CIA 'Angelfire' covert Windows malware system
wikileaks.org
wikileaks.org
People continue to be enthralled by low-on-the-food-chain software security work. There are teenagers that have written stuff like this. It's sort of embarrassing that the CIA commissioned this at all (if that's how it happened), rather than pooling with NSA and getting a proper, reconfigurable, deniable tool built.
(But then: leaks of NSA tooling in the last 2 years have demonstrated that we've all been a bit generous regarding NSA's technical reputation, too).
Virtually everything that Wikileaks has published about the CIA has been like this. To the extent that it damages national security, it does so by making CIA look clownish. And yet, despite the extraordinarily low stakes of publishing, Wikileaks is still milking a drip-drip from the original cache they obtained of CIA warez. It's cynical, and speaks to a general contempt they have of their audience.
That means you have more money to spend on analyst, translators, future operations, etc. You only start developing more capabilities if your targets need more capabilities.
Many important targets today are still being breached by a bunch of office macro's that have been around for ages. Still works, still yields desired results, no need for a passive global adversary or a l33t 0day.
1. Enable the mission.
2. Avoid discovery.
3. Frustrate attribution.
These tools are amateurish. By modern standards, all they accomplish is (1). But rootkit.tar.Z for SunOS 4.1.3 did that too.
Presumably, if the CIA is implanting backdoors, they're doing it in high-stakes situations: the kind where it's important they not be identified, and the kind where it's important that identification of a single compromised machine not instantaneously provide a signature that can be used to identify every other compromised host in their inventory. But, nope.
One obvious possible subtextual revelation from the CIA tool kit that we've seen is that they're not doing high-stakes implantation work at all, and this stuff is all aspirational.
Also low-quality exploits could be made on purpose to be intentionally found. The victim finds it and then thinks they are in the clear, while the a more sophisticated real exploit is lurking undetected.
Seems like a positive advantage?
Snowden did the same and it pisses me off. But then again, wikileaks learned from the cablegate: releasing tons of information will lead to people disregarding most of it.
They're trying to do their due diligence and make sure evety thing they release is fixed already. Given the likely size of things to go through and many companies refusing to interact with Wikileaks, preparation for a release is likely a long process.
[1] https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_...
I think NSA's quality problem comes from the fact that a lot of its raw technical output comes from people that are effectively working in their first real programming jobs.
If we weren't told by first principles in 2000 that all Internet traffic was being surveilled, then Mark Klein certainly did in 2006. And yet the masses continued blissfully adopting webcrapps and other negligently-designed communications systems... until 2013 when Snowden came along with banal "revelations", that were doled out slowly enough to survive the media's short attention span.
I'd love it if there were enough whistleblowers that we did get a new leak from the surveillance-industrial complex every week. And this news item, in the technical context, is utterly boring. But it's a bit disingenuous to condemn a news organization for behavior that every other news org does, likely because you disagree with their politics.
If anything, the last 10 years have diminished my respect for SIGINT capabilities.
A thing I think people lose sight of when trying to put this stuff in historical perspective is that in the 1990s it was not only possible but actually sort of routine for entire ISPs to be owned up. There were instances of solsniff.c getting access to backbone traffic. None of it was encrypted. Internet surveillance in the 1990s wasn't hypothetical. Clueful people's homedirs would get traded in the "underground" and they'd be tarballs full of .pgp files, because everyone knew they were going to get owned up somehow.
Furthermore, there is a distinction between understanding how vulnerable everything is, and believing that the modus operandi of government institutions is actually that of an attacker (and furthermore, the societal effects when that belief becomes widespread. But I digress).
The only point I was picking on is your characterization of Wikileaks's approach to audience-impedance-mismatch as "contempt". Contempt of the lagging-understanders isn't outright wrong - I can try it on myself, but dwelling on having contempt for say everyone using gmail wouldn't be healthy or productive. But it's certainly not charitable to ascribe to others, which is why I said it comes down to pure political disagreement.
Can you give us an example of tech at the very high end level?
Wikileaks isn't contemptuous of its audience; its contemptuous of an ignorant public who have allowed their state to be infiltrated and usurped for the purposes of allowing special interests control over the technological prowess of 5 nation states. And in my opinion, that contempt is quite well targeted - because, just as you have demonstrated, its all very easy to dismiss these incursions into our basic human rights as being 'necessary' or 'so easy even kids can do it, therefore its acceptable', or so on.
The fish is dead. The horse, not so.
big companies go along with this behavior and collude with the government, but if this has a big enough effect on the bottom line, then it will happen less.
"jesus christ. the damage our own government has done to [Iraq, Syria, Libya, North Korea, Vietnam, Serbia, Afghanistan...] is just insane. if i was a [citizen of these countries] I would be so pissed."
At least, the shareholder has his life and his property (sans the missed opportunity due to "the damage our own government has done to microsoft").
I actually blame both, but it's not like MS is an innocent victim here -- there's a lot more they could have done on security, and didn't because it was expensive. If that choice being exploited costs them money, how is that anything but an effect of their own choices?
I'm not sure Microsoft has been making the bad "security is expensive" decisions since XP sp2. Note also that they've been ahead of the curve on security since Vista, which was much maligned (partially) as a result. Nowadays both macOS and windows effectively have UAC, but Vista took the heat for it. Same thing with blocking unknown software; Windows took the heat, but just you try to run non-Apple-signed packages on OS x.
It's also trivial to escalate from a regular user to NT AUTHORITY\SYSTEM (which is a higher privilege than Administrator!). There's so many privilege escalation vulnerabilities in Windows it's hard to keep track of them all! A big reason for that is that Microsoft considers privilege escalation vulnerabilities, "medium risk".
Well, yes, this is technically true. But it's technically true because there's an infinite amount of work you can do on security. Microsoft could have hired every person on the planet who's good at verifiable systems, or could be trained to be good at it, and rewritten the entirety of Windows as provably correct code (a la seL4), taking many years and lots of money. Microsoft could have hired every cryptographer or everyone who could be good at cryptography and developed digital signature algorithms that are far better than the current state of the art. (Remember that it's been proven that the US government, or someone with aligned political goals and roughly equivalent capabilities, used a previously-unknown attack on MD5 to spoof a Windows Update certificate to Iranian nuclear reactors, and it's not like newer hashes are impossible to collide, just harder.) No matter how much time and effort you spend on security, there's always more you can spend.
The engineering decision in security is how to spend enough money to outpace your attackers, but also successfully ship a product.
If your own government is becoming one of the attackers and therefore increasing the cost it takes to stay ahead of your best attacker, to the point where shipping a product becomes unprofitable, that's not a sign that you should have been there anyway, that's a sign that your government should get out of the business of being an attacker.
"We are fighting the evils of terrorism" / "It's their fault for releasing software full of these holes" / "It's the target's fault for installing this OS" pretty easy to rationalize this stuff.
And I think you are implicitly asking them to think "one day this will leak and will damage the reputation of a major US company" and they probably are not allowed to think that way it's more down the line "we'll just keep it hidden and nobody will ever find out, we are the best at this and not like those other agencies whose stuff has been leaked"
The CIA's job is to spy on people. Planting bugs is part of their job. If they didn't plant bugs in computer systems too, what are they being paid for?
I mean, you can argue that their entire charter should be rearranged or abolished, but it's hard to blame them when "sneaking into places they're not wanted and exfiltrating data" is kind of their entire reason for existing.
(the drone program is a whole other kettle of fish)
EDIT: Apple, Google, etc as well.
It's meant for post-compromise use. You need admin rights before you can use it.
I'm not sure what the CIA/NSA would gain by explaining their tactics, I don't understand why they would ever do that. IMO it is a non-sequitor to my comment.
I doubt shareholders are pissed considering the stock has grown 500% since 2009 while paying decent dividends.
> big companies go along with this behavior and collude with the government
Isn't that called mercantilism?
> big companies go along with this behavior and collude with the government, but if this has a big enough effect on the bottom line, then it will happen less.
It hasn't affected their bottom line yet.
It is concerning how intertwined large corporations are with government.
> It hasn't affected their bottom line yet.
it's unknowable what the bottom line or stock price would be with different circumstances, but there is no question that security disclosures like this are a downward pressure on it.
who knows; maybe they did get an even bigger lift from the collusion.
the only way it will change is if consumers start pricing in this kind of behavior (paying less for compromised products).
it's too bad that's such an unlikely goal.
Did they piss someone off too much this time?
https://www.theguardian.com/technology/2017/aug/31/wikileaks...
------
Angelfire 31 August, 2017
Today, August 31st 2017, WikiLeaks publishes documents from the Angelfire project of the CIA. Angelfire is an implant comprised of five components: Solartime, Wolfcreek, Keystone (previously MagicWand), BadMFS, and the Windows Transitory File system. Like previously published CIA projects (Grasshopper[1] and AfterMidnight[2]) in the Vault7[3] series[4], it is a persistent framework that can load and execute custom implants on target computers running the Microsoft Windows operating system (XP or Win7).
Solartime modifies the partition boot sector so that when Windows loads boot time device drivers, it also loads and executes the Wolfcreek implant, that once executed, can load and run other Angelfire implants. According to the documents, the loading of additional implants creates memory leaks that can be possibly detected on infected machines.
Keystone is part of the Wolfcreek implant and responsible for starting malicious user applications. Loaded implants never touch the file system, so there is very little forensic evidence that the process was ever ran. It always disguises as "C:\Windows\system32\svchost.exe" and can thus be detected in the Windows task manager, if the operating system is installed on another partition or in a different path.
BadMFS is a library that implements a covert file system that is created at the end of the active partition (or in a file on disk in later versions). It is used to store all drivers and implants that Wolfcreek will start. All files are both encrypted and obfuscated to avoid string or PE header scanning. Some versions of BadMFS can be detected because the reference to the covert file system is stored in a file named "zf".
The Windows Transitory File system is the new method of installing AngelFire. Rather than lay independent components on disk, the system allows an operator to create transitory files for specific actions including installation, adding files to AngelFire, removing files from AngelFire, etc. Transitory files are added to the 'UserInstallApp'.
[1]: https://wikileaks.org/vault7/grasshopper/
[2]: https://wikileaks.org/vault7/#AfterMidnight
[3]: https://wikileaks.org/ciav7p1/
[4]: https://wikileaks.org/vault7/#
------
And here are the documents linked beside the post:
Angelfire 2.0 -- User Guide: https://wikileaks.org/vault7/document/Angelfire-2_0-UserGuid...
BadMFS -- Developer Guide: https://wikileaks.org/vault7/document/BadMFS_Developer_Guide...
Wolfcreek Docs -- Angelfire User Guide: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Angelfi...
Wolfcreek Docs -- Angelfire Test Matrix: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Angelfi...
Wolfcreek Docs -- NotesSee more: https://wikileaks.org/vault7/document/Wolfcreek-Docs-Notes/
If I ever meet the manager who decided bundling half the services in the OS into svchost was a good idea, I'll give him a piece of my mind. I've lost more hours to that (both cleaning malware and troubleshooting performance or crashes) than anything else on Windows since the 9x days.
So you just see "C:\...\app.jar" unless you dig into the flag halfway through to see it's "--widget-1" and not "--widget-2".
The reason services are bundled into SVCHOST is that it offers reduced memory footprint and lower startup costs, which is still significant on resource constrained systems (which Windows embedded still targets)[0].
If malware didn't copycat SVCHOST they would just copycat one of a dozen other common Windows processes like conhst, dllhost, csrss, etc.
As an aside, in Task Manager if you go to the details tab, select columns, command line. You'll see exactly what each instance of SVCHOST is running. Process Explorer gives you even more information than that.
Process Explorer allows you to turn on Digital Signature checking. Run it as administrator. Select Columns -> Verified Signer. Options -> Verify Image Signatures. But also check your CA store to make sure no custom CA has been injected into the OS.
[0] https://blogs.msdn.microsoft.com/oldnewthing/20030918-00/?p=...
Even so, the original premise of performance doesn't hold water to me. I load a process that has 10 services inside so I can use two of them, and that's somehow reduced memory compared to just running the two, just in case I want to run the other 8 later? Some of those services I have disabled and never want to run. It's still taking up the memory.
Did Microsoft know that this problem existed, and continued to let it exist at the CIA's request?
This is software that has been written by presumably US govt to be installed on a windows machine to maintain control if it once they've compromised it. Think "really advanced malware". It is supposed to be hard to detect and/or remove, and allows long term access to that machine.
Edit: hopefully that helps clear up. Also your line of questioning seems to suspect Microsoft colluding with the govt. zero evidence of that.
Snowden leaks indicated otherwise
If you are trying to proliferate the 'Wikileaks are Russian agents' mantra at least back this up with some facts and observations. Don't simply link to the circlejerk from previous thread - that's kind of lazy.
Am I required to have omniscient knowledge of the subject prior to commenting? You asked me what I was referring to, and I answered your question.
It has been painfully clear, with almost every release in recent history, that wikileaks uses releases as distractions to take the spotlight away from other stories. That's why it's worth bringing this up on every post.
Just because wikileaks wants the story to be about the release, doesn't mean that's where the real story is. I'm curious as to what the real story is. I do not know the answer to that question, hence my initial comment.