Appendix A: Complete Exploit Catalogue
This inventory is compiled statically from the vector-exploit packages'
info.yaml metadata, the repository’s Git history, and its development tree.
Nothing in the repository was built, run, repaired, or improved.
The packages use internal tracking numbers (HT-YYYY-NNN). The loader accepts
clear ZIP archives or archives encrypted with a source-embedded passphrase
from the server’s exploits/ directory. The passphrase is not reproduced.
When the catalogue is requested, the server’s exploit loader scans that
directory and publishes each compatible package’s declared metadata to the
console, using the categories social, zeroday, private, and public.
The three final zeroday package trees contain public stub manifests telling the
user to contact HackingTeam support. The Word and PowerPoint trees also contain
functional-looking info-good.yaml variants, while all three checked-out
trees contain info-fake.yaml. Their names suggest alternate customer-facing
and functional manifests, but no code found in the examined snapshot proves
how or for whom they were selected. That remains an inference, not a catalogue
fact.
The static history scanner recovers 46 paths named info.yaml, which collapse
to 38 normalized catalogue IDs after renames and duplicates are joined.
Seven are present at HEAD. A separate early ht-2011-019.zip has no
recoverable manifest and is excluded from those metadata totals.
The tables merge three sets:
- packages present at repository HEAD
(
2cf574d3bf2ea44f67433e32ccc9906ded6218e0, committed 12 December 2014; manifests declare version20140930); - packages with recoverable metadata in Git history, using each manifest at its last surviving commit; and
- projects in the repository’s
src/development tree.
Removal reasons are copied from the repository’s own CHANGELOG and should be
read as HackingTeam’s descriptions, not independent conclusions.
Present at repository HEAD
The manifests are dated 30 September 2014. “First observed” is the first commit in this repository containing a manifest for the normalized ID; it is not necessarily the package’s original development date.
| ID | Name | Category | Platform / output | First observed | HEAD path |
|---|---|---|---|---|---|
| HT-2012-001 | Executable Document (“FakeWin”) | social | Windows; .pdf, .txt presentation | a37b074e0977, 2012-03-21 | ht-2014-002-FakeWin/info.yaml |
| HT-2012-002 | Executable Document (FakeOSX) | social | OS X; .pdf, .jpg, .rtf presentation | a37b074e0977, 2012-03-21 | ht-2012-002-FakeOSX/info.yaml |
| HT-2012-007 | iOS Cydia Installer | social | iOS; .deb/repository path | cc27dc4faa8d, 2012-06-27 | ht-2012-007-Cydia/info.yaml |
| HT-2014-001 | Self Deleting Executable | social | Windows; .exe | f2a10f1543d5, 2014-04-14 | ht-2014-003-ExeSelfDelete/info.yaml |
| HT-2013-002 | Word 2007/2010/2013 + Adobe Flash | zeroday | Windows; .docx | c126a28414f2, 2013-04-03 | ht-2013-002-Word/info.yaml |
| HT-2013-003 | PowerPoint 2007/2010/2013 + Flash | zeroday | Windows; .ppsx | a286922e6277, 2013-05-02 | ht-2013-003-Powerpoint/info.yaml |
| HT-2013-004 | Internet Explorer 6-10 (32-bit) | zeroday | Windows; .html | af9fbdf8b8d4, 2013-07-29 | ht-2013-004-IE/info.yaml |
Two HEAD directory names disagree with their manifests: the FakeWin directory is numbered 2014-002 but declares HT-2012-001, and the self-delete directory is numbered 2014-003 but declares HT-2014-001. The table keys on the declared ID, which is what the backend returns to the console.
