Professional Documents
Culture Documents
Appelbaum Nsa Ant Catalog
Appelbaum Nsa Ant Catalog
FVEY
DEITYBOUNCE
ANT Product Data
TUMIKG FORK
Post Proc*t*ftg
Target
System s
IRONCHEF
ANT Product Data
CCN STRAITBIZAKRE
N ode C o m p u te * N o d e
r -\—
- j
0-
CCN S e rv e r STRAITBIZARRE
Node
C C N C o m p u te r UNITCORAKt
C o m p u te r N o d e
I
Futoie
Nodoe UNITE O RA KE
S erv er N ode
(TS//SI/REL) This technique supports the HP Proliant 380DL G5 server, onto which
a hardware implant has been installed that communicates over the l?C Interface
(WAGONBED).
(TS//SI//REL) Through interdiction. IRONCHEF. a software CNE implant and the
hardware implant are installed onto the system. If the software CNE implant is
removed from the target machine. IRONCHEF is used to access the machine,
determine the reason for removal of the software, and then reinstall the software
from a listening post to the target system.
POC: S32221.I
O t f iv t d F ro m : NSAJCSSM 1-S2
D ated: 20070108
O e c la s s tfy O n : 20320108
FEEDTROUGH
ANT Product Data
T y p ic a l T arg et
T a rg e t N e tw o rk
I
(S //S I//R E L) P e rs is te n c e O p e ra tio n a l S c e n a rio
Status: (S//SI//REL) FEEDTROUGH has on the shelf solutions for all of the listed platforms.
It has been deployed on many target platforms
GOURMETTROUGH
ANT Product Data
Typical T a rg e t
F irew all o r R o u te r
MPU
I
Target Network
U nit C ost: $0
POC: I S32222,
D e rive d F ro m : NSA/CSSM 1 5 2
O ared 20070108
D e c la s s ify O n: 20320108
HALLUXWATER
ANT Product Data
(TS//SI//REL) The HALLUXWATER Persistence Back Door implant is installed on a
target Huawei Eudemon firewall as a boot ROM upgrade. When the target reboots,
the PBD installer software will find the needed patch points and install the back door 06/24/08
in the inbound packet processing routine.
I
(TS //S I/fR E L) H A L LU X W A T E R P e rs is te n c e Im p la n t C o n c e p t o f O p e ra tio n s
I
(TS//SI//REL) Once installed. HALLUXWATER communicates with an NSA operator
via the TURBOPANDA Insertion Tool (PIT), giving the operator covert access to
read and write memory, execute an address, or execute a packet.
D e rive d P ro m : NSA/CSSM 1 5 2
O afcd 20070108
D e c la s s ify O n : 20320108
JETPLOW
ANT Product Data
(TS//SI//REL) JETPLOW is a firmware persistence implant for Cisco PIX Series and
ASA (Adaptive Security Appliance) firewalls. It persists DNT's BANANAGLEE 06/24/08
software implant. JETPLOW also has a persistent back-door capability.
Typical T a rg e t
F irew all o r R o u te r
M P U /C P U
Op«r»Uf«j SyvUai
Srxt«— bios
MRSlSriNCI
( IMPLANT
0NT »«>*•*«
Target Network
I
(TS//SI//REL) JETPLOW Persistence implant Concept of Operations
(TS//SI//REL) JETPLOW is a firmware persistence implant for Cisco PIX Series and
ASA (Adaptive Security Appliance) firewalls. It persists DNT's BANANAGLEE I
software implant and modifies the Cisco firewall’s operating system (OS) at boot
time. If BANANAGLEE support is not available for the booting operating system, it
can install a Persistent Backdoor (PBD) designed to work with BANANAGLEE's
communications structure, so that full access can be reacquired at a later time.
JETPLOW works on Cisco's 500-series PIX firewalls, as well as most ASA firewalls
(5505, 5510, 5520. 5540. 5550).
Status: (C//REL) Released. Has been widely deployed. Current U nit Cost: SO
availability restncted based on OS version (inquire for details).
