Skip to main content

CIA hacking tools revealed

WikiLeaks

Part 9 - Examples

The CIA's Engineering Development Group (EDG) management system contains around 500 different projects (only some of which are documented by "Year Zero") each with their own sub-projects, malware and hacker tools.

The majority of these projects relate to tools that are used for penetration, infestation ("implanting"), control, and exfiltration.

Another branch of development focuses on the development and operation of Listening Posts (LP) and Command and Control (C2) systems used to communicate with and control CIA implants; special projects are used to target specific hardware from routers to smart TVs.

UMBRAGE

The CIA's hand crafted hacking techniques pose a problem for the agency. Each technique it has created forms a "fingerprint" that can be used by forensic investigators to attribute multiple different attacks to the same entity.

This is analogous to finding the same distinctive knife wound on multiple separate murder victims. The unique wounding style creates suspicion that a single murderer is responsible. As soon one murder in the set is solved then the other murders also find likely attribution.

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

UMBRAGE components cover keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.

Fine Dining

Fine Dining comes with a standardized questionnaire i.e menu that CIA case officers fill out. The questionnaire is used by the agency's OSB (Operational Support Branch) to transform the requests of case officers into technical requirements for hacking attacks (typically "exfiltrating" information from computer systems) for specific operations. The questionnaire allows the OSB to identify how to adapt existing tools for the operation, and communicate this to CIA malware configuration staff. The OSB functions as the interface between CIA operational staff and the relevant technical support staff.

Among the list of possible targets of the collection are 'Asset', 'Liason Asset', 'System Administrator', 'Foreign Information Operations', 'Foreign Intelligence Agencies' and 'Foreign Government Entities'. Notably absent is any reference to extremists or transnational criminals. The 'Case Officer' is also asked to specify the environment of the target like the type of computer, operating system used, Internet connectivity and installed anti-virus utilities (PSPs) as well as a list of file types to be exfiltrated like Office documents, audio, video, images or custom file types. The 'menu' also asks for information if recurring access to the target is possible and how long unobserved access to the computer can be maintained. This information is used by the CIA's 'JQJIMPROVISE' software (see below) to configure a set of CIA malware suited to the specific needs of an operation.

Improvise (JQJIMPROVISE)

'Improvise' is a toolset for configuration, post-processing, payload setup and execution vector selection for survey/exfiltration tools supporting all major operating systems like Windows (Bartender), MacOS (JukeBox) and Linux (DanceFloor). Its configuration utilities like Margarita allows the NOC (Network Operation Center) to customize tools based on requirements from 'Fine Dining' questionairies.

HIVE

HIVE is a multi-platform CIA malware suite and its associated control software. The project provides customizable implants for Windows, Solaris, MikroTik (used in internet routers) and Linux platforms and a Listening Post (LP)/Command and Control (C2) infrastructure to communicate with these implants.

The implants are configured to communicate via HTTPS with the webserver of a cover domain; each operation utilizing these implants has a separate cover domain and the infrastructure can handle any number of cover domains.

Each cover domain resolves to an IP address that is located at a commercial VPS (Virtual Private Server) provider. The public-facing server forwards all incoming traffic via a VPN to a 'Blot' server that handles actual connection requests from clients. It is setup for optional SSL client authentication: if a client sends a valid client certificate (only implants can do that), the connection is forwarded to the 'Honeycomb' toolserver that communicates with the implant; if a valid certificate is missing (which is the case if someone tries to open the cover domain website by accident), the traffic is forwarded to a cover server that delivers an unsuspicious looking website.

The Honeycomb toolserver receives exfiltrated information from the implant; an operator can also task the implant to execute jobs on the target computer, so the toolserver acts as a C2 (command and control) server for the implant.

Similar functionality (though limited to Windows) is provided by the RickBobby project.

***

Source and links:


[1] [2] [3] [4] [5] [6] [7] [8]

Comments

Popular posts from this blog

Capitalism & Genocide - Yanis Varoufakis Speech at the Gaza Tribunal, 23rd October 2025, Istanbul

Yanis Varoufakis   On 23rd October, Yanis Varoufakis testified in front of the Jury of Conscience in the context of the Gaza Tribunal. His speech focused on the economic forces underpinning the genocide of the Palestinian people. In particular, he spoke on the manner in which capitalist dynamics have historically fuelled the white settler colonial project and, more recently, how the accumulation of a new form of capital - which he calls cloud capital - has accelerated, deepened and amplified the economic forces powering and propelling the machinery of genocide. 

Munich Shock: Rubio’s Vision of a New Western Century & World Order

GVS Deep Dive   At the 2026 Munich Security Conference, U.S. Secretary of State Marco Rubio delivered one of the most consequential foreign policy speeches of the year. Framed as a call for Western renewal, his address went far beyond NATO reassurance — outlining a vision of sovereignty, industrial consolidation, and civilizational confidence that may signal the end of the post-Cold War global order.   Is this the beginning of a Second Cold War?   Is the West reorganizing around bloc competition?   Or are we witnessing the construction of a new world order? 

What Iran, Russia & China just did is HUGE, War BACKFIRES on Trump

Danny Haiphong   Iran's shocking response to Trump's imminent attack is sending fear down the spines of the US military as war leaves them defenseless from Iranian missile fire says Mohammad Marandi. This video breaks down why this war is already backfiring on Trump. 

