Catalin Cimpanu, on bleepingcomputer.com, has posted an article about one of the recent Wikileaks Vault 7 series of dumps. “CIA Malware Can Switch Cle
[See the full post at: CIA Malware Cyberweapon – Another SMB “Tool”]

![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
Home » Forums » Newsletter and Homepage topics » CIA Malware Cyberweapon – Another SMB “Tool”
From securityweek.com:
CIA Tool ‘Pandemic’ Replaces Legitimate Files With Malware
Eduard Kovacs | June 2, 2017
The fact that WikiLeaks delayed last week’s dump until the day the Russian government once again denied interfering with U.S. elections has led some members of the infosec community to believe that the leaks may be timed to serve other purposes, not just to expose the CIA’s activities.
Does some part of OneDrive transfer its data to/from online servers through SMB connections?
I know it used to be possible to map drive letters to it. I’m not sure about the current releases because I eliminate the OneDrive feature immediately from every system I install, so I have no recent experience watching OneDrive packets go by…
I do know that if you search online you can find a fair number of cloud services that can (or could) be mapped as “network drives”, implying possible vulnerability to this Pandemic tool. I honestly don’t know if they use SMB under the covers.
Cloud integration sounds neat – the world becomes your storage device – but don’t think for a moment it’s without peril.
-Noel
If the Cloud ever held my interest, it was for a very short time. Because all the eager people selling me the concept would not answer, ‘isn’t your cloud just a new name for your servers holding my data?’
That, and at the time I did not have the luxury of Unlimited Data, as a billing plan. It seemed to me the was an elitist concept that made big bucks off people who did not have a backup plan in place. Not that I’ve always kept mine adequately, but I knew I could if I weren’t lazy.
Most Companies are in business to give good faithful service. But I did not like the business model where I send all my information to someone else, who could one day leverage that hold on my wallet.
Work does not allow access to Wikileaks, I’m not able to get to the detailed information on this. The “manual” sounds interesting.
A question coming to mind for me is: Does the version of SMB come into play for this exploit?
We were fairly well protected from the previous dump’s exploits by disabling SMB1.
Has anyone seen information that would give us any hope that it’s similar for this exploit?
Thanks,
Jim
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.