Skip to main content

CIA hacking tools revealed

WikiLeaks

Part 9 - Examples

The CIA's Engineering Development Group (EDG) management system contains around 500 different projects (only some of which are documented by "Year Zero") each with their own sub-projects, malware and hacker tools.

The majority of these projects relate to tools that are used for penetration, infestation ("implanting"), control, and exfiltration.

Another branch of development focuses on the development and operation of Listening Posts (LP) and Command and Control (C2) systems used to communicate with and control CIA implants; special projects are used to target specific hardware from routers to smart TVs.

UMBRAGE

The CIA's hand crafted hacking techniques pose a problem for the agency. Each technique it has created forms a "fingerprint" that can be used by forensic investigators to attribute multiple different attacks to the same entity.

This is analogous to finding the same distinctive knife wound on multiple separate murder victims. The unique wounding style creates suspicion that a single murderer is responsible. As soon one murder in the set is solved then the other murders also find likely attribution.

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

UMBRAGE components cover keyloggers, password collection, webcam capture, data destruction, persistence, privilege escalation, stealth, anti-virus (PSP) avoidance and survey techniques.

Fine Dining

Fine Dining comes with a standardized questionnaire i.e menu that CIA case officers fill out. The questionnaire is used by the agency's OSB (Operational Support Branch) to transform the requests of case officers into technical requirements for hacking attacks (typically "exfiltrating" information from computer systems) for specific operations. The questionnaire allows the OSB to identify how to adapt existing tools for the operation, and communicate this to CIA malware configuration staff. The OSB functions as the interface between CIA operational staff and the relevant technical support staff.

Among the list of possible targets of the collection are 'Asset', 'Liason Asset', 'System Administrator', 'Foreign Information Operations', 'Foreign Intelligence Agencies' and 'Foreign Government Entities'. Notably absent is any reference to extremists or transnational criminals. The 'Case Officer' is also asked to specify the environment of the target like the type of computer, operating system used, Internet connectivity and installed anti-virus utilities (PSPs) as well as a list of file types to be exfiltrated like Office documents, audio, video, images or custom file types. The 'menu' also asks for information if recurring access to the target is possible and how long unobserved access to the computer can be maintained. This information is used by the CIA's 'JQJIMPROVISE' software (see below) to configure a set of CIA malware suited to the specific needs of an operation.

Improvise (JQJIMPROVISE)

'Improvise' is a toolset for configuration, post-processing, payload setup and execution vector selection for survey/exfiltration tools supporting all major operating systems like Windows (Bartender), MacOS (JukeBox) and Linux (DanceFloor). Its configuration utilities like Margarita allows the NOC (Network Operation Center) to customize tools based on requirements from 'Fine Dining' questionairies.

HIVE

HIVE is a multi-platform CIA malware suite and its associated control software. The project provides customizable implants for Windows, Solaris, MikroTik (used in internet routers) and Linux platforms and a Listening Post (LP)/Command and Control (C2) infrastructure to communicate with these implants.

The implants are configured to communicate via HTTPS with the webserver of a cover domain; each operation utilizing these implants has a separate cover domain and the infrastructure can handle any number of cover domains.

Each cover domain resolves to an IP address that is located at a commercial VPS (Virtual Private Server) provider. The public-facing server forwards all incoming traffic via a VPN to a 'Blot' server that handles actual connection requests from clients. It is setup for optional SSL client authentication: if a client sends a valid client certificate (only implants can do that), the connection is forwarded to the 'Honeycomb' toolserver that communicates with the implant; if a valid certificate is missing (which is the case if someone tries to open the cover domain website by accident), the traffic is forwarded to a cover server that delivers an unsuspicious looking website.

The Honeycomb toolserver receives exfiltrated information from the implant; an operator can also task the implant to execute jobs on the target computer, so the toolserver acts as a C2 (command and control) server for the implant.

Similar functionality (though limited to Windows) is provided by the RickBobby project.

***

Source and links:


[1] [2] [3] [4] [5] [6] [7] [8]

Comments

Popular posts from this blog

Κυβέρνηση Σαμαρά: Πιο νεοφιλελεύθερη και από την Τρόικα!

Ο πρόεδρος της επιτροπής για θέματα ανταγωνισμού του Επαγγελματικού Επιμελητηρίου Αθηνών, Γιώργος Φλωράς, αποκάλυψε στην εκπομπή του δημοσιογράφου, Νίκου Χατζηνικολάου, ότι η έκθεση του ΟΟΣΑ, με βάση την οποία συντάχθηκε το τελευταίο πολυνομοσχέδιο, είναι ουσιαστικά δημιούργημα του ΙΟΒΕ!
Ανέφερε χαρακτηριστικά ότι:
Οι προτάσεις αυτές δεν είναι του ΟΟΣΑ, αλλά του ΙΟΒΕ και της Επιτροπής Ανταγωνισμού, δηλαδή κυρίως των Χατζηδάκη και Στουρνάρα και ότι η κυβέρνηση στην ουσία χρησιμοποιεί την Τρόικα για να περνάει τις θέσεις των πολυεθνικών, μεγάλων αλυσίδων σούπερ μάρκετ, κ.λ.π.
Ο κ. Χατζηδάκης, τονίζει συνεχώς σε ότι έλεγε ότι 'εμείς χρησιμοποιήσαμε τον ΟΟΣΑ γιατί είναι αντικειμενικός, έχει την αξιοπιστία, έχει τη διεθνή εμπειρία κ.τ.λ.' και γι'αυτό βγήκε και ένα κονδύλι 936.000 ευρώ για να γίνει αυτή η έκθεση. Η έκθεση ξεκινάει αναφέροντας στη σελ. 2 ότι οι θέσεις μέσα σ'αυτή δεν εκφράζουν απαραίτητα τον οργανισμό.
Η έκθεση αυτή δεν είναι του ΟΟΣΑ, είναι μια οργανωμένη απάτ…

It seems that Bernie Sanders got it all wrong again, this time regarding the situation in Venezuela - very disappointing

globinfo freexchange
In an unfortunate series of tweets regarding the situation in Venezuela, Bernie Sanders exposed his weak spot again on foreign policy matters.
Sanders tweeted:
The Maduro government has waged a violent crackdown on Venezuelan civil society, violated the constitution by dissolving the National Assembly and was re-elected last year in an election many observers said was fraudulent. The economy is a disaster and millions are migrating. 1/3 — Bernie Sanders (@SenSanders) January 24, 2019
The United States should support the rule of law, fair elections and self-determination for the Venezuelan people. We must condemn the use of violence against unarmed protesters and the suppression of dissent. 2/3 — Bernie Sanders (@SenSanders) January 24, 2019
But we must learn the lessons of the past and not be in the business of regime change or supporting coups—as we have in Chile, Guatemala, Brazil & the DR. The US has a long history of inappropriately intervening in Latin Amer…

Canada has been trying to destabilize Venezuela at least since 2004

globinfo freexchange
Paul Jay, editor in chief at The Real News, gave some very interesting information - some based on personal experience - about Canada's total alignment with the US on its imperialist missions against Venezuela and other countries:
Mexico was part of the Lima Group, but now with the new leadership - with AMLO now taking office in Mexico - Mexico is not going along with this plan to recognize Juan Guaido. And Mexico is not the only country of the region. Many, many countries of CARICOM have come forward and have said they do not support this plan. So, the corporate media is trying to make this sound like the whole region is on board with this scheme.
For months, Canada has been playing a leading role in preparing for - according to the Canadian newspapers - for exactly what happened, the recognition of Juan Guaido.
And Canada has been into this scheme for months. And the rationale is supposedly that the election of 2017 was not a legitimate election because people w…

Former Pentagon official confirms: Trump prepares for war with Iran

globinfo freexchange
Right after Trump's sudden announcement that he will withdraw the US forces from Syria, we had some mixed reactions. Some liberals reacted angrily, but most of the reactions from the liberal machine were rather moderate, or at least not as intensive as someone would normally expect.
On the other hand, Trump's supporters and all those who had enough of the pro-war neoliberal establishment, felt a kind of vindication, as it appeared that Trump would eventually keep its promise for an 'anti-interventionist' policy.
But the blog wrote immediately a 'not so fast' article to explain that most of the Americans and all those who are tired of the US endless wars, should not rush to celebrate. We estimated that Trump's move is probably a sign that he is going to re-organize troops and go after the big target called Iran.
Indeed, shortly after the move, Trump, suddenly again, announced that he will also pullout troops from Afghanistan.
And then, about…

When Venezuela's state-owned Citgo was aiding poor Americans with a 'fuel for heating systems' program

globinfo freexchange
A report from 2011 proves that the Venezuelan government designed a special program to aid the poorest US citizens overcome funding difficulties to heat their homes, through Citgo Petroleum Corporation, subsidiary of the state-run company PDVSA.
Citgo's heating fuel program began in 2005 after the passing of the hurricanes Rita and Katrina, but it didn't stop there. It continued uninterrupted for several years under Hugo Chávez' administration:
For seventh year in a row, the CITGO Petroleum Corporation (or CITGO), subsidiary of the state-run company Petroleos de Venezuela (PDVSA), will aid poor communities of the United States (US) with a program of fuel for heating systems.
CITGO president Alejandro Granado, through a press released in the website of Venezuela's embassy to the United States, said the increasing costs of energy continue affecting the quality of life of millions of US citizens and community organizations in that …

Pompeo's special tweet potentially indirect threat against those who won't follow the orders on Venezuela

globinfo freexchange
After John Bolton indirectly threatened Venezuela with that 'accidental' revelation of about 5,000 US troops to be sent to Colombia, it was Mike Pompeo's turn.
In a peculiar tweet, the other major Trump warhawk essentially sent a clear message to those countries (mostly under the US influence) that refused to recognize Washington's puppet, Juan Guaidó, as the legitimate president of Venezuela.
Pompeo named one by one the countries that obeyed to Washington's orders: “We applaud Austria, Belgium, Croatia, Czech Rep., Denmark, Estonia, Finland, France, Germany, Iceland, Latvia, Lithuania, Luxembourg, Macedonia, Netherlands, Poland, Portugal, Spain, Sweden & UK for supporting Venezuelan people by recognizing @jguaido today as Interim President.
And then he placed a map, colouring the obeyed countries and the US with the same intense color.
We applaud Austria, Belgium, Croatia, Czech Rep., Denmark, Estonia, Finland, France, Germany, Iceland, Latvi…

#HandsOffVenezuela: Brave Italians show us the path of resistance against the European branch of the neoliberal beast

globinfo freexchange
According to RT, Italy vetoed EU recognition of Venezuelan opposition leader Guaido. As RT reported:
Rome has effectively derailed an EU statement meant to recognize Juan Guaido as Venezuela’s interim leader if President Nicolas Maduro fails to set up snap elections, a Five Star Movement source confirmed to RT.
Italy announced the veto at an informal meeting of EU foreign ministers that started on January 31 in Romania, the source said. The statement, which was supposed to be delivered by EU foreign affairs chief Federica Mogherini recognized Guaido as interim president if snap elections were not held.
The European Parliament is the first European body to recognize Guaido “as the only legitimate interim president of the country until new free, transparent and credible presidential elections can be called in order to restore democracy.
The parliament urged the EU to follow suit but the effort stalled due to internal discord.…

Government shutdown, Venezuela: Donald Trump evolves into the best propagator of neoliberal fascism that tends to become a norm

by system failure
Even before the 2016 US presidential election, this blog supported that Donald Trump is a pure sample of neoliberal barbarism. Many almost laughed at this perception because Trump was being already promoted, more or less, as the 'terminator' of the neoliberal establishment. And many people, especially in the US, tired from the economic disasters, the growing inequality and the endless wars, were anxious to believe that this was indeed his special mission.
Right after the elections, we supported that the US establishment gave a brilliant performance by putting its reserve, Donald Trump, in power, against the only candidate that the same establishment identified as a real threat: Bernie Sanders.
Then, Trump sent the first shock wave to his supporters by literally hiring the Goldman Sachs banksters to run the economy. And right after that, he signed for more deregulation in favor of the Wall Street mafia that ruined the economy in 2008.
In 2017, Trump bombed Syria f…

Mass protests in Haiti, like France’s Yellow Vests, threaten modern oligarchic structure

Throughout recent Latin American history, it is hard to find a country that has been as thoroughly manipulated and plundered by the United States as Haiti has.
After over a century of U.S. intervention — from the 19-year-long U.S. military occupation that began in 1915 to the 2010 election rigged by the Hillary Clinton-run State Department — Haiti has become the ultimate neoliberal experiment that has forced its people to live in conditions so horrible that rivers of sewage often run through the city streets.
Even Haiti’s own president, Jovenel Moise — who has presided over the most recent phase of U.S.-backed plunder — recently called the entire country a “latrine.”
Yet — much as in 1791, when Haiti was the site of the first successful slave revolt in the Americas — today the people of Haiti seem to have finally had enough of being slaves in all but name and are taking to the streets en masse in an effort to end the rule of the Haitian Bald-Headed Party (PHTK), the U.S.-backed politica…

EU parliament drops final leaf, recognizes Washington's puppet Juan Guaido in Venezuela

globinfo freexchange
The European branch of the global neoliberal fascism did what was expected: obey to the orders of the US imperialist empire and recognize Washington's puppet Juan Guaido as the 'legitimate' president of Venezuela.
As Al Jazeera reported:
The European Parliament has recognised Venezuela's self-declared interim president Juan Guaido as de facto head of state, heightening international pressure on the OPEC member's socialist President Nicolas Maduro. EU politicians voted 429 in favour to 104 against, with 88 abstentions, at a special session in Brussels on Thursday to recognise Guaido as interim leader.
Meanwhile, the EU parliament wouldn't even think to 'dare' to challenge the legitimacy of Emmanuel Macron in France, even with all these people protesting in the streets. At the same time, the establishment media try to direct the public attention from the Yellow Vest movement towards the situation in Venezuela.
It doesn't matter that N…