WikiLeaks releases new round of CIA malware documents, this time with less supporting material
Full article627 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
WikiLeaks released a new set of CIA cyberwarfare documents on Thursday, marking the 10th installation in the two-month-old Vault 7 series. This publication focuses on Pandemic, a CIA project that infects networks of Windows machines through the Server Message Block (SMB) file sharing protocol with trojanized versions of software that can mean complete compromise of targeted devices. The documents date from April 2014 to January 2015.
WikiLeaks released a new set of CIA cyberwarfare documents on Thursday, marking the 10th installation in the two-month-old Vault 7 series.
This publication focuses on Pandemic, a CIA project that infects networks of Windows machines through the Server Message Block (SMB) file sharing protocol with trojanized versions of software that can mean complete compromise of targeted devices. The documents date from April 2014 to January 2015.
The latest release contains less contextual data and documents than most previous Vault 7 publications, prompting questions from experts about the exact operation of the Pandemic malware. For example: How does it get into the Windows kernel in order to replace normal files with spyware? And why is this document dump seemingly less complete than others?
“Why it’s missing is anyone’s guess,” Williams said. “But you don’t see the operator manual, etc. Everything else, with the exception of MARBLE (which is a library) has a user guide. This does not. Why not?”
WikiLeaks did not respond to questions asked via Twitter.
Last month, Sweden announced the end of the rape investigation into WikiLeaks founder Julian Assange. British authorities still have a warrant out for the Australian hackers’ arrest and American officials have stayed mum on their own potential charges against Assange who continues to live in the Ecuadorian embassy in London.

Despite a still-unfurling trove of documents from one of the most prominent intelligence agencies on earth, the Vault 7 series has fallen relatively quiet when compared to its previous pace and the work of contemporaneous work of groups like the Shadow Brokers.
Over the course of two months of publishing Vault 7, WikiLeaks has been accused by cybersecurity professionals of making misleading claims about encrypted messengers like Signal and the contents of CIA code.
The exception has been outlets like RT, the Russian state-owned news website, that has covered each Vault 7 installation quickly and without a critical eye. It parroted WikiLeaks’ unsubstantiated claim that Signal and WhatsApp are broken.
CyberScoop is continuing a review of the documents and will update this story if necessary.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/wikileaks-releases-new-round-of-cia-documents/