Thursday, March 23, 2017 1:45:30 PM
The latest leaks from WikiLeaks' Vault 7 is titled “Dark Matter” and claims that the CIA has been bugging “factory fresh” iPhones since at least 2008 through suppliers. The full documents are expected to be released after a 10 a.m. EDT “press briefing” that WikiLeaks promoted on its Twitter.
Here is a live stream of the pending press briefing with Julian Assange:
LIVE: WikiLeaks press briefing in some minutes: CIA #Vault7 "darkmatter" ask questions with #AskWL https://t.co/ldG78exSsu
— WikiLeaks (@wikileaks) March 23, 2017
And here is the full press release from WikiLeaks:
Today, March 23rd 2017, WikiLeaks releases Vault 7 "Dark Matter", which contains documentation for several CIA projects that infect Apple Mac Computer firmware (meaning the infection persists even if the operating system is re-installed) developed by the CIA's Embedded Development Branch (EDB). These documents explain the techniques used by CIA to gain 'persistence' on Apple Mac devices, including Macs and iPhones and demonstrate their use of EFI/UEFI and firmware malware.
Among others, these documents reveal the "Sonic Screwdriver" project which, as explained by the CIA, is a "mechanism for executing code on peripheral devices while a Mac laptop or desktop is booting" allowing an attacker to boot its attack software for example from a USB stick "even when a firmware password is enabled". The CIA's "Sonic Screwdriver" infector is stored on the modified firmware of an Apple Thunderbolt-to-Ethernet adapter.
"DarkSeaSkies" is "an implant that persists in the EFI firmware of an Apple MacBook Air computer" and consists of "DarkMatter", "SeaPea" and "NightSkies", respectively EFI, kernel-space and user-space implants.
Documents on the "Triton" MacOSX malware, its infector "Dark Mallet" and its EFI-persistent version "DerStake" are also included in this release. While the DerStake1.4 manual released today dates to 2013, other Vault 7 documents show that as of 2016 the CIA continues to rely on and update these systems and is working on the production of DerStarke2.0.
Also included in this release is the manual for the CIA's "NightSkies 1.2" a "beacon/loader/implant tool" for the Apple iPhone. Noteworthy is that NightSkies had reached 1.2 by 2008, and is expressly designed to be physically installed onto factory fresh iPhones. i.e the CIA has been infecting the iPhone supply chain of its targets since at least 2008.
While CIA assets are sometimes used to physically infect systems in the custody of a target it is likely that many CIA physical access attacks have infected the targeted organization's supply chain including by interdicting mail orders and other shipments (opening, infecting, and resending) leaving the United States or otherwise.
Here is a live stream of the pending press briefing with Julian Assange:
LIVE: WikiLeaks press briefing in some minutes: CIA #Vault7 "darkmatter" ask questions with #AskWL https://t.co/ldG78exSsu
— WikiLeaks (@wikileaks) March 23, 2017
And here is the full press release from WikiLeaks:
Today, March 23rd 2017, WikiLeaks releases Vault 7 "Dark Matter", which contains documentation for several CIA projects that infect Apple Mac Computer firmware (meaning the infection persists even if the operating system is re-installed) developed by the CIA's Embedded Development Branch (EDB). These documents explain the techniques used by CIA to gain 'persistence' on Apple Mac devices, including Macs and iPhones and demonstrate their use of EFI/UEFI and firmware malware.
Among others, these documents reveal the "Sonic Screwdriver" project which, as explained by the CIA, is a "mechanism for executing code on peripheral devices while a Mac laptop or desktop is booting" allowing an attacker to boot its attack software for example from a USB stick "even when a firmware password is enabled". The CIA's "Sonic Screwdriver" infector is stored on the modified firmware of an Apple Thunderbolt-to-Ethernet adapter.
"DarkSeaSkies" is "an implant that persists in the EFI firmware of an Apple MacBook Air computer" and consists of "DarkMatter", "SeaPea" and "NightSkies", respectively EFI, kernel-space and user-space implants.
Documents on the "Triton" MacOSX malware, its infector "Dark Mallet" and its EFI-persistent version "DerStake" are also included in this release. While the DerStake1.4 manual released today dates to 2013, other Vault 7 documents show that as of 2016 the CIA continues to rely on and update these systems and is working on the production of DerStarke2.0.
Also included in this release is the manual for the CIA's "NightSkies 1.2" a "beacon/loader/implant tool" for the Apple iPhone. Noteworthy is that NightSkies had reached 1.2 by 2008, and is expressly designed to be physically installed onto factory fresh iPhones. i.e the CIA has been infecting the iPhone supply chain of its targets since at least 2008.
While CIA assets are sometimes used to physically infect systems in the custody of a target it is likely that many CIA physical access attacks have infected the targeted organization's supply chain including by interdicting mail orders and other shipments (opening, infecting, and resending) leaving the United States or otherwise.
Recent AAPL News
- Tech Stocks Set to Extend Rally as Apple Crushes Estimates: Dow Jones, S&P and Nasdaq Futures • IH Market News • 05/01/2026 01:09:53 PM
- Markets Edge Higher as Apple Outlook Lifts Sentiment, Oil Holds Firm: Dow Jones, S&P, Nasdaq, Wall Street Futures • IH Market News • 05/01/2026 09:29:10 AM
- Markets Inch Higher as Apple Outlook Boosts Confidence, Oil Stays Elevated: Dow Jones, S&P, Nasdaq, Wall Street Futures • UK Market News • 05/01/2026 09:29:01 AM
- Apple Shares Edge Higher on Strong Results and “Remarkable” Margin Outlook • IH Market News • 05/01/2026 09:20:05 AM
- Wall Street Futures Edge Higher After Record Highs as Earnings and Iran Tensions Stay in Focus: Dow Jones, S&P, Nasdaq • IH Market News • 05/01/2026 08:45:30 AM
- Wall Street Futures Edge Higher After Record Rally as Earnings Strength Meets Iran Risks: Dow Jones, S&P, Nasdaq • UK Market News • 05/01/2026 08:45:17 AM
- Form 8-K - Current report • Edgar (US Regulatory) • 04/30/2026 08:30:41 PM
- Apple reports second quarter results • Business Wire • 04/30/2026 08:30:00 PM
- Form SCHEDULE 13G - Statement of Beneficial Ownership by Certain Investors • Edgar (US Regulatory) • 04/29/2026 08:40:10 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 04/27/2026 10:30:44 PM
- Apple Shares Edge Lower on Report of OpenAI Chip Ambitions • IH Market News • 04/27/2026 03:24:55 PM
- Form 144 - Report of proposed sale of securities • Edgar (US Regulatory) • 04/23/2026 08:31:45 PM
- Form 8-K - Current report • Edgar (US Regulatory) • 04/20/2026 09:29:51 PM
- Johny Srouji named Apple’s Chief Hardware Officer • Business Wire • 04/20/2026 08:30:00 PM
- Tim Cook to become Apple Executive Chairman; John Ternus to become Apple CEO • Business Wire • 04/20/2026 08:30:00 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 04/17/2026 10:32:12 PM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 04/17/2026 10:30:34 PM
- Apple iPhone Shipments Jump 20% in China, Defying Broader Market Weakness • IH Market News • 04/17/2026 10:02:31 AM
- Trump Signals Iran Conflict May End “Soon” as Netflix Slides — Market Movers: Dow Jones, S&P, Nasdaq, Wall Street Futures • IH Market News • 04/17/2026 09:10:16 AM
- Trump Signals Iran Conflict May Wrap Up “Soon” as Netflix Slides — Key Market Drivers: Dow Jones, S&P, Nasdaq, Wall Street Futures • UK Market News • 04/17/2026 09:10:03 AM
- Smartphone Market Slips as Chip Shortage Hits, While Apple and Samsung Post Gains • IH Market News • 04/15/2026 10:41:53 AM
- Globalstar Jumps 16% on Reported Amazon Deal Talks to Challenge Starlink • IH Market News • 04/14/2026 10:04:25 AM
- Apple Takes Top Spot in Global Smartphone Market for First Time in Q1 2026 • IH Market News • 04/10/2026 12:29:49 PM
- Apple’s foldable iPhone may face delays due to engineering challenges, report says • IH Market News • 04/07/2026 10:38:53 AM
- Form 4 - Statement of changes in beneficial ownership of securities • Edgar (US Regulatory) • 04/03/2026 10:30:45 PM
