WikiLeaks Reveals “Marble”: Proof CIA Disguises Their Hacks As Russian, Chinese, Arabic…


Tyler Durden's picture

WikiLeaks’ latest Vault 7 release contains a batch of documents, named ‘Marble’, which detail CIA hacking tactics and how they can misdirect forensic investigators from attributing viruses, trojans and hacking attacks to their agency by inserted code fragments in foreign languages.  The tool was in use as recently as 2016.  Per the WikiLeaks release:

“The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion, — but there are other possibilities, such as hiding fake error messages.”

The latest release is said to potentially allow for ‘thousands‘ of cyber attacks to be attributed to the CIA which were originally blamed on foreign governments.

WikiLeaks said Marble hides fragments of texts that would allow for the author of the malware to be identified. WikiLeaks stated the technique is the digital equivalent of a specialized CIA tool which disguises English language text on US produced weapons systems before they are provided to insurgents.

It’s “designed to allow for flexible and easy-to-use obfuscation” as “string obfuscation algorithms” often link malware to a specific developer, according to the whistleblowing site.

The source code released reveals Marble contains test examples in Chinese, Russian, Korean, Arabic and Farsi.

“This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion,” WikiLeaks explains, “But there are other possibilities, such as hiding fake error messages.”

The code also contains a ‘deobfuscator’ which allows the CIA text obfuscation to be reversed. “Combined with the revealed obfuscation techniques, a pattern or signature emerges which can assist forensic investigators attribute previous hacking attacks and viruses to the CIA.”

Previous Vault7 releases have referred to the CIA’s ability to mask its hacking fingerprints.

WikiLeaks claims the latest release will allow for thousands of viruses and hacking attacks to be attributed to the CIA.

And the rabbit hole just got even deeper.

***

Full release from WikiLeaks:

Today, March 31st 2017, WikiLeaks releases Vault 7 “Marble” — 676 source code files for the CIA’s secret anti-forensic Marble Framework. Marble is used to hamper forensic investigators and anti-virus companies from attributing viruses, trojans and hacking attacks to the CIA.

Marble does this by hiding (“obfuscating”) text fragments used in CIA malware from visual inspection. This is the digital equivallent of a specalized CIA tool to place covers over the english language text on U.S. produced weapons systems before giving them to insurgents secretly backed by the CIA.

Marble forms part of the CIA’s anti-forensics approach and the CIA’s Core Library of malware code. It is “[D]esigned to allow for flexible and easy-to-use obfuscation” as “string obfuscation algorithms (especially those that are unique) are often used to link malware to a specific developer or development shop.

The Marble source code also includes a deobfuscator to reverse CIA text obfuscation. Combined with the revealed obfuscation techniques, a pattern or signature emerges which can assist forensic investigators attribute previous hacking attacks and viruses to the CIA. Marble was in use at the CIA during 2016. It reached 1.0 in 2015.

The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion, — but there are other possibilities, such as hiding fake error messages.

The Marble Framework is used for obfuscation only and does not contain any vulnerabilties or exploits by itsel

Tucker Shreds “White Genocide” Professor Who Almost Vomited After 1st Class Passenger Gave Up Seat For Soldier


ZeroPointNow's picture

I haven’t seen a cucking this thorough since the night a binder-wielding Kurt Eichenwald was nearly killed by a post-Tucker tweet…

Last night, Tucker Carlson effortlessly savaged attention craving Drexel University “professor” George Ciccariello – who made headlines in December after calling for White Genocide over Twitter.

On Tuesday, Ciccariello once again made waves after expressing his disgust on an airplane when a 1st class passenger gave up his seat to a uniformed soldier on an airplane. Rational minds on the internet did not take too kindly:

In his latest stunt, the “white genocide” advocate led a group of feeble-voiced children in a protest of writer Charles Murray on the grounds that he’s a racist. The next stop for the Drexel degenerate; out of his safe space and into the lion’s den…

A facially ticking Ciccariello tried his best to match forces with Carlson, who simply kept knocking him on his ass – over, and over, and over. It was absolutely brutal:

Nobody takes you seriously, I’m trying to take you seriously. You’re accusing this guy of racial demagoguery and you called for white genocide, you also applauded the Haitian revolution for killing whites – look those are your views! I’m not saying you shouldn’t be allowed to express them. I’m merely pointing out the irony that you’re trafficking in race hatred and yet saying that Charles Murray shouldn’t be allowed to speak because he trafficks in race hatred. Are you self aware enough to catch that?

Tucker then goes on to read one of Ciccariello’s screeds, concluding “It’s High School writing… it’s crap!”

