An exploit tested on older Macs with OS X Snow Leopard and Lion [WikiLeaks]

We are all aware of the news about the biggest leak in the history of the CIA and the operation called "Vault 7". This operation consists of the release of information by WikiLeaks and it consists of seven parts or deliveries which they are already starting to be published.

In principle there is much more important information than these Described exploits that were being tested on older Macs running OS X Snow Leopard and OS X Lion, but this is simply something else that adds to the long list of news uncovered by WikiLeaks.

Some leaked documents also refer to the sister operating system, iOS, but in this case we focus on OS X which is what is closest to us. This new leak shares a couple of expolits for OS X used by the CIA and whose codename was known as the «project Imperial«.

Feat Achilles, is the name of the first of the Trojans with which they tried to enter the computers using a self-executing .dmg file like the ones we use today and with which they added their .app file that could later be deleted without being seen. This Achilles was only used in OS X 10.6 Snow Leopard, released by Apple in 2009.

Second appears the exploit SeaPea. This is described as a Rootkit for OS X and for those who do not know what they do, it is an application that once installed is capable of hiding or modifying the information offered by the system to third parties. In this case it was tested on Mac with both OS X 10.6 and OS X 10.7 Lion, and to remove it from the machine it was necessary to perform a disk format or upgrade to a new version of the system.

Logically all these vulnerabilities were corrected by Apple in the following updates or even at the same time that the company discovered them, but it is already known that for these things there is no better solution than that of keep equipment updated to the latest versions available.


Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.