Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

INSTALLER STATUS CODES AND MESSAGES
The installer may output the following status codes:
0x80000001 - Firmware Parse Error
0x80000002 - Firmware Append Error
0x80000003 - Firmware Write Error
0x80000004 - Firmware Compression Error
0x80000005 - Firmware Out of Space Error
0x40010000 - Firmware Unlock Patch Warning
0x40020000 - Receipt Warning: The receipt could not be written to the installation
media
0x40040000 - PEI Find Warning: Unable to find PEI Core. Update persistence will not be
enabled.
0x40080000 - PEI Append Receipt Warning: Unable to append implant to PEI Core. Update
persistence will not be enabled
0x40100000 - PEI Write Warning: Unable to write implant to PEI Core. Update
persistence will not be enabled
During Install the following message indicates the installer detected a machine that can be
unlocked by holding the power butter for 10 secs:
ERROR: TRIGGER NOT NEEDED
UNINSTALL COMMENTS
After an uninstall, the flash memory will be unlocked until an Apple firmware update
is applied
If patch firmware option was not enabled, the implant is deactivated by setting a
variable in NVRAM. If NVRAM is cleared and the "Uninstall if NVRAM Cleared option is
not set, then the implant may become active again.
Secure deletion of implant is performed on the first system reboot after an uninstall
is triggered. It increases boot time by 30-60 seconds. Since BIOS/EFI will need to
flush NVRAM every 40-60 boots, it is reasonable to ocassionally see boots that take a
longer amount of time.
If the power button is held down or power is lost during a secure delete of the
implant, MacBooks mid 2012 and newer have run length fields that prevent the laptop
from bricking. Parts of the implant may still forensically exist in firmware, but only
as partial encrypted blobs. On laptops older than mid 2012, there is a possiblity of a
corrupt firmware, but it has also been observed that secure deletes take less time on
older hardware.
BOOTCAMP COMMENTS
Booting Windows may affect the time and date settings in OS X. This can cause Der
Starke to beacon several hours later than expected.
SECRET//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh