccine for a deadly virus but trying to keep it a secret in case one day you decide to start full-scale biological war against $BAD GUYS; if your population is not vaccinated and is hit first by the enemy, you're fucked. The risk-reward ration is absurd.
But then again, I'm not american, so that must mean I'm the enemy, right?
"It is the business of the future to be dangerous" -Alfred North Whitehead
Web programmer, lol. Spoiler alert: you don't deliver anything useful anyway.
Says an AC commenting on the web
What you should ask instead is why no one seams to leak such information to Wikileaks. It's not Wikileaks that hunts down and finds this information, it's sent to them. If you leak Russian secrets to them I'm quite sure that they would distribute them because it's not like the Internet is full of "I leaked Russian data to Wikileaks but they never released them" either.
To all those who keep looking forward to the year of Linux in the desktop - don't. The status quo is excellent. You can run Linux in the desktop without any problems and without much effort, if you want to, to do just about everything that you need and want. As long as Windows maintains its stranglehold, the bad guys and three letter government agencies world over will focus their efforts on Windows, leaving Linux desktops alone. The time has come to understand that the dominance of Windows in the desktop is a blessing to those of us who wish to run Linux in the desktop. We do not want for Linux to rule in the desktop, we want for Windows to carry on taking the heat. Fortunately, the asinine efforts behind Gnome and KDE (and the fading Unity) almost guarantee that Windows will remain the desktop of choice for the masses. And that is a very good thing for the rest of us.