Skip to main content

Vault 7 - Cherry Blossom

WikiLeaks has released further documentation on a tool called Cherry Blossom as a part of Vault 7. According to the leaked documentation, Cherry Blossom is a multi-purpose framework designed and developed to hack into a number of home router models.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

WikiLeaks has released further documentation on a tool called Cherry Blossom as a part of Vault 7. According to the leaked documentation, Cherry Blossom is a multi-purpose framework designed and developed to hack into a number of home router models.

Threat details

According to the quick start guide that was leaked by WikiLeaks, Cherry Blossom (also referred to as CBlossom) provides a means of monitoring the internet activity of and performing software exploits on targets of interest and in particular wireless networking devices (802.11).

It is highly unlikely that large groups of people would be targeted using this method, rather, it is believed that this tool would only be used to target individuals that are deemed to be of high-value to the attackers. These tools have been developed for cyber-espionage campaigns, therefore likely potential targets include high-ranking officials in governmental organisations, and those in the defence, energy, finance and health sectors.

As with any of the Wikileaks dumps, the source code has not been released, however, the impact could be significantly higher if malicious groups were able to obtain the source code.

For CBlossom to work, it requires an implanted firmware to be installed. It has been noted in the documentation that some wireless devices allow a firmware upgrade over a wireless link, mitigating the need for physical access.

Once a wireless device has become implanted, it is referred to as a ‘fly trap’ and communicates with a Command and Control (C2) server, referred to as the Cherry Tree (CT). Data that is sent to the CT contains device status and security information that is logged to a database.

Possible exploits vary greatly, but include;

  • Copying of the targets network traffic.
  • Redirection of the target's browser (for further exploitation).
  • Proxying the target's network connections.
  • Harvesting email addresses, chat usernames and VOIP numbers.
  • Establishing a VPN tunnel between the fly trap and a CB-owned VPN server (to allow connections to other network resources).
  • Application execution wherein an application can be pushed to and executed on a Flytrap.

For the full documentation relating to CBlossom, please see:
https://wikileaks[.]org/vault7/document/#cherryblossom


Remediation steps

Type Step
  • If any of the affected devices are in use, make sure they are running the latest firmware versions.
  • Disable remote administration
  • Monitor for any suspect network traffic patterns that may seem out of the ordinary.

Last edited: 17 February 2020 11:40 am