Skip to main content

The deeper story behind CIA's attempt to 'impersonate' Russian cybersecurity company using hacking tool Hive


In 9 November 2017, WikiLeaks published the source code and development logs to Hive, a major component of the CIA infrastructure to control its malware.

According to WikiLeaks, Hive uses the uncommon Optional Client Authentication so that the user browsing the website is not required to authenticate - it is optional. But implants talking to Hive do authenticate themselves and can therefore be detected by the Blot server. Traffic from implants is sent to an implant operator management gateway called Honeycomb (see graphic above) while all other traffic go to a cover server that delivers the insuspicious content for all other users.

Digital certificates for the authentication of implants are generated by the CIA impersonating existing entities. The three examples included in the source code build a fake certificate for the anti-virus company Kaspersky Laboratory, Moscow pretending to be signed by Thawte Premium Server CA, Cape Town. In this way, if the target organization looks at the network traffic coming out of its network, it is likely to misattribute the CIA exfiltration of data to uninvolved entities whose identities have been impersonated.

This CIA cybertool could be proven very useful for accusing foreign agencies and organizations for hacking US facilities and processes, but beyond that, there is a deeper reason for which CIA has targeted the specific Russian company and it is related to the first discovered malware that spies on and subverts industrial systems.

Former British intelligence officer and Whistleblower, Annie Machon, reveals why CIA has targeted Kaspersky Lab:

Obviously, the CIA will be interested in a very successful Russian-based company that offers protection on the Internet. But it goes back a bit further because, it was 2010 the very first proven cyberwarfare weapon was deployed. And this was against the Iranian domestic civilian nuclear development capability. And this was at the time when the Americans were drumming up the war against Iran.

There was an attack made against their civilian nuclear capability, and in this case, this virus, which was called Stuxnet, was deployed against the centrifuges that enriched the Uranium. Nobody knew where it came from. It seemed to be very weaponized, a state level. And it was actually Kaspersky that unveiled who had developed it. It was the Americans and the Israeli intelligence agencies. So, Kaspersky has been very much in the cross-chairs of both the American and the Israeli intelligence agencies.


From Wikipedia, Stuxnet is a malicious computer worm, first uncovered in 2010 by Kaspersky Labs, the antivirus company. Thought to have been in development since at least 2005, stuxnet targets SCADA systems and was responsible for causing substantial damage to Iran's nuclear program. Although neither country has admitted responsibility, since 2012 the worm is frequently described as a jointly built American/Israeli cyberweapon.

Stuxnet, discovered by Sergey Ulasen, initially spread via Microsoft Windows, and targeted Siemens industrial control systems. While it is not the first time that hackers have targeted industrial systems, nor the first publicly known intentional act of cyberwarfare to be implemented, it is the first discovered malware that spies on and subverts industrial systems, and the first to include a programmable logic controller (PLC) rootkit.

Comments

Popular posts from this blog

Zionists pushed Trump into the war with Iran but this was not the primary reason for this catastrophic decision

by system failure     It is widely reported by various analysts that Trump's catastrophic decision to start a war with Iran, came as a result of the pressure from Netanyahu regime and the Zionist lobby in US. While we can't ignore the strong influence of the Zionist factor on Trump and its significant role on dragging him into such a catastrophe, this was probably not the primary reason for the latest US-Iran war.  One has to look first at Venezuela and the unprecedented and rather bizarre operation there to remove Nicolas Maduro from power, in order to understand the deeper reasoning behind such a risky decision by Trump against Iran. The uniqueness of the operation in Venezuela by the US imperialist beast, has to do not only with the blatant violation of international law with almost zero pretexts, but also with the fact that the rest of the Maduro administration was left untouched and permitted to remain in power. This shows that the primary goal of this operation was ...

Israel CAUGHT Spying On Trump & HERE’S WHY!

The Jimmy Dore Show   What does Donald Trump do to stop Netanyahu, or punish Netanyahu, after he openly defies him and after Donald Trump knows that Israel's intelligence services are spying on him? It appears that he has done nothing.  

