Home LifeStyle & Tech CIA's HIVE project

CIA's HIVE project

by TrickyScribe

@ScribeAditya: WikiLeaks on Friday published six documents from the CIA’s HIVE project created by its “Embedded Development Branch” (EDB).

HIVE is a back-end infrastructure malware with a public-facing HTTPS interface which is used by CIA implants to transfer exfiltrated information from target machines to the CIA and to receive commands from its operators to execute specific tasks on the targets. HIVE is used across multiple malware implants and CIA operations. The public HTTPS interface utilizes unsuspicious-looking cover domains to hide its presence.biharplus-logo

Anti-Virus companies and forensic experts have noticed that some possible state-actor malware used such kind of back-end infrastructure by analyzing the communication behavior of these specific implants but were unable to attribute the back-end (and therefore the implant itself) to operations run by the CIA. In a recent blog post by Symantec, that was able to attribute the “Longhorn” activities to the CIA based on the Vault 7, such back-end infrastructure is described:

For command and control (C&C) servers, Longhorn typically configures a specific domain and IP address combination per target. The domains appear to be registered by the attackers; however, they use privacy services to hide their real identity.octopus-inc-designing-and-printing

The IP addresses are typically owned by legitimate companies offering virtual private server (VPS) or Webhosting services. The malware communicates with C&C servers over HTTPS using a custom underlying cryptographic protocol to protect communications from identification.

The documents from this publication might further enable anti-malware researchers and forensic experts to analyze this kind of communication between malware implants and back-end servers used in previous illegal activities.

seo checker
www.TrickyScribe.in
Protected by Copyscape

You may also like

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More