CIA 'Angelfire' covert Windows malware system(wikileaks.org)
wikileaks.org
CIA 'Angelfire' covert Windows malware system
https://wikileaks.org/vault7/#Angelfire
80 コメント
I think you're too focused on the technical side of things. If your target can be breached with an intern's hobby projects, why not breach your target with an interns hobby project?
That means you have more money to spend on analyst, translators, future operations, etc. You only start developing more capabilities if your targets need more capabilities.
Many important targets today are still being breached by a bunch of office macro's that have been around for ages. Still works, still yields desired results, no need for a passive global adversary or a l33t 0day.
That means you have more money to spend on analyst, translators, future operations, etc. You only start developing more capabilities if your targets need more capabilities.
Many important targets today are still being breached by a bunch of office macro's that have been around for ages. Still works, still yields desired results, no need for a passive global adversary or a l33t 0day.
You're getting concepts mixed up. These aren't exploits. You can't breach a target with them. They're post-exploit persistence tools. A persistence tool has just three jobs:
1. Enable the mission.
2. Avoid discovery.
3. Frustrate attribution.
These tools are amateurish. By modern standards, all they accomplish is (1). But rootkit.tar.Z for SunOS 4.1.3 did that too.
Presumably, if the CIA is implanting backdoors, they're doing it in high-stakes situations: the kind where it's important they not be identified, and the kind where it's important that identification of a single compromised machine not instantaneously provide a signature that can be used to identify every other compromised host in their inventory. But, nope.
One obvious possible subtextual revelation from the CIA tool kit that we've seen is that they're not doing high-stakes implantation work at all, and this stuff is all aspirational.
1. Enable the mission.
2. Avoid discovery.
3. Frustrate attribution.
These tools are amateurish. By modern standards, all they accomplish is (1). But rootkit.tar.Z for SunOS 4.1.3 did that too.
Presumably, if the CIA is implanting backdoors, they're doing it in high-stakes situations: the kind where it's important they not be identified, and the kind where it's important that identification of a single compromised machine not instantaneously provide a signature that can be used to identify every other compromised host in their inventory. But, nope.
One obvious possible subtextual revelation from the CIA tool kit that we've seen is that they're not doing high-stakes implantation work at all, and this stuff is all aspirational.
What is the possibility that this was a deliberate leak meant to obfuscate the true state of the art of what the CIA uses? Would that be too much of the trap of "hyper-competence" or the kind of thing you'd hope-for/expect-from an intelligence service?
True, keeping your enemies in the dark about your true capabilities is a useful strategy (unless it is a doomsday device, then you should tell the world). Strategic leaks of misinformation is one way to go about it.
Also low-quality exploits could be made on purpose to be intentionally found. The victim finds it and then thinks they are in the clear, while the a more sophisticated real exploit is lurking undetected.
Also low-quality exploits could be made on purpose to be intentionally found. The victim finds it and then thinks they are in the clear, while the a more sophisticated real exploit is lurking undetected.
The only kind of people the government can attract are buffoons that can't be successful elsewhere.
If you're the CIA/NSA don't you want to use this kind of low level stuff most of the time because it blends in with the background malware? If it's discovered which it may almost certainly be at some point there's little to point at and say "this is malware created by a nation state" vs "this is malware made by a bored teenager".
Seems like a positive advantage?
Seems like a positive advantage?
Seems like the difference of assassination by hit-and-run/"robbery gone wrong" vs polonium. One screams "state actor", the other is almost entirely deniable..
FWIW its worth, a lot governments occasionally use off the shelf commerical spytech like cheap hidden camera from Ebay exactly fkr deniability purposes.
> Wikileaks is still milking a drip-drip from the original cache they obtained of CIA warez. It's cynical, and speaks to a general contempt they have of their audience.
Snowden did the same and it pisses me off. But then again, wikileaks learned from the cablegate: releasing tons of information will lead to people disregarding most of it.
Snowden did the same and it pisses me off. But then again, wikileaks learned from the cablegate: releasing tons of information will lead to people disregarding most of it.
Did Snowden do that, or did the press do that to string it along. My recollection (could be flawed) said that he turned over all of the data he had, and then the newsies teased it out to keep it around as long as possible. Whether that was to help sales or from preventing an overload, doesn't matter. To me it wasn't Snowden that did it that way.
It was up to the journalists. According to the interview Glenn Greenwald did on "Pod Save the World", Snowden gave the journalists a giant dump of documents and they had to go through them to determine what was newsworthy. Snowden also insisted that the journalists give the NSA a chance to ask for documents to be redacted/kept secret and explain why. Again, according to the interview, Snowden explicitly did not want a wikileaks-style dump of everything, all at one or drip-drip-drip.
What's happening with the Snowden leaks? Havent heard anything in a long time.
Calling it "contempt" is unsupported. Patronizing, condescending, sermonizing - sure.
If we weren't told by first principles in 2000 that all Internet traffic was being surveilled, then Mark Klein certainly did in 2006. And yet the masses continued blissfully adopting webcrapps and other negligently-designed communications systems... until 2013 when Snowden came along with banal "revelations", that were doled out slowly enough to survive the media's short attention span.
I'd love it if there were enough whistleblowers that we did get a new leak from the surveillance-industrial complex every week. And this news item, in the technical context, is utterly boring. But it's a bit disingenuous to condemn a news organization for behavior that every other news org does, likely because you disagree with their politics.
If we weren't told by first principles in 2000 that all Internet traffic was being surveilled, then Mark Klein certainly did in 2006. And yet the masses continued blissfully adopting webcrapps and other negligently-designed communications systems... until 2013 when Snowden came along with banal "revelations", that were doled out slowly enough to survive the media's short attention span.
I'd love it if there were enough whistleblowers that we did get a new leak from the surveillance-industrial complex every week. And this news item, in the technical context, is utterly boring. But it's a bit disingenuous to condemn a news organization for behavior that every other news org does, likely because you disagree with their politics.
We've shared enough threads that I think you can predict my response to this. I find it aggravating when people suggest that our understanding of dragnet Internet surveillance is new, and that it came from leaks. The NSA's access to online communication was understood as a ground truth in the 1990s. You can read the first edition of Applied Cryptography to see it.
If anything, the last 10 years have diminished my respect for SIGINT capabilities.
A thing I think people lose sight of when trying to put this stuff in historical perspective is that in the 1990s it was not only possible but actually sort of routine for entire ISPs to be owned up. There were instances of solsniff.c getting access to backbone traffic. None of it was encrypted. Internet surveillance in the 1990s wasn't hypothetical. Clueful people's homedirs would get traded in the "underground" and they'd be tarballs full of .pgp files, because everyone knew they were going to get owned up somehow.
If anything, the last 10 years have diminished my respect for SIGINT capabilities.
A thing I think people lose sight of when trying to put this stuff in historical perspective is that in the 1990s it was not only possible but actually sort of routine for entire ISPs to be owned up. There were instances of solsniff.c getting access to backbone traffic. None of it was encrypted. Internet surveillance in the 1990s wasn't hypothetical. Clueful people's homedirs would get traded in the "underground" and they'd be tarballs full of .pgp files, because everyone knew they were going to get owned up somehow.
It depends what you mean by "our" understanding. If the "our" refers to us paranoid computer professionals, then I completely agree with your characterization. If the "our" refers to society at large, then I do think there was a sea change with Snowden.
Furthermore, there is a distinction between understanding how vulnerable everything is, and believing that the modus operandi of government institutions is actually that of an attacker (and furthermore, the societal effects when that belief becomes widespread. But I digress).
The only point I was picking on is your characterization of Wikileaks's approach to audience-impedance-mismatch as "contempt". Contempt of the lagging-understanders isn't outright wrong - I can try it on myself, but dwelling on having contempt for say everyone using gmail wouldn't be healthy or productive. But it's certainly not charitable to ascribe to others, which is why I said it comes down to pure political disagreement.
Furthermore, there is a distinction between understanding how vulnerable everything is, and believing that the modus operandi of government institutions is actually that of an attacker (and furthermore, the societal effects when that belief becomes widespread. But I digress).
The only point I was picking on is your characterization of Wikileaks's approach to audience-impedance-mismatch as "contempt". Contempt of the lagging-understanders isn't outright wrong - I can try it on myself, but dwelling on having contempt for say everyone using gmail wouldn't be healthy or productive. But it's certainly not charitable to ascribe to others, which is why I said it comes down to pure political disagreement.
I think you're trying to sell a fish when really all you have is a horse.
