WikiLeaks has just published another hacking tool developed by the CIA. This time, however, the intelligence agency is not targeting US companies or citizens, but colleagues from other intelligence agencies such as the NSA, the FBI and the Department of Homeland Security.
The tool was called ExpressLane, and it was created to help the CIA access information that other agencies refused to share with them, such as biometric data.
The CIA provided technical support for a biometric data collection system to cooperating agencies. As part of this cooperation with other intelligence agencies, the NSA and the FBI agreed to share the biometric data they collected with the CIA. However, in case any of the above agencies did not deliver the agreed data, the CIA had a backup plan.
ExpressLane is available as an updated version of the biometric data collection software, so every time an update was released, checks were automatically carried out to see what each cooperating service was hiding.
WikiLeaks reports that this update did not make changes to the program itself, which could trigger security solutions used by IT, but rather collected data on a USB stick for agents to inspect later.
Furthermore, the ExpressLane app was developed from the ground up to be undetectable, and if any CIA collaborators found anything suspicious, it could self-destruct.
“The core components of the OTS system are based on the products of Cross Match, an American company specializing in biometric software for law enforcement and the Intelligence Community.
In 2011, there were headlines reporting that the US military used a Cross Match product to track down Osama bin Laden during the assassination operation in Pakistan,” WikiLeaks reports.
Today's leak is part of a larger series called Vault 7.
Let us recall that Wikileaks has been releasing documents in the Vault 7 series since March 7, 2017, exposing more and more tools of CIA hackers.
Year Zero: CIA exploits popular hardware and software.
Weeping Angel: the spying tool the agency uses to infiltrate smart TVs, turning them into covert microphones.
Dark Matter: exploits targeting iPhones and Macs.
Marble: the source code of a secret anti-forensic framework. Essentially an obfuscator used by the CIA to hide the true source of malware.
Grasshopper: a framework that allows the intelligence agency to easily create custom malware to compromise Microsoft Windows and bypass any virus protection.
Archimedes: a MitM attack tool allegedly created by the CIA to target computers within a local area network (LAN).
Scribbles: a software designed to add 'web beacons' to classified documents, to allow the intelligence agency to control leaks.
Athena:designed to take complete control of infected Windows computers, allowing the CIA to perform a variety of operations on the target machine, such as deleting data or installing malware, stealing data and sending it to CIA servers.
CherryBlossom: a tool that monitors a target's online activity, redirects the browser, detects email addresses and phone numbers, and more, via the router.
Brutal Kangaroo:a tool that can be used to infect air-gapped computers with malware.
ELSA: Windows malware used by the CIA to determine the location of a specific user using their computer's Wi-Fi.
OutlawCountry: Linux malware used by the CIA to determine the location of a specific user using their computer's Wi-Fi.
BothanSpy – Gyrfalcon: for stealing SSH credentials from Windows and Linux respectively
HighRise: the CIA's tool for monitoring and redirecting SMS messages to a remote server.
Achilles, Aeris and SeaPea: malware that intercepts and transfers data from MacOS and Linux systems
Dumbo: blocks cameras, microphones and surveillance software.
CouchPotato: CIA tool for stealing streaming video from IP Webcams
ExpressLane: CIA tool for monitoring colleagues at the FBI and NSA
