Martin's Blog

Appendix A: Complete Exploit Catalogue

This inventory is compiled statically from the vector-exploit packages' info.yaml metadata, the repository’s Git history, and its development tree. Nothing in the repository was built, run, repaired, or improved.

The packages use internal tracking numbers (HT-YYYY-NNN). The loader accepts clear ZIP archives or archives encrypted with a source-embedded passphrase from the server’s exploits/ directory. The passphrase is not reproduced. When the catalogue is requested, the server’s exploit loader scans that directory and publishes each compatible package’s declared metadata to the console, using the categories social, zeroday, private, and public.

The three final zeroday package trees contain public stub manifests telling the user to contact HackingTeam support. The Word and PowerPoint trees also contain functional-looking info-good.yaml variants, while all three checked-out trees contain info-fake.yaml. Their names suggest alternate customer-facing and functional manifests, but no code found in the examined snapshot proves how or for whom they were selected. That remains an inference, not a catalogue fact.

The static history scanner recovers 46 paths named info.yaml, which collapse to 38 normalized catalogue IDs after renames and duplicates are joined. Seven are present at HEAD. A separate early ht-2011-019.zip has no recoverable manifest and is excluded from those metadata totals.

The tables merge three sets:

  1. packages present at repository HEAD (2cf574d3bf2ea44f67433e32ccc9906ded6218e0, committed 12 December 2014; manifests declare version 20140930);
  2. packages with recoverable metadata in Git history, using each manifest at its last surviving commit; and
  3. projects in the repository’s src/ development tree.

Removal reasons are copied from the repository’s own CHANGELOG and should be read as HackingTeam’s descriptions, not independent conclusions.

Present at repository HEAD

The manifests are dated 30 September 2014. “First observed” is the first commit in this repository containing a manifest for the normalized ID; it is not necessarily the package’s original development date.

IDNameCategoryPlatform / outputFirst observedHEAD path
HT-2012-001Executable Document (“FakeWin”)socialWindows; .pdf, .txt presentationa37b074e0977, 2012-03-21ht-2014-002-FakeWin/info.yaml
HT-2012-002Executable Document (FakeOSX)socialOS X; .pdf, .jpg, .rtf presentationa37b074e0977, 2012-03-21ht-2012-002-FakeOSX/info.yaml
HT-2012-007iOS Cydia InstallersocialiOS; .deb/repository pathcc27dc4faa8d, 2012-06-27ht-2012-007-Cydia/info.yaml
HT-2014-001Self Deleting ExecutablesocialWindows; .exef2a10f1543d5, 2014-04-14ht-2014-003-ExeSelfDelete/info.yaml
HT-2013-002Word 2007/2010/2013 + Adobe FlashzerodayWindows; .docxc126a28414f2, 2013-04-03ht-2013-002-Word/info.yaml
HT-2013-003PowerPoint 2007/2010/2013 + FlashzerodayWindows; .ppsxa286922e6277, 2013-05-02ht-2013-003-Powerpoint/info.yaml
HT-2013-004Internet Explorer 6-10 (32-bit)zerodayWindows; .htmlaf9fbdf8b8d4, 2013-07-29ht-2013-004-IE/info.yaml

Two HEAD directory names disagree with their manifests: the FakeWin directory is numbered 2014-002 but declares HT-2012-001, and the self-delete directory is numbered 2014-003 but declares HT-2014-001. The table keys on the declared ID, which is what the backend returns to the console.

