Skip to main content

The deeper story behind CIA's attempt to 'impersonate' Russian cybersecurity company using hacking tool Hive


In 9 November 2017, WikiLeaks published the source code and development logs to Hive, a major component of the CIA infrastructure to control its malware.

According to WikiLeaks, Hive uses the uncommon Optional Client Authentication so that the user browsing the website is not required to authenticate - it is optional. But implants talking to Hive do authenticate themselves and can therefore be detected by the Blot server. Traffic from implants is sent to an implant operator management gateway called Honeycomb (see graphic above) while all other traffic go to a cover server that delivers the insuspicious content for all other users.

Digital certificates for the authentication of implants are generated by the CIA impersonating existing entities. The three examples included in the source code build a fake certificate for the anti-virus company Kaspersky Laboratory, Moscow pretending to be signed by Thawte Premium Server CA, Cape Town. In this way, if the target organization looks at the network traffic coming out of its network, it is likely to misattribute the CIA exfiltration of data to uninvolved entities whose identities have been impersonated.

This CIA cybertool could be proven very useful for accusing foreign agencies and organizations for hacking US facilities and processes, but beyond that, there is a deeper reason for which CIA has targeted the specific Russian company and it is related to the first discovered malware that spies on and subverts industrial systems.

Former British intelligence officer and Whistleblower, Annie Machon, reveals why CIA has targeted Kaspersky Lab:

Obviously, the CIA will be interested in a very successful Russian-based company that offers protection on the Internet. But it goes back a bit further because, it was 2010 the very first proven cyberwarfare weapon was deployed. And this was against the Iranian domestic civilian nuclear development capability. And this was at the time when the Americans were drumming up the war against Iran.

There was an attack made against their civilian nuclear capability, and in this case, this virus, which was called Stuxnet, was deployed against the centrifuges that enriched the Uranium. Nobody knew where it came from. It seemed to be very weaponized, a state level. And it was actually Kaspersky that unveiled who had developed it. It was the Americans and the Israeli intelligence agencies. So, Kaspersky has been very much in the cross-chairs of both the American and the Israeli intelligence agencies.


From Wikipedia, Stuxnet is a malicious computer worm, first uncovered in 2010 by Kaspersky Labs, the antivirus company. Thought to have been in development since at least 2005, stuxnet targets SCADA systems and was responsible for causing substantial damage to Iran's nuclear program. Although neither country has admitted responsibility, since 2012 the worm is frequently described as a jointly built American/Israeli cyberweapon.

Stuxnet, discovered by Sergey Ulasen, initially spread via Microsoft Windows, and targeted Siemens industrial control systems. While it is not the first time that hackers have targeted industrial systems, nor the first publicly known intentional act of cyberwarfare to be implemented, it is the first discovered malware that spies on and subverts industrial systems, and the first to include a programmable logic controller (PLC) rootkit.

Comments

Popular posts from this blog

F-35s & AI Chips: How MBS Outplayed Washington & Beijing

GVS Deep Dive  Saudi Arabia just secured two of the most powerful assets in modern geopolitics: the U.S. F-35 stealth fighter and tens of thousands of Nvidia’s most advanced AI chips. Washington hoped this would pull Riyadh firmly back into the American orbit. But the outcome is something neither side fully expected: Mohammad bin Salman outplayed both Washington and Beijing — and used the great-power rivalry to his advantage.

How The CIA & Mossad Set Up Sudan for Genocide since the 1990s

MintPress News   Sudan is being systematically destroyed - not by accident, but by design. This investigation reveals how US imperialism, through Israeli and UAE proxies, has engineered Sudan's collapse since the 1990s to crush the axis of resistance, block China's Belt and Road, and loot Africa's resources families are killed, children starve, and the west profits. 

Greece, Palestine & Zionism: FPTV Reports from Athens

Free Palestine TV   Laith Marouf & Rabih Ghannam travel to Athens, Greece, and take a walking tour with local activists Evan Katsounis and Maria Kosmidi, to discover the rich history of anti-Zionist and anti-Fascist actions in the city, as well as the current Zionist incursion into the property sector and the counter actions directed at the presence of these War Criminals on the streets of the city. 

Trump BLEW IT: Israel, Candace Owens & Epstein BURY MAGA (But Not How You Think)

Danny Haiphong   Trump has bent the knee to Israel for the last time. Patrick Henningsen exposes his horrid record and all the elements that has led to his rapidly coming collapse. 

