WikiLeaks Unveils CIA Implants That Steal SSH Credentials From Windows, Linux PCs (thehackernews.com)
An anonymous reader quotes a report from The Hacker News: WikiLeaks has today published the 15th batch of its ongoing Vault 7 leak, this time detailing two alleged CIA implants that allowed the agency to intercept and exfiltrate SSH (Secure Shell) credentials from targeted Windows and Linux operating systems using different attack vectors. Secure Shell or SSH is a cryptographic network protocol used for remote login to machines and servers securely over an unsecured network. Dubbed BothanSpy -- implant for Microsoft Windows Xshell client, and Gyrfalcon -- targets the OpenSSH client on various distributions of Linux OS, including CentOS, Debian, RHEL (Red Hat), openSUSE and Ubuntu. Both implants steal user credentials for all active SSH sessions and then sends them to a CIA-controlled server.
I thought hacking was illegal under the computer crimes and abuse act?
FTA
BothanSpy is installed as a Shellterm 3.x extension on the target machine and only works if Xshell is running on it with active sessions.
The user manual for Gyrfalcon v2.0 says that the implant is consist of "two compiled binaries that should be uploaded to the target platform along with the encrypted configuration file."
You need an attack vector to implant the malware.
I think I remember seeing this very tool in the "NSA catalog" type thing from the big ES leak.
Just more proof; if it's on a computer, its insecure.
You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.
The manual says, "Upload the files to the target using whatever means available."
This is something an agent puts on an already-compromised machine.
This type of shit should stop! What else is hidden from public by those goons?
Do they have any decency? Probably not, needs a certain character to feel superior and protect the country....
But NOT macOS.
Tee Hee.
while still hiding the guns
I knew Python would eventually slither in and undermine my security with it's whitespace of doom!
The POSIX Shell Script Master Race prevails again! ;)
Anons need not reply. Questions end with a question mark.
So it seems the CIA has their own rootkit. Backdoored SSH clients are absolutely nothing new at all. I remember seeing crap like that in the early 2000s. What next, are they going to tell me about their SUPER AWESOME tty snooper too?
Just change your password to . Passwords are a form of control; be free!
-IOVAR Web Dev Platform
You do realize NSA has both a defensive and offensive side of the house right? Guess which one created SELinux....
Its time for the rest of the world to force the United States to disarm. This is clearly an unstable regime and a constant source of military aggression.
Does this mean that SELinux, properly configured to reduce root privileges, would in fact result in the logging and/or defeat of the gyrfalcon payload, without further kernel-level exploits regaining them permissions?
I'm certainly not an selinux expert; but, given that the root user can change the security context of most files and directories, I don't see how selinux would make a meaningful difference.
Corrections are welcome, though.
#DeleteChrome
You do realize NSA has both a defensive and offensive side of the house right?
You know, you're absolutely right!
Why, just the other day I spotted the NSA defense boys by their van, down by the river!!!
Strat
Progressivism (aka US 'Liberalism'): Ideas so good they need a police/surveillance-state to enforce.
No they won't cover their tracks without being noticed. With systemd even root can't modify the logs (seriously)
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
He has the gorgeous Pamela Anderson now, so why should he care?
I believe it should be "held up like a loofah by the foreman of the night".
A republic cannot succeed till it contains a certain body of men imbued with the principles of justice and honour.
We are the third party AVG tech support provider. Activate and install your AVG Antivirus just by visiting our website http://avgretail.co.uk/. AVG Support provide instant AVG technical support service for AVG technical issues. AVG Support provides - 1. AVG Support is one of the best and the most reliable AVG antivirus technical support team which offers quick solutions for any type of antivirus support. 2. AVG Support help in installing with full version of antivirus 3. Sometimes due to technical flaws you are unable to use your antivirus and even run it, you can contact us in this aspect. 4. AVG Support is available with our quick solutions 24*7. 5. To give quick solutions to the users according to their needs and requirements AVG support is the best team. 6. AVG Support help users onremote access and live chat.