POC: I S32222.1 ltg n s a ic.gov D e rive d F ro m : NSA/CSSM 1-52
O ated: 20070108
D e c la s s ify O n: 20320108
SOUFFLETROUGH
ANT Product Data
Typical T a rg e t
F irew all o r R o u te r
M P U /C P U
O p * r » lin g S y s U a i
5 rxt« — s i o s
M R S lS riN C I
IMPLANT
0N T »«>*•*«
(
Target Network
I
(TS//SIMREL) S O U FFLE TR O U G H P e rs is te n c e Im p la n t C o n c e p t o f O p e ra tio n s
Status: (C//REL) Released. Has been deployed. There are no U nit C ost: SO
availability restrictions preventing ongoing deployments.
HEADWATER
ANT Product Data
Typical T a rg e t
Target Network
SCHOOLMONTANA
ANT Product Data
Typical T a rg e t
MPU
Target Network
SIERRAMONTANA
ANT Product Data
(TS//SI//REL) SIERRAMONTANA provides persistence for DNT implants. The DNT
implant will survive an upgrade or replacement of the operating system - including 06/24/08
physically replacing the router's compact flash card.
T y p ic a l T a rg e t
F ire w a ll o r R o u te r
MPU* CPU
T a rg e t N e tw o r k
U nit C ost: S
STUCCOMONTANA
ANT Product Data
(TS//SI//REL) STUCCOMONTANA provides persistence for DNT implants. The
DNT implant will survive an upgrade or replacement of the operating system - 06/24/08
including physically replacing the router’s compact flash card.
Typical Target
Firew all o r Router
M PU CPU
O p * r» « n t| Sy% Um
c
* » io s
M M lfT lM C I
IM » 1 A N ?
C NT » •> ! •> «
Target Network
U nit C ost: S
Status: (U//FOUO) STUCCOMONTANA under development and is expected to be
released by 30 November 2008.
CTX4000
ANT Product Data
Status: unit is operational. However, it is reaching the end of its service life. It is
scheduled to be replaced by PHOTOANGLO starting in September 2008.
POC: I I. S32243. |Q»nsa ic.gov D ef ive d f r o m : NSAJCSSM 1-52
Bailed: 20070108
D e c la s s ify O n : 20320108
LOUDAUTO
ANT Product Data
(U ) C a p a b ilitie s
(TS //S I//R E L TO U S A ,FV E Y ) LOUDAUTO'S 32NDS
current design m axim izes the gain o f the
m icrophone. T h is m akes it extrem ely useful for
16 20
picking up room audio. It can pick up speech at
a standard, office volum e from over 20' away.
(N O TE: C oncealm ents m ay reduce this distance.)
It uses very little pow er (- 1 5 uA at 3.0 V D C ). so
little, in fact, that battery self-discharge is m ore of
an issue for serviceable lifetim e than the pow er
draw from this unit. The sim plicity of the design
allow s the form factor to be tailored for specific
operational requirem ents. All com pon ents at
C O TS and so are non-attributable to NSA.
I
(U ) C o n c e p t o f O p e ra tio n
TS //S I//R E L TO U SA.FVEY) R oom audio is picked up by the m icrophone and
converted into a n analog electrical signal. This signal is used to pulse position
m odulate (PPM ) a square w ave signal running at a pre-set frequency. This
square w ave is used to turn a FE T (field effect transistor) on and off. W hen
I
the unit is illum inated w ith a C W signal from a nearby radar unit, the
illum inating signal is am plitude-m odulated w ith the PPM square w ave. This
signal is re-radiated, w here it is picked up by the radar, then processed to
recover the room audio. P rocessing is currently perform ed by C O TS
equipm ent w ith FM dem odulation capability (R ohde & S chw arz FSH -series
portable spectrum analyzers, etc.) LO U D A U TO is part of the
A N G R Y N E IG H B O R fam ily of radar retro-refiectors.
POC: | | . S32243. .I
O e five d £com : NSA/CSSM 1-S2
D ated: 20070108
O e c la * s .fy O i* 20320108
NIGHTSTAND
W ireless Exploitation I Injection Tool
S y s te m D e ta ils
NIGHTSTAND Hardware
(TS//SI//REL) Use of external amplifiers and antennas in both
experimental and operational scenarios have resulted in successful
NIGHTSTAND attacks from as far away as eight miles under ideal
environmental conditions.
Status: Product has been deployed in the field. Upgrades to the system continue to
be developed.
POC: I S32242. | 1 .1 pSnsa.ic.Qov O e five d £com : NSA/CSSM 1-52
D ated: 20070108
O e c la * s .fy O i* 20320108
NIGHTWATCH
ANT Product Data
(U ) C a p a b ility S u m m a ry
(TS //S I//R E L TO U SA.FVEY) The current
im plem entation of N IG H TW A TC H consists of
a ge neral-purpose PC inside o f a shielded
case. The PC has PCI digitizing and clock
cards to provide the needed interface and
accurate clocking required for video
reconstruction. It also has:
• horizontal sync, vertical sync and video
outputs to drive an external, m ulti-sync
m onitor.
• vide o input
• spectral analysis up to 150 kHz to provide for indications o f horizontal and
vertical sync frequencies
• fram e capture and forw arding I
• P C M C IA cards for program and data storage
• horizontal sync locking to keep the display se t on the N IG H TW A TC H display.
• fram e averaging up to 2A16 (65536) fram es.
(U) C o n c e p t o f O p e ra tio n
I
(TS //S I//R E L TO U S A ,FV E Y ) The vide o output from an appropriate collection
system , such as a C TX 4000, P H O TO A N G LO , or ge neral-purpose receiver, is
connected to the vide o input on the N IG H TW A TC H system . The user, using the
appropriate tools either w ithin N IG H TW A TC H or externally, determ ines the
horizontal and vertical sync frequencies o f the targeted m onitor. O nce the user
m atches the proper frequencies, he activates "S ync Lock" and fram e averaging
to reduce noise and im prove readability o f the targeted m onitor. If w arranted, the
user then forw ards the displayed fram es over a netw ork to N SAW . w here
analysts can look at them for intelligence purposes.
U nit Cost: N/A
Status: This system has reached the end of its service life. All w ork concerning
the N IG H TW A TC H system is strictly for m aintenance purposes. T h is system is
slated to be replaced by the V IE W P LA TE system .
P O C :| ■ S 3 2 2 4 3 .1 H i
D e n ve d F ro m : NSA/CSSM 1-S2
D ated: 20070108
O e c la * s .fy O iv 20320108
PHOTOANGLO
ANT Product Data
(U) C a p a b ilitie s
(TS//SI//R EL TO U S A .FV E Y ) The planned cap abilities for this system are:
•Frequency range: 1 - 2 G H z. w hich w ill be later extended to 1 - 4 GHz.
•M axim um bandw idth: 450 MHz.
•Size: Sm all enough to fit into a slim briefcase.
•W eight: Less than 10 lbs.
•M axim um O utput Power: 2 W
•Output:
•Video
•Transm it antenna
•Inputs:
•E xternal oscillator
•R eceive antenna
(U) C o n c e p t o f O p e ra tio n
(TS //S I//R E L TO U SA.FVEY) TS //S I//R E L TO U S A .FV E Y ) The radar unit
generates an un-m odulated. con tinuo us w ave (CW ) signal. The oscillator is
either generated internally, or exte rna lly through a signal ge nerator or cavity
oscillator. The unit am plifies the signal and sends it ou t to an RF connector,
w here it is directed to som e form o f transm ission antenna (horn, parabolic dish,
LPA, spiral). The signal illum inates the target system and is re-radiated. The
receive antenna picks up the re-radiated signal and directs the signal to the
receive input. The signal is am plified, filtered, and m ixed w ith the transm it
antenna. The result is a hom odyne receiver in w hich the RF signal is m ixed
directly to baseband. The baseband vide o signal is ported to an external BNC
connector. This connects to a processing system , such as N IG H TW A TC H . an
LFS-2. or V IE W P LA TE , to process the signal and provide the intelligence.
POC: S32243. | |
D e rive d F ro m : NSAJCSSM 1-52
Bailed: 20070108
D e c la s s ify O n : 20320108
SPARROW II
W ireless Survey - Airborne Operations - UAV
(U //F O U O ) S y s te m S p e c s
TAWDRYYARD
ANT Product Data
(U ) C a p a b ilitie s
(TS //S I//R E L TO U S A .FV E Y ) TA W D R Y Y A R D is 32NDS
used as a beacon, typically to assist in locating
and identifying deployed R A G E M A S TE R units.
8 16
C urrent design allow s it to be detected and located
quite easily w ithin a 50’ radius o f the radar system
being used to illum inate it. TA W D R Y Y A R D draw s
as 8 pA at 2.5V (20pW ) allow ing a standard lithium
coin cell to pow er it for m onths or years. The
sim plicity o f the design allow s the form factor to
be tailored for specific operational requirem ents.
Future cap abilities being considered are return of
G PS coordinates and a unique target identifier and
autom atic processing to scan a target area for
presence o f TA W D R Y Y A R D s. All com ponents are
I
C O TS and so are non-attributable to NSA.
(U ) C o n c e p t o f O p e ra tio n
(TS //S I//R E L TO U S A .FV E Y ) The board ge nerates a square w ave operating
at a preset frequency. This square w ave is used to turn a FET (field effect
I
transistor) on and off. W hen the unit is illum inated w ith a C W signal, the
illum inating signal is am plitude-m odulated (A M ) with the square w ave. This
signal is re-radiated, w here it is picked up by the radar, then processed to
recover the clock signal. Typically, the fundam ental is used to indicate the
unit's presence, and is sim ply displayed on a low frequency spectrum
analyzer. TA W D R Y Y A R D is part o f the A N G R Y N E IG H B O R fam ily o f radar
retro-reflectors.
S32243. Kg n s a .ic.gov
o e fiv e d £com : NSA/CSSM 1-62
D ated: 20070108
O e c ta * s .fy O i* 20320108
GINSU
ANT Product Data
(TS//SI//REL) GINSU provides software application persistence for the ONE implant. 06 / 20/08
KONGUR, on target systems with the PCI bus hardware implant, BULLDOZER.
Field
Network
I
(TS//SI/REL) This technique supports any desktop PC system that contains at least
one PCI connector (for BULLDOZER installation) and Microsoft Windows 9x, 2000.
2003. XP. or Vista.
(TS//SI//REL) Through interdiction. BULLDOZER is installed in the target system as
a PCI bus hardware implant. After fielding, if KONGUR is removed from the system
as a result of an operating system upgrade or reinstall. GINSU can be set to trigger
on the next reboot of the system to restore the software implant.
HOWLERMONKEY
ANT Product Data
H O W LER M O N KE Y •
H O W LER M O N KE Y - YELLO W PIN
SU TU R ESAILO R
Front
Back
Implant 1 Implant 2
Target
H O W LER M O N KE Y
Transceiver
IRATEMONK
ANT Product Data
WtSTFULTOU
TUNING FORK
R *T Ara*,*i
T a rg e t
Systems
UNITE DRAKE
(TS//SI//REL) This technique supports systems without RAID hardware that boot J f
from a variety of Western Digital. Seagate. Maxtor, and Samsung hard drives. The
supported file systems are: FAT. NTFS. EXT3 and UFS.
(TS//SI//REL) Through remote access or interdiction. UNITEDRAKE, or
STRAITBAZZARE are used in conjunction with SLICKERVICAR to upload the hard
drive firmware onto the target machine to implant IRATEMONK and its payload (the
implant installer). Once implanted. IRATEMONK's frequency of execution (dropping
the payload) is configurable and will occur when the target machine powers on.
JUNIORMINT
ANT Product Data
(TS//SI//REL) JUNIORMINT is a digital core packaged in both a mini Printed Circuit Board
(PCB). to be used in typical concealments, and a miniaturized Flip Chip Module (FCM). to
be used in implants with size constraining concealments.
(TS//SI//REL) JUNIORMINT uses the TAO standard implant architecture. The architecture
provides a robust, reconhgurable. standard digital platform resulting in a dramatic performance
improvement over the obsolete HC12 microcontroller based designs. A mini Printed Circuit
Board (PCB) using packaged parts will be developed and will be available as the standard
platform for applications requiring a digital core. The ultra-miniature Flip Chip Module (FCM)
will be available for challenging concealments. Both will contain an ARM9 microcontroller.
FPGA. Flash. SDRAM and DDR2 memories.
uController Plash SORAM FPGA DDR2
3 0 Stack
Component
64MB
SP1 SDRAM
32MB
1<MXJ2
USART*
use
ARM9
AT9ISAM M >?0
Flash
1SVIO I
R M II 1 M il 400 MHz
!<V « *•
i cv->yv 10
I
I >5 i WCMM* i" - "
me k* ^ v .
A ur. tvrp-.t
FPOA 128MB
contg
XC4 V U 2 5 DDR2
Virtox 4-5 W M X16
JTAG
w’ C -tty H
J2C_ 1 2 V / 1 O v e e r#
i ev-y5v vo 18VlO
I nKJllM
| » It- c * c or BIT £ r w w r
MAESTRO-II
ANT Product Data
aiMtCCM
(TS//SI//REL) MAESTRO-II uses the TAO standard implant architecture. The architecture
provides a robust, reconfigurable. standard digital platform resulting in a dramatic
performance improvement over the obsolete HC12 microcontroller based designs A
development Printed Circuit Board (PCB) using packaged parts has been developed and is
available as the standard platform. The MAESTRO-II Multi-Chip-Module (MCM) contains an
ARM7 microcontroller. FPGA. Flash and SDRAM memories. I
uController Flash SDRAM FPGA
r« UUM KO
SOMBERKNAVE
ANT Product Data
i- i
EXX3
WWW R andom A c c e s s P oint
SOMBERKNAVE
D e rive d P ro m : NSA/CSSM 1 5 2
C (10 V
O afcd 20070108
ALT D e c la s s ify O n : 20320108
SWAP
ANT Product Data
I
I
(TS//SI//REL) This technique supports single or multi-processor systems running
Windows. Linux, FreeBSD, or Solans with the following file systems: FAT32, NTFS,
EXT2. EXT3, or UFS 1.0.
(TS//SI//REL) Through remote access or interdiction. ARKSTREAM is used to re
flash the BIOS and TWISTEDKILT to write the Host Protected Area on the hard
drive on a target machine in order to implant SWAP and its payload (the implant
installer). Once implanted. SWAP's frequency of execution (dropping the payload) is
configurable and will occur when the target machine powers on.
TRINITY
ANT Product Data
(TS//SI//REL) TRINITY uses the TAO standard implant architecture. The architecture
provides a robust, reconligurable. standard digital platform resulting in a dramatic
performance improvement over the obsolete HC12 microcontroller based designs. A
development Printed Circuit Board (PCB) using packaged parts has been developed and is
available as the standard platform. The TRINITY Multi-Chip-Module (MCM) contains an
ARM9 microcontroller. FPGA. Flash and SDRAM memories.
I
180 Mh* 4 MBytes 96 MBytes 1M gates
S tatus: Special Order due vendor selected. U nit Cost: 100 units: S625K
D e rive d F ro m : NSA/CSSM 1-52
POC: S3223. O aied: 20070108
ALT POC: . S3223, D e c la s s ify O n: 20320108
WISTFULTOLL
ANT Product Data
V ttS T F U lT O U .
R 8T A n#yH
R O C T c*« *S
Target
Systems
I
U N ITE D R A K E Server
SURLYSPAWN
ANT Product Data
(U ) C o n c e p t o f O p e ra tio n
(TS //S I//R E L T O U S A .FV E Y ) The board taps into the data line from the
keyboard to the processor. The board generates a square w ave oscillating at
I
a preset frequency. The data-line signal is used to shift the square wave
frequency higher or low er, depending on the level of the data-line signal. The
square w ave, in essence, becom es frequency shift keyed (FSK). W hen the
unit is illum inated by a C W signal from a nearby radar, the illum inating signal I
is am plitude-m odulated (AM ) w ith this square w ave. The signal is re-radiated,
w here it is received by the radar, dem odulated, and the dem odulated signal is
processed to recover the keystrokes. S U R LY S P A W N is part of the
A N G R Y N E IG H B O R fam ily o f radar retro-reflectors.
DROPOUTJEEP
ANT Product Data
(TS//SI//REL) DROPOUTJEEP is a STRAITBIZARRE based software implant for
the Apple iPhone operating system and uses the CHIMNEYPOOL framework.
DROPOUTJEEP is compliant with the FREEFLOW project, therefore it is supported 10/01/08
in the TURBULENCE architecture.
U nit Cost: S 0
GOPHERSET
ANT Product Data
(TS//SI//REL) GOPHERSET is a software implant for GSM (Global System for
Mobile communication) subscriber identify module (SIM) cards. This implant pulls
Phonebook. SMS. and call log information from a target handset and exfiltrates it to 10/01/08
a user-defined phone number via short message service (SMS).
U nit Cost: SO
MONKEYCALENDAR
ANT Product Data
(TS//SI//REL) MONKEYCALENDAR is a software implant for GSM (Global System
for Mobile communication) subscriber identify module (SIM) cards. This implant
pulls geolocation information from a target handset and exfiltrates it to a user- 10 / 01/08
defined phone number via short message service (SMS).
TOP SECRET/ICOMINT
Handset MONKEYCALENDAR
MONKEYCALENDAR
returns commands handset to
sits idle waiting for
location info send encrypted data
trigger
via SMS
MONKEYCALENDAR
receives location info
Handset sends out
from handset
encrypted SMS
i
Handset idle
I
T9PSECRemc.9.M».NT,
(U //FO U O ) M O N K E Y C A LE N D A R - O p e ra tio n a l S c h e m a tic
I
(TS//SI//REL) Modern SIM cards (Phase 2+) have an application program interface
known as the SIM Toolkit (STK). The STK has a suite of proactive commands that
allow the SIM card to issue commands and make requests to the handset.
MONKEYCALENDAR uses STK commands to retrieve location information and to
exfiltrate data via SMS. After the MONKEYCALENDAR file is compiled, the
program is loaded onto the SIM card using either a Universal Serial Bus (USB)
smartcard reader or via over-the-air provisioning. In both cases, keys to the card
may be required to install the application depending on the service provider's
security configuration
U nit Cost: SO
POC: U//FOUOI I . S 3 2 2 2 2 .I
D e n ve d F ro m : NSA/CSSM 1-S2
D ated: 20070108
D e c la s s ify O n : 20320108
PICASSO
GSM HANDSET
(S//SI//REL) Modified GSM (target) handset that collects user data, location
information and room audio. Command and data exfil is done from a laptop and
regular phone via SMS - (Short Messaging Service), without alerting the target. 06 / 20/08
TOTECHASER
ANT Product Data
(TS//SI//REL) TOTECHASER is a Windows CE implant targeting the Thuraya 2520
handset. The Thuraya 2520 is a dual mode phone that can operate either in SAT or
GSM modes. The phone also supports a GPRS data connection for Web browsing, 10/ 01/08
e-mail, and MMS messages. The initial software implant capabilities include
providing GPS and GSM geo-location information. Call log, contact list, and other
user information can also be retrieved from the phone. Additional capabilities are
being investigated.
TO PM CR1T ' I
lliin . iy . iG S M
P flO W CPS - C u r r e n t FIm . L m I FIn . L e s t 10
G S M M C C . M N C . L A C , I v n i n g A rtv
M cm ey M S I.M K I
C a ll I o , | O u t. In .
C o n ta c t L is t H em ss. P A ons N u m b s **
□
a iS k i/
C o lle c tio n
T O P S fC R F T S I ? # ? 5 1 1 7 3
I
[U iib O U O ) TO TbC H ASfcR - O p e ra tio n a l S c h e m a tic
(TS//SI//REL) TOTECHASER will use SMS messaging for the command, control,
and data exfiltration path. The initial capability will use covert SMS messages to
communicate with the handset. These covert messages can be transmitted in
I
either Thuraya Satellite mode or GSM mode and will not alert the user of this
activity. An alternate command and control channel using the GPRS data
connection based on the TOTEGHOSTLY implant is intended for a future version.
(TS//SI//REL) Prior to deployment, the TOTECHASER handsets must be modified.
Details of how the phone is modified are being developed. A remotely deployable
TOTECHASER implant is being investigated. The TOTECHASER system consists
of the modified target handsets and a collection system.
(TS//SI//REL) TOTECHASER will accept configuration parameters to determine
how the implant operates. Configuration parameters will determine what information
is recorded, when to collect that information, and when the information is exfiltrated.
The configuration parameters can be set upon initial deployment and updated
remotely.
U nit C ost: S
Status:
O e five d £com : NSA/CSSM 1-52
D ated: 20070108
POC: U//FOUOI S32222.1 D e c la s s ify O n : 20320108
TOTEGHOSTLY 2.0
ANT Product Data
(TS//SI//REL) TOTEGHOSTLY 2.0 is a STRAITBIZARRE based implant for the
Windows Mobile embedded operating system and uses the CHIMNEYPOOL
framework. TOTEGHOSTLY 2.0 is compliant with the FREEFLOW project, 10/ 01/08
therefore it is supported in the TURBULENCE architecture.
TO* 4 t « U l C O M W l W l
A nalyst
Target Device
R O C L o w S ide j
'V ROC H ig h S id e
\
U nit Cost: SO
C o m m a n d C anter
(S//SI//REL) Typical use scenarios are asset validation, target tracking and
identification as well as identifying hostile surveillance units with GSM handsets.
I
Functionality is predicated on aprion target information.
(S //S I//R E L ) S y s te m H W
CROSSBEAM
ANT Product Data
CWC8SBEAM
I
irrc fc rte o T o w / S w ic*
CTO6SEEAM
COfrTOTC*! NfVCfV
CR C G SE EM I
CYCLONE Hx9
Base Station Router
• Approximately 8 lbs
• Actively cooled for extreme
environments
(S//SI//REL) Multi-purpose. Pico class, tri-band active GSM base station with 01/27/09
internal 802.11/GPS/handset capability.
• Pico-class (lW a tt) Base station >(S//SI//R EL) Separately Priced O ptions:
• Optional Battery Kits • 90 WH Lilon Battery Kit I
• Highly Mobile and Deployable
• Integrated GPS. MS. & 802.11 > (S//SI//REL) Base S tation Router
ENTOURAGE
(S //S I//R E L ) D ire ctio n F in d in g on
H o llo w P o in t P la tfo rm
Status: The system is in the final testing stage and U nit C ost: S70K
will be in production Spring 09.
GENESIS
Covert SIGINT Transceiver
• Internal 16 GB of storage
• Multiple Integrated Antennas
NEBULA
Base Station Router
• 3 Interchangeable RF bands
• AC/DC power converter
(S//SI//REL) Features:
• Antenna to support MS. GPS.
• Dual Carrier System
WIFI. & RF
• EGSM 900MHz
•LA N . R F .& USB cables
• UMTS 2100MHz
• Pelican Case
I
• CDMA2000 1900MHz
• (Field Kit only) Control Laptop
• Macro-class Base station and Accessories
• Optional Battery Kits ^(S//SI//REL) Separately Priced Options:
I
• Highly Mobile and Deployabte • 1500 WH Lilon Battery Kit
• Integrated GPS. MS. & 802.11 r (S//SI//REL) Base Station Router Platform:
TYPHON HX
GSM Base Station Router
Typhon BSR
(S//SI//FVEY) Tactical SIGINT elem ents BTS RtHKjc: 759b Probability Rdtuje
use th is equipm ent to find , fix and fin ish
targeted handset users.
(S//SI) Target GSM handset registers w ith
BSR unit.
I
(S//SI) O perators are able to geolocate
registered handsets, capturing the user.
(S//S I//R E L) The m acro-class Typhon is a N etw ork-ln-a- Ttpl boa H x Priced O p d o e t
I
Box (NIB), w hich includes all the necessary architecture to B re d — FTPCXHT m
support M obile Station ca ll processing and SMS 1 1* 25 w et 1------ — J 117) joe
m essaging in a stand-alone chassis w ith a pre- Ot4 * (•*•<*
provisioning capability. 01004^64*01*4140
KUGf—tOmiVS:
(S//S I//R E L) The Typhon system kit includes the am plified
H t* O i— (IG lV tW X P o:ocr*6*oi«M J
Typhon system . O A M & P Laptop, cables, antennas and 0 1X 41 6 5*0 1 X 41 4 1
A C /D C pow er supply. G 1X 4 . 6 . ' * G 1X 4 ! )S
s e p a ra te ly.
(U ) A bracket and m ounting kit are available upon (U ) Status: A vailable 4 roos ARO
request.
(S //S I//R E L) O p e ra tio n a l R e s tric tio n s
e x is t fo r e q u ip m e n t d e p lo y m e n t.
WATERWITCH
Handheld Finishing Tool
(S//SI) Hand held finishing tool used for geolocating targeted handsets 07/30/08
in the field.