Wikileaks isn't contemptuous of its audience; its contemptuous of an ignorant public who have allowed their state to be infiltrated and usurped for the purposes of allowing special interests control over the technological prowess of 5 nation states. And in my opinion, that contempt is quite well targeted - because, just as you have demonstrated, its all very easy to dismiss these incursions into our basic human rights as being 'necessary' or 'so easy even kids can do it, therefore its acceptable', or so on.
The fish is dead. The horse, not so.
Wikileaks isn't contemptuous of its audience; its contemptuous of an ignorant public who have allowed their state to be infiltrated and usurped for the purposes of allowing special interests control over the technological prowess of 5 nation states. And in my opinion, that contempt is quite well targeted - because, just as you have demonstrated, its all very easy to dismiss these incursions into our basic human rights as being 'necessary' or 'so easy even kids can do it, therefore its acceptable', or so on.
The fish is dead. The horse, not so.
I doubt that teenagers exhibit this level of operational capability. I wouldn't even call commercial red teaming software (cobalt strike) up to par.
Can you give us an example of tech at the very high end level?
Can you give us an example of tech at the very high end level?
>And yet, despite the extraordinarily low stakes of publishing, Wikileaks is still milking a drip-drip from the original cache they obtained of CIA warez. It's cynical, and speaks to a general contempt they have of their audience.
They're trying to do their due diligence and make sure evety thing they release is fixed already. Given the likely size of things to go through and many companies refusing to interact with Wikileaks, preparation for a release is likely a long process.
They're trying to do their due diligence and make sure evety thing they release is fixed already. Given the likely size of things to go through and many companies refusing to interact with Wikileaks, preparation for a release is likely a long process.
interestingly, the NSA ANT catalog from a few years ago[1] had a few things that actually were explicitly intern projects: the one i specifically recall was backdoored hard disk firmware
[1] https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_...
[1] https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_...
Comes with the territory I think. Working in an environment of complete secrecy does not help you create new or unique things. I can only imagine how unpleasant it would be to work in such an environment. You probably wouldn't be allowed to talk to your coworkers about what you are doing, much less someone outside the organization.
No, not really: NSA has the same constraints, and does much more interesting work.
I think NSA's quality problem comes from the fact that a lot of its raw technical output comes from people that are effectively working in their first real programming jobs.
I think NSA's quality problem comes from the fact that a lot of its raw technical output comes from people that are effectively working in their first real programming jobs.
Cynicism is the norm in international relations. I am certain that some of the major leaks such as cablegate were allowed to happen in order to define the foreign policy posture and reach of the US government while maintaining diplomatic niceties.
WL has been known to leave things out of leaks. It wouldn't surprise me if they only dumped the more embarrassing tools.
jesus christ. the damage our own government has done to microsoft is just insane. if i was a shareholder I would be so pissed.
big companies go along with this behavior and collude with the government, but if this has a big enough effect on the bottom line, then it will happen less.
big companies go along with this behavior and collude with the government, but if this has a big enough effect on the bottom line, then it will happen less.
You must see it in a broader context. I'll paraphrase you:
"jesus christ. the damage our own government has done to [Iraq, Syria, Libya, North Korea, Vietnam, Serbia, Afghanistan...] is just insane. if i was a [citizen of these countries] I would be so pissed."
At least, the shareholder has his life and his property (sans the missed opportunity due to "the damage our own government has done to microsoft").
"jesus christ. the damage our own government has done to [Iraq, Syria, Libya, North Korea, Vietnam, Serbia, Afghanistan...] is just insane. if i was a [citizen of these countries] I would be so pissed."
At least, the shareholder has his life and his property (sans the missed opportunity due to "the damage our own government has done to microsoft").
i agree with you completely, but it seems irrelevant to this particular conversation.
Is it really that simple? Didn't a cache of hacking tools recently end up in hackers' hands?
> if i was a shareholder I would be so pissed.
I doubt shareholders are pissed considering the stock has grown 500% since 2009 while paying decent dividends.
> big companies go along with this behavior and collude with the government
Isn't that called mercantilism?
> big companies go along with this behavior and collude with the government, but if this has a big enough effect on the bottom line, then it will happen less.
It hasn't affected their bottom line yet.
It is concerning how intertwined large corporations are with government.
I doubt shareholders are pissed considering the stock has grown 500% since 2009 while paying decent dividends.
> big companies go along with this behavior and collude with the government
Isn't that called mercantilism?
> big companies go along with this behavior and collude with the government, but if this has a big enough effect on the bottom line, then it will happen less.
