Skip to main content

The deeper story behind CIA's attempt to 'impersonate' Russian cybersecurity company using hacking tool Hive


In 9 November 2017, WikiLeaks published the source code and development logs to Hive, a major component of the CIA infrastructure to control its malware.

According to WikiLeaks, Hive uses the uncommon Optional Client Authentication so that the user browsing the website is not required to authenticate - it is optional. But implants talking to Hive do authenticate themselves and can therefore be detected by the Blot server. Traffic from implants is sent to an implant operator management gateway called Honeycomb (see graphic above) while all other traffic go to a cover server that delivers the insuspicious content for all other users.

Digital certificates for the authentication of implants are generated by the CIA impersonating existing entities. The three examples included in the source code build a fake certificate for the anti-virus company Kaspersky Laboratory, Moscow pretending to be signed by Thawte Premium Server CA, Cape Town. In this way, if the target organization looks at the network traffic coming out of its network, it is likely to misattribute the CIA exfiltration of data to uninvolved entities whose identities have been impersonated.

This CIA cybertool could be proven very useful for accusing foreign agencies and organizations for hacking US facilities and processes, but beyond that, there is a deeper reason for which CIA has targeted the specific Russian company and it is related to the first discovered malware that spies on and subverts industrial systems.

Former British intelligence officer and Whistleblower, Annie Machon, reveals why CIA has targeted Kaspersky Lab:

Obviously, the CIA will be interested in a very successful Russian-based company that offers protection on the Internet. But it goes back a bit further because, it was 2010 the very first proven cyberwarfare weapon was deployed. And this was against the Iranian domestic civilian nuclear development capability. And this was at the time when the Americans were drumming up the war against Iran.

There was an attack made against their civilian nuclear capability, and in this case, this virus, which was called Stuxnet, was deployed against the centrifuges that enriched the Uranium. Nobody knew where it came from. It seemed to be very weaponized, a state level. And it was actually Kaspersky that unveiled who had developed it. It was the Americans and the Israeli intelligence agencies. So, Kaspersky has been very much in the cross-chairs of both the American and the Israeli intelligence agencies.


From Wikipedia, Stuxnet is a malicious computer worm, first uncovered in 2010 by Kaspersky Labs, the antivirus company. Thought to have been in development since at least 2005, stuxnet targets SCADA systems and was responsible for causing substantial damage to Iran's nuclear program. Although neither country has admitted responsibility, since 2012 the worm is frequently described as a jointly built American/Israeli cyberweapon.

Stuxnet, discovered by Sergey Ulasen, initially spread via Microsoft Windows, and targeted Siemens industrial control systems. While it is not the first time that hackers have targeted industrial systems, nor the first publicly known intentional act of cyberwarfare to be implemented, it is the first discovered malware that spies on and subverts industrial systems, and the first to include a programmable logic controller (PLC) rootkit.

Comments

Popular posts from this blog

Capitalism & Genocide - Yanis Varoufakis Speech at the Gaza Tribunal, 23rd October 2025, Istanbul

Yanis Varoufakis   On 23rd October, Yanis Varoufakis testified in front of the Jury of Conscience in the context of the Gaza Tribunal. His speech focused on the economic forces underpinning the genocide of the Palestinian people. In particular, he spoke on the manner in which capitalist dynamics have historically fuelled the white settler colonial project and, more recently, how the accumulation of a new form of capital - which he calls cloud capital - has accelerated, deepened and amplified the economic forces powering and propelling the machinery of genocide. 

Iranian Seyed M. Marandi: What REALLY happened in Iran & why U.S. wants to destroy the country

Li Jingjing 李菁菁   Track records of Western interventions tell us we need to be skeptical and cautious whenever some Western politicians and pundits claim they want to liberate people in another country and bring them democracy. Seyed Mohammad Marandi is a professor at the University of Tehran in Iran. In this episode, he told Li Jingjing what happened during the protests in Iran and how Western sanctions hurt the lives of ordinary Iranians.

Israel & CIA Behind Iran Protests To Get U.S. To Attack!

The Jimmy Dore Show    As protests in Iran have heated up, western media has actively exaggerated and selectively framed the violence by using casualty figures from U.S.- and Israel-funded NGOs — all in order to build public support for another regime-change war. Former CIA officer John Kiriakou and guest Scott Ritter claim protests were infiltrated by foreign intelligence networks and that Israel and the U.S. are using “human rights” narratives similarly to the way they were used in Iraq and Syria.   Dore and Ritter contend that Iran’s government responded to armed unrest rather than peaceful protest, while mainstream outlets ignore attacks on police and public infrastructure. They warn that propaganda, sanctions, and media coordination are laying the groundwork for a wider U.S.–Israel conflict with Iran. 

