OutlawCountry: Following the ELSA tool, which according to WikiLeaks is a Windows malware used by the CIA to determine the location of a specific user, comes the revelation of OutlawCountry, a different hacking tool used by the agency, on Linux devices.
A user manual leaked by WikiLeaks reveals that the CIA has been using OutlawCountry since at least June 2015. The tool is specifically designed to redirect outgoing Internet traffic to other addresses.
This essentially means that CIA agents can monitor the activity of a Linux server. However, for OutlawCountry to be effective, the intelligence agency would first need to gain root access privileges.
In other words, the CIA would first have to hack a Linux system with some different method before OutlawCountry could operate.
OutlawCountry
WikiLeaks reports that the first version of OutlawCountry contains a kernel module for CentOS/RHEL 6.x 64-bit and can only work with default kernels, while it only supports adding covert DNAT rules to the PREROUTING chain.
“The malware consists of a kernel module that creates a hidden netfilter table on a Linux target. Knowing the name of the table, the attacker can create rules that override existing netfilter/iptables rules and are hidden from a user or even the system administrator,” WikiLeaks reports
The user manual explains exactly how the hacking tool works, while revealing that the CIA can remove all traces of the malware once the attack is complete.
“The OutlawCountry tool carries a working kernel module for Linux 2.6. The attacker loads the module with a shell on the target. When loaded, the module creates a new netfilter table. The new table allows the creation of certain rules using the iptables command. These rules override existing rules and are only visible to an administrator who knows the table name. When the attacker removes the kernel module, the new table is also removed.”
Just like on Windows, Linux users are advised to update their systems promptly to the latest versions and deploy all available patches released in the official repositories of each distribution.
WikiLeaks Vault 7
Let us recall that Wikileaks has been releasing documents in the Vault 7 series since March 7, exposing more and more tools of CIA hackers
“Year Zero” CIA exploits popular hardware and software.
“Weeping Angel” the spying tool the agency uses to infiltrate smart TVs, turning them into covert microphones.
“Dark Matter” exploits targeting iPhones and Macs.
“Marble” the source code of a secret anti-forensic framework. Essentially an obfuscator the CIA uses to hide the true source of malware.
“Grasshopper” a framework that allows the intelligence agency to easily create custom malware to compromise Microsoft Windows and bypass any virus protection.
“Archimedes”– a MitM attack tool allegedly created by the CIA to target computers within a local area network (LAN).
Scribbles: a software designed to add 'web beacons' to classified documents to allow intelligence agencies to monitor leaks.
Athena:designed to take complete control of infected Windows computers, allowing the CIA to perform a variety of operations on the target machine, such as deleting data or installing malware, stealing data and sending it to CIA servers.
CherryBlossom a tool that monitors a target's internet activity, redirects the browser, detects email addresses and phone numbers, and more, via the router.
Brutal Kangaroo: a tool that can be used to infect air-gapped computers with malware.
ELSA: a Windows malware used by the CIA to determine the location of a specific user using their computer's Wi-Fi.