It hasn't affected their bottom line yet.
It is concerning how intertwined large corporations are with government.
> I doubt shareholders are pissed considering the stock has grown 500% since 2009 while paying decent dividends.
> It hasn't affected their bottom line yet.
it's unknowable what the bottom line or stock price would be with different circumstances, but there is no question that security disclosures like this are a downward pressure on it.
who knows; maybe they did get an even bigger lift from the collusion.
the only way it will change is if consumers start pricing in this kind of behavior (paying less for compromised products).
it's too bad that's such an unlikely goal.
> It hasn't affected their bottom line yet.
it's unknowable what the bottom line or stock price would be with different circumstances, but there is no question that security disclosures like this are a downward pressure on it.
who knows; maybe they did get an even bigger lift from the collusion.
the only way it will change is if consumers start pricing in this kind of behavior (paying less for compromised products).
it's too bad that's such an unlikely goal.
It seems strange to blame the government -- couldn't you see this as self-inflicted damage from creating an insecure OS that runs a vast number of important computers?
I actually blame both, but it's not like MS is an innocent victim here -- there's a lot more they could have done on security, and didn't because it was expensive. If that choice being exploited costs them money, how is that anything but an effect of their own choices?
I actually blame both, but it's not like MS is an innocent victim here -- there's a lot more they could have done on security, and didn't because it was expensive. If that choice being exploited costs them money, how is that anything but an effect of their own choices?
Microsoft has been investing a lot of effort into security. If they had it their way, you wouldn't even be able to install unverified software.
I'm not sure Microsoft has been making the bad "security is expensive" decisions since XP sp2. Note also that they've been ahead of the curve on security since Vista, which was much maligned (partially) as a result. Nowadays both macOS and windows effectively have UAC, but Vista took the heat for it. Same thing with blocking unknown software; Windows took the heat, but just you try to run non-Apple-signed packages on OS x.
I'm not sure Microsoft has been making the bad "security is expensive" decisions since XP sp2. Note also that they've been ahead of the curve on security since Vista, which was much maligned (partially) as a result. Nowadays both macOS and windows effectively have UAC, but Vista took the heat for it. Same thing with blocking unknown software; Windows took the heat, but just you try to run non-Apple-signed packages on OS x.
Does UAC and signing belong to the same bucket though? UAC has always been on macOS 10 because of the bsd root/user separation. For me the main problem is that on windows (Vista at least) the UAC seemed to fire on benign operations while letting you do quite dangerous ones without flinching.
Its true that there are holes and that UAC isn't a particularly strong security barrier (i.e. If an attacker is at the keyboard it won't do shit). But that's the same for OS x and they have some even worse patterns; e.g. I'm pretty sure half the installers I end up using take your password themselves and pass it on to some waiting sudo under the hood. They at the very least don't use the proper system way of doing things; i can tell because some things trigger touch id and some don't. Similarly, there have been many stories about dropbox circumventing system security. I have no doubt that if dropbox can figure it out, malware writers can, too.
Based on the plethora of methods Microsoft has (intentionally) provided to bypass UAC I'd argue that it's the very definition of "security theater". UAC is nothing but a minor annoyance to attackers at this point. An extra step or two they have to add to their payload. Nothing more.
It's also trivial to escalate from a regular user to NT AUTHORITY\SYSTEM (which is a higher privilege than Administrator!). There's so many privilege escalation vulnerabilities in Windows it's hard to keep track of them all! A big reason for that is that Microsoft considers privilege escalation vulnerabilities, "medium risk".
It's also trivial to escalate from a regular user to NT AUTHORITY\SYSTEM (which is a higher privilege than Administrator!). There's so many privilege escalation vulnerabilities in Windows it's hard to keep track of them all! A big reason for that is that Microsoft considers privilege escalation vulnerabilities, "medium risk".
I just read the summary, but it sounds like this is a set of tools you use after compromising a system. (It starts at modifying the MBR.) If that's the case it has as much to do with the security of the OS as it does with the physical security of the building where the computer is sitting.
> there's a lot more they could have done on security, and didn't because it was expensive.
Well, yes, this is technically true. But it's technically true because there's an infinite amount of work you can do on security. Microsoft could have hired every person on the planet who's good at verifiable systems, or could be trained to be good at it, and rewritten the entirety of Windows as provably correct code (a la seL4), taking many years and lots of money. Microsoft could have hired every cryptographer or everyone who could be good at cryptography and developed digital signature algorithms that are far better than the current state of the art. (Remember that it's been proven that the US government, or someone with aligned political goals and roughly equivalent capabilities, used a previously-unknown attack on MD5 to spoof a Windows Update certificate to Iranian nuclear reactors, and it's not like newer hashes are impossible to collide, just harder.) No matter how much time and effort you spend on security, there's always more you can spend.
The engineering decision in security is how to spend enough money to outpace your attackers, but also successfully ship a product.
If your own government is becoming one of the attackers and therefore increasing the cost it takes to stay ahead of your best attacker, to the point where shipping a product becomes unprofitable, that's not a sign that you should have been there anyway, that's a sign that your government should get out of the business of being an attacker.
Well, yes, this is technically true. But it's technically true because there's an infinite amount of work you can do on security. Microsoft could have hired every person on the planet who's good at verifiable systems, or could be trained to be good at it, and rewritten the entirety of Windows as provably correct code (a la seL4), taking many years and lots of money. Microsoft could have hired every cryptographer or everyone who could be good at cryptography and developed digital signature algorithms that are far better than the current state of the art. (Remember that it's been proven that the US government, or someone with aligned political goals and roughly equivalent capabilities, used a previously-unknown attack on MD5 to spoof a Windows Update certificate to Iranian nuclear reactors, and it's not like newer hashes are impossible to collide, just harder.) No matter how much time and effort you spend on security, there's always more you can spend.
The engineering decision in security is how to spend enough money to outpace your attackers, but also successfully ship a product.
If your own government is becoming one of the attackers and therefore increasing the cost it takes to stay ahead of your best attacker, to the point where shipping a product becomes unprofitable, that's not a sign that you should have been there anyway, that's a sign that your government should get out of the business of being an attacker.
They never see it that way. The ones doing it always have a solid propaganda / brainwashing framework to support these kind of actions. Heck they justify running a drone assassination program rationalizing exploiting some windows vulnerabilities is child's play for them.
"We are fighting the evils of terrorism" / "It's their fault for releasing software full of these holes" / "It's the target's fault for installing this OS" pretty easy to rationalize this stuff.
And I think you are implicitly asking them to think "one day this will leak and will damage the reputation of a major US company" and they probably are not allowed to think that way it's more down the line "we'll just keep it hidden and nobody will ever find out, we are the best at this and not like those other agencies whose stuff has been leaked"
"We are fighting the evils of terrorism" / "It's their fault for releasing software full of these holes" / "It's the target's fault for installing this OS" pretty easy to rationalize this stuff.
And I think you are implicitly asking them to think "one day this will leak and will damage the reputation of a major US company" and they probably are not allowed to think that way it's more down the line "we'll just keep it hidden and nobody will ever find out, we are the best at this and not like those other agencies whose stuff has been leaked"
I don't think developing a malware kit for Windows damages Microsoft's reputation materially. I mean, it's just a fancier RAT, isn't it?
The CIA's job is to spy on people. Planting bugs is part of their job. If they didn't plant bugs in computer systems too, what are they being paid for?
I mean, you can argue that their entire charter should be rearranged or abolished, but it's hard to blame them when "sneaking into places they're not wanted and exfiltrating data" is kind of their entire reason for existing.
(the drone program is a whole other kettle of fish)
The CIA's job is to spy on people. Planting bugs is part of their job. If they didn't plant bugs in computer systems too, what are they being paid for?
I mean, you can argue that their entire charter should be rearranged or abolished, but it's hard to blame them when "sneaking into places they're not wanted and exfiltrating data" is kind of their entire reason for existing.
(the drone program is a whole other kettle of fish)
NSA -> Microsoft is a revolving door of employment.
EDIT: Apple, Google, etc as well.
EDIT: Apple, Google, etc as well.
Is this the governments fault for finding the exploits or microsoft's for inadequate testing?
These aren't even exploits. This is just normal OS functionality. There is no security flaw here.
It's meant for post-compromise use. You need admin rights before you can use it.
It's meant for post-compromise use. You need admin rights before you can use it.
The issue is not finding the exploits, but exploiting the exploits.
Why not both?
I seriously doubt it is anything but a quid pro quo arrangement.
Why? What would the CIA/NSA gain by telling Microsoft what they're doing? It's not like it's impossible to find serious security flaws without colluding, independent researchers do it all the time. It seems like asking for a quid pro quo would open up a huge risk of discovery without very much gain.
