WikiLeaks Vault 7 Leak Claims CIA Bugs ‘Factory Fresh’ iPhones

A visitor tries out an Apple iPhone 7 on the first day of sales of the new phone at the Berlin Apple store on September 16, 2016 in Berlin, Germany. (Sean Gallup/Getty Images)

A new WikiLeaks Vault 7 leak titled “Dark Matter” claims, with unreleased documents, that the Central Intelligence Agency has been bugging “factory fresh” iPhones since at least 2008. WikiLeaks further claims that the CIA has the capability to permanently bug iPhones, even if their operating systems are deleted or replaced.

The documents are expected to be released in the next 24-hours. The announced was made after a “press briefing” that WikiLeaks promoted on its Twitter.

Watch a playback of the Assange-led livestream here.

A summary of the documents has been released on the WikiLeaks website. It reads:

Today, March 23rd 2017, WikiLeaks releases Vault 7 “Dark Matter”, which contains documentation for several CIA projects that infect Apple Mac Computer firmware (meaning the infection persists even if the operating system is re-installed) developed by the CIA’s Embedded Development Branch (EDB). These documents explain the techniques used by CIA to gain ‘persistence’ on Apple Mac devices, including Macs and iPhones and demonstrate their use of EFI/UEFI and firmware malware.

Among others, these documents reveal the “Sonic Screwdriver” project which, as explained by the CIA, is a “mechanism for executing code on peripheral devices while a Mac laptop or desktop is booting” allowing an attacker to boot its attack software for example from a USB stick “even when a firmware password is enabled”. The CIA’s “Sonic Screwdriver” infector is stored on the modified firmware of an Apple Thunderbolt-to-Ethernet adapter.

“DarkSeaSkies” is “an implant that persists in the EFI firmware of an Apple MacBook Air computer” and consists of “DarkMatter”, “SeaPea” and “NightSkies”, respectively EFI, kernel-space and user-space implants.

Documents on the “Triton” MacOSX malware, its infector “Dark Mallet” and its EFI-persistent version “DerStake” are also included in this release. While the DerStake1.4 manual released today dates to 2013, other Vault 7 documents show that as of 2016 the CIA continues to rely on and update these systems and is working on the production of DerStarke2.0.

Also included in this release is the manual for the CIA’s “NightSkies 1.2” a “beacon/loader/implant tool” for the Apple iPhone. Noteworthy is that NightSkies had reached 1.2 by 2008, and is expressly designed to be physically installed onto factory fresh iPhones. i.e the CIA has been infecting the iPhone supply chain of its targets since at least 2008.

While CIA assets are sometimes used to physically infect systems in the custody of a target it is likely that many CIA physical access attacks have infected the targeted organization’s supply chain including by interdicting mail orders and other shipments (opening, infecting, and resending) leaving the United States or otherwise.

    • How about we prosecute the CIA SCUM who did this?

      They are supposed to TRACK AMERICA”S ENEMIES, not the ENTIRE COUNTRY.

      Maybe if they took the BILLIONS in OUR tax moneys we give them and concentrate spying ON OUR ENEMIES instead of the entire country, THEY MIGHT BE ABLE TO STOP JIHADI ATTACKS.

      Panetta, Clapper and Brennan belong in jail.

      (Tim Cooke is simply an idiot who focussed Apple ‘s energy on gay emojis instead of professionalizing the apps and PROTECTING HIS CUSTOMERS)

      • I do not disagree with your points. But we will not be effective in suing the CIA. This must be handled (I would think) at cutting off the “pathetic” hand the CIA uses with the power of the law, meaning hit the fools that have been willingly used by the CIA to open it’s users to this kind of venerability.

        As long as corporations find it a smooth trail to take advantage of it’s users/consumers, the powers that not been held in check (aka: CIA, etc) will have an open door (literally) available to them to abuse the power given to them.

        I’m just suggesting a more methodical approach, instead of one lead by futile instincts.

        But, I fully agree with your other points of just some of the minion that are being used by much bigger fish that need the oxygen taken from their own tanks. ;)

    • Do you sue your auto manufacturer when some punk breaks in with a screwdriver and hotwires it?
      Are Ford or GMC or Lamborghini responsible for other peoples actions?

      • Wow, the last comment has no clue, or even took the time to read the article. Obviously a shill. Apple is responsible, and all other manufacturers (of any product) are responsible for defects, malfunctions, or any other issue when selling a product. That is why there is a warranty. Apple, Samsung, etc, are responsible to secure each OS they create, or represent with the product they sell. Especially since sensitive information is sent and placed on these devices. And the devices are created for this very purpose.

        The only moron, is the one that stands idly by, and speaks before thinking. Your ignorance is obvious, and humorous to boot. A class action law suit is very viable, and has thousands of examples of precedence in the courts to support this very thing. God bless your feeble mind.

  1. So pick your poison. A Samsung that catches fire or an iPhone with big ears? It’s not that I think someone will be listening to me. I’m a nobody. But, just the fact that someone can listen to my calls, makes me wonder if I will ever buy another Apple product.

    • Your logic is defective and you are severely ignorant of what it means to be a free individual who has inalienable rights to live apart from tyranny and oppression.

    • It’s not just Iphone… It’s all of them.

      Jezuz… can’t you put 2 and 2 together?

      When the stories first came out about them hacking android all the apple fanboi’s were doing the “my phone is awesome they can’t hack me” now you guys are doing it? WTF?

    • You might benefit from reading The Gulag Archipelago.
      It may give you further insight into what a real Police State is all about.
      Any and all information is of value to them.
      Solzhenitsyn lived it for real, and survived it.
      Most Americans have not a clue what real evil is.

  2. None of you are going to do a thing about it.

    Some of you may whine and moan, but the next time they roll out an advertising campaign about how their phone has 1 more megapixel you’ll be lining up in droves with your wallets out.

    You were warned about your phones and you parroted the “ive got nothing to hide line”

    You’ve been warned about driverless cars, drones, the surveillance state, all of it and you keep making excuses for it.

    Until you stop acting like a willing participant in the establishment of a surveillance state the East Germans only dreamed of will this stop.


  3. Literally Knew this for years. when you see all media start pushing a product In the US start looking for why. I remember when I phone and android was being pushed by my local and national news outlets. When i saw this instantly Knew their was an underlying reason and its not for you benefit. Look at what Elite politicians use, Oboma Blackberry, Merkle Blackberry ,Prince of whales blackberry. And now in the US blackberry has been all but banned. Blackberry refused to release their encryption to the Cia and thus the companies branch in the US was systematically dismantled by the media,Tv shows every outlet.
    People have to stop waiting for the dots to be connected for them. Look at what the media pushes and accept they are not doing things for your benefit. Then you will start seeing the truth.

  4. Now start looking into why all signals have been forced over to digital instead of Analog. And if you say its because of better reception or digital tv screens your not thinking. Think what can you do with Analog signal you cant do with digital. Think frequency range


  6. Was Apple allegedly complicit with this? Or was it a CIA workaround? Will Apple upgrade their software to block these hacks? If Apple does not, the credibility they won by refusing to break their security under FBI pressure turns to stool.

  7. The ones so upset about this must have very sinister things to hide. I couldn’t care less about this. Big whoop. The CIA knows what I do on my smartphone. If it’s not illegal, why do you care?! Privacy is no longer a right in this new world. Adapt to it or keep whining.

    • “Privacy is no longer a right in this new world.”

      People like yourself have created this brave New World. It gets worse in the future. You can put a stop to its progress, yet you refuse, and go along for the ride because you’ve nothing to hide.

      Have you not read Huxley or Orwell?

    • Paranoid you are not hiding anything However it appears someone else is PARANOID………When you do things wrong and you have to hide it, you must make sure no one else knows.
      We must understand we are slaves and once you understand this you are free.

    • Got a little girl? Want to keep her safe from things like paedos?

      Then you should care.

      Not all of these guys have honorable intentions. There is plenty of abuse in the system.

      But even if there weren’t, just the potential is an awful risk. For your family’s safety.

      And besides, what happens when the camera in your phone activates while you are potty training your daughter because of this? And then the photo(s) is shared amongst the creeps worldwide? Because remember, once it’s in the internet it’s there forever.

      Still say you have “nothing to hide”?

  8. What most people don’t know is that the police and the intelligence agencies are using the intelligence they are gathering up on all of us to be used for revenge purposes. The FBI did precisely this during the 1960s with their illegal COINTELPRO program. It supposedly ended in 1971 but a very similar program continues to run to this day that goes by the name of organized stalking or gang stalking. Here in London, New Scotland Yard are involved in this crime.

  9. The CIA was established to ensure that the law is followed. Now they seem to be in the subterfuge forefront in breaking it. There may be an earmark on page 1,947 of some obscure bill somewhere stating that (by the way), this is legal, slipped in just for them as insurance.

  10. Why wouldn’t they ? Apple works hand in hand with them anyway. They also had spyware in nearly every single harddrive manufactured on planet earth, if you recall. There are no secrets, it is just that simple.

  11. You have to realize that most of this activity is corporate welfare for politically connected consulting and defense firms. I was a government military contractor so I know the dance. Scare people, authorize tons of money, spend immense amounts on large complex data systems that take huge amounts of consulting resources and expensive hardware. The data collected is mostly useless (unless you want to target a political enemy), but it feeds the government/industrial cyber complex, with lavish contributions going to congressional patrons (my consulting firm’s patron was Charlie Rangel).

  12. We the people need to simply plan a Constitutional Convention, completely ignore everyone saying it will be meaningless, and agree upon our own amendments. We then pass them and if 3/4 of the states agree BAM- law without Congress, law that the courts have no power to challenge, law that the president must obey. It is our only hope.