/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

WikiLeaks: After Russian-made Carberp financial malware was leaked in 2013, CIA borrowed elements of the malware for deployment on Windows systems

The CIA's hacking operations allegedly borrowed elements from the Carberp financial malware when the code was leaked in 2013

ITworld.com Michael Kan

Context & Ripple Effects

This report lands mid-way through WikiLeaks' 2017 Vault 7 drip, which had already published [[a:917594|decade-old CIA documents describing EFI, UEFI, and firmware malware targeting Macs and iOS devices]]. The new claim extends the picture from CIA-built tooling to recycled criminal tooling: elements of Carberp, a Russian-made financial malware whose source code leaked in 2013, allegedly reappearing in CIA deployments on Windows systems.

The reuse cuts both ways. Later, WikiLeaks would publish the source of the CIA's Hive malware control system, showing certificates that allegedly impersonated Kaspersky — meaning state and criminal malware ecosystems were leaking into each other from both directions. The pattern also has a criminal-side mirror: FireEye later found Carbanak source code, from the group that stole over €1B from banks, sitting on VirusTotal for two years.

First-order effects

  • Windows users and the banks Carberp originally targeted face a threat whose code now allegedly has a state sponsor, since leaked criminal malware was repurposed rather than retired after the 2013 leak.
  • WikiLeaks' allegation, if accurate, ties the CIA to code lineage that antivirus vendors had already signature-tracked as financial crime — forcing vendors to re-evaluate detections built on criminal-family assumptions.

Second-order effects

  • Russian-speaking cybercrime groups, whose leaked code the CIA allegedly borrowed, gain a propaganda and attribution shield: any future Carberp-family attack can be argued to be state, not criminal, muddying forensic attribution for defenders.
  • The CIA's alleged reliance on recycled criminal code puts pressure on the vulnerability-equities process debate already opened by the Vault 7 releases, since reused malware leaves the same victims — banks and Windows users — exposed to both original and state operators.

Third-order effects

  • If state agencies routinely harvest leaked criminal source code, malware families stop belonging to their authors and become shared infrastructure — collapsing the clean distinction between cybercrime and state operations that attribution, sanctions, and prosecution all rest on.
  • The 2019 Carbanak finding shows criminal source code circulating publicly for years, suggesting a structural loop: leaks feed state toolkits, state toolkits get leaked by WikiLeaks, and defenders face an evergreen, self-replenishing malware commons.

The trend: Leaked malware source code is becoming shared raw material for both states and criminals, eroding the boundary between cybercrime toolkits and intelligence-agency arsenals.