Why would it be a quid pro quo? A government-hackable system allows intelligence services to 'keep the country safe' by helping data gathering (remember the arguments put forth during the iPhone/FBI kerfuffle). So governments support them through the means at their disposal, funding, govt contracts, State dept deals etc. The company gains because they shift product. Win-win.
I'm not sure what the CIA/NSA would gain by explaining their tactics, I don't understand why they would ever do that. IMO it is a non-sequitor to my comment.
I'm not sure what the CIA/NSA would gain by explaining their tactics, I don't understand why they would ever do that. IMO it is a non-sequitor to my comment.
Is the WikiLeaks site not responding to requests?
It loaded for me. Here's the text of the post:
------
Angelfire 31 August, 2017
Today, August 31st 2017, WikiLeaks publishes documents from the Angelfire project of the CIA. Angelfire is an implant comprised of five components: Solartime, Wolfcreek, Keystone (previously MagicWand), BadMFS, and the Windows Transitory File system. Like previously published CIA projects (Grasshopper[1] and AfterMidnight[2]) in the Vault7[3] series[4], it is a persistent framework that can load and execute custom implants on target computers running the Microsoft Windows operating system (XP or Win7).
Solartime modifies the partition boot sector so that when Windows loads boot time device drivers, it also loads and executes the Wolfcreek implant, that once executed, can load and run other Angelfire implants. According to the documents, the loading of additional implants creates memory leaks that can be possibly detected on infected machines.
Keystone is part of the Wolfcreek implant and responsible for starting malicious user applications. Loaded implants never touch the file system, so there is very little forensic evidence that the process was ever ran. It always disguises as "C:\Windows\system32\svchost.exe" and can thus be detected in the Windows task manager, if the operating system is installed on another partition or in a different path.
BadMFS is a library that implements a covert file system that is created at the end of the active partition (or in a file on disk in later versions). It is used to store all drivers and implants that Wolfcreek will start. All files are both encrypted and obfuscated to avoid string or PE header scanning. Some versions of BadMFS can be detected because the reference to the covert file system is stored in a file named "zf".
The Windows Transitory File system is the new method of installing AngelFire. Rather than lay independent components on disk, the system allows an operator to create transitory files for specific actions including installation, adding files to AngelFire, removing files from AngelFire, etc. Transitory files are added to the 'UserInstallApp'.
[1]: https://wikileaks.org/vault7/grasshopper/
[2]: https://wikileaks.org/vault7/#AfterMidnight
[3]: https://wikileaks.org/ciav7p1/
[4]: https://wikileaks.org/vault7/#
------
And here are the documents linked beside the post:
Angelfire 2.0 -- User Guide: https://wikileaks.org/vault7/document/Angelfire-2_0-UserGuid...
BadMFS -- Developer Guide: https://wikileaks.org/vault7/document/BadMFS_Developer_Guide...
Wolfcreek Docs -- Angelfire User Guide: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Angelfi...
Wolfcreek Docs -- Angelfire Test Matrix: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Angelfi...
Wolfcreek Docs -- NotesSee more: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Notes/
------
Angelfire 31 August, 2017
Today, August 31st 2017, WikiLeaks publishes documents from the Angelfire project of the CIA. Angelfire is an implant comprised of five components: Solartime, Wolfcreek, Keystone (previously MagicWand), BadMFS, and the Windows Transitory File system. Like previously published CIA projects (Grasshopper[1] and AfterMidnight[2]) in the Vault7[3] series[4], it is a persistent framework that can load and execute custom implants on target computers running the Microsoft Windows operating system (XP or Win7).
Solartime modifies the partition boot sector so that when Windows loads boot time device drivers, it also loads and executes the Wolfcreek implant, that once executed, can load and run other Angelfire implants. According to the documents, the loading of additional implants creates memory leaks that can be possibly detected on infected machines.
Keystone is part of the Wolfcreek implant and responsible for starting malicious user applications. Loaded implants never touch the file system, so there is very little forensic evidence that the process was ever ran. It always disguises as "C:\Windows\system32\svchost.exe" and can thus be detected in the Windows task manager, if the operating system is installed on another partition or in a different path.
BadMFS is a library that implements a covert file system that is created at the end of the active partition (or in a file on disk in later versions). It is used to store all drivers and implants that Wolfcreek will start. All files are both encrypted and obfuscated to avoid string or PE header scanning. Some versions of BadMFS can be detected because the reference to the covert file system is stored in a file named "zf".
