Skip to main content

CIA hacking tools revealed

WikiLeaks

Part 9 - Examples

The CIA's Engineering Development Group (EDG) management system contains around 500 different projects (only some of which are documented by "Year Zero") each with their own sub-projects, malware and hacker tools.

The majority of these projects relate to tools that are used for penetration, infestation ("implanting"), control, and exfiltration.

Another branch of development focuses on the development and operation of Listening Posts (LP) and Command and Control (C2) systems used to communicate with and control CIA implants; special projects are used to target specific hardware from routers to smart TVs.

UMBRAGE

The CIA's hand crafted hacking techniques pose a problem for the agency. Each technique it has created forms a "fingerprint" that can be used by forensic investigators to attribute multiple different attacks to the same entity.

This is analogous to finding the same distinctive knife wound on multiple separate murder victims. The unique wounding style creates suspicion that a single murderer is responsible. As soon one murder in the set is solved then the other murders also find likely attribution.

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

UMBRAGE components cover keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.

Fine Dining

Fine Dining comes with a standardized questionnaire i.e menu that CIA case officers fill out. The questionnaire is used by the agency's OSB (Operational Support Branch) to transform the requests of case officers into technical requirements for hacking attacks (typically "exfiltrating" information from computer systems) for specific operations. The questionnaire allows the OSB to identify how to adapt existing tools for the operation, and communicate this to CIA malware configuration staff. The OSB functions as the interface between CIA operational staff and the relevant technical support staff.

Among the list of possible targets of the collection are 'Asset', 'Liason Asset', 'System Administrator', 'Foreign Information Operations', 'Foreign Intelligence Agencies' and 'Foreign Government Entities'. Notably absent is any reference to extremists or transnational criminals. The 'Case Officer' is also asked to specify the environment of the target like the type of computer, operating system used, Internet connectivity and installed anti-virus utilities (PSPs) as well as a list of file types to be exfiltrated like Office documents, audio, video, images or custom file types. The 'menu' also asks for information if recurring access to the target is possible and how long unobserved access to the computer can be maintained. This information is used by the CIA's 'JQJIMPROVISE' software (see below) to configure a set of CIA malware suited to the specific needs of an operation.

Improvise (JQJIMPROVISE)

'Improvise' is a toolset for configuration, post-processing, payload setup and execution vector selection for survey/exfiltration tools supporting all major operating systems like Windows (Bartender), MacOS (JukeBox) and Linux (DanceFloor). Its configuration utilities like Margarita allows the NOC (Network Operation Center) to customize tools based on requirements from 'Fine Dining' questionairies.

HIVE

HIVE is a multi-platform CIA malware suite and its associated control software. The project provides customizable implants for Windows, Solaris, MikroTik (used in internet routers) and Linux platforms and a Listening Post (LP)/Command and Control (C2) infrastructure to communicate with these implants.

The implants are configured to communicate via HTTPS with the webserver of a cover domain; each operation utilizing these implants has a separate cover domain and the infrastructure can handle any number of cover domains.

Each cover domain resolves to an IP address that is located at a commercial VPS (Virtual Private Server) provider. The public-facing server forwards all incoming traffic via a VPN to a 'Blot' server that handles actual connection requests from clients. It is setup for optional SSL client authentication: if a client sends a valid client certificate (only implants can do that), the connection is forwarded to the 'Honeycomb' toolserver that communicates with the implant; if a valid certificate is missing (which is the case if someone tries to open the cover domain website by accident), the traffic is forwarded to a cover server that delivers an unsuspicious looking website.

The Honeycomb toolserver receives exfiltrated information from the implant; an operator can also task the implant to execute jobs on the target computer, so the toolserver acts as a C2 (command and control) server for the implant.

Similar functionality (though limited to Windows) is provided by the RickBobby project.

***

Source and links:


[1] [2] [3] [4] [5] [6] [7] [8]

Comments

Popular posts from this blog

"Kidnapped in Int'l Waters": Israel Intercepts Gaza-Bound Aid Ship, Detains Greta Thunberg & Others

Democracy Now!   Eleven peace activists and one journalist on board the Gaza Freedom Flotilla ship, the "Madleen," were detained by Israeli soldiers as their ship carrying vital humanitarian aid for starving Palestinians approached Gaza.    The ship was intercepted by Israeli forces in the middle of the night in international waters. Its supplies were seized and communications jammed. The unarmed activists will likely be transported to Israeli detention or "immediately deported," says Ann Wright, a U.S. military veteran who has participated in four Freedom Flotilla journeys and now serves on the steering committee of the Freedom Flotilla Coalition. She calls on citizens of countries around the world to push for the activists' release and an end to Israel's war on Gaza. 

How Israel’s Supporters Play Victim to Justify Genocide & Silence Critics

BreakThrough News   As Israel commits a live-streamed genocide in Gaza, Western media and political elites continue to center one narrative: Jewish fear. But what about the actual victims of this genocide—Palestinians? Journalist Nora Barrows-Friedman joins Rania Khalek on Dispatches for a fearless conversation on Zionist indoctrination in the Jewish diaspora, how antisemitism is being weaponized to silence critics of Israel, and how Jewish identity politics has been manipulated to cover for unspeakable crimes. From the media blackout on Israeli war crimes to the erasure of anti-Palestinian hate crimes—even in the diaspora—Nora lays bare the contradictions and power structures behind it all. 