(that wasn’t even the best part… just watch until you see Tucker use air quotes)

  

Content originally generated at iBankCoin.com * Follow on Twitter @ZeroPointNow

Tucker Carlson Interviews Dr. Stephen Cohen RE: The Vast Russian Conspiracy…


Dr. Stephen Cohen appeared on Tucker Carlson Fox broadcast to discuss the ‘vast Russian planetary conspiracy’ plot against America:

.

Riddle me this: The Mexican government openly admits to spending millions of dollars to influence U.S. elections; a Mexican billionaire owns the most influential U.S. media outlet (NYT); the Mexican government spends tens of millions to lobby congress; and the Mexican government has dedicated $50 million to pay for U.S. legal services to keep illegal aliens from being returned to Mexico; yet somehow it’s the Russian government that is a concern. Odd no?

The French Elections


Macron Emmanuel

Fillon-WifeThe French Elections are in complete chaos. We are witnessing the collapse of the Fifth Republic of France. Our computer correctly forecasted that the Socialist Party would lose. It also forecasted that Le Pen’s party would beat the Socialists and most likely even the conservatives, which is led by Francois Fillon. Yet, the scandal around him paying his wife nearly what the President of the United States is paid to be an assistant has taken its toll. She is now formerly under investigation. However, a new party was just formed after August 2016 En Marche! (meaning forward or on the march) by the newcomer Emmanuel Macron, but he is really offering nothing to help France – only to keep Brussels on life-support.

We are witnessing an all-out war in France. The banks have been told not to lend any money to Le Pen to save Brussels. Just about every other party is starting to throw their support behind Macron. The former Socialist, PM Valls, now supports Macron because the socialists are dead in the water. Macron was a bureaucrat in the socialist government. He certainly offers nothing but doom for France or the euro going forward for if he is elected. Brussels will keep on going as it has until the whole thing goes belly up which looks to be in 2018.

Le Pen MarineOf course, the media is following the same scheme as they did in Britain and the USA – supporting Macron to keep the status quo. The polls are now claiming that Macron will trample Le Pen on May 7th if it comes down to the two. So how to model the French elections presents a huge problem. The only party that is now surviving is Le Pen’s. The latest polls by  PrésiTrack OpinionWay / ORPI for Les Echos and Radio Classique, show Le Pen still in the lead with 25% of the first round of voting in April. Her lead has dropped by two points, and she is now just one percentage point ahead of Macron, who is set to come in second place with 24%. Francois Fillon is now trailing behind at 19%, with Socialist candidate Benoit Hamon currently on 11%. The poll taken by a separate poll by Odoxa revealed that 75% of the French voters want Mr. Fillon to pull out of the presidential race following the “Penelopegate” scandal of his wife. Here too, we see the strongest position is against corruption. This is surfacing in Russia, but it was also what put Trump in the White House. Fillon has been accused of paying his wife Penelope and two of his children around €900,000 for jobs that they did not actually do. While he denies all allegations that they didn’t work, the President of the United States is paid $400,000 (€370,000).

What makes this very difficult to now have the computer forecast the election after it was correct that the current socialist government would collapse, is the fact that the entire political party system has disintegrated. We have people from the socialists now support Macron and the same thing is happening from the conservatives abandoning Fillon who desperately hopes to win to prevent prosecution for corruption. If we throw all other parties together and extrapolate the pretense that Macron’s brand new party is the sum of all others, then he may win. But this is a very big IF, because there is no past history that we can rely upon. What does appear on the horizon for France is that the Fifth Republic will fall in the years ahead.

1959 Franc 5th Republic Liberty Walking

We are currently in the Fifth Republic of France, which was established by Charles de Gaulle in 1958. Our models are warning that this may completely capitulate followed the end of this currency Economic Confidence Wave 2020 going into 2021.

FrenchFranc-Y 1900-1998 IBFFVF-Y FOR 1999-2010

IBEUUS-Y TEK TO 2020 1-22-2016

 

The Surveillance State Behind Russia-gate


It would appear that these guys know what they are talking about!

You Will Never Hear These Truths Discussed In The Mainstream


Good Reading 🙂

LIMBAUGH: ‘Tunnel Visioned Ideologue’ Evelyn Farkas May Have Outed Herself As Source Of Leaks


What more do you need?

MARK LEVIN: Interview Between Mika And Evelyn Farkas On Trump Spying Is A SMOKING GUN


Mark is right about this!

N. Korea warns of ‘disastrous consequences’ after McCain calls Kim Jong-un ‘crazy fat kid’


Insane obese kid would probably be the best words but for once I do have to agree with McCain in principle.

Sean Spicer White House Press Conference – March 30th…


Source: Sean Spicer White House Press Conference – March 30th…