HomeinetWikileaks Vault 7: Pandemic

Wikileaks Vault 7: Pandemic

Pandemic: WikiLeaks has released new documents in its Vault 7 series. This time it details a tool used by the CIA to spread malware into networks of targeted organizations, agencies, or companies.

It is called “pandemic,” or “Pandemic,” and it can install a filter driver on the file system on a network, replacing legitimate files with a malicious payload remotely via the SMB (Server Message Block) protocol.

“Pandemic does NOT make any physical changes to the targeted file on disk. The targeted file on the Pandemic system is installed and remains unchanged. Targeted users with Pandemic use SMB to download the targeted file, with the “Replacement File,” the tool’s description states.Pandemic

This makes this tool very interesting since it is particularly difficult to detect infected systems. Pandemic overwrites files in transit, rather than modifying them on the device, so the legitimate file remains unchanged.

Pandemic is a tool designed to run on 32- and 64-bit Windows systems and is initially installed on machines from which users download and execute files remotely. Files released by WikiLeaks show that up to 20 files can be replaced at a time, with a maximum size of 800 Mb.

“As the name suggests, a single computer on a local network with shared drives that is infected with the Pandemic implant will act as patient zero in the spread of a disease. It will infect remote computers if the user runs programs.”

The documents explicitly state that it is technically possible for “remote computers providing file shares to automatically become new Pandemic file servers on a local network to achieve infections on new targets,” WikiLeaks reports.

The new leaks contain information, even on how to check if a system has been infected with Pandemic.

Let us recall that Wikileaks has been releasing documents in the Vault 7 series since March 7, exposing more and more tools of CIA hackers.

“Year Zero” CIA exploits popular hardware and software.
“Weeping Angel” the spying tool the agency uses to infiltrate smart TVs, turning them into covert microphones.
“Dark Matter” exploits targeting iPhones and Macs.
“Marble” the source code of a secret anti-forensic framework. Essentially an obfuscator the CIA uses to hide the true source of malware.
“Grasshopper” a framework that allows the intelligence agency to easily create custom malware to compromise Microsoft Windows and bypass any virus protection.

“Archimedes”– a MitM attack tool allegedly created by the CIA to target computers within a local area network (LAN).
Scribbles” a software designed to add 'web beacons' to classified documents, to allow for the control of leaks by the secret services.
Athena:designed to be able to gain complete control of infected Windows computers, allowing the CIA to perform a multitude of functions on the target machine, such as deleting data or installing malware, stealing data and sending it to CIA servers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS