Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
• ./Internal/Dlls/DllPayload.dll – The 32-bit version of Emotional Simian dll
payload.
• ./Internal/WhackDrive.exe – This tool is called by
Emotional_Simian_Config.exe to weaponize a local thumb drive.
3.3 Prerequisites
• The configuration must be executed on a Windows 7 machine.
• Access to the primary host must be gained through other means.
• Access to the thumb drive (if not a remote operation).
• The primary host must be running Windows XP or later.
• Server.exe or Server64.exe must be run with administrative privileges.
• Persistence is to be set up by the operator.
4. Operation
4.1 Quick Overview
The following is a quick overview of the end-to-end process for Emotional Simian and
the tools used during each portion of the operation. A more detailed explanation of each
step will come later.
6
SECRET//X1
CL BY: 2397517
REASON: 1.4(c)
DECL: 20361019
DRV: COL S-06