The Windows Transitory File system is the new method of installing AngelFire. Rather than lay independent components on disk, the system allows an operator to create transitory files for specific actions including installation, adding files to AngelFire, removing files from AngelFire, etc. Transitory files are added to the 'UserInstallApp'.
[1]: https://wikileaks.org/vault7/grasshopper/
[2]: https://wikileaks.org/vault7/#AfterMidnight
[3]: https://wikileaks.org/ciav7p1/
[4]: https://wikileaks.org/vault7/#
------
And here are the documents linked beside the post:
Angelfire 2.0 -- User Guide: https://wikileaks.org/vault7/document/Angelfire-2_0-UserGuid...
BadMFS -- Developer Guide: https://wikileaks.org/vault7/document/BadMFS_Developer_Guide...
Wolfcreek Docs -- Angelfire User Guide: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Angelfi...
Wolfcreek Docs -- Angelfire Test Matrix: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Angelfi...
Wolfcreek Docs -- NotesSee more: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Notes/
> It always disguises as "C:\Windows\system32\svchost.exe"
If I ever meet the manager who decided bundling half the services in the OS into svchost was a good idea, I'll give him a piece of my mind. I've lost more hours to that (both cleaning malware and troubleshooting performance or crashes) than anything else on Windows since the 9x days.
If I ever meet the manager who decided bundling half the services in the OS into svchost was a good idea, I'll give him a piece of my mind. I've lost more hours to that (both cleaning malware and troubleshooting performance or crashes) than anything else on Windows since the 9x days.
Seems like a kneejerk reaction.
The reason services are bundled into SVCHOST is that it offers reduced memory footprint and lower startup costs, which is still significant on resource constrained systems (which Windows embedded still targets)[0].
If malware didn't copycat SVCHOST they would just copycat one of a dozen other common Windows processes like conhst, dllhost, csrss, etc.
As an aside, in Task Manager if you go to the details tab, select columns, command line. You'll see exactly what each instance of SVCHOST is running. Process Explorer gives you even more information than that.
Process Explorer allows you to turn on Digital Signature checking. Run it as administrator. Select Columns -> Verified Signer. Options -> Verify Image Signatures. But also check your CA store to make sure no custom CA has been injected into the OS.
[0] https://blogs.msdn.microsoft.com/oldnewthing/20030918-00/?p=...
The reason services are bundled into SVCHOST is that it offers reduced memory footprint and lower startup costs, which is still significant on resource constrained systems (which Windows embedded still targets)[0].
If malware didn't copycat SVCHOST they would just copycat one of a dozen other common Windows processes like conhst, dllhost, csrss, etc.
As an aside, in Task Manager if you go to the details tab, select columns, command line. You'll see exactly what each instance of SVCHOST is running. Process Explorer gives you even more information than that.
Process Explorer allows you to turn on Digital Signature checking. Run it as administrator. Select Columns -> Verified Signer. Options -> Verify Image Signatures. But also check your CA store to make sure no custom CA has been injected into the OS.
[0] https://blogs.msdn.microsoft.com/oldnewthing/20030918-00/?p=...
Now that there are nice tools like Process Explorer, it's less of an issue. Back in the day, you'd pull your hair out.
Even so, the original premise of performance doesn't hold water to me. I load a process that has 10 services inside so I can use two of them, and that's somehow reduced memory compared to just running the two, just in case I want to run the other 8 later? Some of those services I have disabled and never want to run. It's still taking up the memory.
Even so, the original premise of performance doesn't hold water to me. I load a process that has 10 services inside so I can use two of them, and that's somehow reduced memory compared to just running the two, just in case I want to run the other 8 later? Some of those services I have disabled and never want to run. It's still taking up the memory.
Still, if MS is going to do it, then the onus seems to be on them to surface it in built-in tools.
My work doubled down on that idea, and half of our software is packaged into the same JAR and run subsystems through CLI flags.
So you just see "C:\...\app.jar" unless you dig into the flag halfway through to see it's "--widget-1" and not "--widget-2".
So you just see "C:\...\app.jar" unless you dig into the flag halfway through to see it's "--widget-1" and not "--widget-2".
I'm getting dns lookup failure.
Did they piss someone off too much this time?
Did they piss someone off too much this time?
