Skip to main content

The CIA’s top secret virus control system

Early Friday morning, Wikileaks released its fifth batch of Vault 7 documents exposing the U.S. Central Intelligence Agency’s hacking techniques. The latest release, titled “Hive,” exposes the agency’s multi-platform malware suite that allows the CIA to monitor targets via malware as well as the ability to realize specific tasks on compromised machines.

Hive is said to provide customizable implants for a variety of operating systems for distinct types of devices, not just computers, tablets, and phones. Among the platforms vulnerable to Hive include Linux, Windows, Solaris, MikroTik (used in Internet routers), and AVTech Network Video Recorders (often used in CCTV recording). First released in 2010, Hive is essentially an “implant” that functions as both a beacon and shell, allowing CIA hackers to gain a foothold in devices that allow them to deploy any number of other tools, such as those detailed in previous releases.

Wikileaks has described Hive’s function as a “back-end infrastructure malware” that uses public HTTPS interfaces which provide “unsuspicious-looking cover domains” to hide its presence on infected devices. Each of those domains is linked to an IP address at a commercial Virtual Private Server (VPS) provider, which forwards all incoming traffic to what is termed a “Blot” server. All re-directed traffic is then examined by CIA hackers to see if it contains a valid beacon. If it does, then a tool handler – called Honeycomb in the released documents – and the CIA then begins initiating other actions on the target computer. The released user guide shows that Hive allows for the uploading and deleting of files as well as the execution of applications on the device.

Unlike some other Vault 7 tools which can persist indefinitely on targeted devices, Hive comes with a “self-delete” function that allows the malware to destroy itself if it receives no signal from the CIA for a set amount of time. The self-deletion leaves only a log and configuration file, containing only a time-stamp behind. Apparently this feature posed difficulties to CIA developers as the self-deletion can “be problematic due to the inability to accurately assess the reliability of the host’s system clock,” according to the Hive Developers Guide.

Wikileaks noted that anti-virus companies along with forensic experts have noticed before that malware, potentially originating from a state-actor, utilized the same back-end infrastructure implantation that Hive employs. Through the analysis of the communication between specific implants, these experts and software companies were able to determine that the malware’s origin came from a “well-resourced organization which was involved in intelligence gathering operations.”

However, there had been unable to attribute the back-end or the implants to the CIA, though Wikileaks’ release of Hive may change that. Indeed, Wikileaks noted in its press release that “The documents from this publication might further enable anti-malware researchers and forensic experts to analyse this kind of communication between malware implants and back-end servers used in previous illegal activities.

Wikileaks’ latest release comes on the heels of CIA director Mike Pompeo’s aggressive statements against the transparency organization in which he labeled them “non-state hostile intelligence service.” He also condemned Wikileaks’ editor-in-chief, Julian Assange of making “common cause with dictators.” While other CIA directors have targeted both Wikileaks and Assange in the past, Wikileaks now five releases of top secret CIA hacking tools may have prompted an escalation in Pompeo’s rhetoric. It remains to be seen if this rhetoric will translate into action, however.

Assange, for his part, doesn’t seem too concerned, choosing to respond with a witty retort that incisively pointed out the CIA’s lack of credibility in making such accusations:


Source and links:

Comments

Popular posts from this blog

Jeremy Corbyn: Gaza, Nuclear War & Why Movements Must Rise Now

Empire Files   Abby Martin sits down with MP Jeremy Corbyn in Bogotá during The Hague Group summit on Gaza. They discuss the limits of electoral politics, the danger of nuclear weapons, the central role of the US and UK in the Gaza genocide, and more.  

How China & Russia help Global South countries defend against US imperialism: Nicaragua explains

Geopolitical Economy Report   China and Russia help formerly colonized countries in the Global South defend their sovereignty amid constant US meddling and aggression, argues Daniel Ortega, President of Nicaragua, a Latin American country that has been invaded and militarily occupied by the USA multiple times. Ben Norton reports on the history of the Sandinista Revolution, and the struggle against Western imperialism.  

GAME OVER, Trump: Putin, China & BRICS Just CRUSHED US Dollar

Danny Haiphong   Donald Trump's war on BRICS is backfiring as the Russia & China-led Global South moves to dump the US dollar and build a new order independent of its dictates. Journalist and geopolitical analyst Ben Norton breaks it all down.    Related: Trump's tariffs: A unique opportunity for BRICS and the Global South to fully escape from dollar tyranny

Rule by the rich: Western governments are oligarchies, not democracies

Geopolitical Economy Report   Western governments claim to be models of democracy, and demonize their geopolitical adversaries as "authoritarian", but empirical evidence shows that the USA and European countries are oligarchies dominated by economic elites and large corporations. Billionaire Donald Trump is the perfect symbol of this, but he's by no means the only one. Ben Norton explains. 

Israel's DARK SECRET Genocide Economy EXPOSED

Double Down News   The REAL Reason US Sanctioned UN Special Rapporteur Francesca Albanese. 

New Corbyn Party Could Already TIE With Labour - Bombshell Poll

Owen Jones  

X of the day

In just over 5 hours, more than 80,000 people have signed up to help build a new kind of political party. We believe in democracy — and the establishment are running scared. We’re offering people something very precious: hope. Sign up at https://t.co/0bhBHhWvVa . pic.twitter.com/12Rkg6pEMr — Jeremy Corbyn (@jeremycorbyn) July 24, 2025

Several states vow to take six 'concrete' steps against Israel at Bogota summit

Colombia says 'we will no longer allow international law to be treated as optional' as nations pledge to prevent arms transfers to Israel for Gaza atrocities   by Laura Gamba in Bogota  A coalition of states from around the world gathering in Bogota on Wednesday agreed to implement six measures to stop Israel's onslaught on Gaza and prevent violations of international law. The announcement came as part of an "emergency summit" in the Colombian capital, co-hosted by the governments of Colombia and South Africa as co-chairs of The Hague Group, to coordinate diplomatic and legal action to counter what they describe as "a climate of impunity" enabled by Israel and its powerful allies. The Hague Group is currently a bloc of eight states, launched on 31 January in the eponymous Dutch city, with the stated goal of holding Israel accountable under international law. The conference brought together more than 30 states, including Algeria; Bolivia; Botswana; Brazil...

Media finally admits: Israel is committing genocide in Gaza, as US corporations profit

Geopolitical Economy Report   The New York Times finally admitted Israel is carrying out a genocide against the Palestinian people in Gaza, in an article by an Israeli scholar who studies the Holocaust. A United Nations report detailed how US corporations are profiting from these crimes, although the Trump administration responded by imposing sanctions on the UN expert who exposed it, Francesca Albanese. Ben Norton explains.