28 July 2017

WikiLeaks Releases A Slew From Vault 7: IMPERIAL

Imperial
Today, July 27th 2017, WikiLeaks publishes documents from the Imperial project of the CIA.
Achilles is a capability that provides an operator the ability to trojan an OS X disk image (.dmg) installer with one or more desired operator specified executables for a one-time execution. 
Aeris is an automated implant written in C that supports a number of POSIX-based systems (Debian, RHEL, Solaris, FreeBSD, CentOS). It supports automated file exfiltration, configurable beacon interval and jitter, standalone and Collide-based HTTPS LP support and SMTP protocol support - all with TLS encrypted communications with mutual authentication. It is compatible with the NOD Cryptographic Specification and provides structured command and control that is similar to that used by several Windows implants.
SeaPea is an OS X Rootkit that provides stealth and tool launching capabilities. It hides files/directories, socket connections and/or processes. It runs on Mac OSX 10.6 and 10.7.
[Leaked Documents links are provided in this announcement
Source: https://gbhackers.com/cia-hacking-tools-achilles-aeris-seapea-revealed/
Achilles
A CIA Tool called Achilles V. 1.0 Developed to Create a trojanized OS X disk image (.dmg) installer.
Desire Execution files and Bash script inst are Allocated in Specific Tool_Directory and DMG installer installer-name.dmg obtain to Trojan.
Trojanized OS X Disk Image (dmg) behave as Original dmg and the first-time user needs to run all the application Executable then real Application launched later.
All the Traces files will be removed after the Execution of Trojan from .app and it will be replaced by original Trojan .app
It leads to developing a trojanized OS X Disk Image by an Operator.
Aeris
A second tool called Aeris 2. 1 is malware Developed for POSIX systems. which is Written in C language.
According to Document, it has an Ability to support automated file Exfiltration, configurable beacon interval and jitter, standalone and Collide-based HTTPS LP support and SMTP protocol support.
 
It has structured command & Control that is similar that used by several Windows malware.
These tools utilities seem it used to steal information from targeted hosts via secure TLS-encrypted channels.
This Malware Targeting following Linux Platform:
Debian Linux 7 (i386)
Debian Linux 7 (amd64)
Debian Linux 7 (ARM)
Red Hat Enterprise Linux 6 (i386)
Red Hat Enterprise Linux 6 (amd64)
Solaris 11 (i386)
Solaris 11 (SPARC)
FreeBSD 8 (i386)
FreeBSD 8 (amd64)
CentOS 5.3 (i386)
CentOS 5.7 (i386)
 
SeaPea
The third tool called SeaPea is an OS X Rootkit that provides a stealth and tool launching capabilities.
It was Developed in Shell Script and it was calling as Buildinstaller.py.
it has an ability to interact with the kernel of OS X  by CIA operators which lead to infect with OS X systems while rebooting.
SeaPea can able to hide files, Start socket connections and launch the malicious Files.
According to CIA’s SeaPea, Document Rootkit Operate in 3 categories.
  • Normal: A normal process is the default category for any process. The activity of a normal process is not hidden by the rootkit.
  • Elite: An elite process is hidden from normal processes and elite processes. That means that an elite process cannot see its own activity.
  • Super-Elite: A super-elite process is a type of elite process. A super-elite process is hidden from normal processes and elite processes, but not super-elite processes. This means that a super-elite process can see all activity. Only an elite process can become super-elite.
GBHackers On Security || Lands into Top 100 Information Security Blogs in the Planet








Vault 7: Projects All Releases

No comments: