About the CIA’s Spying Techniques
Documents don’t support contention that CIA impersonates other countries to mask provenance of its cyberattacks.
WASHINGTON—The “Vault 7” trove of documents released Tuesday by WikiLeaks has been cited by commentators to claim that the Central Intelligence Agency may have been masquerading as other foreign states while conducting its cyberhacks.
The documents being cited, however, offer no smoking gun.
The idea that the CIA posed as foreign actors has gained currency among people who are using the WikiLeaks disclosure to question the U.S. intelligence community’s conclusion that Russia hacked the Democratic National Committee and Hillary Clinton’s campaign chairman last year in order to help elect President Donald Trump.
These political commentators and outlets are implying the campaign hacks could have been a CIA operation.
“CIA uses techniques to make cyberattacks look like they originated from enemy state.
It turns DNC/Russia hack allegation by CIA into a JOKE,” internet entrepreneur Kim Dotcom wrote after the release in a tweet picked up by ZeroHedge, a financial blog known for its antiestablishment worldview.
Mr. Dotcom, who founded the file-sharing website Megaupload, is wanted in the U.S. on charges including criminal copyright infringement, money laundering and conspiracy to commit racketeering.
Conservative commentator Laura Ingraham promoted the same line of reasoning in an exchange with host Sean Hannity on Fox News, claiming the leaks show U.S. intelligence agencies using countries like Russia as a scapegoat for their own attacks.
“If [CIA agents] were using specific deceptive techniques to look like the Russians, then that opens up the question…in all of this Russian conspiracy... did [the CIA] do it internally?
The same people that were leaking on Trump?” Mr. Hannity replied.
WikiLeaks tweeted the Fox News segment to its millions of followers.Infowars, an online outlet associated with the far right, ran a story titled: “VAULT 7: CIA CAN STAGE FAKE RUSSIAN HACKING TO UNDERMINE TRUMP.”
One problem: The documents WikiLeaks released on Tuesday don’t show examples of CIA operatives masquerading as any foreign actors, let alone Russian military intelligence, while conducting cyberattacks.
What they do show: The CIA appears to have a group called Umbrage that maintains a library of malware samples and techniques from external sources for agency programmers to repurpose when developing their own hacking tools.
Some of the Umbrage library appears to include pieces of malware linked to Russian criminal hackers and Chinese state actors, as well as publicly available malware, such as a program a French coder released that can take over a web camera remotely.
WikiLeaks suggested in its news release accompanying the leak the CIA is collecting these samples to leave the fingerprints of foreign actors at the crime scene of attacks and to confuse investigators.
But the documents released so far say nothing about the CIA using the Umbrage malware library to cover the tracks of an attack.
The documents say the library there is for a different purpose: to save time and money in programming.