Vault 8 Reveals How CIA Can Impersonate Russia Cyberattack

More CIA spyware and malware tools have been exposed in Wikileaks latest release, Vault 8. Source code for the CIA malware control program Hive is included as well as other back-end infrastructure that allows for covert electronic communication between controlled computers and the CIA.

Hive adds another layer of security between CIA hacking and scraping tools so that even if they're discovered it is difficult to attribute the malware back to the CIA. Hive is a multitasking tool that can oversee multiple implants on targetted workstations. The front end involves covering the domain whose servers run relay for the <a href="">hidden CIA server (called Blot)</a> passing traffic over a VPN.

Hive uses an Optional Client Authentication which circumvents authentication on the user's side. Hive traffic from implanted CIA malware can then be spirited away to a management gateway aptly called Honeycomb.

Just as interesting as all this is the fact that the CIA wrote code that would impersonate Kaspersky lab antivirus and build fake certificates. Kaspersky lab has been under fire since 2010 when they revealed the <a href="">US and Israeli cyber-spies behind the Stuxnet malware.</a>

More recently, Department of Homeland Security ordered all government agents to cease the use of the Kaspersky antivirus citing "security risks." Hive was first uncovered in Vault 7 in March. <a href="">Ray McGovern, former CIA analyst explained</a> that Hive “enables the CIA to hack into computer, or network and ‘obfuscate’ is the word in CIA document… To conceal who hacked in and then leave traces like in Cyrillic [alphabet], or the name of the first head of the Soviet secret police… Just to show that it might be the Russians,” McGovern, who has decades of experience in the CIA, said.

