Brutal Kangaroo
22 June, 2017
Today, June 22nd 2017, WikiLeaks publishes documents from the Brutal Kangaroo project of the CIA. Brutal Kangaroo is a tool suite for Microsoft Windows that targets closed networks by air gap jumping using thumbdrives.
Source: https://wikileaks.org/vault7

The documents describe how a CIA operation can infiltrate a closed network (or a single air-gapped computer) within an organization or enterprise without direct access. It first infects a Internet-connected computer within the organization (referred to as "primary host") and installs the BrutalKangaroo malware on it.


The Brutal Kangaroo project consists of the following components:
- Drifting Deadline is the thumbdrive infection tool,
- Shattered Assurance is a server tool that handles automated infection of thumbdrives (as the primary mode of propagation for the Brutal Kangaroo suite),
- Broken Promise is the Brutal Kangaroo postprocessor (to evaluate collected information)
- Shadow is the primary persistence mechanism (a stage 2 tool that is distributed across a closed network and acts as a covert command-and-control network; once multiple Shadow instances are installed and share drives, tasking and payloads can be sent back-and-forth).
The primary execution vector used by infected thumbdrives is a vulnerability in the Microsoft Windows operating system that can be exploited by hand-crafted link files that load and execute programs (DLLs) without user interaction. Older versions of the tool suite used a mechanism called EZCheese that was a 0-day exploit until March 2015; newer versions seem use a similar, but yet unknown link file vulnerability (Lachesis/RiverJack) related to the library-ms functionality of the operating system.
RELATED CONTENT:
All with more details readers might be interested in
WikiLeaks publishes information about CIA's covert program 'Brutal Kangaroo'
Updated: Jun 22, 2017 18:14 ISTLink > http://www.aninews.in/newsdetail-MTY/MzIxMTE4/wikileaks-publishes-information-about-cia-039-s-covert-program-039-brutal-kangaroo-039-.html
Brutal Kangaroo: CIA-developed Malware for Hacking Air-Gapped Networks Covertly
2017-06-22T00:23:00-11:00Thursday, June 22, 2017
Link > http://thehackernews.com/2017/06/wikileaks-Brutal-Kangaroo-airgap-malware.html
RELATED CONTENT:
All with more details readers might be interested in
WikiLeaks publishes information about CIA's covert program 'Brutal Kangaroo'
Updated: Jun 22, 2017 18:14 ISTLink > http://www.aninews.in/newsdetail-MTY/MzIxMTE4/wikileaks-publishes-information-about-cia-039-s-covert-program-039-brutal-kangaroo-039-.html
Brutal Kangaroo: CIA-developed Malware for Hacking Air-Gapped Networks Covertly
2017-06-22T00:23:00-11:00Thursday, June 22, 2017
Link > http://thehackernews.com/2017/06/wikileaks-Brutal-Kangaroo-airgap-malware.html
No comments:
Post a Comment