Skip to main content

WikiLeaks Has Exposed More CIA-Developed Malware [Achilles, Aeris, SeaPea]


WikiLeaks has been exposing CIA-developed hacking tools on a regular basis since early 2017. These leaks are a part of Vault 7 leaks, which have witnessed tons of hacking tools that target different operating systems with different attack vectors. In this series, WikiLeaks has exposed
CIA’s Imperial project.
The Imperial project contains information regarding this hacking tools. While Achilles and SeaPea target Apple’s macOS operating system, Aeris targets Linux-based systems.
Let’s tell you about these Linux and macOS hacking tools one by one:

Aeris 2.1

Aeris, named after Final Fantasy VII’s Aeris Gainsborough, is an implant designed to infect Linux-based systems. It’s an automated implant written in C that supports numerous POSIX-based systems. The supported platforms are:
  • Debian Linux 7 (i386)
  • Debian Linux 7 (amd64)
  • Debian Linux 7 (ARM)
  • Red Hat Enterprise Linux 6 (i386)
  • Red Hat Enterprise Linux 6 (amd64)
  • Solaris 11 (i386)
  • Solaris 11 (SPARC)
  • FreeBSD 8 (i386)
  • FreeBSD 8 (amd64)
  • CentOS 5.3 (i386)
  • CentOS 5.7 (i386)
This highlight features of Aeris are configurable beacon interval, standalone HTTPS LS support, SMTP protocol support, TLS encrypted communications, automated file exfiltration, structured C&C, and compatibility with NOD cryptographic specification.
The distribution of Aeris Linux malware takes place with a set of Python utilities with one binary per platforms listed above.
Find detailed information: Aeris

Achilles 1.0

Achilles malware comes with the capability to inject trojans into a macOS installer, i.e., a DMG file, for a one-time execution.
Achilles has been tested in Intel processors running OS 10.6. The brief instruction manual of Achilles tells that the malicious DMG file should behave like the original DMG file. After the user runs the infected file, the payload will be installed and later removed. This way, the malware tried to erase its footprints and avoid suspicion.
Find Achilles user guide: Achilles

SeaPea 4.0

SeaPea is a macOS toolkit that comes with stealth and tool launching features. It’s also able to hide files, socket connections, and processes on the infected systems. CIA has tested the SeaPea malware on OS X 10.6 and 10.7 operating systems.
The SeaPea toolkit operates by assigning the processes to one of the 3 different categories: Normal, Elite, and Super-Elite. All the commands in SeaPea are run as an Elite process.
Find SeaPea user guide: SeaPea

Comments

Follow Us

WHAT'S HOT

VIDEO: KLY & DJ Maphorisa ft. eMTee & Patoranking – SnapThatSh!t

Ambitiouz Entertainment presents the official music video to “SnapThatSh!t” by its budding act, KLYalongside prolific South African producer, Maphorisa, raving South African rapper, eMTee and Nigeria’s music sensation, Patoranking.

How To Install Ubuntu MATE For The Raspberry Pi 2 and Raspberry Pi 3

Ubuntu MATE:  We have done what we can to optimise the build for the Raspberry Pi 2 and Raspberry Pi 3, you can comfortably use applications such as LibreOffice and Firefox. But the microSDHC I/O throughput is a bottleneck so  we  highly  recommend that you use a Class 6 or Class 10 microSDHC  card.  Ubuntu MATE 16.04 also fully supports the built-in Bluetooth and Wifi on

Windows Subsystem For Linux Is Beta No More, Gets “Full Support” In Windows 10 Fall Creators Update

As we told you earlier, WSL on Windows 10  moved out of beta  in August. It still carries the beta tag in Windows 10 Creators Update. Also, it won’t require people to enable developer

KLY Ft. Wizkid – Scrrr Pull Up (Remix)

Starboy, Wizkid blends with KLY as he adds a verse to Kly’s hottest tune Pull up Scrr!!. The remix comes with heavy greatness verse from the starboy boss as he blended another magic lyrics on the self enriched tune. Song Production credit goes to Wichi 1080.