Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//20330530
This will not regenerate the unnecessary configfiles used to create an implant. Replace all the files on
the LP with the newly generated files contained in the tarball (example: website_d25.tar.gz). The
tarball generated will have the same name as your “output folder name”. See below.
(S) Creating and editing the Configuration (using pkgcreator.py) Reference
pkgcreator.py will present a set of menus to help with implant tasking and management. This
document will present a walkthrough and further details about each menu item.
==== Menu ====
config: Create/Edit a configuration
generate: Generate all files needed base on above configuration
help: Help (print this menu)
quit: Quit this menus
First, choose the config option to edit a configuration or create one if none was passed in on the
command-line.
main> config
==== NSConfig Utility ====
wizard: Start Configuration Wizard
tasks: Tasking Menu
show: Show current configuration
help: Help (print this menu)
save: Save configuration
quit: Exit program
Next we use the wizard to generate the initial configuration settings.
ns> wizard
The wizard will prompt for the initial settings to be used by the NightSkies implant. Most settings
have a default value, but the “Full URL to LP Beacon” path must be set to the current URL of the
listening post. If this is incorrect, the implant will not be able to beacon to the LP.
>Full URL to LP Beacon [http://localhost/page.php]: http://yours.xyz.com/page.php
For each other setting, either type in the new setting or leave it blank to accept the default value in the
square brackets.
Setting Details Type
Build for Desktop Desktop builds use NVRAM,
mobile builds use a configuration
file on the target system
Y or N
Full URL to LP Beacon
(KEY_URL)
The full URL that points to the
php page holding the LP tasking
String
Client ID
(KEY_CLIENTID)
Implant-specific identifier String
Magic string An innocuous HTML tag that is String
SECRET//20330530
5

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh