Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
Personal Security Products (PSPs)
(S) Kaspersky AV blocked the installation of the device driver necessary for Dumbo to
function properly on XP. PSPs also often log processes that attempt to use a webcam, and
Dumbo may cause interactive pop-up notifications altering the user that the tool is attempting
to connect to the camera. Additionally, some PSPs were seen to prevent a fully functioning
bluescreen exit option. Although no alerts were raised in this case, the exit functionality was
blocked. Because of these potential hindrances, it is recommended that the operator consider
disabling any PSP running on the target machine prior to running Dumbo. It is recognized
that this choice has trade-offs, including that the system will explicitly log that the PSP was
disabled, and should be considered on a case-by-case basis.
Camera Emulation
(S) Dumbo works by discovering which processes have access to the physical camera device
and uses that information to corrupt video files. In some instances, programs emulate a
camera input to other programs; such is the case with Fujitsu’s YouCam.exe. When this
occurs, YouCam.exe will have control of the actual webcam, and feed input to other
processes that record images to files as needed. In this scenario, Dumbo will suspend
YouCam.exe, but will not be able to detect the other processes to which YouCam.exe is
feeding images. Although the camera will not be able to record additional frames, Dumbo
will not be able to corrupt files that were being written to, as it is unaware of the processes
writing the video files. If the operator sees a process using the camera device, but Dumbo
detects no files being written, the operator should manually search for video files.
Previously Saved Files
(S) Dumbo has the capability to detect only files are were being written at the moment a
recording program was suspended. Previously saved files such as earlier recordings or
snapshot images will not be detected. If Dumbo detects a process using the camera, the
operator should search around all reported files paths for potentially problematic prior
recordings.
Recording Software Restarts
(S) In some instances, video recording software has the ability to detect it is not responding,
and will restart itself; such is the case with iSpy.exe. When Dumbo detects a process using a
camera device, it also claims control of the device. If the recording software were to restart
itself, it would no longer be able to access the camera until Dumbo exits. In the case of iSpy,
although the program may restart, it will be unable to record any additional frames; it will
appear as if it was unable to access the camera, due to it already being in use.
4.0 (U) Sample Screenshots
[UNCLASSIFIED]
SECRET//NOFORN
8

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh