The CIA created a modified version of VLC, distributed via targeted ads or fake websites, which included a malicious DLL (psapi.dll) to steal and encrypt user documents. This highlights a significant security vulnerability where open-source software can be deceptively bundled with malware, making it crucial to download only from official sources.
Impact: High. Exposes a sophisticated cyber threat where a trusted open-source tool was weaponized, emphasizing the critical importance of verifying software sources.
In the source video, this keypoint occurs from 03:11:04 to 03:13:50.
Sources in support: Jean-Baptiste Kempf (Lead Developer of VLC, President of VideoLAN)

