[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsEOHmQy7vUo4LFxwqZqT2WUbg57A1-oXkXkXJtg_FAs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},710,"What is VBR persistence and how is it used to execute backdoors during Windows startup?","VBR (Volume Boot Record) persistence, as detailed in the [Analysis of Windows Backdoor Exploitation Methods in CIA Vault7 RDB](\u002Fnews\u002Fanalysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb), involves hooking kernel code during the Windows startup process to load unsigned drivers. This technique, implemented by the tool Stolen Goods 2.0, is compatible with WinXP (x86) and Win7 (x86\u002Fx64) and was derived from the Carberp source code. It allows backdoors to execute before system defenses are fully active.","\u003Cp>VBR (Volume Boot Record) persistence, as detailed in the [Analysis of Windows Backdoor Exploitation Methods in CIA Vault7 RDB](\u002Fnews\u002Fanalysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb), involves hooking kernel code during the Windows startup process to load unsigned drivers. This technique, implemented by the tool Stolen Goods 2.0, is compatible with WinXP (x86) and Win7 (x86\u002Fx64) and was derived from the Carberp source code. It allows backdoors to execute before system defenses are fully active.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-vbr-persistence-and-how-is-it-used-to-execute-backdoors-during-windows-s-1777482317640","VBR persistence, Volume Boot Record, Stolen Goods 2.0, Windows startup, kernel hooking, Carberp",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},176,"Analysis of Windows Backdoor Exploitation Methods in CIA Vault7 RDB","analysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb","Analysis of Windows backdoor exploitation methods from CIA Vault7 RDB, including VBR persistence, registry hijacking, and DLL injection techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'CIA Hive Testing Guide – Source Code Acquisition and Brief Analysis', we studied the documents codenamed Vault 8 released by WikiLeaks, providing a brief analysis of the server remote control tool Hive.\u003C\u002Fp>\u003Cp>This article will continue analyzing the CIA-related materials released by WikiLeaks, introducing the Windows backdoor exploitation methods mentioned in the Remote Development Branch (RDB) of Vault 7.\u003C\u002Fp>\u003Cp>Material address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fciav7p1\u002Fcms\u002Fpage_2621760.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will analyze the following backdoor exploitation methods:\u003C\u002Fp>\u003Cul>\u003Cli>VBR Persistence\u003C\u002Fli>\u003Cli>Image File Execution Options\u003C\u002Fli>\u003Cli>OCI.DLL Service Persistence\u003C\u002Fli>\u003Cli>Shell Extension Persistence\u003C\u002Fli>\u003Cli>Windows FAX DLL Injection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VBR Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Used to execute backdoors during the Windows system startup process, capable of hooking kernel code\u003C\u002Fp>\u003Cp>VBR stands for Volume Boot Record (also known as the Partition Boot Record)\u003C\u002Fp>\u003Cp>The corresponding tool is Stolen Goods 2.0 (not publicly released)\u003C\u002Fp>\u003Cp>Documentation address for Stolen Goods:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwikileaks.org\u002Fvault7\u002Fdocument\u002FStolenGoods-2_0-UserGuide\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Can load drivers during the Windows startup process (drivers do not require signatures)\u003C\u002Fli>\u003Cli>Compatible with WinXP (x86), Win7 (x86\u002Fx64)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This method is sourced from https:\u002F\u002Fgithub.com\u002Fhzeroo\u002FCarberp\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The source code included in https:\u002F\u002Fgithub.com\u002Fhzeroo\u002FCarberp is worth in-depth study\u003C\u002Fp>\u003Ch2>0x03 Image File Execution Options\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Redirecting executable programs through registry configuration\u003C\u002Fp>\u003Cp>Modification method (hijacking notepad.exe):\u003C\u002Fp>\u003Cp>Registry path:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\\u003C\u002Fp>\u003Cp>Create new key notepad.exe\u003C\u002Fp>\u003Cp>Create new string value, name: notepad.exe, path \"C:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003Cp>Corresponding cmd command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\notepad.exe\" \u002Fv Debugger \u002Ft REG_SZ \u002Fd \"C:\\windows\\system32\\calc.exe\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>When starting notepad.exe, the actual executed program is \"C:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Typically, modifying registry at this location will be intercepted by antivirus software\u003C\u002Fp>\u003Ch2>0x04 OCI.DLL Service Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Utilizing MSDTC service to load dll for achieving auto-start\u003C\u002Fp>\u003Cp>A backdoor used by Shadow Force in domain environments, documentation suggests CIA also discovered this method can be used in non-domain environments\u003C\u002Fp>\u003Cp>I introduced this exploitation method in a previous article, the address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsome-open-source-project\u002FUse-msdtc-to-maintain-persistence\u002F\u003C\u002Fp>\u003Cp>The method used in my article is to save the dll in C:\\Windows\\System32\\\u003C\u002Fp>\u003Cp>The method used by the CIA is to save the dll in C:\\Windows\\System32\\wbem\\\u003C\u002Fp>\u003Cp>Both locations are viable; the MSDTC service will search these two locations in sequence upon startup\u003C\u002Fp>\u003Ch2>0x05 Shell Extension Persistence\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Hijacking the startup process of explorer.exe via COM dll\u003C\u002Fp>\u003Cp>I have also introduced this approach in a previous article, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsome-open-source-project\u002FUse-COM-Object-hijacking-to-maintain-persistence-Hijack-explorer.exe\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method has been used by several well-known malware, such as COMRAT, ZeroAccess rootkit, and BBSRAT\u003C\u002Fp>\u003Ch2>0x06 Windows FAX DLL Injection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Hijacking Explorer.exe's loading of fxsst.dll through DLL hijacking\u003C\u002Fp>\u003Cp>Explorer.exe loads c:\\Windows\\System32\\fxsst.dll at startup (service enabled by default for fax services)\u003C\u002Fp>\u003Cp>Saving payload.dll as c:\\Windows\\fxsst.dll enables DLL hijacking, hijacking Explorer.exe's loading of fxsst.dll\u003C\u002Fp>\u003Cp>An earlier publicly disclosed exploitation method, reference link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Froom362.com\u002Fpost\u002F2011\u002F2011-06-27-fxsstdll-persistence-the-evil-fax-machine\u002F\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the Windows backdoor exploitation methods mentioned in the Remote Development Branch (RDB) of Vault7, showing that this content draws on publicly disclosed exploitation methods\u003C\u002Fp>\u003Cp>I have systematically collected publicly disclosed Windows backdoor exploitation methods (including my own disclosed methods), address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:38:21.203Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"CIA Vault7 Windows Backdoor Exploitation Methods Analysis","CIA Vault7, Windows backdoor, exploitation methods, persistence, RDB, WikiLeaks, VBR, Image File Execution Options, OCI.DLL, Shell Extension, FAX DLL injection",false,[],{"docs":41,"hasNextPage":38},[42,43,44,45,4],714,713,712,711,{"title":30,"description":30,"image":30},"2026-07-24T02:07:20.115Z","2026-07-23T16:01:59.799Z","draft","2026-07-23T16:14:20.328Z"]