WikiLeaks Unveils CIA Implants That Steal SSH Credentials From Windows, Linux PCs (thehackernews.com)
An anonymous reader quotes a report from The Hacker News: WikiLeaks has today published the 15th batch of its ongoing Vault 7 leak, this time detailing two alleged CIA implants that allowed the agency to intercept and exfiltrate SSH (Secure Shell) credentials from targeted Windows and Linux operating systems using different attack vectors. Secure Shell or SSH is a cryptographic network protocol used for remote login to machines and servers securely over an unsecured network. Dubbed BothanSpy -- implant for Microsoft Windows Xshell client, and Gyrfalcon -- targets the OpenSSH client on various distributions of Linux OS, including CentOS, Debian, RHEL (Red Hat), openSUSE and Ubuntu. Both implants steal user credentials for all active SSH sessions and then sends them to a CIA-controlled server.
I thought hacking was illegal under the computer crimes and abuse act?
FTA
BothanSpy is installed as a Shellterm 3.x extension on the target machine and only works if Xshell is running on it with active sessions.
The user manual for Gyrfalcon v2.0 says that the implant is consist of "two compiled binaries that should be uploaded to the target platform along with the encrypted configuration file."
You need an attack vector to implant the malware.
I think I remember seeing this very tool in the "NSA catalog" type thing from the big ES leak.
Just more proof; if it's on a computer, its insecure.
You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.
The manual says, "Upload the files to the target using whatever means available."
This is something an agent puts on an already-compromised machine.
This type of shit should stop! What else is hidden from public by those goons?
Do they have any decency? Probably not, needs a certain character to feel superior and protect the country....
But NOT macOS.
Tee Hee.
This is just another proof of Russian hacking.
while still hiding the guns
I knew Python would eventually slither in and undermine my security with it's whitespace of doom!
The POSIX Shell Script Master Race prevails again! ;)
Anons need not reply. Questions end with a question mark.
"(S//NF) Many Bothan spies will die to bring you this information, remember their
sacrifice"
This sentence was classified Secret//No Foreign? Good grief, somebody sic Disney on the CIA.
Secure Shell or SSH is a cryptographic network protocol used for remote login to machines and servers securely over an unsecured network.
[ The restraint exhibited in explaining SSH, on a tech site, but *not* "cryptographic" is amazing. /sarcasm ]
It must have been something you assimilated. . . .
Does this mean that SELinux, properly configured to reduce root privileges, would in fact result in the logging and/or defeat of the gyrfalcon payload, without further kernel-level exploits regaining them permissions?
while true ; do killall bothanspy ; done
This is disgusting... Vault 7 leaks just get better and better.
You run the pre-bugged OSes if you so wish. I'll still run Linux over Windows or Mac OS any day thank you. You are mistaken of course but I won't waste any more breath on a troll. Have a nice day.
That would mean something if you didn't have to already have compromised the system you wanted to use this on. Try again next time.
For this to work on a Linux system they must first get root password then take control of groups and make install from root. So they need root password for this to work and they need to alter authorisation log file which gives the time and date in which the root password was used authorisation at blah blah date and blah blah time.
So how do they ( get ) the root password and how do they alter the authorisation log.
pam_unix(sudo:session): session opened for user root by ( Hazelnut Hidetsugu Yoshikawa )
They don't have proof. They have speculation, timely releases, and "diplomacy."
Assange is a conman and WikiLeaks are information launderers at best.
Just use Telnet instead.
So it seems the CIA has their own rootkit. Backdoored SSH clients are absolutely nothing new at all. I remember seeing crap like that in the early 2000s. What next, are they going to tell me about their SUPER AWESOME tty snooper too?
That would be 'revved up like a deuce'.
Just change your password to . Passwords are a form of control; be free!
-IOVAR Web Dev Platform
When you misuse technical terms. Repeatedly.
I'm sure the general public will be impressed by all these previously known things, Mr. Assange.
So true...
Its time for the rest of the world to force the United States to disarm. This is clearly an unstable regime and a constant source of military aggression.
those evil North Koreans....wait...Chinese...wait...Russians...wait....damn!
Fedora is noticeably absent from the list. Pre-compromised? It would not surprise me. However, I would be very disappointed. If Fedora is compromised, it's likely in the form of a kernel patch.
I'm disappointed in you, CIA. And Wikileaks, too - what the hell is Russia paying you for?
He has the gorgeous Pamela Anderson now, so why should he care?
I believe it should be "held up like a loofah by the foreman of the night".
A republic cannot succeed till it contains a certain body of men imbued with the principles of justice and honour.
We are the third party AVG tech support provider. Activate and install your AVG Antivirus just by visiting our website http://avgretail.co.uk/. AVG Support provide instant AVG technical support service for AVG technical issues. AVG Support provides - 1. AVG Support is one of the best and the most reliable AVG antivirus technical support team which offers quick solutions for any type of antivirus support. 2. AVG Support help in installing with full version of antivirus 3. Sometimes due to technical flaws you are unable to use your antivirus and even run it, you can contact us in this aspect. 4. AVG Support is available with our quick solutions 24*7. 5. To give quick solutions to the users according to their needs and requirements AVG support is the best team. 6. AVG Support help users onremote access and live chat.