TOTEGHOSTLY 2.0: NSA Exploit of the Day
Today's item from the NSA's Tailored Access Operations (TAO) group 
implant catalog:
TOTEGHOSTLY 2.0
(TS//SI//REL) TOTEGHOSTLY 2.0 is  STRAITBIZARRE based implant for the
 Windows Mobile embedded operating system and uses the CHIMNEYPOOL 
framework. TOTEGHOSTLY 2.0 is compliant with the FREEFLOW project, 
therefore it is supported in the TURBULENCE architecture.
(TS//SI//REL) TOTEGHOSTLY 2.0 is a software implant for the Windows 
Mobile operating system that utilizes modular mission applications to 
provide specific SIGINT functionality. This functionality includes the 
ability to remotely push/pull files from the device, SMS retrieval, 
contact list retrieval, voicemail, geolocation, hot mic, camera capture,
 cell tower location, etc. Command, control, and data exfiltration can 
occur over SMS messaging or a GPRS data connection. A FRIEZERAMP 
interface using HTTPSlink2 transport module handles encrypted 
communications.
(TS//SI//REL) The initial release of TOTEGHOSTLY 2.0 will focus on 
installing the implant via close access methods. A remote installation 
capability will be pursued for a future release.
(TS//SI//REL) TOTEGHOSTLY 2.0 will be controlled using an interface 
tasked through the NCC (Network Control Center) utilizing the XML based 
tasking and data forward scheme under the TURBULENCE architecture 
following the TAO GENIE Initiative.
Unit Cost: $0
Status: (U) In development
Page, with graphics, is 
here. General information about TAO and the catalog is 
here.
 
 
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.