The Vault 7 series from WikiLeaks keeps surprising. In April we talked about Weeping Angel, a spyware used to hack Samsung smart TVs. Then came the tool Athena, whose goal is to gain total control of a system and install itself. Now it's the turn of the package Brutal Kangaroo, and its priority is the infection of isolated internal networks with air gaps using USB drives. Its operation shares certain aspects with Stuxnet, something that, to tell the truth, doesn't surprise us much.

Brutal Kangaroo: CIA Tool That Infects Machines Without Internet
Brutal Kangaroo

The world has learned the hard way about the power of the toys that intelligence agencies keep in their systems, after the leak of a couple of exploits, and the massive deployment of WannaCry. Needless to say, there isn't a single ounce of regret coming from those responsible, and every time they meet they only think about deepening their actions, with greater regulation on the Internet and new attacks on encryption platforms. Information is our first line of defense, and that's where WikiLeaks steps in. The portal carries its share of scandals on its shoulders (starting with its strange relationship with the Russian government and certain announcements out of proportion), but the Vault 7 series keeps making noise. What's next on the list? The name is Brutal Kangaroo.

Brutal Kangaroo: CIA Tool That Infects Machines Without Internet
They even went to the trouble of creating a logo...

According to the available information (150 pages on average), Brutal Kangaroo is a CIA package with four tools: Drifting Deadline (infection of USB drives and terminals), Shattered Assurance (automatic tools that control the infection of USB drives), Broken Promise (processor of collected information), and Shadow (persistence). Brutal Kangaroo uses different vectors to infect terminals even when the user didn't open any file. Some of the names circulating are EZCheese, Lachesis, and RiverJack. Microsoft confirmed that it has blocked these three elements with patches, although it didn't share exact dates (the hotfix for EZCheese is from 2015). Brutal Kangaroo must be installed on a primary host responsible for receiving the USB drives that are then used in the isolated network. Once the infected USB drive is connected to one of the terminals, the malware will try to spread to the rest of the network and create a covert network.

Brutal Kangaroo: CIA Tool That Infects Machines Without Internet
Part of the Drifting Deadline configuration

The text suggests that the entry point for Brutal Kangaroo (the primary host) requires a manual infection, which translates into physical access to the hardware (probably with another USB drive) and reduced effectiveness, but if Microsoft already released the fixes that block its operation, the question we're left with is: “What are they using now?”

Official site: