Skip to main content

CIA hacking tools revealed

WikiLeaks

Part 9 - Examples

The CIA's Engineering Development Group (EDG) management system contains around 500 different projects (only some of which are documented by "Year Zero") each with their own sub-projects, malware and hacker tools.

The majority of these projects relate to tools that are used for penetration, infestation ("implanting"), control, and exfiltration.

Another branch of development focuses on the development and operation of Listening Posts (LP) and Command and Control (C2) systems used to communicate with and control CIA implants; special projects are used to target specific hardware from routers to smart TVs.

UMBRAGE

The CIA's hand crafted hacking techniques pose a problem for the agency. Each technique it has created forms a "fingerprint" that can be used by forensic investigators to attribute multiple different attacks to the same entity.

This is analogous to finding the same distinctive knife wound on multiple separate murder victims. The unique wounding style creates suspicion that a single murderer is responsible. As soon one murder in the set is solved then the other murders also find likely attribution.

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

UMBRAGE components cover keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.

Fine Dining

Fine Dining comes with a standardized questionnaire i.e menu that CIA case officers fill out. The questionnaire is used by the agency's OSB (Operational Support Branch) to transform the requests of case officers into technical requirements for hacking attacks (typically "exfiltrating" information from computer systems) for specific operations. The questionnaire allows the OSB to identify how to adapt existing tools for the operation, and communicate this to CIA malware configuration staff. The OSB functions as the interface between CIA operational staff and the relevant technical support staff.

Among the list of possible targets of the collection are 'Asset', 'Liason Asset', 'System Administrator', 'Foreign Information Operations', 'Foreign Intelligence Agencies' and 'Foreign Government Entities'. Notably absent is any reference to extremists or transnational criminals. The 'Case Officer' is also asked to specify the environment of the target like the type of computer, operating system used, Internet connectivity and installed anti-virus utilities (PSPs) as well as a list of file types to be exfiltrated like Office documents, audio, video, images or custom file types. The 'menu' also asks for information if recurring access to the target is possible and how long unobserved access to the computer can be maintained. This information is used by the CIA's 'JQJIMPROVISE' software (see below) to configure a set of CIA malware suited to the specific needs of an operation.

Improvise (JQJIMPROVISE)

'Improvise' is a toolset for configuration, post-processing, payload setup and execution vector selection for survey/exfiltration tools supporting all major operating systems like Windows (Bartender), MacOS (JukeBox) and Linux (DanceFloor). Its configuration utilities like Margarita allows the NOC (Network Operation Center) to customize tools based on requirements from 'Fine Dining' questionairies.

HIVE

HIVE is a multi-platform CIA malware suite and its associated control software. The project provides customizable implants for Windows, Solaris, MikroTik (used in internet routers) and Linux platforms and a Listening Post (LP)/Command and Control (C2) infrastructure to communicate with these implants.

The implants are configured to communicate via HTTPS with the webserver of a cover domain; each operation utilizing these implants has a separate cover domain and the infrastructure can handle any number of cover domains.

Each cover domain resolves to an IP address that is located at a commercial VPS (Virtual Private Server) provider. The public-facing server forwards all incoming traffic via a VPN to a 'Blot' server that handles actual connection requests from clients. It is setup for optional SSL client authentication: if a client sends a valid client certificate (only implants can do that), the connection is forwarded to the 'Honeycomb' toolserver that communicates with the implant; if a valid certificate is missing (which is the case if someone tries to open the cover domain website by accident), the traffic is forwarded to a cover server that delivers an unsuspicious looking website.

The Honeycomb toolserver receives exfiltrated information from the implant; an operator can also task the implant to execute jobs on the target computer, so the toolserver acts as a C2 (command and control) server for the implant.

Similar functionality (though limited to Windows) is provided by the RickBobby project.

***

Source and links:


[1] [2] [3] [4] [5] [6] [7] [8]

Comments

Popular posts from this blog

Telegram Founder & CEO Pavel Durov Arrested in France as Online Censorship Escalates

Glenn Greenwald  

Όσοι περνάν των χώρα της απόγνωσης παθαίνουν αμνησία ...

globinfo freexchange Δανειστήκαμε αυτή τη φράση από ένα παλιό κομμάτι της Ελληνικής ροκ μπάντας "Τρύπες", για να περιγράψουμε με λίγα λόγια αυτό που φαίνεται να έχει πάθει η Ελληνική κοινωνία.  Πώς είναι δυνατόν μια ολόκληρη κοινωνία να έχει ξεχάσει ποιοι τη χρεοκόπησαν; Ποιοι έστησαν το άθλιο σύστημα των κρατικοδίαιτων 'ημέτερων' και της οικογενειοκρατίας; Ποιοι έσωσαν τις τράπεζες με πακτωλό δισεκατομμυρίων σε βάρος της μεσαίας τάξης; Ποιοι έκαναν τη μίζα και το ρουσφέτι επάγγελμα; Πώς είναι δυνατόν αυτή η κοινωνία να ετοιμάζεται να ξαναφέρει στην εξουσία ένα κομμάτι αυτού του άθλιου πολιτικού κατεστημένου, με την επιστροφή μάλιστα του αμετανόητα νεοφιλελεύθερου Κυριάκου Μητσοτάκη και της ομάδας του;   Η απόγνωση που έφεραν εννέα χρόνια βάρβαρων νεοφιλελεύθερων πολιτικών και σκληρής λιτότητας και που ανάγκασε τη χώρα να διαβεί τον εφιαλτικό μονόδρομο της μόνιμης χρεοκοπίας, πρέπει να έπαιξε σημαντικό ρόλο.  Διότι ως γνωστόν, η απελπισία...

Netanyahu Threatens Lebanon With Genocidal Mayhem

Owen Jones   Where is the media outrage?  

Jul 2018 picks

Retired US army colonel implies that a war with Iran could start with a Vietnam-type false flag operation Corporate media begin typical operations to make progressives comply with the establishment WikiLeaks paper shows France & UK pioneers behind Libya breakup Twitter under fire on European Commission hypocrisy to 'stand with the Greek people' IMF mafia ready to repeat the big crime in Argentina The financial system of chaos: no one can tell the 'when', 'where' and ‘how’ of the next financial meltdown Standard and Poor's 'coincidentally' upgrades the Greek economy after Greece expels two Russian diplomats Jill Stein, Jeremy Corbyn, Bernie Sanders: a continuously rising political triplet proves that Socialism unites generations The idiotic circus of terror leads us to the final collapse WikiLeaks paper reveals Ecuadorian private business elites declared war on Rafael Correa right after his election and asked for US support Ho...

Trump PANICS As US BOMBS WEDDING & Iran GETS REVENGE!!

Secular Talk  /  Breaking Points

Norman Finkelstein & Jeremy Corbyn: THE INTERVIEW ISRAEL WANT TO BAN

Double Down News In a powerful and deeply personal conversation, political scientist Dr. Norman Finkelstein sits down with MP and former UK Labour Leader Jeremy Corbyn to analyse the ongoing crisis in Gaza, Western diplomatic inaction, and the media's framing of the conflict. From evaluating ICJ proceedings to dismantling mainstream media "gatekeeper" tactics, Finkelstein and Corbyn provide an unsparing critique of current geopolitical realities and explain why Gaza has become a defining moral touchstone for a new generation. Beyond foreign policy, the pair explore the broader societal shifts shaping world politics today. Drawing on four decades of political activism, they compare today's student movement to historical anti-Apartheid and anti-Vietnam War struggles, while examining the decline of social mobility, the commercialisation of higher education, and the impact of digital media on critical thinking and long-term political engagement.

Houthis Have Inflicted "Astronomical" Damage On U.S. & Israel

Katie Halper Katie Halper talks to Ashok Kumar about how the Houthis are making history: "this is the first time in history that you had the maintenance of a blockade from a force with no navy," Trump "doesn't know what to do about it" and they're inflicting "astronomical liabilities" on Israel and the U.S.  Ashok Kumar is a University of London Professor and a Green Party activist in the U.K.

CNN Host COMPLETELY DESTROYED By RFK For Lying About COVID & Vaxx!

The Jimmy Dore Show   In this video, Jimmy Dore offers a scathing critique of CNN's Dana Bash and her colleagues in the legacy media for their COVID-19 coverage, accusing them of being paid mouthpieces for pharmaceutical companies rather than skeptical journalists. He argues that Anthony Fauci systematically lied about masks, social distancing, natural immunity, and the virus's origin, while CNN and other networks censored dissenting scientists like Dr. Robert Malone and Dr. Peter McCullough. Dore points to documented financial ties between Pfizer and CNN, as well as statements from former medical journal editors confirming widespread industry corruption, to support claims that the pandemic response was manufactured for profit. The segment defends RFK Jr.'s questioning of vaccine science and measles narratives, concluding that mainstream media journalists who ridicule truth-tellers are cowardly accessories to a deadly medical fraud.

EXPOSED: Zohran Reveals MASSIVE 9/11 Cover Up & SHOCKS ALL!!

Secular Talk

Προβλέψεις ...

GR elections Update (15/9): Αναθεωρημένες προβλέψεις (μετά το δεύτερο debate): ΣΥΡΙΖΑ 28-30% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 2,5-3% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (11/9): Αναθεωρημένες προβλέψεις (μετά το πρώτο debate): ΣΥΡΙΖΑ 25-28% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 11-13% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ + ΔΗΜΑΡ 3-4% ΑΝΕΛ 2,5-3,5% Update (04/9): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 3,5-4% ΠΟΤΑΜΙ 2,5-3,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update (29/8): Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 23-25% ΛΑΕ + ΣΧΕΔΙΟ Β' κ.λ.π. 20-23% ΝΔ 12-15% ΧΑ 6-8% ΚΚΕ 5-5,5% ΕΝΩΣΗ ΚΕΝΤΡΩΩΝ 4-4,5% ΠΟΤΑΜΙ 4-4,5% ΠΑΣΟΚ 3-4% ΑΝΕΛ 2,5-3,5% Update : Αναθεωρημένες προβλέψεις: ΣΥΡΙΖΑ 26-27% ...