Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

WikiLeaks Details CIA’s Air-Gapped Network Hacking Tool

WikiLeaks published several documents on Thursday detailing a tool allegedly used by the U.S. Central Intelligence Agency (CIA) to hack air-gapped networks through USB drives.

WikiLeaks published several documents on Thursday detailing a tool allegedly used by the U.S. Central Intelligence Agency (CIA) to hack air-gapped networks through USB drives.

Dubbed “Brutal Kangaroo,” it has been described by its developer as a tool suite designed for targeting closed networks. The infected systems will form a covert network, and the attacker will be able to obtain information and execute arbitrary files.

One component of Brutal Kangaroo is called “Shattered Assurance” and it’s designed to automatically spread the tool to USB drives connected to a device within the targeted organization that was infected remotely via the Internet. Shattered Assurance relies on a tool named “Drifting Deadline” to infect thumb drives.

Once the victim connects the infected drive to an air-gapped network and Brutal Kangaroo is deployed, a component named “Broken Promise” is used to evaluate the harvested data. The last component, dubbed “Shadow,” acts as the primary persistence mechanism and command and control (C&C) server on the closed network.

The documents published by WikiLeaks show that Drifting Deadline and Shattered Assurance replaced two previous tools named “EZCheese” and “Emotional Simian.”

Brutal Kangaroo

Brutal Kangaroo infects USB drives by exploiting Windows vulnerabilities that allow an attacker to execute arbitrary DLL files using specially crafted shortcut (LNK) files. At least some of the exploits do not require users to actually run the malicious files.

Earlier versions of EZCheese leveraged a Windows vulnerability (CVE-2015-0096) discovered and patched in 2015. The flaw is a newer variant of CVE-2010-2568, which the notorious Stuxnet worm used in attacks aimed at Iran’s nuclear program.

One exploit used in later versions, dubbed “Lachesis” and designed for Windows 7, relies on autorun.inf to execute the malicious file as soon as the thumb drive is plugged in. Another exploit, named “RiverJack” and designed for Windows 7, 8 and 8.1, leverages library-ms functionality.

Advertisement. Scroll to continue reading.

Microsoft said the vulnerabilities used by these exploits have already been patched in supported versions of Windows, but it’s unclear when. The company this month patched a LNK remote code execution flaw (CVE-2017-8464) that has been actively exploited, but no information has been provided on these attacks.

While the exploits may have been successful in some cases, the Brutal Kangaroo documents show that security products from Symantec, Avira, Avast, Bitdefender and Kaspersky did block at least some functionality and attack vectors.

WikiLeaks has been publishing CIA files, which are part of a leak dubbed “Vault 7,” nearly every week since March 23. The tools exposed by the whistleblower organization include ones designed for replacing legitimate files with malware, hacking Samsung smart TVs and routers, MitM tools, a framework used to make malware attribution and analysis more difficult, and a platform for creating custom malware installers.

Security firms have found links between the tools exposed by Wikileaks and the malware used by a cyber espionage group tracked as “Longhorn” and “The Lamberts.”

Related Reading: Hackers Can Use Scanners to Control Air-Gapped Malware

Related Reading: Router LEDs Allow Data Theft From Air-Gapped Computers

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cybersecurity Funding

Network security provider Corsa Security last week announced that it has raised $10 million from Roadmap Capital. To date, the company has raised $50...

Network Security

Attack surface management is nothing short of a complete methodology for providing effective cybersecurity. It doesn’t seek to protect everything, but concentrates on areas...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Identity & Access

Hackers rarely hack in anymore. They log in using stolen, weak, default, or otherwise compromised credentials. That’s why it’s so critical to break the...