Iran’s Missiles will DESTROY US Bases & Israel if Trump Attacks

Danny Haiphong   Iran is ready for war, and its hypersonic ballistic missile system could destroy Israel & US military presence forever says Scott Ritter who joined the show to break down the consequences of Trump's march to war with Iran. The former UN Weapons Inspector does a deep dive into Iran's readiness and why it should terrify Trump & Israel together. 

US & Israel support protests in Iran: Trump calls for regime change

Geopolitical Economy Report   The US government is openly backing the protests in Iran. An Israeli media outlet admitted foreign powers are arming Iranian rioters with weapons to try to overthrow the government. Ben Norton explains the geopolitical context and why the USA has sought regime change ever since the 1979 Iranian Revolution.   

Ο βασικός λόγος που ο Τραμπ διστάζει να χτυπήσει το Ιράν

"Μικρά και ασήμαντα" από τον Πίκο Απίκο Ο βασικός λόγος που δεν έγινε η επίθεση στο Ιράν, είναι το γεγονός ότι πρόσφατα, το Ιράν αποχώρησε από το δορυφορικό σύστημα GPS που είναι Αμερικανικό και εντάχθηκε στο Κινεζικό BeiDou. Που σημαίνει ότι οι Αμερικανοί δεν έχουν τη δυνατότητα να σαμποτάρουν τους Ιρανικούς πυραύλους.  Έτσι εξηγείται και το μεγάλο ποσοστό ευστοχίας των Ιρανικών πυραύλων στην τελευταία σύγκρουση με το Ισραήλ, μέσα στο Ισραηλινό έδαφος. Αλλά και το γεγονός ότι πριν λίγες μέρες, οι ίδιοι οι Ισραηλινοί ζήτησαν τη διαμεσολάβηση της Ρωσίας, προκειμένου να αποκλιμακωθεί η ένταση με το Ιράν, αφού Ισραηλινές εφημερίδες και αξιωματούχοι είχαν παραδεχθεί ανοιχτά την παρουσία πρακτόρων της Μοσάντ σε Ιρανικό έδαφος και τον κομβικό τους ρόλο στις πρόσφατες εξεγέρσεις. Οι Αμερικανοί επομένως γνωρίζουν ότι αυτή τη στιγμή οι Ιρανοί έχουν τη δυνατότητα να χτυπήσουν Αμερικανικές βάσεις (όπως απείλησαν ότι θα κάνουν αν ο Τραμπ κάνει πράξη τις απειλές του), χωρίς να μπορούν να ...

Exposed: USA plans to use this country to hurt China & help Israel

Geopolitical Economy Report   In Cold War Two, the USA is pressuring countries to cut ties with China and recognize Taiwan separatists. Donald Trump blatantly meddled in Honduras' 2025 election and backed a political coup to put in power right-wing oligarch Nasry "Tito" Asfura, who strongly supports Taiwan and Israel. Ben Norton discusses US imperialism in Latin America.  

Iran's Next Strike OBLITERATES US Navy & Israel, War Has BEGUN

Danny Haiphong   Prof. Mohammad Marandi joins the show to react to Iran's vow to strike a devastating blow to the heart of Tel Aviv and US Navy as imminent US war approaches. Trump has moved military assets to the region and now Iran has responded by moving its missiles and drones in strike position. Watch until the end for an in-depth analysis of a war that's already begun, and is about to change everything with one fatal move by the US empire.

A response to misinformation on Nicaragua: it was a coup, not a ‘massacre’

There is so much misinformation in mainstream corporate media about recent events in Nicaragua that it is a pity that Mary Ellsberg’s article for Pulse has added to it with a seemingly leftish critique. Ellsberg claims that recent articles, including from this website, often “ paint a picture of the crisis in Nicaragua that is dangerously misleading. ” Unfortunately, her own article does just that. It looks at the situation entirely from the perspective of those opposing Daniel Ortega’s government while whitewashing their malevolent behavior and downplaying the levels of US support they have relied on. Her piece is an incomplete depiction of what is happening on the ground, ignoring many salient facts that have come to light and which have been outdated by recent events. The following is a brief response to Ellsberg’s main points from someone who lives in Nicaragua and has observed the situation directly and intimately: https://grayzoneproject.com/2018/08/15/a-res...

Billionaires are social distancing in super yachts as tens of millions lose jobs

Everyday, it becomes clearer: the COVID-19 pandemic is hitting poor, working, and marginalized communities the hardest. Millions of workers – especially low-wage retail, food service, hospitality, and care workers – have faced the terrible choice daily between going to work and risking their health, or staying home and risking their paychecks. Many other workers don’t even have that choice, with around 30 million people in the US filing for unemployment in the past six weeks. But billionaires don’t face these same problems. As tens of millions have lost their jobs over the past two months, billionaire wealth soared by a whopping $282 billion between March 18 and April 10, according to a new study from the Institute for Policy Studies.  And while finding enough space to wait out the pandemic is something many struggle with, billionaires have been escaping to their second (or third, or fourth) homes to ride it out in luxury – all while they position themselves to ...