{"id":32009,"date":"2017-06-05T06:47:43","date_gmt":"2017-06-05T10:47:43","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/wikileaks-cia-pandemic-malware-infected-servers-to-spread-breitbart-news.php"},"modified":"2017-06-05T06:47:43","modified_gmt":"2017-06-05T10:47:43","slug":"wikileaks-cia-pandemic-malware-infected-servers-to-spread-breitbart-news","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/wikileaks\/wikileaks-cia-pandemic-malware-infected-servers-to-spread-breitbart-news.php","title":{"rendered":"WikiLeaks: CIA &#8216;Pandemic&#8217; Malware Infected Servers to Spread &#8230; &#8211; Breitbart News"},"content":{"rendered":"<p><p>      SIGN UP FOR OUR NEWSLETTER    <\/p>\n<p>    In thelatest leak, published on Thursday, WikiLeaks    outlines the use of the CIAs Pandemic    project. This leak is a virus that targets Windows computers,    sharing files with remote users in a local network. WikiLeaks    described the program on their website writing,  <\/p>\n<p>    Today, June 1st 2017, WikiLeaks publishes documents from the    Pandemic project of the CIA, a persistent implant for    Microsoft Windows machines that share files (programs) with    remote users in a local network. Pandemic targets remote    users by replacing application code on-the-fly with a trojaned    version if the program is retrieved from the infected machine.    To obfuscate its activity, the original file on the file server    remains unchanged; it is only modified\/replaced while in    transit from the pandemic file server before being executed on    the computer of the remote user. The implant allows the    replacement of up to 20 programs with a maximum size of 800 MB    for a selected list of remote users (targets).  <\/p>\n<p>    As the name suggests, a single computer on a local network    with shared drives that is infected with the Pandemic implant    will act like a Patient Zero in the spread of a disease. It    will infect remote computers if the user executes programs    stored on the pandemic file server. Although not explicitly    stated in the documents, it seems technically feasible that    remote computers that provide file shares themselves become new    pandemic file servers on the local network to reach new    targets.  <\/p>\n<p>    Documentation published by WikiLeaks states that the virus is    installed via aminifilter    device driver.Jake Williams, a malware expert at    Rendition InfoSec, spoke to     Ars Technica about the virus stating,This code looks    like it was developed with a very specific use in mind. Many    larger organizations dont use Windows file servers to serve    files. They use special built storage devices (network attached    storage). My guess here would be that this was designed to    target a relatively small organization.  <\/p>\n<p>    Williams worked at theNational Security Agencys elite    Tailored Access Operation until 2013 and believes that    WikiLeaks may be withholding some documentation relating to    Pandemic. If you handed me this tool, I dont have enough    information to make it go, he said. Theres more    documentation than this. Its anyones guess as to why it    wasnt released.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>See the article here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/www.breitbart.com\/tech\/2017\/06\/02\/wikileaks-cia-pandemic-malware-infected-servers-to-spread-virus-to-computers\/\" title=\"WikiLeaks: CIA 'Pandemic' Malware Infected Servers to Spread ... - Breitbart News\">WikiLeaks: CIA 'Pandemic' Malware Infected Servers to Spread ... - Breitbart News<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> SIGN UP FOR OUR NEWSLETTER In thelatest leak, published on Thursday, WikiLeaks outlines the use of the CIAs Pandemic project. This leak is a virus that targets Windows computers, sharing files with remote users in a local network. WikiLeaks described the program on their website writing, Today, June 1st 2017, WikiLeaks publishes documents from the Pandemic project of the CIA, a persistent implant for Microsoft Windows machines that share files (programs) with remote users in a local network. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-32009","post","type-post","status-publish","format-standard","hentry","category-wikileaks"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32009"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=32009"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32009\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=32009"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=32009"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=32009"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}