New CIA Leak Reveals Ability to Infect Air-Gapped Systems

2025-11-13

The CIA hasn’t been doing extraordinarily well, with leaks coming out of the organization like wildfire over the last few years. Most famous of these leaks was the Vault 7 incident where several documents from the agency came out of the woodwork, revealing advanced hacking methodologies, tools, and frameworks that could compromise a great deal of devices around the world.

A new leak on 22 June 2017 revealed that it could not only infect computers across networks but even infiltrate air-gapped systems at will using a couple of cunning tactics and a USB thumb drive.

Why Would You Want to Infect Air-Gapped Systems?

vault7airgap-drives

Air-gapping has been used for several years as a strong line of defense against outside infiltration. As networks become more convenience-centric, they become more vulnerable. To help counteract this, some companies and government institutions have completely removed sensitive systems from their networks, using them only as offline storage to be accessed only by select personnel.

As the CIA’s new leaks have proven, this is a highly-effective method of protection … until it isn’t anymore.

Since no entity really wants to spend an inordinate amount of resources on maintaining systems it doesn’t need, it’s a safe bet that the ones it air-gaps are full of secret data they do not want just anyone to access. This information usually consists of trade secrets, military strategies, unrevealed technologies, and anything else that is more important than a couple of credit card numbers.

How the Tool Works

The CIA tool, known as Brutal Kangaroo, relies on “hopping,” a method of replication where a virus writes itself and any relevant information onto a new platform. The idea here is to infect a networked computer, wait until an employee inserts a USB drive, write itself onto the platform, wait until the USB drive is inserted into an air-gapped computer, then grab any information of interest from the system. As soon as the USB drive is once again inserted into a networked computer, the virus will relay the information to the “controller,” allowing them to have a bird’s eye view of all air-gapped computers.

How to Prevent the Attack

vault7airgap-infiltration

Once your systems have been infected, there is no way to “unsend” the data that gets through. Once again, prevention is key. I’d recommend putting every networked system through a sanitation procedure where every single change is checked and accounted for (i.e. log every activity on each networked system, then go through the log just before transferring to an air-gapped system).

In addition to this, if you can, run your air-gapped system on something other than Windows (Brutal Kangaroo only runs on that operating system). If it’s just a database you’re storing and nothing else, you should get by just fine on Linux. Just don’t get complacent – Linux isn’t a magical weapon against hackers.

Minimize the amount of staff that is allowed to touch the air-gapped system and encrypt the file system whenever possible. Air-gapping by itself is just one of many tools in your arsenal. It should ideally be used in conjunction with several other safety procedures and policies that prevent your organization from looking like something made of egg shells.

Are there more things that organizations can do to prevent air gap infiltration? Tell us about it in a comment!

Comments on " New CIA Leak Reveals Ability to Infect Air-Gapped Systems" :

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Related Article

    The Easy Way of Doing Résumés, with Novorésumé
    INTERNET

    The Easy Way of Doing Résumés, with Novorésumé

    All of us have had that panic: There’s a great job available that you want to apply for, but they

    Everything You Need to Know About Usenet
    INTERNET

    Everything You Need to Know About Usenet

    This is a sponsored article and was made possible by Usenet Storm. The actual contents and opinions

    WebVR Explained and How It Affects You
    INTERNET

    WebVR Explained and How It Affects You

    Google Chrome and Mozilla Firefox now both offer out-of-the-box support for WebVR. This open virtual

    5 Common PayPal Scams and How to Avoid Them
    INTERNET

    5 Common PayPal Scams and How to Avoid Them

    Since its start eighteen years ago, PayPal has become one of the de-facto ways to send money online.

    How to Mute and Unmute an Email Thread in Gmail
    INTERNET

    How to Mute and Unmute an Email Thread in Gmail

    Email isn’t exactly easy to manage. It never stops arriving, and half of what shows up is junk. GM

    How to Revive the “View Image” Button In Google Image Search
    INTERNET

    How to Revive the “View Image” Button In Google Image Search

    Google recently removed the “View Image” button in Google Image search much to the fury of hardc

    How to Find the Best Alternative DNS Server
    INTERNET

    How to Find the Best Alternative DNS Server

    Changing your DNS server is a good idea. You will get better security, privacy, accuracy, and speed

    How to Get the Most from the New Opera Touch
    INTERNET

    How to Get the Most from the New Opera Touch

    Everyone seems to have loyalty to their favorite browsers. Sometimes the debate becomes as heated as

    About Netverse

    We are a premier digital platform committed to delivering high-quality content to our readers. Our mission is to provide accurate, reliable, and engaging information that adds value to our audience's daily lives.

    Our team consists of experienced content creators and subject matter experts who uphold the highest standards of professionalism. In an era of information overload, we curate content with care, ensuring our users receive only the most relevant and trustworthy information.

    Beyond just reporting facts, we focus on depth and context. Through expert analysis, comprehensive research, and clear presentation, we help our audience gain meaningful insights and make informed decisions.

    We take pride in being a trusted information source for our growing community of readers. Our user-first approach means we continuously adapt to provide content that meets our audience's evolving needs and interests.

    Innovation and excellence drive everything we do. We're committed to improving our platform and services to deliver the best possible experience for our users.