Skip to main content

CIA hacking tools revealed

WikiLeaks

Part 9 - Examples

The CIA's Engineering Development Group (EDG) management system contains around 500 different projects (only some of which are documented by "Year Zero") each with their own sub-projects, malware and hacker tools.

The majority of these projects relate to tools that are used for penetration, infestation ("implanting"), control, and exfiltration.

Another branch of development focuses on the development and operation of Listening Posts (LP) and Command and Control (C2) systems used to communicate with and control CIA implants; special projects are used to target specific hardware from routers to smart TVs.

UMBRAGE

The CIA's hand crafted hacking techniques pose a problem for the agency. Each technique it has created forms a "fingerprint" that can be used by forensic investigators to attribute multiple different attacks to the same entity.

This is analogous to finding the same distinctive knife wound on multiple separate murder victims. The unique wounding style creates suspicion that a single murderer is responsible. As soon one murder in the set is solved then the other murders also find likely attribution.

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

UMBRAGE components cover keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.

Fine Dining

Fine Dining comes with a standardized questionnaire i.e menu that CIA case officers fill out. The questionnaire is used by the agency's OSB (Operational Support Branch) to transform the requests of case officers into technical requirements for hacking attacks (typically "exfiltrating" information from computer systems) for specific operations. The questionnaire allows the OSB to identify how to adapt existing tools for the operation, and communicate this to CIA malware configuration staff. The OSB functions as the interface between CIA operational staff and the relevant technical support staff.

Among the list of possible targets of the collection are 'Asset', 'Liason Asset', 'System Administrator', 'Foreign Information Operations', 'Foreign Intelligence Agencies' and 'Foreign Government Entities'. Notably absent is any reference to extremists or transnational criminals. The 'Case Officer' is also asked to specify the environment of the target like the type of computer, operating system used, Internet connectivity and installed anti-virus utilities (PSPs) as well as a list of file types to be exfiltrated like Office documents, audio, video, images or custom file types. The 'menu' also asks for information if recurring access to the target is possible and how long unobserved access to the computer can be maintained. This information is used by the CIA's 'JQJIMPROVISE' software (see below) to configure a set of CIA malware suited to the specific needs of an operation.

Improvise (JQJIMPROVISE)

'Improvise' is a toolset for configuration, post-processing, payload setup and execution vector selection for survey/exfiltration tools supporting all major operating systems like Windows (Bartender), MacOS (JukeBox) and Linux (DanceFloor). Its configuration utilities like Margarita allows the NOC (Network Operation Center) to customize tools based on requirements from 'Fine Dining' questionairies.

HIVE

HIVE is a multi-platform CIA malware suite and its associated control software. The project provides customizable implants for Windows, Solaris, MikroTik (used in internet routers) and Linux platforms and a Listening Post (LP)/Command and Control (C2) infrastructure to communicate with these implants.

The implants are configured to communicate via HTTPS with the webserver of a cover domain; each operation utilizing these implants has a separate cover domain and the infrastructure can handle any number of cover domains.

Each cover domain resolves to an IP address that is located at a commercial VPS (Virtual Private Server) provider. The public-facing server forwards all incoming traffic via a VPN to a 'Blot' server that handles actual connection requests from clients. It is setup for optional SSL client authentication: if a client sends a valid client certificate (only implants can do that), the connection is forwarded to the 'Honeycomb' toolserver that communicates with the implant; if a valid certificate is missing (which is the case if someone tries to open the cover domain website by accident), the traffic is forwarded to a cover server that delivers an unsuspicious looking website.

The Honeycomb toolserver receives exfiltrated information from the implant; an operator can also task the implant to execute jobs on the target computer, so the toolserver acts as a C2 (command and control) server for the implant.

Similar functionality (though limited to Windows) is provided by the RickBobby project.

***

Source and links:


[1] [2] [3] [4] [5] [6] [7] [8]

Comments

Popular posts from this blog

Trump Talks COLLAPSE SPECTACULARLY As Iran REFUSES DEMANDS & HUMILIATES HIM Again & Again!!

Secular Talk    

Προβλέψεις ...

GR elections Update (15/9): Αναθεωρημένες προβλέψεις (μετά το δεύτερο debate): ΣΥΡΙΖΑ 28-30% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 2,5-3% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (11/9): Αναθεωρημένες προβλέψεις (μετά το πρώτο debate): ΣΥΡΙΖΑ 25-28% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (04/9): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update (29/8): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 4-4,5% ΠΟΤΑΜΙ 4-4,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update : Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 26-27% ...

Greeks BLOCK Israelis From Entering Their Country

Revolutionary Change   In a continuing worldwide trend, Greeks are now attempting to block Israelis from entering their country amid them attempting to flee the consequences of their actions. Peter Hager delves into this recent trend.

The West's hypocrisy has been exposed: This is how

Geopolitical Economy Report   Donald Trump's attacks on longtime US "allies" have forced Western leaders to admit their warmongering foreign policy was hypocritical. Canada's Prime Minister Mark Carney said the truth in his speech at the World Economic Forum in Davos: the "rules-based order" was "false". Ben Norton explains how the global balance of power is shifting.