Fallout from this perhaps? Their DNS got hacked today or yesterday, report's a bit vague.
https://www.theguardian.com/technology/2017/aug/31/wikileaks...
https://www.theguardian.com/technology/2017/aug/31/wikileaks...
I can't connect with my mobile (3G/4G) connection but can connect with my fixed line (VDSL) connection. Interesting...
Had to update https://www.npmjs.com/package/nsaname again. It never stops...
Why? Was one of the Angelfire names used on the NPM usage examples?
No. I added the new names.
WikiLeaks was taken down by hackers last night
DNS was hijacked, that's it.
Except I believe people were still showing a successful HTTPS connection, were they not?
Up again/resolves fine for me now (Norway).
gressquel(1)
Gonna guess Sovereign U.S. forces on this one.
I wonder what political news story this is trying to take attention away from...
I don't understand what you are implying here. Would you kindly tell us which political news story are those pesky russian hackers at wikileaks trying to cover up?
Discussion from last: https://news.ycombinator.com/item?id=14920664
What's the point of saying 'Wikileaks is trying to distract us from happenings in Russia' when you are not even specifying the things we are supposedly being distracted from?
If you are trying to proliferate the 'Wikileaks are Russian agents' mantra at least back this up with some facts and observations. Don't simply link to the circlejerk from previous thread - that's kind of lazy.
If you are trying to proliferate the 'Wikileaks are Russian agents' mantra at least back this up with some facts and observations. Don't simply link to the circlejerk from previous thread - that's kind of lazy.
>What's the point of saying 'Wikileaks is trying to distract us from happenings in Russia' when you are not even specifying the things we are supposedly being distracted from?
Am I required to have omniscient knowledge of the subject prior to commenting? You asked me what I was referring to, and I answered your question.
It has been painfully clear, with almost every release in recent history, that wikileaks uses releases as distractions to take the spotlight away from other stories. That's why it's worth bringing this up on every post.
Just because wikileaks wants the story to be about the release, doesn't mean that's where the real story is. I'm curious as to what the real story is. I do not know the answer to that question, hence my initial comment.
Am I required to have omniscient knowledge of the subject prior to commenting? You asked me what I was referring to, and I answered your question.
It has been painfully clear, with almost every release in recent history, that wikileaks uses releases as distractions to take the spotlight away from other stories. That's why it's worth bringing this up on every post.
Just because wikileaks wants the story to be about the release, doesn't mean that's where the real story is. I'm curious as to what the real story is. I do not know the answer to that question, hence my initial comment.
Can someonebody please help me understand what this is? Is it software which Microsoft has included in Windows maliciously for such exploitation, or is it the fact that the CIA has identified a Windows exploit and taken advantage of it?
Did Microsoft know that this problem existed, and continued to let it exist at the CIA's request?
Did Microsoft know that this problem existed, and continued to let it exist at the CIA's request?
Neither. This was not written by Microsoft. This is not an exploit. Further, you never "identify an exploit" - you identify a vulnerability, and the exploit is what you build to take advantage of that vulnerability.
This is software that has been written by presumably US govt to be installed on a windows machine to maintain control if it once they've compromised it. Think "really advanced malware". It is supposed to be hard to detect and/or remove, and allows long term access to that machine.
Edit: hopefully that helps clear up. Also your line of questioning seems to suspect Microsoft colluding with the govt. zero evidence of that.
This is software that has been written by presumably US govt to be installed on a windows machine to maintain control if it once they've compromised it. Think "really advanced malware". It is supposed to be hard to detect and/or remove, and allows long term access to that machine.
Edit: hopefully that helps clear up. Also your line of questioning seems to suspect Microsoft colluding with the govt. zero evidence of that.
People continue to be enthralled by low-on-the-food-chain software security work. There are teenagers that have written stuff like this. It's sort of embarrassing that the CIA commissioned this at all (if that's how it happened), rather than pooling with NSA and getting a proper, reconfigurable, deniable tool built.
(But then: leaks of NSA tooling in the last 2 years have demonstrated that we've all been a bit generous regarding NSA's technical reputation, too).
Virtually everything that Wikileaks has published about the CIA has been like this. To the extent that it damages national security, it does so by making CIA look clownish. And yet, despite the extraordinarily low stakes of publishing, Wikileaks is still milking a drip-drip from the original cache they obtained of CIA warez. It's cynical, and speaks to a general contempt they have of their audience.