Saudi Arabia & Qatar caught Mossad agents planning false flag operations inside their soil to blame Iran

Tucker Carlson says Saudi Arabia & Qatar caught & arrested Israeli Mossad agents planning bombings in those countries. pic.twitter.com/6PUxWeUymu — Jackson Hinkle 🇺🇸 (@jacksonhinklle) March 3, 2026

US-Israeli attack on Iran expands into GLOBAL WAR: EU & UK join, Canada supports, Gulf regimes hit

Geopolitical Economy Report   The US-Israeli war on Iran is expanding into a global conflict. The European Union supports it. The UK is letting Trump use British bases. Germany and France are involved. Canada backs it. Tehran has retaliated, in self-defense, hitting US military bases in Gulf countries. Ben Norton explains. 

Billionaires are social distancing in super yachts as tens of millions lose jobs

Everyday, it becomes clearer: the COVID-19 pandemic is hitting poor, working, and marginalized communities the hardest. Millions of workers – especially low-wage retail, food service, hospitality, and care workers – have faced the terrible choice daily between going to work and risking their health, or staying home and risking their paychecks. Many other workers don’t even have that choice, with around 30 million people in the US filing for unemployment in the past six weeks. But billionaires don’t face these same problems. As tens of millions have lost their jobs over the past two months, billionaire wealth soared by a whopping $282 billion between March 18 and April 10, according to a new study from the Institute for Policy Studies.  And while finding enough space to wait out the pandemic is something many struggle with, billionaires have been escaping to their second (or third, or fourth) homes to ride it out in luxury – all while they position themselves to ...

A response to misinformation on Nicaragua: it was a coup, not a ‘massacre’

There is so much misinformation in mainstream corporate media about recent events in Nicaragua that it is a pity that Mary Ellsberg’s article for Pulse has added to it with a seemingly leftish critique. Ellsberg claims that recent articles, including from this website, often “ paint a picture of the crisis in Nicaragua that is dangerously misleading. ” Unfortunately, her own article does just that. It looks at the situation entirely from the perspective of those opposing Daniel Ortega’s government while whitewashing their malevolent behavior and downplaying the levels of US support they have relied on. Her piece is an incomplete depiction of what is happening on the ground, ignoring many salient facts that have come to light and which have been outdated by recent events. The following is a brief response to Ellsberg’s main points from someone who lives in Nicaragua and has observed the situation directly and intimately: https://grayzoneproject.com/2018/08/15/a-res...

Iran's Next Strike OBLITERATES US Navy & Israel, War Has BEGUN

Danny Haiphong   Prof. Mohammad Marandi joins the show to react to Iran's vow to strike a devastating blow to the heart of Tel Aviv and US Navy as imminent US war approaches. Trump has moved military assets to the region and now Iran has responded by moving its missiles and drones in strike position. Watch until the end for an in-depth analysis of a war that's already begun, and is about to change everything with one fatal move by the US empire.

Five reasons a war with Iran will mark the final fall of US empire

globinfo freexchange   1. The nature of war has changed dramatically since the Iraq war, due to technological developments. A ground invasion, especially against Iran, would be catastrophic for the US empire with unpredictable consequences, even if the regime-change mission successfully completed.  2. The Iran allies in the region are still active, despite their losses. This is connected with the first reason in a way because armed groups dispersed in the Middle-East and affiliated with Iran, can lead to an asymmetric, out-of-control conflict to the point where US forces may suddenly find themselves trapped in a wider deadly warzone with no exit. The new, relatively cheap technology of drones and small/middle range missiles, is easily accessible to these groups. The Ansar Allah group in Yemen, already demonstrated their ability to sabotage US military operations. 3. Iran is not Iraq. Not only due to its size and the fact that we live now in a very different period, but also be...

Ο βασικός λόγος που ο Τραμπ διστάζει να χτυπήσει το Ιράν

"Μικρά και ασήμαντα" από τον Πίκο Απίκο Ο βασικός λόγος που δεν έγινε η επίθεση στο Ιράν, είναι το γεγονός ότι πρόσφατα, το Ιράν αποχώρησε από το δορυφορικό σύστημα GPS που είναι Αμερικανικό και εντάχθηκε στο Κινεζικό BeiDou. Που σημαίνει ότι οι Αμερικανοί δεν έχουν τη δυνατότητα να σαμποτάρουν τους Ιρανικούς πυραύλους.  Έτσι εξηγείται και το μεγάλο ποσοστό ευστοχίας των Ιρανικών πυραύλων στην τελευταία σύγκρουση με το Ισραήλ, μέσα στο Ισραηλινό έδαφος. Αλλά και το γεγονός ότι πριν λίγες μέρες, οι ίδιοι οι Ισραηλινοί ζήτησαν τη διαμεσολάβηση της Ρωσίας, προκειμένου να αποκλιμακωθεί η ένταση με το Ιράν, αφού Ισραηλινές εφημερίδες και αξιωματούχοι είχαν παραδεχθεί ανοιχτά την παρουσία πρακτόρων της Μοσάντ σε Ιρανικό έδαφος και τον κομβικό τους ρόλο στις πρόσφατες εξεγέρσεις. Οι Αμερικανοί επομένως γνωρίζουν ότι αυτή τη στιγμή οι Ιρανοί έχουν τη δυνατότητα να χτυπήσουν Αμερικανικές βάσεις (όπως απείλησαν ότι θα κάνουν αν ο Τραμπ κάνει πράξη τις απειλές του), χωρίς να μπορούν να ...