WikiLeaks Vault 7: CIA's "Pandemic" Tool Replaces Files With Malware

Bot

AI-powered Bot
Thread author
Verified
Apr 21, 2016
3,405
WikiLeaks has released a new set of documents from its Vault 7 series, this time detailing a tool that the CIA allegedly uses to spread malware on a targeted organization's network.

Appropriately called "Pandemic," the tool can install a file system filter driver on a network, replacing legitimate files with malicious payload when they are accessed remotely via the Server Message Block (SMB) protocol.

"Pandemic does NOT//NOT make any physical changes to the targeted file on disk. The targeted file on the system Pandemic is installed on remains unchanged. Users that are targeted by Pandemic, and use SMB to download the targeted file, will receive the 'replacement' file," reads the tool's description.

This makes this tool a rather interesting one to have since it is particularly difficult to identify infected systems. Since Pandemic replaces files while in transit, instead of modifying them on the device the malware is running on, the legitimate files remain unchanged.

Read more: WikiLeaks Vault 7: CIA's "Pandemic" Tool Replaces Files with Malware
 

EASTER

Level 4
Verified
Well-known
May 9, 2017
145
Have a sneaky suspicion that we haven't seen even the tip of the iceberg yet on all the available roadways NSA is fashioned and categorized for punching into the O/S for all sorts of purposes.

I still wonder if Bill Gates has an opinion on all of these recent revelations from his perspective that are rapidly being made known lately.

Feel free to share a link if there is one. Windows after all was his brainchild and it would be noteworthy IMO what his own take on it is now.
 

ravi prakash saini

Level 13
Verified
Top Poster
Well-known
Apr 22, 2015
636
Im pretty sure NSA and co has access to some of the code of Windows.
it is obvious no company can fight it's respective govt. if it has to do business.
freedom of speech and things like this are good only for debate on TV
it has always been the same just name changes
be it king,President or prime minister.
 
  • Like
Reactions: AtlBo and EASTER

tryfon

Level 2
Verified
May 13, 2017
76
Hopefully people don't try figuring out how to recreate this.

I find it pretty funny how every time there is a CIA dump with wikileaks, it shows up on here. CNN at one point said it was illegal for us to look at wikileaks stuff because it is confidential and that only their reporters are allowed to :p. What a joke of a news organization
 
  • Like
Reactions: AtlBo

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,711
I find it pretty funny how every time there is a CIA dump with wikileaks, it shows up on here. CNN at one point said it was illegal for us to look at wikileaks stuff because it is confidential and that only their reporters are allowed to :p. What a joke of a news organization

Credit to alot of sources including posters here for getting out information on these issues, or we wouldn't know anything. Television news agencies are out of their minds with self interest these days.
 

tryfon

Level 2
Verified
May 13, 2017
76
Credit to alot of sources including posters here for getting out information on these issues, or we wouldn't know anything. Television news agencies are out of their minds with self interest these days.
100% agreed.
 
  • Like
Reactions: AtlBo

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top