WikiLeaks Doc Dump Reveals CIA Tools For Hacking Air-Gapped PCs (bleepingcomputer.com)
An anonymous reader writes: "WikiLeaks dumped today the manuals of several hacking utilities part of Brutal Kangaroo, a CIA malware toolkit for hacking into air-gapped (offline) networks using tainted USB thumb drives," reports Bleeping Computer. The CIA uses these tools as part of a very complex attack process, that allows CIA operatives to infect offline, air-gapped networks. The first stage of these attacks start with the infection of a "primary host," an internet-connected computer at a targeted company. Malware on this primary host automatically infects all USB thumb drives inserted into the machine. If this thumb drive is connected to computers on an air-gapped network, a second malware is planted on these devices. This malware is so advanced, that it can even create a network of hacked air-gapped PCs that talk to each other and exchange commands. To infect the air-gapped computers, the CIA malware uses LNK (shortcut) files placed on the USB thumb drive. Once the user opens and views the content of the thumb drive in Windows Explorer, his air-gapped PC is infected without any other interaction.
Once again, no love for macOS, Linux and BSD.
#DeleteFacebook
If this thumb drive is connected to computers on an air-gapped network, a second malware is planted on these devices.
If you work at a company that has an air-gapped private network for security reasons and you actually do this, then you are a moron and deserve to be fired. I've worked for a defense contractor. We were all trained to not do stupid things like this; basic OPSEC.
When there is a will there is a way.
...any computer that can run software isn't secure. Mind blown.
Years ago there was an article about USB malware dongles that are so small that you couldn't see that they were there... and could still plug another USB device into the same port.
virtually unstoppable
Never create a weapon that you wouldn't want to fall into the hands of your worst enemy... because it will.
Anons need not reply. Questions end with a question mark.
Some other file manager instead of windows explorer might not trigger the exploit, assuming autoplay is disabled? Maybe?
You were so close to understanding the solution. If only you hadn't added the word "explorer" to your sentence.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
I get that part. I'm saying if you use a non-explorer file browser and disable autorun, does that defeat the vector used here - not all vectors, dip.
Next time, listen.
I blame the router and modem manufacturers for this, actually.
"Oh, what harm could ever come from releasing source code to the Russians, it's not like they would subvert the elections in all Western nations"
Sure.
oh, and you should totally trust your anti-virus security to Russian firms too.
The surprising thing is you've pretty much only realized the tools we designed a few decades ago, until we realized how deeply the Russians had burrowed into you.
-- Tigger warning: This post may contain tiggers! --
So they managed to create a network requiring no persistent connections? They should claim their 2 mil prize!
Great point ... because when you have an air-gapped computer for security reasons, the last thing you want to do is eliminate as many attack vectors as possible.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
Whoever released these tools to Wikileaks is absolutely a traitor.
This is a weaker example of our atomic secrets being leaked to Russia. These are legitimate weapons in the modern era and someone is leaking them to all of our adversaries. These are not examples of government overreach like with the mass collection of call metadata.
You really are so close to understanding the basic *(minor) point I was making, but your overlarge head got stuck in your ass on the way.
Midnight Commander might be a good alternative. It's not just GPL, it's an official GNU project. Windows binaries are available if you don't want to build it from source.
It's a clone of the classic Norton Commander.
Once the CIA, MI6, GCHQ and NSA get interested they will find out what consumer grade OS the interesting site is using.
The question is then to risk a network detecting the data moment and blame "malware" with another nations code litter.
Or to walk, post the USB stick using some cover story.
Domestic spying is now "Benign Information Gathering"
Whoever believes this is absolutely an idiot.
Yes I said it again.
This sounds a lot like the BadBIOS malware that was reported by Dragos Ruiu in 2013.
https://en.wikipedia.org/wiki/BadBIOS
the NSA/CIA have methods beyond this. they use satellites and ground based radar to literally focus laser beams into computers/people remotely, allowing them to copy DRAM, CPU, hard drive, brain, and the like. the system uses interferometry to do it. the system can even flip polarity states of electrons, flip bits in DRAM, and alter hard drives.
capabilities include: deleting a file, and adding a file to any type of file system or storage medium.
reading/'writing encryption codes from DRAM, or reading a certificate from a hard drive.
reading/writing out Trusted Computing Platform codes directly from the chip.
reading/writing memory, passwords, thoughts, and feeling from human beings.
they can even watch you type, or corrupt and crash computer systems.
all of this is possible thanks to the Electromagnetic Pulse from infinite distances.
they are flooding the market with these lower tech methods they don't rely on very much. Snowden, and now the CIA dumps from WikiLeaks, are the low-tech side they don't rely on very much.
I know this. I am secretly running with people with higher clearance than Edward Snowden had. I'm even personal friends with the CIA/NSA/DOD/NASA/US DOJ whistleblowers.
https://www.trumpsweapons.com/
https://www.drrobertduncan.com...
when will the public catch up.
I get that part. I'm saying if you use a non-explorer file browser and disable autorun, does that defeat the vector used here - not all vectors, dip.
just use another OS, as a multimedia producer I can only deliver an autoplay (with minor popup window accept thingy) in "some" windows versions, other OSes had drop that thing like 15 years ago.
I second Midnight Commander.
It's an amazing application. One of its best features is it looks and works the same on Windows, macOS, Linux, and *BSD. Once you learn it (which isn't hard at all -- it's pretty darn self evident), you've boosted your productivity in all of the aforementioned operating systems.
Bonus feature: No Microsoft OneDrive advertisements built into the application!
What if we had a TLA that searched for ways the Bad Guys could Fuck Us Up. Now imagine we had a TLA that searched for ways the Bad Guys could Fuck Us Up, but it turns out our TLA are The Bad Guys.
This shit needs to stop. Hopefully the NSA and whomever have figured out they aren't the smartest kids in the room and decide to make us all more secure.
Damn, meds are wearing off and I'm back to reality. Shit, real life really sucks ass.
Open machines and cut the fucking wires.
Ha!....
if you're a branch of government or municipality, or in industry and finance, just get rid of the Windows machines.
The only place where it may prove difficult is certain parts of manufacturing and design that depend on f.ex. Autocad, but there's a lot of maneuverability here in isolating machines from the Internet or other networks they don't really need to access.
Ultimately, you have the upper hand in this, not Microsoft or the U.S. agencies that are attacking and sabotaging your government and industry.
I got your phenomenally stupid point dumbfuck.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
What purpose does this serve except to inform governments that want to cause harm, build weapons, and improve intelligence countermeasures? Were any civil liberties of Americans violated, or any paranoid people think that the government will use this against them?
Some other file manager instead of windows explorer might not trigger the exploit, assuming autoplay is disabled? Maybe?
If I'm forced to use Windows, I like to use Far Manager. It's a text mode file manager so I can stroke my neckbeard while I use it.
Remember, USB requires *absolute* trust. Any USB device plugged into the bus can rewrite the low level firmware and plant itself inside the USB controller on your motherboard. There is no authentication to defeat, all physically present USB devices own the entire box if they wish. If you've gone to the trouble of air-gapping your PC I assume you knew to glue-gun the USB ports too. If not, then yes, you will be pwned.