Stephen Hawking confirms: The problem is Capitalism, not robots!

globinfo freexchange According to world famous physicist Stephen Hawking, the rising use of automated machines may mean the end of human rights – not just jobs. But he’s not talking about robots with artificial intelligence taking over the world, he’s talking about the current capitalist political system and its major players. On Reddit, Hawking said that the economic gap between the rich and the poor will continue to grow as more jobs are automated by machines, and the owners of said machines hoard them to create more wealth for themselves. The insatiable thirst for capitalist accumulation bestowed upon humans by years of lies and terrible economic policy has affected technology in such a way that one of its major goals has become to replace human jobs. If we do not take this warning seriously, we may face unfathomable corporate domination. If we let the same people who buy and sell our political system and resources maintain control of automated technology, the...

The dominant elite ready to break the "social contract"

Hyper-automation will allow the super-rich to “get rid” of the rest by system failure Since the French revolution and the new form of the urban states-democracies, the ruling class had to make the so-called "social contract" with the majority. From the moment that the dominant urban class took the power from feudalism and monarchy, should had to find a way to protect the means of production and the labor force. Therefore, the ethnic consciousness in each state served to bound the majority in order to shape national armies to protect the ruling class interests. In exchange, the ruling urban class had given the so-called social state, labor rights, etc., through the nation-state as a carrier and guarantor for all these benefits for the middle and lower classes. Since then, there have been a lot of battles and the majority managed to conquer some benefits. At the start of 20th century, the technology progress had brought the mass production. Western s...

Project Mythos: Too Dangerous to Release — So the U S Got It First

GVS Deep Dive   In the middle of rising geopolitical tensions and the Iran–U.S. conflict, a powerful new AI model quietly emerged—one that may reshape cybersecurity, financial systems, and the global economy. Built by Anthropic, the model—Claude Mythos—was reportedly considered too dangerous to release publicly. Instead, it is being tested under Project Glasswing by major tech companies like Amazon, Apple, Microsoft, and cybersecurity leaders like CrowdStrike and Palo Alto Networks. The model has demonstrated the ability to detect and exploit software vulnerabilities across operating systems, web infrastructure, and critical digital systems—raising serious questions about cyber warfare, financial security, and national defense. With involvement from U.S. institutions like the U.S. Department of the Treasury and the Federal Reserve, this may represent a major shift in how governments approach artificial intelligence, cybersecurity, and global power competition. As AI capabilities a...

Iranian Women Resist Invasion, Hospitals Targeted & Petrodollar Collapse

MintPress News   MintPress News founder Mnar Adley, this essential interview with University of Tehran professor Dr. Setareh Sadeghi reveals the devastating reality of US-Israeli aggression against Iran that corporate media refuses to report. With over 307 medical facilities destroyed in one month, schools bombed, and universities targeted, Iran faces what officials describe as a genocidal campaign. Dr. Sadeghi exposes: • How BBC journalists calling for Iran to be "nuked" are tied to CIA-backed regime change networks • Why Iranian women are leading mass rallies in defense of their nation—not against it • The collapse of Western propaganda as independent Iranian creators go viral worldwide • How Iran's regulation of the Strait of Hormuz is accelerating the petrodollar's decline • UAE's covert complicity in war crimes while positioning itself as a neutral party • Why Russia and China are aligning with Iran against unipolar imperial domination As Trump threatens to ...

Billionaires are social distancing in super yachts as tens of millions lose jobs

Everyday, it becomes clearer: the COVID-19 pandemic is hitting poor, working, and marginalized communities the hardest. Millions of workers – especially low-wage retail, food service, hospitality, and care workers – have faced the terrible choice daily between going to work and risking their health, or staying home and risking their paychecks. Many other workers don’t even have that choice, with around 30 million people in the US filing for unemployment in the past six weeks. But billionaires don’t face these same problems. As tens of millions have lost their jobs over the past two months, billionaire wealth soared by a whopping $282 billion between March 18 and April 10, according to a new study from the Institute for Policy Studies.  And while finding enough space to wait out the pandemic is something many struggle with, billionaires have been escaping to their second (or third, or fourth) homes to ride it out in luxury – all while they position themselves to ...

First predictions for the snap elections in Greece

Greek elections globinfo freexchange First predictions for the snap elections in Greece have started already. According to the German newspaper Bild, SYRIZA appears with heavy losses with a percentage of 28%. Close to SYRIZA is the right-Wing New Democracy with 25% (little less than 3% lower than in previous elections) and the new Popular Unity party that came from the split of SYRIZA, appears to gather 8% of the votes. All first polls show significant losses for Alexis Tsipras and SYRIZA. In the last few days, many members of the party have resigned and Tsipras has to deal also with the internal crisis in his party after the split according to the plan B of the Brussels bureaufascists. Most of the early predictions give Lafazanis' Popular Unity a percentage of 7-8%, while SYRIZA's partners in the coalition government, Independent Greeks, struggle to reach the crucial 3% to enter the new parliament. In any case, the split of SYRIZA creates an even...