Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

IOC ERB: 26
Jan 2009
3
SECRET//NOFORN
SECRET//NOFORN
Requirements
Requirement # 2009-0247
Provide persistence (DarkMatter), process and file hiding (SeaPea), and a
beacon (NightSkies), integrated onto a MacBook Air with current Mac OSX
NightSkies shall support the Macbook Air using Mac OSX 10.5.x
NightSkies shall be compatible with DarkMatter persistence and kernel
patching tool
DarkMatter shall have the capability to disable itself after a configurable
amount of time
DarkMatter shall have the capability of removing its payload from the EFI of
the MacBook Air
NightSkies shall be compatible with SeaPea rootkit
NightSkies shall support the following implant features:
Beaconing to a listening post (LP)
Command receipt and execution from a LP
File transfer to and from the LP
Program file execution on the MacBook Air
Delay after browser starts to beacon
The tool shall be packaged manually, according to the parameters to be
provided by COG

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh