Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//20350112
9.11.15 (U) Step 15: Add PoPs (Mission Workflow 8)
(S) On the “PoP Assignment” page of the Mission workflow (see Figure 35), select the
PoPs the Flytrap should use to communicate back to the CherryTree. Note that the list
boxes work similarly to the Target Assignment list boxes of 9.11.10. The order of the
“Selected” list can be changed by selecting a PoP and clicking the “Move Up” and
“Move Down” arrows. The PoP at the top of the list will be the first PoP the Flytrap
attempts to communicate through, and so on.
(S) Select the “Use Firmware Default PoP(s) in Mission”: “No” means that the default
PoP addresses built into the Flytrap implant (see 15.5.2) will be ignored – i.e., the Flytrap
will no longer beacon to these addresses; “Yes” means that the default PoP addresses
built into the Flytrap implant will continue to be used – i.e., the Flytrap will continue to
beacon to these addresses. If “No” is chosen, at least one PoP must be selected (an error
is posted otherwise); otherwise Flytrap communication would not be possible. Note this
feature is only supported in v5.0 and newer Flytraps (svn revisions greater than 8900).
Figure 35: Cherry Web PoP Assignment Mission Workflow Page
(S) IMPORTANT: if possible, at least one PoP with an IP address (as opposed to a
domain) should be selected in a Mission. It is possible that a Flytrap could be configured
such that a process running on the Flytrap cannot successfully perform a DNS lookup
(e.g., if the Flytrap has a static IP assigned and does not have DNS servers configured).
(S) When you have finished adding PoPs, click the “Next” button to continue to the
original Mission Workflow page.
86
SECRET//20350112

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh