TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Wikileaks CIA Leak – Dark Matter

17 点作者 ShaneWilton大约 8 年前

1 comment

ShaneWilton大约 8 年前
I&#x27;ve finished reading all of the leak now (except the Broadcom manual that was included for some reason?), and at least to me, the most interesting piece is the manual for DerStarke [0].<p>It&#x27;s a diskless, EFI-persistent implant for Mac OS X 10.8 and 10.9, that does most of its network communications through a browser process. The manual explicitly calls out that this is done to make it difficult to detect the implant using tools like Little Snitch.<p>This is in contrast to a lot of the tools referenced in the previous leak, which went to great efforts to keep their disk &#x2F; memory footprint low, but didn&#x27;t otherwise get into much of the details about how they cloaked their network comms.<p>Overall, the leak didn&#x27;t include any capabilities that I was surprised to see. Things like using adapters to install an implant on boot (Sonic Screwdriver [1] in this dump) are super cool, but they aren&#x27;t anything we haven&#x27;t seen done before. See Thunderstrike [2] for a really great lecture on this type of attack.<p>Also, obligatory warning about WikiLeaks dumps: it&#x27;s usually worth just reading the leaked documents themselves, and avoiding the editorializing that WikiLeaks always does. They tend to make unsubstantiated claims that end up getting the brunt of the media&#x27;s focus.<p>[0] <a href="https:&#x2F;&#x2F;wikileaks.org&#x2F;vault7&#x2F;darkmatter&#x2F;document&#x2F;DerStarke_v1_4_DOC&#x2F;" rel="nofollow">https:&#x2F;&#x2F;wikileaks.org&#x2F;vault7&#x2F;darkmatter&#x2F;document&#x2F;DerStarke_v...</a><p>[1] <a href="https:&#x2F;&#x2F;wikileaks.org&#x2F;vault7&#x2F;darkmatter&#x2F;document&#x2F;SonicScrewdriver_1p0" rel="nofollow">https:&#x2F;&#x2F;wikileaks.org&#x2F;vault7&#x2F;darkmatter&#x2F;document&#x2F;SonicScrewd...</a><p>[2] <a href="https:&#x2F;&#x2F;events.ccc.de&#x2F;congress&#x2F;2014&#x2F;Fahrplan&#x2F;events&#x2F;6128.html" rel="nofollow">https:&#x2F;&#x2F;events.ccc.de&#x2F;congress&#x2F;2014&#x2F;Fahrplan&#x2F;events&#x2F;6128.htm...</a>