Skip to main content

CIA hacking tools revealed

WikiLeaks

Part 9 - Examples

The CIA's Engineering Development Group (EDG) management system contains around 500 different projects (only some of which are documented by "Year Zero") each with their own sub-projects, malware and hacker tools.

The majority of these projects relate to tools that are used for penetration, infestation ("implanting"), control, and exfiltration.

Another branch of development focuses on the development and operation of Listening Posts (LP) and Command and Control (C2) systems used to communicate with and control CIA implants; special projects are used to target specific hardware from routers to smart TVs.

UMBRAGE

The CIA's hand crafted hacking techniques pose a problem for the agency. Each technique it has created forms a "fingerprint" that can be used by forensic investigators to attribute multiple different attacks to the same entity.

This is analogous to finding the same distinctive knife wound on multiple separate murder victims. The unique wounding style creates suspicion that a single murderer is responsible. As soon one murder in the set is solved then the other murders also find likely attribution.

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

UMBRAGE components cover keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.

Fine Dining

Fine Dining comes with a standardized questionnaire i.e menu that CIA case officers fill out. The questionnaire is used by the agency's OSB (Operational Support Branch) to transform the requests of case officers into technical requirements for hacking attacks (typically "exfiltrating" information from computer systems) for specific operations. The questionnaire allows the OSB to identify how to adapt existing tools for the operation, and communicate this to CIA malware configuration staff. The OSB functions as the interface between CIA operational staff and the relevant technical support staff.

Among the list of possible targets of the collection are 'Asset', 'Liason Asset', 'System Administrator', 'Foreign Information Operations', 'Foreign Intelligence Agencies' and 'Foreign Government Entities'. Notably absent is any reference to extremists or transnational criminals. The 'Case Officer' is also asked to specify the environment of the target like the type of computer, operating system used, Internet connectivity and installed anti-virus utilities (PSPs) as well as a list of file types to be exfiltrated like Office documents, audio, video, images or custom file types. The 'menu' also asks for information if recurring access to the target is possible and how long unobserved access to the computer can be maintained. This information is used by the CIA's 'JQJIMPROVISE' software (see below) to configure a set of CIA malware suited to the specific needs of an operation.

Improvise (JQJIMPROVISE)

'Improvise' is a toolset for configuration, post-processing, payload setup and execution vector selection for survey/exfiltration tools supporting all major operating systems like Windows (Bartender), MacOS (JukeBox) and Linux (DanceFloor). Its configuration utilities like Margarita allows the NOC (Network Operation Center) to customize tools based on requirements from 'Fine Dining' questionairies.

HIVE

HIVE is a multi-platform CIA malware suite and its associated control software. The project provides customizable implants for Windows, Solaris, MikroTik (used in internet routers) and Linux platforms and a Listening Post (LP)/Command and Control (C2) infrastructure to communicate with these implants.

The implants are configured to communicate via HTTPS with the webserver of a cover domain; each operation utilizing these implants has a separate cover domain and the infrastructure can handle any number of cover domains.

Each cover domain resolves to an IP address that is located at a commercial VPS (Virtual Private Server) provider. The public-facing server forwards all incoming traffic via a VPN to a 'Blot' server that handles actual connection requests from clients. It is setup for optional SSL client authentication: if a client sends a valid client certificate (only implants can do that), the connection is forwarded to the 'Honeycomb' toolserver that communicates with the implant; if a valid certificate is missing (which is the case if someone tries to open the cover domain website by accident), the traffic is forwarded to a cover server that delivers an unsuspicious looking website.

The Honeycomb toolserver receives exfiltrated information from the implant; an operator can also task the implant to execute jobs on the target computer, so the toolserver acts as a C2 (command and control) server for the implant.

Similar functionality (though limited to Windows) is provided by the RickBobby project.

***

Source and links:


[1] [2] [3] [4] [5] [6] [7] [8]

Comments

Popular posts from this blog

‘SHEER EVIL’: MASS PANIC As Israel BOMBS HOSPITAL & RESORT, ‘FLATTENS’ BEIRUT!!

