From Vault7 – The Keystone?
"Angelfire is an implant comprised of 5 components: Solartime, Wolfcreek,
Keystone, BadMFS, and the Windows Transitory File system.
…
Keystone is responsible for starting user applications. Any application started by MW is
done without the implant ever being dropped to the file system. In other words, a process
is created and the implant is loaded directly into memory. Currently all processes will be
created as svchost. When viewed in task manager (or another process viewing tool) all
properties of the process will be consistent with a real instance of svchost.exe including
image path and parent process. Furthermore, since the implant code never touches the
file system (aside from the possibility of paging) there is very little forensic evidence that
the process was ever ran."
https:// wikileaks.org/vault7/document/Angelfire-2_0-UserGuide/page-4/#pagination