Jump to content

CIA Pandemic Malware: Cute little bug that switches out your files on SMB

Wikileaks has just released some documentation on another one of the CIA tools which appears to have a neat trick and name.  The Pandemic Tool infects a target computer that has shared folders and will begin to distribute malware instead of the requested file when someone downloads it via SMB.  

 

https://www.bleepingcomputer.com/news/security/cia-malware-can-switch-clean-files-with-malware-when-you-download-them-via-smb/

Quote

According to a leaked CIA manual, Pandemic is installed on target machines as a "file system filter driver." This driver's function is to listen to SMB traffic and detect attempts from other users to download shared files from the infected computer.

 

Pandemic will intercept this SMB request and answer on behalf of the infected computer. Instead of the legitimate file, Pandemic will deliver a malware-infected file instead. According to the CIA manual, Pandemic can replace up to 20 legitimate files at a time, with a maximum size of 800MB per file, and only takes 15 seconds to install. Support is include for replacing both 32-bit and 64-bit files. The tool was specifically developed to replace executable files, especially those hosted on enterprise networks via shared folders.

 

The role of this cyberweapon is to infect corporate file sharing servers and deliver a malicious executable to other persons on the network, hence the tool's name of Pandemic.

According to the article, this little gem of malicious code can be difficult to detect as when a local user accesses one of the shared files, it will execute the clean version.  The only two methods so far to detect this tool appear to be for a sysadmins to download and scan the files from another computer via SMB or via:

Quote

Section 3 of the tool's leaked manual provides a different method of detecting Pandemic malware.

Quote

Pandemic registers a minifilter driver using Windows' Flt* functions. As a result, FltMgr requires that all drivers registering as minifilters contain certain registry keys. Pandemic uses the 'Null' service key (on all Windows systems) as its own driver service key.  Pandemic will create 2 sub keys and 3 values under the 'Null' service key in the registry. These values and sub keys are deleted when Pandemic is uninstalled at the end of its configured run timer, or when it is uninstalled via a special F&F (v2) DLL. These keys will NOT//NOT be deleted if the system is rebooted before the aforementioned scenarios occur.

 

I have to admit that this is an interesting little bug that the CIA either cooked up or paid to have cooked up, especially considering how much work it would appear that you have to go through to find it...  

Link to comment
Share on other sites

Link to post
Share on other sites

well that cute bug sounds like a whole ton of fun.

linus sex tips

Link to comment
Share on other sites

Link to post
Share on other sites

Why the hell would the CIA want something like this? Just to give the finger to countries we don't like? seemssmartbatman.vbs

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, tmcclelland455 said:

Why the hell would the CIA want something like this? Just to give the finger to countries we don't like? seemssmartbatman.vbs

It's a driver that can give out malware to every single computer from a corporation building at the same time and without being detected. I feel like it's a pretty powerful tool if the CIA decided they don't want people using iPhones anymore.

We have a NEW and GLORIOUSER-ER-ER PSU Tier List Now. (dammit @LukeSavenije stop coming up with new ones)

You can check out the old one that gave joy to so many across the land here

 

Computer having a hard time powering on? Troubleshoot it with this guide. (Currently looking for suggestions to update it into the context of <current year> and make it its own thread)

Computer Specs:

Spoiler

Mathresolvermajig: Intel Xeon E3 1240 (Sandy Bridge i7 equivalent)

Chillinmachine: Noctua NH-C14S
Framepainting-inator: EVGA GTX 1080 Ti SC2 Hybrid

Attachcorethingy: Gigabyte H61M-S2V-B3

Infoholdstick: Corsair 2x4GB DDR3 1333

Computerarmor: Silverstone RL06 "Lookalike"

Rememberdoogle: 1TB HDD + 120GB TR150 + 240 SSD Plus + 1TB MX500

AdditionalPylons: Phanteks AMP! 550W (based on Seasonic GX-550)

Letterpad: Rosewill Apollo 9100 (Cherry MX Red)

Buttonrodent: Razer Viper Mini + Huion H430P drawing Tablet

Auralnterface: Sennheiser HD 6xx

Liquidrectangles: LG 27UK850-W 4K HDR

 

Link to comment
Share on other sites

Link to post
Share on other sites

Man, it's all about intelligence war now.

|EVGA 850 P2| |1440p PG279Q| |X570 Aorus Extreme| |Ryzen 9 3950x WC| |FE 2080Ti WC|TridentZ Neo 64GB| |Samsung 970 EVO M.2 1TB x3

 |Logitech G900|K70 Cherry MX Speed|  |Logitech Z906 |  |HD650|  |CaseLabs SMA8 (one of the last ones made)

 

Link to comment
Share on other sites

Link to post
Share on other sites

30 minutes ago, WMGroomAK said:

Support is include for replacing both 32-bit and 64-bit files.

So is there a CIA phone number one rings for support of their malware. Like those ones that charge by the minute

             ☼

ψ ︿_____︿_ψ_   

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Foxxer said:

Man, it's all about intelligence war now.

It's been like this since the before WW1 and intensified with the Cold War.

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, SCHISCHKA said:

So is there a CIA phone number one rings for support of their malware. Like those ones that charge by the minute

You just have to walk to their offices in Guantanamo. Cuba.

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, tmcclelland455 said:

Why the hell would the CIA want something like this? Just to give the finger to countries we don't like? seemssmartbatman.vbs

If we ever got into a war with Russia or China, we could completely destroy any infrastructure connected to the cloud. That would make it surprisingly easy to handicap an enemy that would be otherwise very difficult to destroy.

Royal Rumble: https://pcpartpicker.com/user/N3v3r3nding_N3wb/saved/#view=NR9ycf

 

"How fortunate for governments that the people they administer don't think." -- Adolf Hitler
 

"I am always ready to learn although I do not always like being taught." -- Winston Churchill

 

"We must learn to live together as brothers or perish together as fools." -- Martin Luther King Jr.

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, Foxxer said:

Man, it's all about intelligence war now.

I doubt the phrase "knowledge is power" came into existence without being heavily influenced by how valuable information about your foes can end up being.

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, tmcclelland455 said:

Why the hell would the CIA want something like this? Just to give the finger to countries we don't like? seemssmartbatman.vbs

You gotta think beyond the realm of malware being destructive and into the realm of stealth access. Having Pandemic deliver rootkits to every machine on a corporate network could be very useful to the CIA.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, WMGroomAK said:

I have to admit that this is an interesting little bug that the CIA either cooked up or paid to have cooked up, especially considering how much work it would appear that you have to go through to find it...  

It only shows that NSA's nefarious activities are now backfiring at them. 

 

6 hours ago, Foxxer said:

Man, it's all about intelligence war now.

Yeah. Who needs battleships and nuclear weapons when you can have an army of black hat hackers? 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, Energycore said:

It's a driver that can give out malware to every single computer from a corporation building at the same time and without being detected. I feel like it's a pretty powerful tool if the CIA decided they don't want people using iPhones anymore.

What does a computer malware have to do with iPhones?  ?

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, N3v3r3nding_N3wb said:

If we ever got into a war with Russia or China, we could completely destroy any infrastructure connected to the cloud. That would make it surprisingly easy to handicap an enemy that would be otherwise very difficult to destroy.

if you drop a nuke there is no infrastructure left to defend. 

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×