>WikiLeaks: New files show how CIA hides malware on Windows computers

The new batch of 27 documents includes alleged manuals for the spy agency’s Grasshopper program, which WikiLeaks says the CIA uses to build Windows malware. The online activist group had previously released files March 23 on the CIA's hacking of Apple Macs and iPhones, and March 31 on the agency's tools for thwarting investigators and antivirus programs.

Most of the documents describe how the CIA builds “persistence modules,” software that lets malware survive on a target machine despite reboots, reinstallations and other attempts to wipe the system clean.

One alleged persistence module, “Stolen Goods,” uses code from the Carberp malware tool, which is believed to come from Russia’s criminal hacker underground.

Some of the other modules — with code names like “Wheat,” “Crab” and “Buffalo” — smuggle malware onto a system and preserve it using Windows components like drivers and executable files. Another module, “Netman,” piggybacks on Windows’ network connection system.


Network security analyst here. I read all of it and nothing substantial can be found in these documents. I wouldn't waist any time on this.

These kinds of posts were so bad during the part one release that I had added all of their mispellings of 'substantial' to my filters (among other key words) . I'm not sure if its a shill or someone meming, but either way, what they are saying is false.

No, not really. Just like the rest of this entire release, they're just good old computer viruses. You download a virus from a shady website, you can expect it to fuck up your computer. This has been a thing for what, a few decades? Especially if someone has physical access to your computer, they can do a lot. The only reason your average fake download website doesn't give you viruses like these is because they're not made by teams of people paid to work on viruses all day.

It looks like it just analyzes your system and depending on certain conditions, installs certain viruses. Not really noteworthy.

Apple BTFO. For real though if you can't actually wipe the hard drive clean and re-install everything from scratch that kind of persistent virus isn't surprising. Unless it somehow gets stored somewhere else, but yeah that's a pretty bad vulnerability.

These leaks are from 2013-14. Doesn't mean Microsoft and Samsung stopped supplying backdoors for the CIA.

Do we know if they're actually providing backdoors or if the CIA is just finding vulnerabilities? Or is it just speculation?

