Wikileaks today published a manual for a CIA tool that can remotely intercept streaming video and store it on disk for further analysis.
The tool's name is CouchPotato and it is described in a user manual dated February 14, 2014.
According to the manual, CIA agents can use it from a command line interface. They launch the tool by giving the URL of a video streaming in RTSP or H.264 format that they are interested in and the location where they want to save the file on their disk.
RTSP and H.264 format files are often used by IP-based surveillance cameras to stream video over the Internet or within a closed network.
CouchPotato appears to be a tool that can be used without compromising the victim's network, if the CIA agent manages to discover the URLs of the video streams.
CouchPotato can save streaming to disk in classic AVI video format or as JPEG images, in case the tool operator wants to save space.
In the latter case, CouchPotato can analyze, detect, and store images from the stream that have significant changes from the previous photo, thus only capturing images in which an object has moved.
CouchPotato, according to the manual published by Wikileaks, uses the FFmpeg utility for the video download process. However, the user manual seems to warn about a major drawback of the tool: its high use of basic CPU resources. CIA tests reveal that CouchPotato uses between 50% and 70% of the resources of the machine being used.
Today's leak is part of a larger series called Vault 7.
Let us recall that Wikileaks has been releasing documents in the Vault 7 series since March 7, 2017, exposing more and more tools of CIA hackers.
Year Zero: CIA exploits popular hardware and software.
Weeping Angel: the spying tool the agency uses to infiltrate smart TVs, turning them into covert microphones.
Dark Matter: exploits targeting iPhones and Macs.
Marble: the source code of a secret anti-forensic framework. Essentially an obfuscator used by the CIA to hide the true source of malware.
Grasshopper: a framework that allows the intelligence agency to easily create custom malware to compromise Microsoft Windows and bypass any virus protection.
Archimedes: a MitM attack tool allegedly created by the CIA to target computers within a local area network (LAN).
Scribbles: a software designed to add 'web beacons' to classified documents, to allow the intelligence agency to control leaks.
Athena:designed to take complete control of infected Windows computers, allowing the CIA to perform a variety of operations on the target machine, such as deleting data or installing malware, stealing data and sending it to CIA servers.
CherryBlossom: a tool that monitors a target's online activity, redirects the browser, detects email addresses and phone numbers, and more, via the router.
Brutal Kangaroo:a tool that can be used to infect air-gapped computers with malware.
ELSA: Windows malware used by the CIA to determine the location of a specific user using their computer's Wi-Fi.
OutlawCountry: Linux malware used by the CIA to determine the location of a specific user using their computer's Wi-Fi.
BothanSpy – Gyrfalcon: for stealing SSH credentials from Windows and Linux respectively
HighRise: the CIA's tool for monitoring and redirecting SMS messages to a remote server.
Achilles, Aeris and SeaPea: malware that intercepts and transfers data from MacOS and Linux systems
Dumbo: blocks cameras, microphones and surveillance software.
CouchPotato: CIA tool for stealing streaming video from IP Webcams