Secular Talk    

Πως οι δημοσκόποι χειραγωγούν την κοινή γνώμη υπέρ του καθεστώτος Μητσοτάκη

Ένα χαρακτηριστικό παράδειγμα του system failure Άλλο ένα τσουνάμι δημοσκοπήσεων σαρώνει τα μυαλά των Ελλήνων, το οποίο αναμένεται να δυναμώσει όσο πλησιάζουμε στις εκλογές και όσο τα νέα πολιτικά κόμματα θα μπαίνουν πιο βαθιά στο πολιτικό παιχνίδι. Υπάρχουν ουκ ολίγα παραδείγματα που δείχνουν ότι οι δημοσκοπήσεις στην ουσία χρησιμοποιούνται για να δημιουργήσουν το επιθυμητό κλίμα για το καθεστώς Μητσοτάκη, παρά για να μετρήσουν απλώς τις δυνάμεις των κομμάτων σε κάθε χρονική στιγμή. Θα θέλαμε όμως να σταθούμε σε ένα συγκεκριμένο ερώτημα που οι εταιρίες συμπεριλαμβάνουν στις ¨μετρήσεις¨ τους όλο και πιο συχνά και ειδικά μετά την εμφάνιση των κομμάτων Τσίπρα και Καρυστιανού στην πολιτική αρένα. Οι ερωτώμενοι λοιπόν καλούνται να απαντήσουν αν θέλουν "πολιτική αλλαγή" ή "σταθερότητα". Χωρίς να χρειάζεται περαιτέρω ανάλυση, είναι ξεκάθαρο ότι από μόνο του αυτό το μανιχαϊστικού τύπου ερώτημα, είναι ουσιαστικά η γραμμή του καθεστώτος για το τι σημαίνει σταθερότητα, που εί...

“Russia & China Preparing For War With The US!”

The Jimmy Dore Show   Colonel Douglas Macgregor explains that as a result of recent military conflicts, Russia, China, and Iran have become allies, and that Beijing and Moscow have concluded that "if we let Iran fail, we're next on the menu" from what he describes as a "rogue state led by a rogue personality," meaning they will intervene to prevent Iran's collapse if the US threatens it. He tells Jimmy Dore that Putin called Trump for an hour and a half to make it clear that a military campaign in Iran would not succeed and would make the situation much worse, offering to store Iran's enriched uranium as a diplomatic gesture. Macgregor warns that if the US restarts the war, China could send 40 or 50 surface combatants and submarines to the Indian Ocean, and Russia could fly MiG-31s into Iranian airspace — not to provoke a direct confrontation but to "make a point." He concludes that the British Empire overreached and overextended with World War...

A response to misinformation on Nicaragua: it was a coup, not a ‘massacre’

There is so much misinformation in mainstream corporate media about recent events in Nicaragua that it is a pity that Mary Ellsberg’s article for Pulse has added to it with a seemingly leftish critique. Ellsberg claims that recent articles, including from this website, often “ paint a picture of the crisis in Nicaragua that is dangerously misleading. ” Unfortunately, her own article does just that. It looks at the situation entirely from the perspective of those opposing Daniel Ortega’s government while whitewashing their malevolent behavior and downplaying the levels of US support they have relied on. Her piece is an incomplete depiction of what is happening on the ground, ignoring many salient facts that have come to light and which have been outdated by recent events. The following is a brief response to Ellsberg’s main points from someone who lives in Nicaragua and has observed the situation directly and intimately: https://grayzoneproject.com/2018/08/15/a-res...

Billionaires are social distancing in super yachts as tens of millions lose jobs

Everyday, it becomes clearer: the COVID-19 pandemic is hitting poor, working, and marginalized communities the hardest. Millions of workers – especially low-wage retail, food service, hospitality, and care workers – have faced the terrible choice daily between going to work and risking their health, or staying home and risking their paychecks. Many other workers don’t even have that choice, with around 30 million people in the US filing for unemployment in the past six weeks. But billionaires don’t face these same problems. As tens of millions have lost their jobs over the past two months, billionaire wealth soared by a whopping $282 billion between March 18 and April 10, according to a new study from the Institute for Policy Studies.  And while finding enough space to wait out the pandemic is something many struggle with, billionaires have been escaping to their second (or third, or fourth) homes to ride it out in luxury – all while they position themselves to ...

Προβλέψεις ...

