PDA

View Full Version : WikiLeaks releases Vault 7 "Marble"



Ares
31st March 2017, 04:51 AM
Today, March 31st 2017, WikiLeaks releases Vault 7 "Marble" -- 676 source code files for the CIA's secret anti-forensic Marble Framework. Marble is used to hamper forensic investigators and anti-virus companies from attributing viruses, trojans and hacking attacks to the CIA.

Marble does this by hiding ("obfuscating") text fragments used in CIA malware from visual inspection. This is the digital equivallent of a specalized CIA tool to place covers over the english language text on U.S. produced weapons systems before giving them to insurgents secretly backed by the CIA.

Marble forms part of the CIA's anti-forensics approach and the CIA's Core Library of malware code. It is "[D]esigned to allow for flexible and easy-to-use obfuscation" as "string obfuscation algorithms (especially those that are unique) are often used to link malware to a specific developer or development shop."

The Marble source code also includes a deobfuscator to reverse CIA text obfuscation. Combined with the revealed obfuscation techniques, a pattern or signature emerges which can assist forensic investigators attribute previous hacking attacks and viruses to the CIA. Marble was in use at the CIA during 2016. It reached 1.0 in 2015.

The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion, --- but there are other possibilities, such as hiding fake error messages.

The Marble Framework is used for obfuscation only and does not contain any vulnerabilties or exploits by itself.


https://wikileaks.org/vault7/?marble#Marble%20Framework

madfranks
31st March 2017, 08:43 AM
I have to admit I don't quite understand this, but it sounds really important!

Ares
31st March 2017, 09:21 AM
In coding the language used by the author as well as their coding structure can be used to identify them. So this framework obfuscates the coders language, as well as the coding structure and can even misrepresent the author as being someone else.

It basically means that whoever looks at the code the CIA wrote, won't be able to identify them as the creators of said software.

PatColo
31st March 2017, 10:50 AM
vlogger Bait & Sketch

https://i.ytimg.com/vi/GnZSqSXfUu0/hqdefault.jpg?custom=true&w=336&h=188&stc=true&jpg444=true&jpgq=90&sp=67&sigh=N_CAiOUFrcSh4Lws5K6DsyldaGM (https://www.youtube.com/watch?v=GnZSqSXfUu0) 9:11
NEW Vault 7: CIA Faking Proof of Russian Hacking? (https://www.youtube.com/watch?v=GnZSqSXfUu0)

298 views
2 hours ago

crimethink
31st March 2017, 02:06 PM
I have to admit I don't quite understand this, but it sounds really important!

It's the digital equivalent of having a box of foreign flags. When a hacking job is done, the relevant foreign flag is hoisted.

Ares
31st March 2017, 03:29 PM
It's the digital equivalent of having a box of foreign flags. When a hacking job is done, the relevant foreign flag is hoisted.

The Russians did it, we have proof.. ;)

PatColo
31st March 2017, 04:37 PM
vlogger Bait & Sketch again,

https://i.ytimg.com/vi/4y6sy2V9xu0/hqdefault.jpg?custom=true&w=336&h=188&stc=true&jpg444=true&jpgq=90&sp=67&sigh=a61cKApYiBE-IxGnDs44XjQhmqQ (https://www.youtube.com/watch?v=4y6sy2V9xu0) 1:33:03
altNews | WikiLeaks Vault 7: Marble Framework & SpaceX is a Hoax - 3.31.2017 (https://www.youtube.com/watch?v=4y6sy2V9xu0)

652 views
1 hour ago

Joshua01
1st April 2017, 06:35 AM
That pretty much invalidates the "mah Russians' argument. You have to hand it to Trump. Every time you think they have him backed into a corner he wins another round. It's like watching last years Super Bowl....You can't ever count the Patriots out, and neither can you count out Trump. Some of us thought Trump would go right in and drain the swamp. What we failed to realize is that process is much more involved and will indeed be a process, not en event! Grab more popcorn and enjoy the fun
It's the digital equivalent of having a box of foreign flags. When a hacking job is done, the relevant foreign flag is hoisted.