Vault 7: Projects

Der Starke 1.4 Companion User Guide
DESCRIPTION
Der Starke is a diskless, EFI-persistent version of Triton. Once active on a target system,
the implant executed within diskarbitrationd and typically performs network communications
through a browser process so that PSPs like Little Snitch cannot easily detect it's
presence. This Companion User Guide is meant to supplement the Triton User Guide.
SYSTEM REQUIREMENTS
Supported Build/Postprocessing Systems
Mac OS X 10.7+
Linux with openssl and fdisk
Supported Target Systems: Mac OS X 10.8 or 10.9; MacBook Air or MacBook Pro from
2012-Present
Tested Hardware:
MacBook Air 6,1 (Mid 2013 - 11")
MacBook Air 5,2 (Mid 2012 - 13")
MacBook Air 4,1 (Mid 2011 - 11")
MacBook Air 4,2 (Mid 2011 - 13")
MacBook Pro 11,2 (Late 2013 - 15" Retina)
MacBook Pro 10,1 (Mid 2012 - 15" Retina)
MacBook Pro 10,2 (Mid 2012 - 13" Retina)
MacBook Pro 9,1 (Mid 2012 - 15")
MacBook Pro 8,1 (Late 2011 - 13")
MacBook Pro 8,2 (Late 2011 - 15")
MacBook Pro 6,2 (Mid 2010 - 15")
BUILD INSTRUCTIONS
Run tar -zxf DerStarkeBuilder.tar.gz
Edit config.plist
Run derstarke_builder.pyz -c config.plist
After building, a directory called DerStarkeDeployment_XXXX will be created; The
following notable files will be present:
dmconfig...........................configuration information
TRITON-XXXX/.......................Triton-related build files
triton.pz..........................The build/tasking binary for the implant
originalConfig.plist...............The build config
mkusb.sh...........................Script to create a USB drive with the disk
image from this build
InstallImageFortargetID.iso........Disk image containing implant installer
Refer to the Triton 1.3 User Guide on how to task the implant. Note
derstarke_builder.pyz automatically executed "triton.pz created". User can skip
straight to tasking.
INSTALLATION INSTRUCTIONS
Create the installation media
Insert a USB device to be formatted1.
Run "diskutil list" to determine the device's name2.
Run "mkusb.sh /dev/device_name InstallimageFortargetID.iso"3.
Confirm that the USB device contains the following files:
/EFI/BOOT/BOOTX64.EFI1.
/S.efi2.
/VI.efi3.
4.
Unmount/remove the USB device5.
1.
Turn Off the target system2.
Insert USB install device3.
Hold the power button for 10 seconds4.
SECRET//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh