Vault 7 - The "Elsa" Tracking Implant

in #vault77 years ago (edited)

To perform the data collection the target machine does not have to be online or connected to an access point; it only needs to be running with an enabled WiFi device.

- Wikileaks.org



Yet another release from the Wikileaks Vault 7 CIA malware cache by the publisher/whistleblower organization has exposed the latest Incarnation of CIA malware - "Elsa". The latest piece of CIA malware is an implant that works to geolocate a target laptop, desktop or device by using the WiFi signals in the immediate area.


image: the hacker news

image: pinterest

WikiLeaks on Twitter   RELEASE  CIA  ELSA  implant to geolocate laptops desktops by intercepting the surrounding WiFi signals https   t.co XjyyXIqXAz https   t.co XAYMlBbY7i .png


Courage Foundation on Twitter   WikiLeaks Releases Files on CIA Spying Geo Location Malware for WiFi Devices https   t.co WDY2GWmIWj .png

From wikileaks.org:

Elsa
28 June, 2017

Today, June 28th 2017, WikiLeaks publishes documents from the ELSA project of the CIA. ELSA is a geo-location malware for WiFi-enabled devices like laptops running the Micorosoft Windows operating system. Once persistently installed on a target machine using separate CIA exploits, the malware scans visible WiFi access points and records the ESS identifier, MAC address and signal strength at regular intervals. To perform the data collection the target machine does not have to be online or connected to an access point; it only needs to be running with an enabled WiFi device. If it is connected to the internet, the malware automatically tries to use public geo-location databases from Google or Microsoft to resolve the position of the device and stores the longitude and latitude data along with the timestamp. The collected access point/geo-location information is stored in encrypted form on the device for later exfiltration. The malware itself does not beacon this data to a CIA back-end; instead the operator must actively retrieve the log file from the device - again using separate CIA exploits and backdoors.

The ELSA project allows the customization of the implant to match the target environment and operational objectives like sampling interval, maximum size of the logfile and invocation/persistence method. Additional back-end software (again using public geo-location databases from Google and Microsoft) converts unprocessed access point information from exfiltrated logfiles to geo-location data to create a tracking profile of the target device.

Link to Wikileaks Vault 7 - Elsa

https://wikileaks.org/vault7/#Elsa


Only a week ago, @fortified reported on the release of Brutal Kangaroo that allows the CIA to jump air gaps from one device to another.

https://steemit.com/wikileaks/@fortified/vault-7-or-wikileaks-releases-the-air-gap-jumping-brutal-kangaroo


The internet is steadily becoming more dangerous place to be with both the CIA and NSA losing control of their vicious cyber weapons. The full extent of the spy agencies arsenals, and the potentially grave and lasting impacts associated with these hacking tools, are as yet still unknown.


image: YouTube


V4vapid1.png

Sort:  

Resharing @phibetaiota

Imgur

The world is such a corrupt place. The greater powers abuse their technology to the fullest while using propaganda to persuade the masses everything is A' OKAY. Great post, I had no idea about the Elsa project. Awesome information. @v4vapid you're doing gods work by sharing this stuff and waking people up! I followed and upvoted! Check my blog out too, i touch base on similar things going on in our world.

Will do! thanks for reading. This CIA/NSA spying is way outta control.

If you created a weapon that got stolen and was then used to do massive damage, you would be in an underground cell right now for creating it, but if the NSA does it, no one seems to give 2 shits. Go figure.

No doubt! And they're wrecking the goddamn internet with this shit.

45.png

Trump: CIA...Tremendous people...just tremendous. They are investigating things Bigly.

Trump: Media...Dumb Dumbs

@lecrazycanuckeh, you're probably aware of the @minnowsupport project by @aggroed. But just in case you missed it come check it out on Discord.

https://discord.gg/HYj4yvw

Good way to network and promote your work.

Thanks for info @v4vapid

Jeez, the hits just keep on coming. Maybe I'll downgrade to hammer and chisel -- or does the CIA have malware for those, too?

LOL, at this point who knows how far reaching these tools are. Seems like they have blanket coverage already!

Right. Speaking of blankets, I think when I'm picking up my chisel, maybe I'll look for some of those space blankets like Chuck McGill used on Better Call Saul. In fact, none of this is actually funny, but at the point where they can compromise air-gapped hardware, what can you do but joke about it.

Note to self: Design a Trezor-sized Faraday cage to sell on Etsy

Thank you for good information.
i follow you.

I write something a bit realated, maybe not the exact related, but please take a look on my article about governments and blockchain in clash this is my first serious article on steemit I`ve put in it a lot of work:
https://steemit.com/bitcoin/@bolgan/blockchain-vs-governments-my-prediction

Congratulations! This post has been upvoted from the communal account, @minnowsupport, by v4vapid from the Minnow Support Project. It's a witness project run by aggroed, ausbitbank, teamsteem, theprophet0, and someguy123. The goal is to help Steemit grow by supporting Minnows and creating a social network. Please find us in the Peace, Abundance, and Liberty Network (PALnet) Discord Channel. It's a completely public and open space to all members of the Steemit community who voluntarily choose to be there.

If you like what we're doing please upvote this comment so we can continue to build the community account that's supporting all members.

Coin Marketplace

STEEM 0.18
TRX 0.16
JST 0.029
BTC 63656.97
ETH 2473.22
USDT 1.00
SBD 2.66