Retired packages with 2010-2013 catalogue IDs

IDName / external identifierCat.Ver.First observed → deletionHistorical manifest path
HT-2010-031Acrobat Reader 9.2/9.3 authplay.dllprivate20120701a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13ht-2010-031-Acrobat/info.yaml
HT-2010-036PowerPoint 2003 SP3 heap overflow (KB957784)private20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2010-036-PowerPoint/info.yaml
HT-2010-037Excel 2007 SP2 (MS09-067; bulletin only)private20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2010-037-Excel2007/info.yaml
HT-2010-038Excel 2002 SP3 (KB973471)private20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2010-038-Excel2002/info.yaml
HT-2010-044Word XP/2007, multiple versionszeroday20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2010-044-Word/info.yaml
HT-2010-046Word 2007 SP2/2003 SP3/2002 SP3private20120701a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13ht-2010-046-Word/info.yaml
HT-2010-056Excel 2007 SP2/2003 SP3/2002 SP3private20120701a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13ht-2010-056-Excel/info.yaml
HT-2010-059iPad/iPhone PDF Reader; manifest’s CVE-2010-1095 claim is contradicted by the CVE recordprivate20130311a37b074e0977 2012-03-21 → e96788656416 2013-05-09ht-2010-059-iOS/info.yaml
HT-2011-002Word XP/2007 SP2private20120701a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13ht-2011-002-Word/info.yaml
HT-2011-007¹Flash AVM bytecode verification; CVE-2011-0609 validatedpublic20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-007-Flash/info.yaml
HT-2011-008Flash Player 10.2.xprivate20120701a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13ht-2011-008-Flash/info.yaml
HT-2011-009Safari 5.0.x for Windowsprivate20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-009-Safari/info.yaml
HT-2011-012VLC Media Player 1.1.xprivate20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-012-VLC/info.yaml
HT-2011-013Safari 5 for Windowszeroday20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-013/info.yaml; renamed ht-2011-013-Safari/info.yaml
HT-2011-014IE 8, MS11-031; CVE-2011-0663 validatedprivate20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-014-IE8/info.yaml
HT-2011-015Safari 5.0 SVG for Windowsprivate20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-015-Safari/info.yaml
HT-2011-016Flash MP4 stack overflow (APSB11-21; bulletin only)private20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-016-Flash/info.yaml
HT-2011-017Shockwave (APSB11-19; bulletin only)private20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-017-Shockwave/info.yaml
HT-2011-018Flash ActionScript (APSB11-18; bulletin only)private20120101a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22ht-2011-018-Flash/info.yaml
HT-2011-019Opaque package; no recoverable manifestunknown1c46b6bdc5b 2012-03-19 → cf8956c20cc2 2012-03-20ht-2011-019.zip
HT-2011-020Fake Zip Archivesocial20120101a37b074e0977 2012-03-21 → fb1097b97ff3 2012-03-22ht-2011-020-nsisZip/info.yaml
HT-2011-021Fake Rar Archivesocial20120101a37b074e0977 2012-03-21 → fb1097b97ff3 2012-03-22ht-2011-021-nsisRar/info.yaml
HT-2011-022Safari 5.1 URI processing RCEpublic20120701a37b074e0977 2012-03-21 → ef68ce2503a1 2013-02-07ht-2011-022-Safari/info.yaml
HT-2011-023IE 8 before KB2586448 (MS11-081; bulletin only)private20120701a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13ht-2011-023-IE8/info.yaml
HT-2011-024Safari 5.1x for Windowszeroday20120701a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13ht-2011-024_Safari/info.yaml; renamed with hyphen
HT-2012-003Word 2010private20120701b46b7a29606b 2012-03-26 → 83adf736066c 2012-07-10ht-2012-003-Word2010/info.yaml
HT-2012-004Word XP/2003/2007private20120701b46b7a29606b 2012-03-26 → 83adf736066c 2012-07-10ht-2012-004-Word2007/info.yaml
HT-2012-005Word XP/2003/2007 SP3zeroday201207016ac385d5b0eb 2012-04-23 → 041b3aae6c5a 2012-08-29ht-2012-005-Word2007/info.yaml
HT-2012-006Word 2007/2010 + Flashzeroday201207013d9df5f30bc9 2012-05-22 → 5494acb6ccf7 2012-11-07ht-2012-006-Word/info.yaml
HT-2012-008Word 2003/2007zeroday201207013230efd2f731 2012-06-29 → 041b3aae6c5a 2012-08-29ht-2012-008-Word2007/info.yaml
HT-2012-009Word XP/2003/2007/2010 + Flashzeroday20120701c2e46e5d78d8 2012-09-18 → 79116db1f246 2013-02-08ht-2012-009-Word/info.yaml
HT-2013-001Word XP/2003/2007/2010/2013 + Flashzeroday2012070151b17135bb15 2013-01-24 → 79116db1f246 2013-02-08ht-2013-001-Word/info.yaml

¹ The historical manifest spells the ID HT-2011-0O7 with a capital letter O. The path and mapped CVE make the intended HT-2011-007 clear. The table normalizes it while preserving the discrepancy here.

Most removals that lack an individual explanation occurred in the February 2013 cleanup commit whose changelog says “Removed all dangerous exploits detected by AV.” Repeated folder names in history such as ht-2012-001-nsis, ht-2012-002-OSXFake, and makeosFake are iterations of IDs still present at repository HEAD rather than separate catalogue entries.

Development projects at repository HEAD

These projects were present in src/ but were not packaged in the operator catalogue at the examined repository tip.

SourceWhat the source tree declares or containsPlatform
flash-0day-vitaly1 / flash-0day-vitaly2 / flash0dayFlash ByteArray use-after-free research; AS3 sources, an egghunt stage, and packaging notesWindows (IE, Chrome/Firefox sandbox) and macOS (Safari/Firefox/projector)
PMIEFuck-Java / PMIEFuck-WinWordStage-two helpers for an IE chain using a Java applet or Word COM automationWindows
Shellcode-Stage1 / Shellcode-Stage2-IETwo-stage shellcode projects for the IE workWindows
ht-Office-Shellcode and No-Respawn variantOffice payload stagesWindows
ht-android-shellcodeAndroid payload stagesAndroid
ht-webkit-Android23Stock Android 2.3 browser/WebKit workAndroid 2.3
ht-webkit-Android4-srcAndroid Browser 4.0.x-4.3.x “remote2local” work with local-root and per-device compatibility dataAndroid 4.0-4.3
edn2/2013-002-Word-TLSTLS-delivery variant of HT-2013-002Windows
edn2/2013-003-PowerPoint-TLSTLS-delivery variant of HT-2013-003Windows
edn2/2013-005-IE-TLSIE work with TLS delivery and CA-validation builds; no catalogue ID assignedWindows
edn2/2014-004-AndroidBrowserAndroid browser work packaged for the edn2 delivery nodeAndroid 4.0-4.3
exploit_vpsVPS delivery helper with scout-hash generator and HTMLSupport component

Initial observations

Windows dominates the normalized catalogue: 34 of 38 metadata-bearing IDs (89%) name it, while macOS and iOS have two each. Categories divide into 19 private, 11 zeroday, six social, and two public entries. At repository HEAD, five of seven packages are Windows-focused; the categories have narrowed to four social and three zeroday entries. Android appears only in development trees in this inventory.

The catalogue’s center of gravity also changes. The 2010-2011 history contains a broad mix of private, public, and claimed zeroday vulnerabilities. By 2013, the packaged catalogue had narrowed toward Office-plus-Flash and IE chains. The repeated removal notes about patching and antivirus detection make product maintenance visible in repository history.

The Flash ByteArray use-after-free exposed in the leak was assigned CVE-2015-5119 and patched by Adobe shortly after the archive became public. Chapter 11 treats it as a separately sourced case study rather than inferring the mapping from filenames.

Finally, the version skew is direct: packages at repository HEAD declare version: 20140930, while the examined 9.2.3 server accepts only 20140512. The catalogue therefore targets a server line newer than the reconstructed database snapshot.

Validation state

The lifecycle, version, source path, and category totals above are generated from the reproducible static inventory. CVE-2011-0609 and CVE-2011-0663 are validated mappings. CVE-2010-1095 is retained only as a contradicted manifest claim. Broad bulletin references remain bulletin-level labels rather than guessed CVE mappings. The author-side publication-safety pass found that the metadata remains historical rather than procedural, removed the archive passphrase, and confirmed that no exploit command line, payload, or build procedure is included. Final review must still ensure later edits do not turn the descriptions into execution guidance.

Sources and evidence

↑ HackingTeam's RCS: Bringing a Commercial Spyware Platform Back to Life