Skip to main content

The deeper story behind CIA's attempt to 'impersonate' Russian cybersecurity company using hacking tool Hive


In 9 November 2017, WikiLeaks published the source code and development logs to Hive, a major component of the CIA infrastructure to control its malware.

According to WikiLeaks, Hive uses the uncommon Optional Client Authentication so that the user browsing the website is not required to authenticate - it is optional. But implants talking to Hive do authenticate themselves and can therefore be detected by the Blot server. Traffic from implants is sent to an implant operator management gateway called Honeycomb (see graphic above) while all other traffic go to a cover server that delivers the insuspicious content for all other users.

Digital certificates for the authentication of implants are generated by the CIA impersonating existing entities. The three examples included in the source code build a fake certificate for the anti-virus company Kaspersky Laboratory, Moscow pretending to be signed by Thawte Premium Server CA, Cape Town. In this way, if the target organization looks at the network traffic coming out of its network, it is likely to misattribute the CIA exfiltration of data to uninvolved entities whose identities have been impersonated.

This CIA cybertool could be proven very useful for accusing foreign agencies and organizations for hacking US facilities and processes, but beyond that, there is a deeper reason for which CIA has targeted the specific Russian company and it is related to the first discovered malware that spies on and subverts industrial systems.

Former British intelligence officer and Whistleblower, Annie Machon, reveals why CIA has targeted Kaspersky Lab:

Obviously, the CIA will be interested in a very successful Russian-based company that offers protection on the Internet. But it goes back a bit further because, it was 2010 the very first proven cyberwarfare weapon was deployed. And this was against the Iranian domestic civilian nuclear development capability. And this was at the time when the Americans were drumming up the war against Iran.

There was an attack made against their civilian nuclear capability, and in this case, this virus, which was called Stuxnet, was deployed against the centrifuges that enriched the Uranium. Nobody knew where it came from. It seemed to be very weaponized, a state level. And it was actually Kaspersky that unveiled who had developed it. It was the Americans and the Israeli intelligence agencies. So, Kaspersky has been very much in the cross-chairs of both the American and the Israeli intelligence agencies.


From Wikipedia, Stuxnet is a malicious computer worm, first uncovered in 2010 by Kaspersky Labs, the antivirus company. Thought to have been in development since at least 2005, stuxnet targets SCADA systems and was responsible for causing substantial damage to Iran's nuclear program. Although neither country has admitted responsibility, since 2012 the worm is frequently described as a jointly built American/Israeli cyberweapon.

Stuxnet, discovered by Sergey Ulasen, initially spread via Microsoft Windows, and targeted Siemens industrial control systems. While it is not the first time that hackers have targeted industrial systems, nor the first publicly known intentional act of cyberwarfare to be implemented, it is the first discovered malware that spies on and subverts industrial systems, and the first to include a programmable logic controller (PLC) rootkit.

Comments

Popular posts from this blog

Capitalism & Genocide - Yanis Varoufakis Speech at the Gaza Tribunal, 23rd October 2025, Istanbul

Yanis Varoufakis   On 23rd October, Yanis Varoufakis testified in front of the Jury of Conscience in the context of the Gaza Tribunal. His speech focused on the economic forces underpinning the genocide of the Palestinian people. In particular, he spoke on the manner in which capitalist dynamics have historically fuelled the white settler colonial project and, more recently, how the accumulation of a new form of capital - which he calls cloud capital - has accelerated, deepened and amplified the economic forces powering and propelling the machinery of genocide. 

Saudi Arabia & Qatar caught Mossad agents planning false flag operations inside their soil to blame Iran

Tucker Carlson says Saudi Arabia & Qatar caught & arrested Israeli Mossad agents planning bombings in those countries. pic.twitter.com/6PUxWeUymu — Jackson Hinkle 🇺🇸 (@jacksonhinklle) March 3, 2026

What Iran, Russia & China just did is HUGE, War BACKFIRES on Trump

Danny Haiphong   Iran's shocking response to Trump's imminent attack is sending fear down the spines of the US military as war leaves them defenseless from Iranian missile fire says Mohammad Marandi. This video breaks down why this war is already backfiring on Trump. 

US-Israeli attack on Iran expands into GLOBAL WAR: EU & UK join, Canada supports, Gulf regimes hit

Geopolitical Economy Report   The US-Israeli war on Iran is expanding into a global conflict. The European Union supports it. The UK is letting Trump use British bases. Germany and France are involved. Canada backs it. Tehran has retaliated, in self-defense, hitting US military bases in Gulf countries. Ben Norton explains. 

This Is Why Iran Will DEFEAT The United States & Israel!

The Jimmy Dore Show    

Munich Shock: Rubio’s Vision of a New Western Century & World Order

GVS Deep Dive   At the 2026 Munich Security Conference, U.S. Secretary of State Marco Rubio delivered one of the most consequential foreign policy speeches of the year. Framed as a call for Western renewal, his address went far beyond NATO reassurance — outlining a vision of sovereignty, industrial consolidation, and civilizational confidence that may signal the end of the post-Cold War global order.   Is this the beginning of a Second Cold War?   Is the West reorganizing around bloc competition?   Or are we witnessing the construction of a new world order? 

A response to misinformation on Nicaragua: it was a coup, not a ‘massacre’

There is so much misinformation in mainstream corporate media about recent events in Nicaragua that it is a pity that Mary Ellsberg’s article for Pulse has added to it with a seemingly leftish critique. Ellsberg claims that recent articles, including from this website, often “ paint a picture of the crisis in Nicaragua that is dangerously misleading. ” Unfortunately, her own article does just that. It looks at the situation entirely from the perspective of those opposing Daniel Ortega’s government while whitewashing their malevolent behavior and downplaying the levels of US support they have relied on. Her piece is an incomplete depiction of what is happening on the ground, ignoring many salient facts that have come to light and which have been outdated by recent events. The following is a brief response to Ellsberg’s main points from someone who lives in Nicaragua and has observed the situation directly and intimately: https://grayzoneproject.com/2018/08/15/a-res...

Trump's war in Iran crushes US working class, enriches cronies

The Grayzone   The Grayzone 's Max Blumenthal and Aaron Mate discuss how Trump's cronies are exploiting the Strait of Hormuz crisis he instigated to manipulate markets while US consumers feel the pain. 

Iran War Collapses U.S. Neoliberal Economy

Glenn Diesen   Yanis Varoufakis is an economist, the former Finance Minister of Greece, and the author of numerous bestselling books. Yanis Varoufakis discusses the historical mistake of attacking Iran (again). 

Five reasons a war with Iran will mark the final fall of US empire

globinfo freexchange   1. The nature of war has changed dramatically since the Iraq war, due to technological developments. A ground invasion, especially against Iran, would be catastrophic for the US empire with unpredictable consequences, even if the regime-change mission successfully completed.  2. The Iran allies in the region are still active, despite their losses. This is connected with the first reason in a way because armed groups dispersed in the Middle-East and affiliated with Iran, can lead to an asymmetric, out-of-control conflict to the point where US forces may suddenly find themselves trapped in a wider deadly warzone with no exit. The new, relatively cheap technology of drones and small/middle range missiles, is easily accessible to these groups. The Ansar Allah group in Yemen, already demonstrated their ability to sabotage US military operations. 3. Iran is not Iraq. Not only due to its size and the fact that we live now in a very different period, but also be...