Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

5.11.15 (U) Step 15: Add PoPs (Mission Workflow 8)
(S) On the “PoP Assignment” page of the Mission workflow (see Figure 32), select the
PoPs the Flytrap should use to communicate back to the CherryTree. Note that the list
boxes work similarly to the Target Assignment list boxes of 5.11.10. The order of the
“Selected” list can be changed by selecting a PoP and clicking the “Move Up” and
“Move Down” arrows. The PoP at the top of the list will be the first PoP the Flytrap
attempts to communicate through, and so on.
(S) Select the “Use Firmware Default PoP(s) in Mission”: “No” means that the default
PoP addresses built into the Flytrap implant will be ignored – i.e., the Flytrap will no
longer beacon to these addresses; “Yes” means that the default PoP addresses built into
the Flytrap implant will continue to be used – i.e., the Flytrap will continue to beacon to
these addresses. If “No” is chosen, at least one PoP must be selected (an error is posted
otherwise); otherwise Flytrap communication would not be possible. Note this feature is
only supported in v5.0 and newer Flytraps (svn revisions greater than 8900).
Figure 32: Cherry Web PoP Assignment Mission Workflow Page
(S) IMPORTANT: if possible, at least one PoP with an IP address (as opposed to a
domain) should be selected in a Mission. It is possible that a Flytrap could be configured
such that a process running on the Flytrap cannot successfully perform a DNS lookup
(e.g., if the Flytrap has a static IP assigned and does not have DNS servers configured).
(S) When you have finished adding PoPs, click the “Next” button to continue to the
original Mission Workflow page.
45

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh