While the whole world is trying to deal with the threat of the devastating WannaCry ransomware, WikiLeaks has released a new batch of CIA leaks in Vault 7. This time it describes two more CIA malware for the Windows platform.
They are called AfterMidnight and Assassin. Both malicious applications are designed to monitor and report actions from the victim's computer to a remote host apparently controlled by the CIA.
Since March, WikiLeaks has published hundreds of thousands of documents and secret hacking tools that it claims come from the US Central Intelligence Agency (CIA).
This latest batch is the 8th edition of the Vault 7 series.
AfterMidnight
According to WikiLeaks, AfterMidnight allows its operators to dynamically load and execute malicious payloads on the target's system.
The main controller of the malicious payload is a disguised DLL (Dynamic Link Library) file and executes “Gremlins” (small payloads that remain hidden on the target machine), undermining the functionality of the targeted software, or providing services to other Gremlins.
Once installed, AfterMidnight uses an HTTPS-based Post Listening Post (LP) system called Octopus to check for any scheduled events. If any are found, the malware downloads and stores all the necessary data before loading all new gremlins into memory.
According to the user guide provided in the latest WikiLeaks leak, the local storage performed by AfterMidnight is encrypted with a key that is not stored on the target machine.
A special payload, called AlphaGremlin, contains a custom script, which allows operators to schedule custom tasks to be executed on the targeted system.
Assassin
Assassin is similar to AfterMidnight and is described as “an automated implant that provides a simple collection platform on remote computers running the Microsoft Windows operating system.”.
Once installed on a victim's computer, this tool places malicious "implants" inside a Windows service process, allowing operators to perform malicious tasks on an infected machine, just like with AfterMidnight.
The Assassin consists of four subsystems: Implant, Builder, Command and Control, and Listening Post.
The 'Implant' provides the core logic and functionality of this tool on the victim's machine, and "takes care of communications and all task execution. It is configured using the 'Builder' and deployed to the target computer via a designated carrier.
Builder configures “implants” and “Deployment Executables” before deployment and “provides a custom command-line interface for configuring the implant configuration before building it,” the tool’s user guide.
The “Command and Control” subsystem acts as an interface between the operator and the Listening Post (LP), while the LP allows the Implant Assassin to communicate with the Command and Control subsystem via a Web server.
Recall that last week, WikiLeaks released a man-in-the-middle (MitM) attack tool, called Archimedes, allegedly created by the CIA to target computers within a local area network (LAN).
_____________________________________
This practice by US intelligence agencies of knowing about vulnerabilities and not disclosing them to development companies is also the cause of the spread of the WannaCry ransomware. The SMB flaw discovered by the NSA was never publicly disclosed until it was leaked by the Shadow Brokers a month ago.
Here we should mention that Microsoft, through Brad Smith, condemned the practice of the American intelligence agency, saying that the "widespread damage" caused by WannaCry occurred because of the NSA, the CIA and other intelligence agencies.
Since March, WikiLeaks has made 8 publications in the “Vault 7” series, including major leaks:
“Year Zero” CIA exploits popular hardware and software.
“Weeping Angel” the spying tool the agency uses to infiltrate smart TVs, turning them into covert microphones.
“Dark Matter” exploits targeting iPhones and Macs.
“Marble” the source code of a secret anti-forensic framework. Essentially an obfuscator the CIA uses to hide the true source of malware.
“Grasshopper” a framework that allows the intelligence agency to easily create custom malware to compromise Microsoft Windows and bypass any virus protection.
“Scribbles” is a software designed to add 'web beacons' to classified documents, to allow for control of leaks by the secret services.
