SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Politics : Formerly About Advanced Micro Devices

 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext  
To: Thomas A Watson who wrote (1004737)3/8/2017 3:52:43 PM
From: scamp1 Recommendation

Recommended By
POKERSAM

   of 1575549
 
CIA USES ‘STOLEN’ MALWARE TO ‘ATTRIBUTE’ CYBERATTACKS TO OTHER STATES LIKE RUSSIA – WIKILEAKS
22 43 0 Share0 0



65

WikiLeaks has published documents, proving the fact that the CIA kept records of malware attacks, stolen from outside agents, to use them to ‘misdirect attribution’ of hacking sources.

The lobby of the headquarters of the Central Intelligence Agency in Langley, Va (Photo: Melanie Stetson Freeman / The Christian Science Monitor / File)

WikiLeaks released a series of documents, which reveal the fact that the Central Intelligence Agency (CIA) kept records of malware attacks supposedly stolen from outside agents, including the Russian government, and used them to ‘misdirect attribution’ of hacking sources.

“The CIA’s hand crafted hacking techniques pose a problem for the agency,” WikiLeaks noted, adding that “each technique it has created forms a ‘fingerprint’ that can be used by forensic investigators to attribute multiple different attacks to the same entity.”

According to WikiLeaks, the CIA has the so-called UMBRAGE team, which activities is described by the non-profit organization as follows: “The UMBRAGE team maintains a library of application development techniques borrowed from in-the-wild malware. The goal of this repository is to provide functional code snippets that can be rapidly combined into custom solutions. Rather than building feature-rich tools, which are often costly and can have significant CI value, this effort focuses on developing smaller and more targeted solutions built to operational specifications.”

As the WikiLeaks’ website noted, then the UMBRAGE team “collects and maintains a substantial library of attack techniques ‘stolen’ from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the ‘fingerprints’ of the groups that the attack techniques were stolen from.”

In this way, the CIA has an opportunity to use a malware attack, developed by another country to “misdirect attribution” for the hack away from themselves. The UMBRAGE’s arsenal of malware includes a collection of “keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.” WikiLeaks published a directory of the tools collected by the UMBRAGE team.
Report TOU ViolationShare This Post
 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext