May 12, 2017
1 min read

Vault 7: AfterMidnight

WikiLeaks publishes “AfterMidnight” and “Assassin”, two CIA malware frameworks for the Microsoft Windows platform.

“AfterMidnight” allows operators to dynamically load and execute malware payloads on a target machine. The main controller disguises as a self-persisting Windows Service DLL and provides secure execution of “Gremlins” via a HTTPS based Listening Post (LP) system called “Octopus”. Once installed on a target machine AM will call back to a configured LP on a configurable schedule, checking to see if there is a new plan for it to execute. If there is, it downloads and stores all needed components before loading all new gremlins in memory. “Gremlins” are small AM payloads that are meant to run hidden on the target and either subvert the functionality of targeted software, survey the target (including data exfiltration) or provide internal services for other gremlins. The special payload “AlphaGremlin” even has a custom script language which allows operators to schedule custom tasks to be executed on the target machine.

“Assassin” is a similar kind of malware; it is an automated implant that provides a simple collection platform on remote computers running the Microsoft Windows operating system. Once the tool is installed on the target, the implant is run within a Windows service process. “Assassin” (just like “AfterMidnight”) will then periodically beacon to its configured listening post(s) to request tasking and deliver results. Communication occurs over one or more transport protocols as configured before or during deployment. The “Assassin” C2 (Command and Control) and LP (Listening Post) subsystems are referred to collectively as” The Gibson” and allow operators to perform specific tasks on an infected target..

 

Leaked Documents

Julian Assange

Australian editor, publisher, and activist who founded WikiLeaks in 2006. He came to international attention in 2010 after WikiLeaks published a series of leaks.

Previous Story

Vault 7: Archimedes

Next Story

Vault 7: Athena

Latest from All Leaks

Hunter Biden Email Archive

WikiLeaks publishes large array of emails extracted from a digital device belonging to Hunter Biden. This publication is not exclusive, in accordance with our principles, but provides additional opportunity for analysis to

Fishrot

Fishrot Files All Releases  /  Documents Fishrot Files – Part 2 Today WikiLeaks releases documents pertaining to the Fishrot case that have come to light as a result of investigation into bribes,

OPCW Douma

All Releases OPCW-DOUMA – Release Part 4 Today WikiLeaks releases more internal documents from the OPCW regarding the investigation into the alleged chemical attack in Douma in April 2018. One of the

Pope’s Orders

All Releases  /  Documents Pope’s Private Letter Reveals Early Involvement in Power Struggle Documents released by WikiLeaks today shed light on a power struggle within the highest offices of the Catholic Church.

US Embassy Shopping List

Today WikiLeaks publishes confidential documents from dozens of United States Embassies around the world. The embassies’ requests ranged widely, from supplies of gardening equipment to hiring a Chinese company to create Chinese-language

Most Popular

Amazon Atlas

October 11, 2018
WikiLeaks publishes a “Highly Confidential” internal document from the cloud

Dealmaker: Al Yousef

September 28, 2018
Today WikiLeaks publishes a secret document from the International Chamber
Go toTop