Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//20350629
(S) If the payload(s) you are dropping need to wait before moving on to the next
executable click the box next to “Wait until process terminates?”.
(S) EZCheese has the option to “securely” delete a payload. If you click the “secure
delete payload” box the payload will be overwritten with zeroes three passes and the
filename will also be overwritten with random characters three times. Additionally,
Secure delete requires the “Wait until process terminates” box to be checked so that the
process has full access to the file.
(S) Click on “Add” after all the parameters have been entered. This adds a row to the
Payload Table. You can continue adding payloads with arguments and blacklists using
the previous steps.
Configuring the link(s) and Dll(s) with Mac-n-Cheese.
(S) Important: Close all explorer windows displaying any contents of the target thumb
drive. This will prevent inadvertent launch of the tool on the configuration system. Use
dir /a from a command prompt to view.
(S) Launch the Mac-n-Cheese executable. A tabbed configuration tool appears as in
figure 5 below. The Load Config and Save Config buttons allow a user to create or load
an XML file specifying a full configuration. When all fields are complete, the Create
Link(s) button writes the link(s) and Dll(s) to launch a specified payload.
SECRET//20350629
9

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh