Sunday, March 30, 2025
HomeHacksVault 7 Leaks:CIA Hacking Tool "Dumbo" Hack WebCams & Corrupt Video Recordings...

Vault 7 Leaks:CIA Hacking Tool “Dumbo” Hack WebCams & Corrupt Video Recordings – WikiLeaks

Published on

SIEM as a Service

Follow Us on Google News

WikiLeaks Revealed New CIA Cyber Weapon called “Dumbo” that has been developed with Sophisticated functionality  to hacking Webcams and Corrupt Video Recordings by physical Accessibility Control .

This Physical Deployment done by Special Intelligence group called PAG (Physical Access Group) which is performing special Task to gain and exploit physical access to target computers in CIA field operations.

Few Days Before WikiLeaks revealed CIA Hacking Tools “Achilles, Aeris, SeaPea” Revealed to Hack Mac and Linux OS.

This intelligence Tool Executed from USB Thumb Drive once Gaining Physical Access of the Target Computer that running the Windows Operating System.

Once Dumbo Gaining access the Target System , it identify the devices that  installed with infected Systems such as webcams and microphones, either locally or connected by wireless (Bluetooth, WiFi) or wired networks.

Dumbo Execution Method

If the operator Physically  injects the Exploit into the Target machine via USB Thumb Drive, its will identified and stopped all the connected Devices such as recording, monitoring or detection of video/audio/network streams.

Dumbo will Log all the actions in logging file called “log.txt” and will also log all processes running at the start of its execution in a file called “proclist.txt” located in the same folder as the program’s execution.

According to the Document,Dumbo supports 32bit Windows XP, Windows Vista, and newer versions of Windows operating system. 64bit Windows XP, or Windows versions prior to XP, are not supported.

Operator of this Malware can creating fake or destroying actual evidence of the intrusion operation by deleting and Manipulating the recordings.

Avoid the action that gets recorded , Manual suggest  to turn of the Anti Virus by the Operator.

Camera And Microphone

Since CIA Tool infect the Windows Operating systems , it showing the list of Camera that Connected with Device.

Operator can select the camera to taking the desire action by using table of Process running in this target Computer and also it required System Level Privilege.

List of selected camera devices Displays with unique camera name and by default last camera detected as  selected to take the relevant action by operator.

Operator can able to do any kind of action with the selected Devices later infection done by the Dumbo.

Also it shows all the Microphones that muted and unmuted and also Selectively corrupted or delete recordings.

Dumbo can’t Perform its Malicious action if the Camera being used by other Program.

USB Thumb Drive should be remain Plugged into the Target computer to being Maintain the control the targeted Machine.

Previous CIA Leaked Tools by WikiLeaks

 Vault 7 Leaks : CIA Hacking Tools “Achilles, Aeris, SeaPea” Revealed to Hack Mac and Linux OS -WikiLeaks

Raytheon – Vault 7 Leaks : CIA Owned PoC Malware Development Surveillance Projects “UCL Under Raytheon” Leaked – WikiLeaks

HighRise – Vault 7 Leaks : CIA Android Ha Vault 7 Leaks : CIA Hacking Tools “Achilles, Aeris, SeaPea” Revealed to Hack Mac and Linux OS -WikiLeaks

Hacking Tool “HighRise” Steals Data From Compromised Android Phones via SMS – WikiLeaks

Gyrfalcon –  Vault 7 Leaks: CIA Hacking Tools “BothanSpy” and “Gyrfalcon” Steals SSH Credentials From Windows and Linux Computers – WikiLeaks

OutlawCountry – Vault 7 Leaks: CIA Malware “OutlawCountry” Controls Linux Machine and Redirect the Victims Traffic into CIA Controlled Machine – WikiLeaks

ELSA – Vault 7 Leaks: CIA Malware “ELSA” Tracking Geo-Location of WiFi Enabled Windows Computers – WikiLeaks

Brutal Kangaroo – CIA Hacking Tool “Brutal Kangaroo” Revealed to Hack Air-Gapped Networks by using USB Thumb Drives -WikiLeaks

CherryBlossom –  Wikileaks Revealed New CIA Wireless Hacking Tool “Cherry Blossom” Compromise Your Wireless Network Devices using MITM Attack

Pandemic –  New CIA Cyberweapon Malware “Pandemic” installed in Victims Machine and Replaced Target files where remote users use SMB to Download

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Gamaredon Hackers Weaponize LNK Files to Deliver Remcos Backdoor

Cisco Talos has uncovered an ongoing cyber campaign by the Gamaredon threat actor group,...

“Crocodilus” A New Malware Targeting Android Devices for Full Takeover

Researchers have uncovered a dangerous new mobile banking Trojan dubbed Crocodilus actively targeting financial...

SquareX Discloses Browser-Native Ransomware that Puts Millions at Risk

From WannaCry to the MGM Resorts Hack, ransomware remains one of the most damaging...

Hackers Exploit DNS MX Records to Create Fake Logins Imitating 100+ Brands

Cybersecurity researchers have discovered a sophisticated phishing-as-a-service (PhaaS) platform, dubbed "Morphing Meerkat," that leverages...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

New Specter Insight C2 Tool Fuels ClickFix-Based Hacking Campaigns

A recent cybersecurity investigation has uncovered a previously unidentified Command and Control (C2) framework,...

Four Members of Hacker Group Behind 90 Worldwide Data Breaches Exposed

A recent investigation by Group-IB has shed light on a notorious cybercriminal operating under...

Attackers Hide Malicious Word Files Inside PDFs to Evade Detection

A newly identified cybersecurity threat involves attackers embedding malicious Word files within PDFs to...