{"id":32634,"date":"2017-07-21T08:42:43","date_gmt":"2017-07-21T12:42:43","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/5-new-cia-malware-unveiled-by-wikileaks-httpbrowser-nflog-regin-hammerloss-gamker-fossbytes.php"},"modified":"2017-07-21T08:42:43","modified_gmt":"2017-07-21T12:42:43","slug":"5-new-cia-malware-unveiled-by-wikileaks-httpbrowser-nflog-regin-hammerloss-gamker-fossbytes","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/wikileaks\/5-new-cia-malware-unveiled-by-wikileaks-httpbrowser-nflog-regin-hammerloss-gamker-fossbytes.php","title":{"rendered":"5 New CIA Malware Unveiled By WikiLeaks  HTTPBrowser, NfLog, Regin, HammerLoss, Gamker &#8211; Fossbytes"},"content":{"rendered":"<p><p>    Short Bytes: As a part of the ongoing CIA    Vault 7 series, WikiLeaks has published some new documents. The    leaks share details regarding CIAs partnership    withRaytheon Blackbird Technologies, which helped CIA    with insights into the malware development. The documents also    briefly describe 5 CIA-Raytheon malware and their attack    vectors.  <\/p>\n<p>    The leaked documents were submitted to the CIA between 21st    Nov2014 and 11th Sep2015. The documents submitted    by Raytheon contained proof-of-concept assessments for malware    attack vectors.  <\/p>\n<p>    It should be noted thatRaytheon acted as a technology    scout for CIAs Remote Development Branch (RDB). The scout made    recommendations to the CIA teams for further research and    malware development.  <\/p>\n<p>    So, without further delay, lets tell you about the 5    CIA-Raytheon malware described in the leaked documents:  <\/p>\n<p>    The first document gives an introduction to a new variant of    the HTTPBrowserRemote Access Tool (RAT). The malwares    dropper has a zip file that contains3 files. This RAT    captures keystrokes and writes it to a file. It continuously    talks to the C&C (command and control) server in clear text    communications.  <\/p>\n<p>    NfLogRAT is also known as IsSpace. This new malware    variant is deployed using the leaked Hacking Team Adobe Flash    exploit which uses CVE 2015-5122. For C&C communications,    NfLog also uses the Google App Engine. By using UAC bypass    technique, it attempts UAC bypass and privilege escalation on    Windows operating system.  <\/p>\n<p>    Reign is a sophisticated malware sample that has been in use as    early as 2008, with its new iteration appearing in 2013. What    makes Reign special is its modular architecture that grants    flexibility to the attackers. It also features the capability    to hide itself from detection. The attack via Reign is carried    out in 5 stages, with the last granting functionalities like    file system access, networking, event logging, port loading,    rootkit functions, etc.  <\/p>\n<p>    HammerToss is probably a Russian-sponsored malware. It    leverages compromised websites, GitHub, Twitter accounts, and    cloud storage for taking care of theC&C functions.    Written in C#, HammerToss uses a dedicated program to create    new Twitter accounts and use them to execute commands and get    the data uploaded by the victim.  <\/p>\n<p>    Gamker is an information stealing Trojan that uses the process    of self-code injection to make sure that nothing is written to    disk. Gamker is also able to gain someobfuscation    characteristics by using Assembly language instruction in    hooking routine.  <\/p>\n<p>    Have something to add to this story? Dont forget to share your    views with us.  <\/p>\n<p>    Source: WikiLeaks  <\/p>\n<p>    Read our    complete WikiLeaksVault 7 coverage    here.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Here is the original post:<br \/>\n<a target=\"_blank\" href=\"https:\/\/fossbytes.com\/cia-raytheon-malware-vault7\/\" title=\"5 New CIA Malware Unveiled By WikiLeaks  HTTPBrowser, NfLog, Regin, HammerLoss, Gamker - Fossbytes\">5 New CIA Malware Unveiled By WikiLeaks  HTTPBrowser, NfLog, Regin, HammerLoss, Gamker - Fossbytes<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Short Bytes: As a part of the ongoing CIA Vault 7 series, WikiLeaks has published some new documents. The leaks share details regarding CIAs partnership withRaytheon Blackbird Technologies, which helped CIA with insights into the malware development. The documents also briefly describe 5 CIA-Raytheon malware and their attack vectors<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-32634","post","type-post","status-publish","format-standard","hentry","category-wikileaks"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32634"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=32634"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32634\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=32634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=32634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=32634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}