How the EU is using anti-Russia sanctions to criminalise journalism

The EU sanctioned me and my media outlet for covering Palestine protests in Germany. It’s part of Europe’s growing authoritarianism and militarism, cloaked in language of fighting disinformation and defending democracy.   by Hüseyin Dogru   Part 2 - How the EU uses anti-Russian hysteria to smear Palestine solidarity journalism   The official rationale for sanctioning me hinges on red .’s alleged links to Russian influence. The EU sanctions listing cited just two pieces of “evidence”: that some red. staff had previously worked for Russian-funded media, and that we covered “politically controversial subjects” – specifically: Palestine. That’s it. The listing accuses me, through my work with red ., of “facilitating violent demonstrations”, amplifying “radical Islamic terrorist narratives” and claims our staff “coordinated with occupiers”. Not a single piece of evidence is cited, apart from the fact that we published footage of a pro-Palestine student occupation in Berlin. I...

UN report confirms: Israel is a terrorist state and its goal is to exterminate all Palestinians

Israeli attacks on educational, religious and cultural sites in the Occupied Palestinian Territory amount to war crimes and the crime against humanity of extermination, UN Commission says.     globinfo freexchange Israel has obliterated Gaza’s education system and destroyed over half of all religious and cultural sites in the Gaza Strip, part of a widespread and relentless assault against the Palestinian people in which Israeli forces have committed war crimes and the crime against humanity of extermination, the UN Independent International Commission of Inquiry on the Occupied Palestinian Territory, including East Jerusalem and Israel, said in a new report [yesterday]. While the Commission paid special attention to the situation in Gaza, the report focuses on attacks in the Occupied Palestinian Territory as a whole, and in Israel. “We are seeing more and more indications that Israel is carrying out a concerted campaign to obliterate Palestinian life in Gaza,” said Navi Pi...

Keir Starmer admits Ukraine a proxy war

The Grayzone   The Grayzone 's Max Blumenthal and Aaron Mate on the British PM's unintentional acknowledgement of an inconvenient truth. 

[LIVE] War in the Middle East after Iran's retaliation against Israel

globinfo freexchange      Explosions in Tel Aviv as sirens sound across Israel amid Iranian missile attacks in response to Israeli strikes.      The Israeli military continues to launch waves of strikes against Iranian military and nuclear sites, as well as major cities.   Updates:  https://www.aljazeera.com/news/liveblog/2025/6/13/live-explosions-reported-in-iran-amid-israel-tensions  

UNHINGED CNN, FOX War Propaganda After Iran Strikes

Breaking Points   Krystal and Saagar discuss unhinged war propaganda on mainstream media. 

How the U.S. & Israel Used Rafael Grossi to Hijack the IAEA and Start a War on Iran

Rafael Grossi, Director General of the International Atomic Energy Agency (IAEA), allowed the IAEA to be used by the United States and Israel—an undeclared nuclear weapons state in long-term violation of IAEA rules—to manufacture a pretext for war on Iran, despite his agency’s own conclusion that Iran had no nuclear weapons program.   by Medea Benjamin - Nicolas J. S. Davies On June 12th, based on a damning report by Grossi, a slim majority of the IAEA Board of Governors voted to find Iran in non-compliance with its obligations as an IAEA member. Of the 35 countries represented on the Board, only 19 voted for the resolution, while 3 voted against it, 11 abstained and 2 did not vote. The United States contacted eight board member governments on June 10th to persuade them to either vote for the resolution or not to vote. Israeli officials said they saw the U.S. arm-twisting for the IAEA resolution as a significant signal of U.S. support for Israel’s war plans, revealing how much Isra...

War criminal Netanyahu is pushing the Orange Clown and the US into the abyss

globinfo freexchange   It seems that the war criminal Benjamin Netanyahu, is rushing to accelerate the decline of the US empire by forcing Donald Trump into an utterly devastating war with Iran.   Trump shot himself in the foot during his first term by killing the Iran nuclear deal just because he wanted to erase everything from the Obama legacy. His insane narcissism pushed him into crazy acts and made him believe that he could make another deal with Iran credited solely on him.   But now he is in big trouble because he has to deal with a corrupted psychopath who won't hesitate to burn the entire planet just to save himself.  As if the genocide of Palestinians in Gaza was not enough, the out-of-control psychopath Netanyahu, is doing whatever he can to drag the US into a war with Iran. As he realized that the Iranians are approaching the negotiating table again, (rather surprisingly with the man that killed the first deal and assassinated Qasem Soleimani), he decide...

Trump in SHOCK: Putin & China FLIP His Grave Mistake into STUNNING Victory

Danny Haiphong   Putin & China just gave Trump a rude BRICS awakening, and this bombshell will change everything for generations to come. Geopolitical analyst Ben Norton details the truth about Trump's biggest failure against the rising power of BRICS led by Russia and China, and why the US's role as super power is now in serious question.     Related: Trump's tariffs: A unique opportunity for BRICS and the Global South to fully escape from dollar tyranny