TOTECHASER: NSA Exploit of the Day
Today's item from the NSA's Tailored Access Operations (TAO) group
implant catalog:
TOTECHASER
(TS//SI//REL) TOTECHASER is a Windows CE implant targeting the
Thuraya 2520 handset. The Thuraya is a dual mode phone that can operate
either in SAT or GSM modes. The phone also supports a GPRS data
connection for Web browsing, e-mail, and MMS messages. The initial
software implant capabilities include providing GPS and GSM geo-location
information. Call log, contact list, and other user information can
also be retrieved from the phone. Additional capabilities are being
investigated.
(TS//SI//REL) TOTECHASER will use SMS messaging for the command,
control, and data exfiltration path. The initial capability will use
covert SMS messages to communicate with the handset. These covert
messages can be transmitted in either Thuraya Satellite mode or GMS mode
and will not alert the user of this activity. An alternate command and
control channel using the GPRS data connection based on the TOTEGHOSTLY
impant is intended for a future version.
(TS//SI//REL) Prior to deployment, the TOTECHASER handsets must be
modified. Details of how the phone is modified are being developed. A
remotely deployable TOTECHASER implant is being investigated. The
TOTECHASER system consists of the modified target handsets and a
collection system.
(TS//SI//REL) TOTECHASER will accept configuration parameters to
determine how the implant operates. Configuration parameters will
determine what information is recorded, when to collect that
information, and when the information is exfiltrated. The configuration
parameters can be set upon initial deployment and updated remotely.
Unit Cost: $
Status:
Page, with graphics, is
here. General information about TAO and the catalog is
here.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.