Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
SECRET//20350112
• [Flytrap Config] - Mission support parameters
• [Flytrap Status Data] – Flytrap status information
• [Flytrap Security Data] – Flytrap security info (i.e., password, WPA key, etc.)
• [Target Email Config] - a target email hash, as well as "Action(s)" type/id to take
for this target
• [Target MAC Config] - a target MAC hash, as well as "Action(s)" type/id to take
for this target
• [Alert Data] - data pertaining to an actual alert (when to send – immediately, in
traffic, etc.)
• [Action Copy Config] - config info for Flytrap copying (e.g., ip of server to copy
to). This maps to Copy action type/id in the [Target Email/MAC Config] blocks
• [Action Redirect Config] - config info for Flytrap redirecting (e.g., ip of server to
copy to). This maps to Redirect action type/id in the [Target Email/MAC Config]
blocks
• [Action Proxy Config] - config info for Flytrap proxying. This maps to Redirect
action type/id in the [Target Email/MAC Config] blocks
(S) A Message Type is then constructed from a number of blocks. Here are some
example Message Types, and the blocks they might include:
• Initial/Periodic Beacon (Flytrap -> CT):
o [Flytrap Status Data]
o [Flytrap Security Data]
• Mission (CT -> Flytrap):
o [Flytrap Config]
o [Target Email Config] (multiple)
o [Target MAC Config] (multiple)
o [Action Redirect Config] (multiple)
o [Action Copy Config] (multiple)
o [Action Proxy Config] (multiple)
• Alert:
o [Flytrap Status Data]
o [Action Alert Data]
15.1.2 (U) Flytrap Status Data
(S) This section enumerates the information that is sent in the Flytrap Status Block
portion of a Beacon or Alert/Target Monitor message.
• Platform make/model/hardware version/firwmare version
• Cherry Blossom Firmware version
• Platform constraints (e.g., Max targets/actions that can be configured)
• Network interface information (i.e., WAN, LAN, and WLAN MAC and IP
addresses). The WLAN MAC address is the unique identifier used by CherryTree
to refer to the Flytrap
• Ontime – the approximate total time the Flytrap has been powered on (see 15.2
for the importance of Ontime in sending Beacons)
128
SECRET//20350112