(S//SI) Features:
• Split display/controller for
flexible deployment
capability
• External antenna for DFing
target; internal antenna for
communication with active
interrogator
•M ultiple technology
capability based on SDR (s//si) w a t e r w i t c h Handset d f se t
COTTONMOUTH-I
ANT Product Data
(TS//SI//REL) CM-I will provide air-gap bridging, software persistence capability. *in-field" re-
programmability. and covert communications with a host software implant over the USB. The
RF link v/ill enable command and data infiltration and exfiltration. CM-I will also communicate
with Data Network Technologies (DNT) software (STRAITBIZARRE) through a covert
channel implemented on the USB. using this communication channel to pass commands and
data between hardware and software implants. CM-I will be a GENIE-compliant implant
based on CHIMNEYPOOL.
(TS//SI//REL) CM-I conceals digital components (TRINITY). USB 1.1 FS hub. switches, and
HOWLERMONKEY (HM) RF Transceiver within the USB Series-A cable connector.
MOCCASIN is the version permanently connected to a USB keyboard. Another version can
be made with an unmodified USB connector at the other end. CM-I has the ability to
I
communicate to other CM devices over the RF link using an over-the-air protocol called
SPECULATION. c o t t o n m o u t m c o n o *>
MTERNET S cona iw
I
low
COTTONMOUTH-II
ANT Product Data
COTTONMOUTH-III
ANT Product Data
(TS//SI//REL) CM-III will provide air-gap bridging, software persistence capability. *in-field"
re-programmability, and covert communications with a host software implant over the USB.
The RF link will enable command and data infiltration and exfiltration. CM-III will also
communicate with Data Network Technologies (DNT) software (STRAITBIZARRE) through a
covert channel implemented on the USB. using this communication channel to pass
I
commands and data between hardware and software implants. CM-III will be a GENIE-
compliant implant based on CHIMNEYPOOL.
(TS//SI//REL) CM -lll conceals digital components (TRINITY), a USB 2.0 HS hub. switches,
and HOWLERMONKEY (HM) RF Transceiver within a RJ45 Dual Stacked USB connector.
CM-I has the ability to communicate to other CM devices over the RF link using an over-the-
I
air protocol called SPECULATION. CM-III can provide a short range inter-chassis link to
other CM devices or an intra-chassis RF link to a long haul relay subsystem.
C O TTO N M O U TM COM OP
IN TE R N E T S c e n a rio
FIREWALK
ANT Product Data
__
I
FIREWALK allows active exploitation of a target network with a firewall or air gap protection.
(TS//SI//REL) FIREWALK uses the HOWLERMONKEY transceiver for back-end
communications. It can communicate with an LP or other compatible HOWLERMONKEY
based ANT products to increase RF range through multiple hops.
I
(Internet
• o r*
FWIdNet)
• o c - D A N D c n c e n r T . - .p o o f* . i f 4 m a c a a n *
H U m H O W L C R M O fK R Y
I HR - L o r v j H a u l VWiay
RAGEMASTER
ANT Product Data
(TS//SI//REL TO USA.FVEY) RF retro-reflector that provides an enhanced radar
cross-section for VAGRANT collection. It's concealed in a standard computer video
24 Jul 2008
graphics array (VGA) cable between the video card and video monitor. It's typically
installed in the ferrite on the video cable.
(U ) C a p a b ilitie s
(TS //S I//R E L TO U S A .FV E Y ) R A G EM AS TER provides a target for RF flooding
and allow s for easier collection of the V A G R A N T vide o signal. The current
R A G EM AS TER unit taps the red video line on the V G A cable. It w as found that,
em pirically, this provides the best video return and cleanest readout of the
m onitor contents.
I
(U) C o n c e p t o f O p e ra tio n
(TS//SI//R EL TO U SA.FVEY) The R A G EM AS TER taps the red video line
I
betw een the video card w ithin the desktop unit and the com puter m onitor,
typically an LCD. W hen the R A G EM AS TER is illum inated by a radar unit, the
illum inating signal is m odulated w ith the red vide o inform ation. T h is inform ation
is re-radiated, w here it is picked up at the radar, dem odulated, and passed
onto the processing unit, such as a LFS-2 and an external m onitor.
N IG H TW A TC H . G O TH AM , or (in the future) V IE W P LA TE . The processor
recreates the horizontal and vertical sync o f the targeted m onitor, thus allow ing
TA O personnel to see w ha t is displayed on the targeted m onitor.
U nit Cost: S 30