{"id":23856,"date":"2017-05-05T14:28:55","date_gmt":"2017-05-05T19:28:55","guid":{"rendered":"http:\/\/olduvai.ca\/?p=23856"},"modified":"2017-05-05T14:28:55","modified_gmt":"2017-05-05T19:28:55","slug":"wikileaks-reveals-archimedes-malware-used-to-hack-local-area-networks","status":"publish","type":"post","link":"https:\/\/olduvai.ca\/?p=23856","title":{"rendered":"WikiLeaks Reveals &#8220;Archimedes&#8221;: Malware Used To Hack Local Area Networks"},"content":{"rendered":"<h3 class=\"title\"><a href=\"http:\/\/www.zerohedge.com\/news\/2017-05-05\/wikileaks-reveals-archimedes-malware-used-hack-local-area-networks\">WikiLeaks Reveals &#8220;Archimedes&#8221;: Malware Used To Hack Local Area Networks<\/a><\/h3>\n<section class=\"node node-type-story node-full node-nid-595278 ads-injected\">\n<div class=\"content\">\n<p>In its seventh CIA leak since March 23rd, WikiLeaks has just revealed the user manual of a CIA hacking tool known as \u2018Archimedes\u2019 which is purportedly used to attack computers inside a Local Area Network (LAN).\u00a0 The CIA tool works by redirecting a target&#8217;s webpage search to a CIA server which serves up a webpage that looks exactly like the original page they were expecting to be served, but which contains malware. It\u2019s only possible to detect the attack by examining the page source.\u00a0 Per <a href=\"https:\/\/wikileaks.org\/vault7\/releases\/#Archimedes\">WikiLeaks<\/a>:<\/p>\n<blockquote>\n<div class=\"quote_start\"><strong>Today, May 5th 2017, WikiLeaks publishes &#8220;Archimedes&#8221;, a tool used by the CIA to attack a computer inside a Local Area Network (LAN), usually used in offices.<\/strong> It allows the re-directing of traffic from the target computer inside the LAN through a computer infected with this malware and controlled by the CIA. <strong>This technique is used by the CIA to redirect the target&#8217;s computers web browser to an exploitation server while appearing as a normal browsing session.<\/strong><\/div>\n<p class=\"excl\">The document illustrates a type of attack within a &#8220;protected environment&#8221; as the the tool is deployed into an existing local network abusing existing machines to bring targeted computers under control and allowing further exploitation and abuse.<\/p>\n<\/blockquote>\n<hr \/>\n<article class=\"MediaCard\n           MediaCard--mediaForward\n\n           customisable-border\" dir=\"ltr\" data-scribe=\"component:card\"><\/p>\n<div class=\"MediaCard-media\"><a class=\"MediaCard-borderOverlay\" tabindex=\"-1\" title=\"View image on Twitter\" href=\"https:\/\/twitter.com\/wikileaks\/status\/860424440051634176\/photo\/1\"><span class=\"u-hiddenVisually\">View image on Twitter<\/span><\/a><\/p>\n<div class=\"MediaCard-widthConstraint js-cspForcedStyle\" data-style=\"max-width: 671px\">\n<div class=\"MediaCard-mediaContainer js-cspForcedStyle\" data-style=\"padding-bottom: 61.9970%\"><a class=\"MediaCard-mediaAsset\n                    NaturalImage\n\" href=\"https:\/\/twitter.com\/wikileaks\/status\/860424440051634176\/photo\/1\" data-scribe=\"element:photo\"><img loading=\"lazy\" decoding=\"async\" class=\"NaturalImage-image\" title=\"View image on Twitter\" src=\"https:\/\/pbs.twimg.com\/media\/C_DXcvaWsAEm8pN.jpg:small\" alt=\"View image on Twitter\" width=\"671\" height=\"416\" data-srcset=\"https%3A%2F%2Fpbs.twimg.com%2Fmedia%2FC_DXcvaWsAEm8pN.jpg%3Asmall 671w,https%3A%2F%2Fpbs.twimg.com%2Fmedia%2FC_DXcvaWsAEm8pN.jpg%3Alarge 671w,https%3A%2F%2Fpbs.twimg.com%2Fmedia%2FC_DXcvaWsAEm8pN.jpg 671w\" \/><\/a><\/div>\n<\/div>\n<\/div>\n<\/article>\n<div class=\"EmbeddedTweet-tweet\">\n<blockquote class=\"Tweet h-entry js-tweetIdInfo subject expanded \n<p>                    is-deciderHtmlWhitespace\" cite=\"https:\/\/twitter.com\/wikileaks\/status\/860424440051634176\" data-tweet-id=\"860424440051634176\" data-scribe=\"section:subject\"><\/p>\n<div class=\"Tweet-header u-cf\">\n<div class=\"Tweet-brand u-floatRight\">\n<div class=\"Icon Icon--twitter \" title=\"\"><a class=\"FollowButton follow-button profile\" title=\"Follow WikiLeaks on Twitter\" href=\"https:\/\/twitter.com\/wikileaks\" data-scribe=\"component:followbutton\">Follow<\/a><\/div>\n<\/div>\n<div class=\"TweetAuthor \" data-scribe=\"component:author\"><a class=\"TweetAuthor-link Identity u-linkBlend\" href=\"https:\/\/twitter.com\/wikileaks\" data-scribe=\"element:user_link\"><span class=\"TweetAuthor-avatar Identity-avatar\"><img decoding=\"async\" class=\"Avatar\" src=\"https:\/\/pbs.twimg.com\/profile_images\/512138307870785536\/Fe00yVS2_normal.png\" alt=\"\" data-scribe=\"element:avatar\" data-src-2x=\"https:\/\/pbs.twimg.com\/profile_images\/512138307870785536\/Fe00yVS2_bigger.png\" data-src-1x=\"https:\/\/pbs.twimg.com\/profile_images\/512138307870785536\/Fe00yVS2_normal.png\" \/><\/span><span class=\"TweetAuthor-name Identity-name customisable-highlight\" title=\"WikiLeaks\" data-scribe=\"element:name\">WikiLeaks<\/span> <\/a><a class=\"TweetAuthor-link Identity u-linkBlend\" href=\"https:\/\/twitter.com\/wikileaks\" data-scribe=\"element:user_link\"><span class=\"TweetAuthor-verifiedBadge\" data-scribe=\"element:verified_badge\"><b class=\"u-hiddenVisually\">\u2714<\/b><\/span><span class=\"TweetAuthor-screenName Identity-screenName\" dir=\"ltr\" title=\"@wikileaks\" data-scribe=\"element:screen_name\">@wikileaks<\/span><\/a><\/div>\n<\/div>\n<div class=\"Tweet-body e-entry-content\" data-scribe=\"component:tweet\">\n<p class=\"Tweet-text e-entry-title\" dir=\"ltr\" lang=\"en\">RELEASE: CIA &#8216;<a class=\"PrettyLink hashtag customisable\" dir=\"ltr\" href=\"https:\/\/twitter.com\/hashtag\/Archimedes?src=hash\" rel=\"tag\" data-query-source=\"hashtag_click\" data-scribe=\"element:hashtag\"><span class=\"PrettyLink-prefix\">#<\/span><span class=\"PrettyLink-value\">Archimedes<\/span><\/a>&#8216; system for exfiltration and browser hijacking.\u00a0Includes manuals and binary signatures. <a class=\"link customisable\" dir=\"ltr\" title=\"https:\/\/wikileaks.org\/vault7\/releases\/#Archimedes\" href=\"https:\/\/t.co\/XWr33GMGDN\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-expanded-url=\"https:\/\/wikileaks.org\/vault7\/releases\/#Archimedes\" data-scribe=\"element:url\"><span class=\"u-hiddenVisually\">https:\/\/<\/span>wikileaks.org\/vault7\/release<span class=\"u-hiddenVisually\">s\/#Archimedes\u00a0<\/span>\u2026<\/a><\/p>\n<div class=\"Tweet-metadata dateline\"><time class=\"dt-updated\" title=\"Time posted: 05 May 2017, 09:22:27 (UTC)\" datetime=\"2017-05-05T09:22:27+0000\"><a class=\"u-linkBlend u-url customisable-highlight long-permalink\" href=\"https:\/\/twitter.com\/wikileaks\/status\/860424440051634176\" data-datetime=\"2017-05-05T09:22:27+0000\" data-scribe=\"element:full_timestamp\">5:22 AM &#8211; 5 May 2017<\/a><\/time><\/div>\n<\/div>\n<\/blockquote>\n<hr \/>\n<p>The <a href=\"https:\/\/www.rt.com\/viral\/387216-wikileaks-cia-vault-7\/\">RT<\/a> provided more details:<\/p>\n<blockquote class=\"Tweet h-entry js-tweetIdInfo subject expanded \n<p>                    is-deciderHtmlWhitespace\" cite=\"https:\/\/twitter.com\/wikileaks\/status\/860424440051634176\" data-tweet-id=\"860424440051634176\" data-scribe=\"section:subject\"><\/p>\n<blockquote>\n<p class=\"excl\"><strong>The Archimedes tool enables traffic from one computer inside the LAN to be redirected through a computer infected with this malware and controlled by the CIA,<\/strong> according to WikiLeaks.<\/p>\n<p class=\"excl\">The technique is used to redirect the target\u2019s computer web browser to an exploitation server while appearing as a normal browsing session, the whistleblowing site said. In this way, the hackers gain an entry point that allows them access to other machines on that network.<\/p>\n<\/blockquote>\n<\/blockquote>\n<p>&#8230;click on the above link to read the rest of the article&#8230;<\/p>\n<blockquote class=\"Tweet h-entry js-tweetIdInfo subject expanded \n<p>                    is-deciderHtmlWhitespace\" cite=\"https:\/\/twitter.com\/wikileaks\/status\/860424440051634176\" data-tweet-id=\"860424440051634176\" data-scribe=\"section:subject\"><\/p>\n<p class=\"Tweet-text e-entry-title\" dir=\"ltr\" lang=\"en\">\n<p class=\"Tweet-text e-entry-title\" dir=\"ltr\" lang=\"en\">\n<\/blockquote>\n<\/div>\n<\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>WikiLeaks Reveals &#8220;Archimedes&#8221;: Malware Used To Hack Local Area Networks In its seventh CIA leak since March 23rd, WikiLeaks has just revealed the user manual of a CIA hacking tool known as \u2018Archimedes\u2019 which is purportedly used to attack computers inside a Local Area Network (LAN).\u00a0 The CIA tool works by redirecting a target&#8217;s webpage [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[6],"tags":[15239,135,15240,15241,880,4318],"class_list":["post-23856","post","type-post","status-publish","format-standard","hentry","category-liberty","tag-archimedes","tag-cia","tag-lan","tag-local-area-network","tag-wikileaks","tag-zerohedge"],"_links":{"self":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts\/23856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23856"}],"version-history":[{"count":1,"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts\/23856\/revisions"}],"predecessor-version":[{"id":23857,"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts\/23856\/revisions\/23857"}],"wp:attachment":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}