Athena: WikiLeaks has published a new batch of Vault 7 leaks, which describe a spyware eavesdropping tool. The new CIA tool “provides the ability to remotely connect to and load malware onto target computers,” and is supposedly used by the intelligence agency for every version of Microsoft’s operating systems, from Windows XP to Windows 10.
The spyware is designed to gain complete control over infected Windows computers, allowing the CIA to perform a multitude of functions on the target machine, such as deleting data or installing malware, stealing data and sending it to CIA servers.
The leak includes an Athena user manual, an overview of the technology, and a demonstration of how to use the spyware. It reveals that the malicious application can have two uses:
Primary: Athena from XP to Windows 10
Secondary: Hera for Windows 8 through Windows 10
According to WikiLeaks, Athena allows CIA agents to modify their configuration in real time, while the implant can be “adapted to a function.”.
“Once installed, the malware provides the ability to take snapshots, configure and manage tasks, load and unload malicious payloads into memory for specific tasks, and deliver and retrieve files from and to specific folders on the target system.”.
The leaked documents suggest that Athena, written in the Python programming language, was developed in August 2015, a month after Microsoft released the Windows 10 operating system.
Interestingly, a document warns CIA agents to make sure that the spyware will not be detected by antivirus software programs, such as Kaspersky AV.
Athena was developed by the CIA in partnership with Siege Technologies – an American cybersecurity company that offers offensive technologies and works closely with the United States government.
However, WikiLeaks did not provide any details about the activities for which Athena has been used, although it is not difficult to imagine how the CIA would use this program.
Since March, WikiLeaks has released nine leaked articles in the “Vault 7” series:
“Year Zero” CIA exploits popular hardware and software.
“Weeping Angel” the spying tool the agency uses to infiltrate smart TVs, turning them into covert microphones.
“Dark Matter” exploits targeting iPhones and Macs.
“Marble” the source code of a secret anti-forensic framework. Essentially an obfuscator the CIA uses to hide the true source of malware.
“Grasshopper” a framework that allows the intelligence agency to easily create custom malware to compromise Microsoft Windows and bypass any virus protection.
“Archimedes”– a MitM attack tool allegedly created by the CIA to target computers within a local area network (LAN).
Scribbles” a software designed to add 'web beacons' to classified documents, to allow for control of leaks by the secret services.