Trump RUINED: Israel First Lies & Economic Freefall Just ENDED MAGA

Danny Haiphong   Tucker Carlson isn't the only journalist breaking with Trump. In this video, Patrick Henningsen goes scorched earth on Trump's massive betrayal of what he promised his "MAGA" base and blows the lid off how his massive lies serve as a cover up for a much bigger structural problem in America's 'Israel First' political system, what Tucker and major voices in elite MAGA won't tell you.  

Trump Welcomes Syrian Leader & “REFORMED” TERRORIST To White House!

The Jimmy Dore Show   President Donald Trump is planning a White House welcome for Syria’s new president, former al-Qaeda in Iraq leader Ahmed al-Sharaa, who was installed after the overthrow of Bashar al-Assad. Jimmy Dore argues that the U.S. and its allies, including Israel, have long funded extremist groups such as ISIS and al-Qaeda to serve foreign policy interests in the Middle East, so the embrace of al-Sharaa makes sense, even if it might confuse anyone who thought we took seriously the so-called “War on Terror.” He and Americans’ Comedian Kurt Metzger contrast Trump’s willingness to meet with alleged terrorists to his refusal to engage in dialogue with leaders like Venezuela’s Nicolás Maduro, accusing U.S. policy of hypocrisy and imperialism.  

Zionists’ LONG HISTORY Of False Flags & STAGED Attacks!

The Jimmy Dore Show   In recent years several alleged anti-Semitic incidents, including graffiti and vandalism, were later revealed to have been staged or “false flag” operations carried out by Jewish perpetrators to create sympathy or shift the public narrative in Israel’s favor. Jimmy Dore presents investigations that revealed hoaxes and uses them to argue that media and political institutions exploit victimhood to silence criticism of Israel. He then expands the discussion to accuse Israeli and Zionist figures of deceit in global politics and misinformation about Gaza. It ends with commentary that the term “anti‑Semitic” has lost meaning due to its politicization and misuse.

A response to misinformation on Nicaragua: it was a coup, not a ‘massacre’

There is so much misinformation in mainstream corporate media about recent events in Nicaragua that it is a pity that Mary Ellsberg’s article for Pulse has added to it with a seemingly leftish critique. Ellsberg claims that recent articles, including from this website, often “ paint a picture of the crisis in Nicaragua that is dangerously misleading. ” Unfortunately, her own article does just that. It looks at the situation entirely from the perspective of those opposing Daniel Ortega’s government while whitewashing their malevolent behavior and downplaying the levels of US support they have relied on. Her piece is an incomplete depiction of what is happening on the ground, ignoring many salient facts that have come to light and which have been outdated by recent events. The following is a brief response to Ellsberg’s main points from someone who lives in Nicaragua and has observed the situation directly and intimately: https://grayzoneproject.com/2018/08/15/a-res...

Racing Extinction

suggested by failedevolution.blogspot 18th Thessaloniki Documentary Festival Scientists predict that humanity’s footprint on the planet may cause the loss of 50% of all species by the end of the century. They believe we have entered the sixth major extinction in Earth’s history, following the fifth great extinction which took out the dinosaurs. Our era is called the Anthropocene, or “Age of Man,” because evidence shows that humanity has sparked a cataclysmic change of the world’s natural environment and animal life. Yet, we are the only ones who can stop the change we have created. The Oceanic Preservation Society (OPS), the group behind the Academy Award-winning film The Cove, is back with a new groundbreaking documentary. Joined by new innovators, this highly charged, impassioned collective of activists brings a voice to the thousands of species teetering on the very edge of life. The director has crafted an ambitious mission to clearly and artfu...

Varoufakis: IT technologies will overthrow Capitalism

globinfo freexchange The former Greek Minister of Finance, Yanis Varoufakis, ended his recent speech on the Future of Capitalism, at the New School, New York, with some interesting remarks. As he said: The world we live in, is increasingly rudderless, in a constant slow burning recession, while at the very same time, the increasing concentration in the IT sector is creating the new technologies that will do that which the Left has failed to do: overthrow Capitalism. It is really very simple. The moment machines pass the Turing test properly, and you pick up the phone and you do not know whether the person you are talking to is a human being or a machine ˙ the moment we are going to have 3D printers operating as public utilities - you can send any blueprint to it and it can print from one pin to a motorcycle, or to a car - the moment that this happens, we have not just a process of Schumpeterian creative destruction, but we have a process where economies of sc...