WikiLeaks: After Russian-made Carberp financial malware was leaked in 2013, CIA borrowed elements of the malware for deployment on Windows systems
The CIA's hacking operations allegedly borrowed elements from the Carberp financial malware when the code was leaked in 2013
Context & Ripple Effects
This report lands mid-way through WikiLeaks' 2017 Vault 7 drip, which had already published [[a:917594|decade-old CIA documents describing EFI, UEFI, and firmware malware targeting Macs and iOS devices]]. The new claim extends the picture from CIA-built tooling to recycled criminal tooling: elements of Carberp, a Russian-made financial malware whose source code leaked in 2013, allegedly reappearing in CIA deployments on Windows systems.
The reuse cuts both ways. Later, WikiLeaks would publish the source of the CIA's Hive malware control system, showing certificates that allegedly impersonated Kaspersky — meaning state and criminal malware ecosystems were leaking into each other from both directions. The pattern also has a criminal-side mirror: FireEye later found Carbanak source code, from the group that stole over €1B from banks, sitting on VirusTotal for two years.
First-order effects
- Windows users and the banks Carberp originally targeted face a threat whose code now allegedly has a state sponsor, since leaked criminal malware was repurposed rather than retired after the 2013 leak.
- WikiLeaks' allegation, if accurate, ties the CIA to code lineage that antivirus vendors had already signature-tracked as financial crime — forcing vendors to re-evaluate detections built on criminal-family assumptions.
Second-order effects
- Russian-speaking cybercrime groups, whose leaked code the CIA allegedly borrowed, gain a propaganda and attribution shield: any future Carberp-family attack can be argued to be state, not criminal, muddying forensic attribution for defenders.
- The CIA's alleged reliance on recycled criminal code puts pressure on the vulnerability-equities process debate already opened by the Vault 7 releases, since reused malware leaves the same victims — banks and Windows users — exposed to both original and state operators.
Third-order effects
- If state agencies routinely harvest leaked criminal source code, malware families stop belonging to their authors and become shared infrastructure — collapsing the clean distinction between cybercrime and state operations that attribution, sanctions, and prosecution all rest on.
- The 2019 Carbanak finding shows criminal source code circulating publicly for years, suggesting a structural loop: leaks feed state toolkits, state toolkits get leaked by WikiLeaks, and defenders face an evergreen, self-replenishing malware commons.
The trend: Leaked malware source code is becoming shared raw material for both states and criminals, eroding the boundary between cybercrime toolkits and intelligence-agency arsenals.