Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
Flash Bang v1.0 (Current Version)
SECRET//NOFORN
Flash Bang v1.0
Description:
Flash Bang is a tool designed to be able to migrate from a browser process, escalate privileges, and memory load a NODNetwork Operations Division Persistence Spec dll. Flash Bang does not currently include a sandbox breakout. To do these things Flash Bang is broken into two parts: FlashBangLoader.dll and FlashBang.dll. FlashBangLoader.dll runs from within the browser process for the duration of execution. FlashBang.dll is written to disk and never runs from within the browser. When loaded into the browser process (Fire and Forget Spec), FlashBangLoader.dll writes FlashBang.dll to disk and then uses a shell folder identified by a COM class to force explorer.exe to load FlashBang.dll. Once Flash Bang is loaded into explorer.exe, the tool escalates privileges and memory loads a NODNetwork Operations Division Persistence spec dll.
This tool was built for a specific CONOPConcealed Operation but could be modified to fit a wider set of CONOPS. Currently, it is assumed that the target is exploited initially by Windex. It is also assumed that all browser sandboxes are defeated. Then, the ShellTerm instance running inside the browser loads the FlashBangLoader.dll. For this specific build FlashBangLoader is configured to install a Grasshopper/Anthill/Assassin package.
Design and Concept of Operations:
Stash Repository: Flash Bang Repository
Testing Repoistory: Project Tests Repository
Documentation:
('section' missing)
Latest Testing Results:
Operational Use:
JQJVIGOR
Highlights:
Technique Tracking:
List of techniques used by Project
Technique 1
Technique 2
Change Log:
('excerpt' missing)
Older Versions:
SECRET//NOFORN