HomeSecurityWikiLeaks Brutal Kangaroo: CIA tools for air-gapped computers

WikiLeaks Brutal Kangaroo: CIA tools for air-gapped computers

WikiLeaks Brutal Kangaroo: WikiLeaks has published more classified CIA documents online describing the agency's hacking tools. This time the software it describes is referred to as Brutal Kangaroo, and can be used to infect air-gapped computers with malware.

The documents, originally created on May 11, 2015, and revised on February 23 of the following year, describe the Brutal Kangaroo project, which uses compromised Windows computers to spread malware to non-networked machines via USB sticks.

The CIA suite published by WikiLeaks replaces previous CIA tools called EZCheese and Emotional Simian, a type of cyber-weapon used by the US intelligence agency to spread Stuxnet.

WikiLeaks Brutal Kangaroo
THN Image

According to the user guide [PDF], the software consists of four specific applications.

Shattered Assurance is the server-side code that forms the basis of the attack system and infects USBG drives connected to an infected computer with the Drifting Deadline.

Once an infected thumb drive is plugged into a computer, it automatically runs its contents and uses Windows 7 as the operating system. Immediately after running .Net 4.5, Drifting Deadline serves up Shadow malware to the system.

Shadow malware is a very old piece of software – the user manual [PDF] dates back to August 31, 2012 – and comes in both client and server versions. It is very specifically configured for specific purposes. The operator can configure it to collect system data up to 10% of the system’s memory, watermark all the data it collects, and store it in an encrypted partition on the infected computer’s hard drive.

Once the infection is complete, Shadow will search for other connected systems and infect them. It can be configured to place the stolen data on any new drive installed on the system or send it somewhere if it detects an open internet connection.

The latest application in Brutal Kangaroo is Broken Promise, which is a tool used for easy and fast data examination. Overall, the Brutal Kangaroo suite could be very useful for neutralizing air-gapped machines that are commonly used for more security in internal corporate networks.

There is nothing particularly strange about the Brutal Kangaroo suite released by WikiLeaks as part of the Vault 7 archive. The software described is something we would expect an intelligence agency to use.

Let us recall that Wikileaks has been releasing documents in the Vault 7 series since March 7, exposing more and more tools of CIA hackers.

“Year Zero” CIA exploits popular hardware and software.
“Weeping Angel” the spying tool the agency uses to infiltrate smart TVs, turning them into covert microphones.
“Dark Matter” exploits targeting iPhones and Macs.
“Marble” the source code of a secret anti-forensic framework. Essentially an obfuscator the CIA uses to hide the true source of malware.
“Grasshopper” a framework that allows the intelligence agency to easily create custom malware to compromise Microsoft Windows and bypass any virus protection.

“Archimedes”– a MitM attack tool allegedly created by the CIA to target computers within a local area network (LAN).
Scribbles: a software designed to add 'web beacons' to classified documents to allow intelligence agencies to monitor leaks.
Athena:designed to take complete control of infected Windows computers, allowing the CIA to perform a variety of operations on the target machine, such as deleting data or installing malware, stealing data and sending it to CIA servers.
CherryBlossom: a tool that monitors a target's online activity, redirects the browser, detects email addresses and phone numbers, and more, via the router.
Brutal Kangaroo: a tool that can be used to infect air-gapped computers with malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS