Skip to main content

The deeper story behind CIA's attempt to 'impersonate' Russian cybersecurity company using hacking tool Hive


In 9 November 2017, WikiLeaks published the source code and development logs to Hive, a major component of the CIA infrastructure to control its malware.

According to WikiLeaks, Hive uses the uncommon Optional Client Authentication so that the user browsing the website is not required to authenticate - it is optional. But implants talking to Hive do authenticate themselves and can therefore be detected by the Blot server. Traffic from implants is sent to an implant operator management gateway called Honeycomb (see graphic above) while all other traffic go to a cover server that delivers the insuspicious content for all other users.

Digital certificates for the authentication of implants are generated by the CIA impersonating existing entities. The three examples included in the source code build a fake certificate for the anti-virus company Kaspersky Laboratory, Moscow pretending to be signed by Thawte Premium Server CA, Cape Town. In this way, if the target organization looks at the network traffic coming out of its network, it is likely to misattribute the CIA exfiltration of data to uninvolved entities whose identities have been impersonated.

This CIA cybertool could be proven very useful for accusing foreign agencies and organizations for hacking US facilities and processes, but beyond that, there is a deeper reason for which CIA has targeted the specific Russian company and it is related to the first discovered malware that spies on and subverts industrial systems.

Former British intelligence officer and Whistleblower, Annie Machon, reveals why CIA has targeted Kaspersky Lab:

Obviously, the CIA will be interested in a very successful Russian-based company that offers protection on the Internet. But it goes back a bit further because, it was 2010 the very first proven cyberwarfare weapon was deployed. And this was against the Iranian domestic civilian nuclear development capability. And this was at the time when the Americans were drumming up the war against Iran.

There was an attack made against their civilian nuclear capability, and in this case, this virus, which was called Stuxnet, was deployed against the centrifuges that enriched the Uranium. Nobody knew where it came from. It seemed to be very weaponized, a state level. And it was actually Kaspersky that unveiled who had developed it. It was the Americans and the Israeli intelligence agencies. So, Kaspersky has been very much in the cross-chairs of both the American and the Israeli intelligence agencies.


From Wikipedia, Stuxnet is a malicious computer worm, first uncovered in 2010 by Kaspersky Labs, the antivirus company. Thought to have been in development since at least 2005, stuxnet targets SCADA systems and was responsible for causing substantial damage to Iran's nuclear program. Although neither country has admitted responsibility, since 2012 the worm is frequently described as a jointly built American/Israeli cyberweapon.

Stuxnet, discovered by Sergey Ulasen, initially spread via Microsoft Windows, and targeted Siemens industrial control systems. While it is not the first time that hackers have targeted industrial systems, nor the first publicly known intentional act of cyberwarfare to be implemented, it is the first discovered malware that spies on and subverts industrial systems, and the first to include a programmable logic controller (PLC) rootkit.

Comments

Popular posts from this blog

Netanyahu Is Getting His War Between The U.S. & Iran!

The Jimmy Dore Show   Little progress is being made in negotiations between the United States and Iran over the latter’s nuclear program, and that may be by design. The U.S. is demanding a complete dismantling of Iran’s nuclear enrichment program, which is a non-starter for the Iranians. Meanwhile, the U.S. appears to have reneged on a promise to get a ceasefire and humanitarian aid into Gaza in exchange for the release of the last American hostage, so Hamas — and by extension Iran — feel the U.S. cannot be trusted in negotiations. Jimmy Dore and Americans’ Comedian Kurt Metzger discuss how Israel appears to be orchestrating a U.S. attack on Iran that few Americans have any interest in.    Related: Trump makes key move to beat Biden in their race to start a war with Iran

Trump in SHOCK: Putin & China FLIP His Grave Mistake into STUNNING Victory

Danny Haiphong   Putin & China just gave Trump a rude BRICS awakening, and this bombshell will change everything for generations to come. Geopolitical analyst Ben Norton details the truth about Trump's biggest failure against the rising power of BRICS led by Russia and China, and why the US's role as super power is now in serious question.     Related: Trump's tariffs: A unique opportunity for BRICS and the Global South to fully escape from dollar tyranny

Trump's attempt to divide Russia & China is failing, badly

Geopolitical Economy Report   Donald Trump claimed he would "un-unite" Russia and China, but the US divide-and-conquer strategy is failing. In a meeting in Moscow celebrating the 80th anniversary of their nations' victory in World War Two, Presidents Xi Jinping and Vladimir Putin reaffirmed that "China-Russia relations have reached the highest level in history" and will "jointly resist any attempts to interfere with and disrupt the traditional friendship and deep mutual trust between China and Russia". Ben Norton explains.     Related:   Why China supports Russia

Inside Iran's Savak torture museum

The Grayzone   Caution: This report contains depictions of simulated violence that may upset some viewers. Max Blumenthal tours one of the most disturbing museums on the planet. Set in Tehran's former Ebrat Prison run by the anti-sabotage unit of Shah Reza Pahlavi's Savak intelligence services, the museum is filled with shockingly graphic exhibits featuring lifelike mannequins recreating the hideous torture tactics deployed to repress dissidents rebelling against Iran's monarchy. Many mannequins on display represent notorious torturers who either fled or were executed after the Islamic revolution in 1979, while others are modeled after famous prisoners locked away in Ebrat like the current Leader of Iran, Ayatollah Khamanei.  

"Kidnapped in Int'l Waters": Israel Intercepts Gaza-Bound Aid Ship, Detains Greta Thunberg & Others

Democracy Now!   Eleven peace activists and one journalist on board the Gaza Freedom Flotilla ship, the "Madleen," were detained by Israeli soldiers as their ship carrying vital humanitarian aid for starving Palestinians approached Gaza.    The ship was intercepted by Israeli forces in the middle of the night in international waters. Its supplies were seized and communications jammed. The unarmed activists will likely be transported to Israeli detention or "immediately deported," says Ann Wright, a U.S. military veteran who has participated in four Freedom Flotilla journeys and now serves on the steering committee of the Freedom Flotilla Coalition. She calls on citizens of countries around the world to push for the activists' release and an end to Israel's war on Gaza. 

14,000 babies could die if aid doesn’t enter Gaza in 48 hours, UN warns

Some 14,000 babies could die in Gaza in 48 hours if aid does not reach them in time, the UN’s humanitarian chief, Tom Fletcher, told the BBC today. Though Israel said it would allow “basic aid” into Gaza, only five trucks entered the enclave yesterday, two carrying shrouds to help bury Palestinians killed in Israel’s bombs. Others were in Gaza, but were being held by occupation forces and had not reached Palestinians. This was the first delivery of aid since 2 March, when Israel completely sealed the enclave. This, Fletcher explained, is a “drop in the ocean” and totally inadequate for a population of over 2.3 million, and for which no aid has been allowed to enter for 80 days.    “Tonnes of food is blocked at the [Gaza] border” by Israel, Director General of the World Health Organisation (WHO), Tedros Adhanom Ghebreyesus, said yesterday. This comes just weeks after the UN agency of Palestinian refugees (UNRWA) warned that hundreds of thousands of Palestinians eat only one mea...

Latest on Los Angeles anti-ICE protests in US

CGTN     Views of downtown Los Angeles where protests against immigration raids entered their third day on Sunday local time.   Protesters clashed with National Guard troops in downtown Los Angeles during the latest wave of demonstrations against statewide immigration enforcement operations that swept across California over the weekend.  

Never, Ever Let Anyone Forget What They Did To Gaza

by Caitlin Johnstone   I will never forget the Gaza holocaust. I will never let anyone else forget about the Gaza holocaust. No matter what happens or how this thing turns out, I will never let anyone my voice touches forget that our rulers did the most evil things imaginable right in front of us and lied to us about it the entire time. I will never stop doing everything I can with my own small platform to help ensure that the perpetrators of this mass atrocity are brought to justice. I will never stop doing everything I can to help bring down the western empire and to help free Palestine from the Zionist entity. I will never forget those shaking children. Those tiny shredded bodies. Those starved, skeletal forms. The explosions followed by screams. The atrocities followed by western media silence.   I will never forget, and I will never forgive. I will never forgive our leaders. I will never forgive the western press. I will never forgive Israel. I will never forgive the main...

They Will Starve You In A Killing Cage Too

by Nate Bear   Starvation is taking hold in Gaza. Twenty-nine people have starved to death in the last few days.  Death by starvation is horrific, the body feeding on itself, first consuming carbohydrates and fats, and then moving on to the protein parts of tissue. Once these are used up, vital organs and tissues start to fail as they aren’t being nourished by essential nutrients. The heart, lungs, muscles, ovaries, testes and brain physically shrink and shrivel. The kidneys start to fail. Eventually the body begins scavenging muscle, including the heart muscle. When this starts to happen, death is hours away, preceded by hallucinations, severe mental disturbances and convulsions. With less stored fat and higher metabolic needs, children die first. Starving parents hold their dying children, at this point nothing but skin and bone, in their arms. Adults can survive anywhere between twenty and forty days without food. Those already weak, chronically ill or immuno-compromised di...