Retired packages with 2010-2013 catalogue IDs
| ID | Name / external identifier | Cat. | Ver. | First observed → deletion | Historical manifest path |
|---|---|---|---|---|---|
| HT-2010-031 | Acrobat Reader 9.2/9.3 authplay.dll | private | 20120701 | a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13 | ht-2010-031-Acrobat/info.yaml |
| HT-2010-036 | PowerPoint 2003 SP3 heap overflow (KB957784) | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2010-036-PowerPoint/info.yaml |
| HT-2010-037 | Excel 2007 SP2 (MS09-067; bulletin only) | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2010-037-Excel2007/info.yaml |
| HT-2010-038 | Excel 2002 SP3 (KB973471) | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2010-038-Excel2002/info.yaml |
| HT-2010-044 | Word XP/2007, multiple versions | zeroday | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2010-044-Word/info.yaml |
| HT-2010-046 | Word 2007 SP2/2003 SP3/2002 SP3 | private | 20120701 | a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13 | ht-2010-046-Word/info.yaml |
| HT-2010-056 | Excel 2007 SP2/2003 SP3/2002 SP3 | private | 20120701 | a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13 | ht-2010-056-Excel/info.yaml |
| HT-2010-059 | iPad/iPhone PDF Reader; manifest’s CVE-2010-1095 claim is contradicted by the CVE record | private | 20130311 | a37b074e0977 2012-03-21 → e96788656416 2013-05-09 | ht-2010-059-iOS/info.yaml |
| HT-2011-002 | Word XP/2007 SP2 | private | 20120701 | a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13 | ht-2011-002-Word/info.yaml |
| HT-2011-007¹ | Flash AVM bytecode verification; CVE-2011-0609 validated | public | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-007-Flash/info.yaml |
| HT-2011-008 | Flash Player 10.2.x | private | 20120701 | a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13 | ht-2011-008-Flash/info.yaml |
| HT-2011-009 | Safari 5.0.x for Windows | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-009-Safari/info.yaml |
| HT-2011-012 | VLC Media Player 1.1.x | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-012-VLC/info.yaml |
| HT-2011-013 | Safari 5 for Windows | zeroday | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-013/info.yaml; renamed ht-2011-013-Safari/info.yaml |
| HT-2011-014 | IE 8, MS11-031; CVE-2011-0663 validated | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-014-IE8/info.yaml |
| HT-2011-015 | Safari 5.0 SVG for Windows | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-015-Safari/info.yaml |
| HT-2011-016 | Flash MP4 stack overflow (APSB11-21; bulletin only) | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-016-Flash/info.yaml |
| HT-2011-017 | Shockwave (APSB11-19; bulletin only) | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-017-Shockwave/info.yaml |
| HT-2011-018 | Flash ActionScript (APSB11-18; bulletin only) | private | 20120101 | a37b074e0977 2012-03-21 → 11cc2da5c4ad 2012-03-22 | ht-2011-018-Flash/info.yaml |
| HT-2011-019 | Opaque package; no recoverable manifest | unknown | — | 1c46b6bdc5b 2012-03-19 → cf8956c20cc2 2012-03-20 | ht-2011-019.zip |
| HT-2011-020 | Fake Zip Archive | social | 20120101 | a37b074e0977 2012-03-21 → fb1097b97ff3 2012-03-22 | ht-2011-020-nsisZip/info.yaml |
| HT-2011-021 | Fake Rar Archive | social | 20120101 | a37b074e0977 2012-03-21 → fb1097b97ff3 2012-03-22 | ht-2011-021-nsisRar/info.yaml |
| HT-2011-022 | Safari 5.1 URI processing RCE | public | 20120701 | a37b074e0977 2012-03-21 → ef68ce2503a1 2013-02-07 | ht-2011-022-Safari/info.yaml |
| HT-2011-023 | IE 8 before KB2586448 (MS11-081; bulletin only) | private | 20120701 | a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13 | ht-2011-023-IE8/info.yaml |
| HT-2011-024 | Safari 5.1x for Windows | zeroday | 20120701 | a37b074e0977 2012-03-21 → f9ffc7a38a85 2013-02-13 | ht-2011-024_Safari/info.yaml; renamed with hyphen |
| HT-2012-003 | Word 2010 | private | 20120701 | b46b7a29606b 2012-03-26 → 83adf736066c 2012-07-10 | ht-2012-003-Word2010/info.yaml |
| HT-2012-004 | Word XP/2003/2007 | private | 20120701 | b46b7a29606b 2012-03-26 → 83adf736066c 2012-07-10 | ht-2012-004-Word2007/info.yaml |
| HT-2012-005 | Word XP/2003/2007 SP3 | zeroday | 20120701 | 6ac385d5b0eb 2012-04-23 → 041b3aae6c5a 2012-08-29 | ht-2012-005-Word2007/info.yaml |
| HT-2012-006 | Word 2007/2010 + Flash | zeroday | 20120701 | 3d9df5f30bc9 2012-05-22 → 5494acb6ccf7 2012-11-07 | ht-2012-006-Word/info.yaml |
| HT-2012-008 | Word 2003/2007 | zeroday | 20120701 | 3230efd2f731 2012-06-29 → 041b3aae6c5a 2012-08-29 | ht-2012-008-Word2007/info.yaml |
| HT-2012-009 | Word XP/2003/2007/2010 + Flash | zeroday | 20120701 | c2e46e5d78d8 2012-09-18 → 79116db1f246 2013-02-08 | ht-2012-009-Word/info.yaml |
| HT-2013-001 | Word XP/2003/2007/2010/2013 + Flash | zeroday | 20120701 | 51b17135bb15 2013-01-24 → 79116db1f246 2013-02-08 | ht-2013-001-Word/info.yaml |
¹ The historical manifest spells the ID HT-2011-0O7 with a capital letter
O. The path and mapped CVE make the intended HT-2011-007 clear. The table
normalizes it while preserving the discrepancy here.
Most removals that lack an individual explanation occurred in the February
2013 cleanup commit whose changelog says “Removed all dangerous exploits
detected by AV.” Repeated folder names in history such as
ht-2012-001-nsis, ht-2012-002-OSXFake, and makeosFake are iterations of
IDs still present at repository HEAD rather than separate catalogue entries.
Development projects at repository HEAD
These projects were present in src/ but were not packaged in the operator
catalogue at the examined repository tip.
| Source | What the source tree declares or contains | Platform |
|---|---|---|
flash-0day-vitaly1 / flash-0day-vitaly2 / flash0day | Flash ByteArray use-after-free research; AS3 sources, an egghunt stage, and packaging notes | Windows (IE, Chrome/Firefox sandbox) and macOS (Safari/Firefox/projector) |
PMIEFuck-Java / PMIEFuck-WinWord | Stage-two helpers for an IE chain using a Java applet or Word COM automation | Windows |
Shellcode-Stage1 / Shellcode-Stage2-IE | Two-stage shellcode projects for the IE work | Windows |
ht-Office-Shellcode and No-Respawn variant | Office payload stages | Windows |
ht-android-shellcode | Android payload stages | Android |
ht-webkit-Android23 | Stock Android 2.3 browser/WebKit work | Android 2.3 |
ht-webkit-Android4-src | Android Browser 4.0.x-4.3.x “remote2local” work with local-root and per-device compatibility data | Android 4.0-4.3 |
edn2/2013-002-Word-TLS | TLS-delivery variant of HT-2013-002 | Windows |
edn2/2013-003-PowerPoint-TLS | TLS-delivery variant of HT-2013-003 | Windows |
edn2/2013-005-IE-TLS | IE work with TLS delivery and CA-validation builds; no catalogue ID assigned | Windows |
edn2/2014-004-AndroidBrowser | Android browser work packaged for the edn2 delivery node | Android 4.0-4.3 |
exploit_vps | VPS delivery helper with scout-hash generator and HTML | Support component |
Initial observations
Windows dominates the normalized catalogue: 34 of 38 metadata-bearing IDs (89%) name it, while macOS and iOS have two each. Categories divide into 19 private, 11 zeroday, six social, and two public entries. At repository HEAD, five of seven packages are Windows-focused; the categories have narrowed to four social and three zeroday entries. Android appears only in development trees in this inventory.
The catalogue’s center of gravity also changes. The 2010-2011 history contains a broad mix of private, public, and claimed zeroday vulnerabilities. By 2013, the packaged catalogue had narrowed toward Office-plus-Flash and IE chains. The repeated removal notes about patching and antivirus detection make product maintenance visible in repository history.
The Flash ByteArray use-after-free exposed in the leak was assigned
CVE-2015-5119 and patched by Adobe shortly after the archive became public.
Chapter 11 treats it as a separately sourced case study rather than inferring
the mapping from filenames.
Finally, the version skew is direct: packages at repository HEAD declare
version: 20140930, while the examined 9.2.3 server accepts only 20140512.
The catalogue therefore targets a server line newer than the reconstructed
database snapshot.
Validation state
The lifecycle, version, source path, and category totals above are generated from the reproducible static inventory. CVE-2011-0609 and CVE-2011-0663 are validated mappings. CVE-2010-1095 is retained only as a contradicted manifest claim. Broad bulletin references remain bulletin-level labels rather than guessed CVE mappings. The author-side publication-safety pass found that the metadata remains historical rather than procedural, removed the archive passphrase, and confirmed that no exploit command line, payload, or build procedure is included. Final review must still ensure later edits do not turn the descriptions into execution guidance.
Sources and evidence
- SOURCE:
vector-exploitcommit2cf574d3bf2ea44f67433e32ccc9906ded6218e0, its history,VERSION,CHANGELOG, package manifests, andsrc/names/readmes. - SOURCE:
rcs-db/lib/rcs-db/build/exploit.rb:238-254at commit6cff59d28634d718cac9fdd17cb629fd59a3cf3ffor the accepted manifest version. - SOURCE:
research/hackingteam-rcs/exploit-catalogue/inventory.rband its README for the normalization method and totals. - Microsoft, MS11-031 and MS11-081.
- NIST NVD, CVE-2011-0609, CVE-2010-1095, and CVE-2015-5119.
↑ HackingTeam's RCS: Bringing a Commercial Spyware Platform Back to Life