It's official: Iran won the war, and the US lost - This is how

Geopolitical Economy Report  The US government has signed an agreement to end its war on Iran. It is now widely admitted that Washington lost, and Tehran won. Ben Norton explains why Donald Trump failed, and how this has massive geopolitical implications for the Global South.

Trump CAVES On Uranium & Ballistic Missiles!

The Jimmy Dore Show   Jimmy Dore and Glenn Greenwald argue that President Trump is engaging in a stark retreat from earlier hardline positions on Iran by signaling acceptance of both Iranian uranium enrichment for civilian energy purposes and allowing Iran to possess conventional ballistic missiles. The two contend that these comments amount to major concessions, with Jimmy describing them as “another big win for Iran” and evidence that the administration has abandoned key objectives it previously promoted. Greenwald cites the Nuclear Non-Proliferation Treaty, arguing that Iran has the same right as other signatory nations to enrich uranium for peaceful purposes and notes that previous agreements imposed unusually strict inspections on Iran’s program. The segment emphasizes Trump’s remarks that “it’s a little bit unfair for them not to have some” ballistic missiles and that restrictions on civilian nuclear energy require “a little common sense.” 

‘SHEER EVIL’: MASS PANIC As Israel BOMBS HOSPITAL & RESORT, ‘FLATTENS’ BEIRUT!!

Secular Talk    

IRAN WAR: How Israel HIJACKED Trump & Lost the Middle East

Double Down News  

Προβλέψεις ...

GR elections Update (15/9): Αναθεωρημένες προβλέψεις (μετά το δεύτερο debate): ΣΥΡΙΖΑ 28-30% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 2,5-3% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (11/9): Αναθεωρημένες προβλέψεις (μετά το πρώτο debate): ΣΥΡΙΖΑ 25-28% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (04/9): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update (29/8): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 4-4,5% ΠΟΤΑΜΙ 4-4,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update : Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 26-27% ...

How Western societies lost their faith in Vision

Why people don't rise up massively today? Why there are no real revolutions? How we tolerate all things that have been imposed to us? These questions come up in people's minds more and more often today in Greece and abroad, due to the economic crisis. Some theories are circulated as an answer, among these, explanations which include, for example, the psychosynthesis of modern Greeks, but the truth is that there is something more fundamental behind this passive behaviour and concerns not only Greece, but the entire Western world. by system failure Prior to the beginning of the 20th century, Friedrich Nietzsche declares God's death and Western world will put all its hopes in science. Laplace's Determinism leads to the almighty man, who through science, can find all the answers for the world. Technology, which naturally comes from scientific discoveries, promises prosperity and a better life for the majority. Science becomes the central "pylon...

Iranian Professor Vali Nasr Reveals the TRUTH of Iran War

Cyrus Janssen  Professor Vali Nasr is one of the world’s leading experts on Iran, the Middle East, and U.S. foreign policy. In this exclusive interview, Nasr explains why the recent conflict may have strengthened Iran rather than weakened it, what Washington continues to misunderstand about Tehran, and whether the region has entered a new geopolitical era. They discuss Iran’s nuclear ambitions, the country’s relationship with China, America’s changing position in the world, and why 2026 could become a turning point for the Middle East.   

Israeli Military Analyst: IDF "Lost & D*ing In Great Numbers" in Lebanon

Katie Halper   Haim Bresheeth Zabner, ex Israeli military analyst explains why Hezbollah is so superior to the IDF. He says, "the IDF are lost and dying in great numbers in Lebanon. He also notes that Hezbollah are "amazing fighters". Haim Bresheeth Zabnner was Professor of Media and Cultural Studies at University of East London and then a Professorial Research Associate at the School of Oriental and African Studies (SOAS).He is Filmmaker, photographer, film studies scholar, and historian. His films include “A State of Danger,” a documentary on the first Palestinian Intifada. His books include "An Army Like No Other: How the Israel Defense Force Made a Nation."    Haim is the son of two Holocaust survivors and was raised in Israel. He is a member of Holocaust survivors and Descendents Against the Genocide and a founding member of Jewish Network for Palestine. On November 4, Haim was arrested over a speech he gave at a pro Palestine demonstration outside the res...