Vault 7 - Cherry Blossom
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
According to the quick start guide that was leaked by WikiLeaks, Cherry Blossom (also referred to as CBlossom) provides a means of monitoring the internet activity of and performing software exploits on targets of interest and in particular wireless networking devices (802.11).
It is highly unlikely that large groups of people would be targeted using this method, rather, it is believed that this tool would only be used to target individuals that are deemed to be of high-value to the attackers. These tools have been developed for cyber-espionage campaigns, therefore likely potential targets include high-ranking officials in governmental organisations, and those in the defence, energy, finance and health sectors.
As with any of the Wikileaks dumps, the source code has not been released, however, the impact could be significantly higher if malicious groups were able to obtain the source code.
For CBlossom to work, it requires an implanted firmware to be installed. It has been noted in the documentation that some wireless devices allow a firmware upgrade over a wireless link, mitigating the need for physical access.
Once a wireless device has become implanted, it is referred to as a ‘fly trap’ and communicates with a Command and Control (C2) server, referred to as the Cherry Tree (CT). Data that is sent to the CT contains device status and security information that is logged to a database.
Possible exploits vary greatly, but include;
- Copying of the targets network traffic.
- Redirection of the target's browser (for further exploitation).
- Proxying the target's network connections.
- Harvesting email addresses, chat usernames and VOIP numbers.
- Establishing a VPN tunnel between the fly trap and a CB-owned VPN server (to allow connections to other network resources).
- Application execution wherein an application can be pushed to and executed on a Flytrap.
For the full documentation relating to CBlossom, please see:
https://wikileaks[.]org/vault7/document/#cherryblossom
Remediation steps
Last edited: 17 February 2020 11:40 am