GR elections Update (15/9): Αναθεωρημένες προβλέψεις (μετά το δεύτερο debate): ΣΥΡΙΖΑ 28-30% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 2,5-3% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (11/9): Αναθεωρημένες προβλέψεις (μετά το πρώτο debate): ΣΥΡΙΖΑ 25-28% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (04/9): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update (29/8): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 4-4,5% ΠΟΤΑΜΙ 4-4,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update : Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 26-27% ...

How Western societies lost their faith in Vision

Why people don't rise up massively today? Why there are no real revolutions? How we tolerate all things that have been imposed to us? These questions come up in people's minds more and more often today in Greece and abroad, due to the economic crisis. Some theories are circulated as an answer, among these, explanations which include, for example, the psychosynthesis of modern Greeks, but the truth is that there is something more fundamental behind this passive behaviour and concerns not only Greece, but the entire Western world. by system failure Prior to the beginning of the 20th century, Friedrich Nietzsche declares God's death and Western world will put all its hopes in science. Laplace's Determinism leads to the almighty man, who through science, can find all the answers for the world. Technology, which naturally comes from scientific discoveries, promises prosperity and a better life for the majority. Science becomes the central "pylon...

Iran ALREADY HAS A Nuclear Weapon – Says Inside Source!

The Jimmy Dore Show   Guest host Garland Nixon interviews former intelligence analyst Larry Johnson about escalating tensions involving Iran, Israel, and the United States, focusing on reports that Israel is not only urging Washington to abandon negotiations, but is also pressuring the U.S. to assassinate Iran’s lead negotiator. Johnson claims that Iran has withdrawn from talks with the U.S., may leave the nuclear non-proliferation framework, and could potentially conduct a public nuclear test to demonstrate deterrence capabilities, citing information he says came from intelligence sources. The discussion examines the strategic roles of Pakistan, China, and Russia in the region, as well as disputes over the Strait of Hormuz, Israeli military actions, and the prospects for a new Middle East security architecture independent of U.S. influence. The speakers argue that Israeli efforts to weaken Iran have instead strengthened Tehran's regional position and altered the geopolitical balan...

Οι ιδιώτες 'επενδυτές' ως η μόνη επιλογή για ανάκαμψη: άλλο ένα παραμύθι του νεοφιλελέ κατεστημένου

Άλλη μια 'ιερή αγελάδα' της νεοφιλελεύθερης χούντας που κανείς δεν επιτρέπεται ούτε καν να διανοηθεί να αμφισβητήσει του system failure Το Ελληνικό πείραμα διανύει ήδη τον έβδομο χρόνο του με την οικονομία ρημαγμένη και κανένα σημάδι ανάκαμψης στον ορίζοντα. Εκτός από την απόλυτη αποτυχία των νεοφιλελεύθερων πολιτικών που επιβλήθηκαν στην Ελλάδα από την Τρόικα της καταστροφής, έχει ενδιαφέρον κανείς να εξετάσει και τον τρόπο που τα νεοφιλελεύθερα αφηγήματα έχουν επηρεάσει σε μεγάλο βαθμό την κοινή γνώμη, με αποτέλεσμα να καταλήγουν αναπόσπαστο κομμάτι ενός στρεβλού ορθολογισμού μέσα στις κοινωνίες. Η διαδικασία αυτή γίνεται με όχημα, κυρίως, την προπαγάνδα και την πλύση εγκεφάλου από τα ΜΜΕ και το πολιτικό κατεστημένο. Ένα από τα κεντρικά κλισέ των φερέφωνων του νεοφιλελευθερισμού στην Ελλάδα και αλλού αφορά την απόλυτη αναγκαιότητα των ιδιωτών 'επενδυτών' για την ανάκαμψη της οικονομίας. Τα ιδιωτικά κυρίαρχα μίντια και το πολιτικό κατεστημένο κατ...

From Moscow to Beijing: Eye on good neighbors with deep people-to-people ties

CGTN   Russian President Vladimir Putin has wrapped up his state visit to China. The bilateral meeting in Beijing has led to the extension of the 25-year-long Treaty of Good-Neighborliness and Friendly Cooperation, with high political mutual trust the backbone. Meanwhile, China and Russia issued a joint statement on promoting a multipolar world and a new type of international relations. What does the China-Russia relationship seriously mean to the two countries and to the world?