August 31, 2017
1 min read

Vault 7: Angelfire

WikiLeaks publishes documents from the Angelfire project of the CIA. Angelfire is an implant comprised of five components: Solartime, Wolfcreek, Keystone (previously MagicWand), BadMFS, and the Windows Transitory File system. Like previously published CIA projects (Grasshopper and AfterMidnight) in the Vault7 series, it is a persistent framework that can load and execute custom implants on target computers running the Microsoft Windows operating system (XP or Win7).

Solartime modifies the partition boot sector so that when Windows loads boot time device drivers, it also loads and executes the Wolfcreek implant, that once executed, can load and run other Angelfire implants. According to the documents, the loading of additional implants creates memory leaks that can be possibly detected on infected machines.

Keystone is part of the Wolfcreek implant and responsible for starting malicious user applications. Loaded implants never touch the file system, so there is very little forensic evidence that the process was ever ran. It always disguises as “C:\Windows\system32\svchost.exe” and can thus be detected in the Windows task manager, if the operating system is installed on another partition or in a different path.

BadMFS is a library that implements a covert file system that is created at the end of the active partition (or in a file on disk in later versions). It is used to store all drivers and implants that Wolfcreek will start. All files are both encrypted and obfuscated to avoid string or PE header scanning. Some versions of BadMFS can be detected because the reference to the covert file system is stored in a file named “zf”.

The Windows Transitory File system is the new method of installing AngelFire. Rather than lay independent components on disk, the system allows an operator to create transitory files for specific actions including installation, adding files to AngelFire, removing files from AngelFire, etc. Transitory files are added to the ‘UserInstallApp’.

Leaked Documents

Australian editor, publisher, and activist who founded WikiLeaks in 2006. He came to international attention in 2010 after WikiLeaks published a series of leaks.

Previous Story

Vault 7: ExpressLane

Next Story

Vault 7: Protego

Latest from All Leaks

BioLab Lugara Files

All Releases  /  Documents: Georgia, Armenia December 12, 2025 Today, WikiLeaks publishes the second release of archive from the Ministry of Health of Georgia and the Lugar Biolaboratory in Tbilisi. This release

Hunter Biden Email Archive

WikiLeaks publishes large array of emails extracted from a digital device belonging to Hunter Biden. This publication is not exclusive, in accordance with our principles, but provides additional opportunity for analysis to

Fishrot

Fishrot Files All Releases  /  Documents Fishrot Files – Part 2 Today WikiLeaks releases documents pertaining to the Fishrot case that have come to light as a result of investigation into bribes,

OPCW Douma

All Releases OPCW-DOUMA – Release Part 4 Today WikiLeaks releases more internal documents from the OPCW regarding the investigation into the alleged chemical attack in Douma in April 2018. One of the

Pope’s Orders

All Releases  /  Documents Pope’s Private Letter Reveals Early Involvement in Power Struggle Documents released by WikiLeaks today shed light on a power struggle within the highest offices of the Catholic Church.

Most Popular

BioLab Lugara Files

December 12, 2025
All Releases  /  Documents: Georgia, Armenia December 12, 2025 Today,
Go toTop