WikiLeaks Unveils CIA Implants That Steal SSH Credentials From Windows, Linux PCs (thehackernews.com)
An anonymous reader quotes a report from The Hacker News: WikiLeaks has today published the 15th batch of its ongoing Vault 7 leak, this time detailing two alleged CIA implants that allowed the agency to intercept and exfiltrate SSH (Secure Shell) credentials from targeted Windows and Linux operating systems using different attack vectors. Secure Shell or SSH is a cryptographic network protocol used for remote login to machines and servers securely over an unsecured network. Dubbed BothanSpy -- implant for Microsoft Windows Xshell client, and Gyrfalcon -- targets the OpenSSH client on various distributions of Linux OS, including CentOS, Debian, RHEL (Red Hat), openSUSE and Ubuntu. Both implants steal user credentials for all active SSH sessions and then sends them to a CIA-controlled server.
I thought hacking was illegal under the computer crimes and abuse act?
FTA
BothanSpy is installed as a Shellterm 3.x extension on the target machine and only works if Xshell is running on it with active sessions.
The user manual for Gyrfalcon v2.0 says that the implant is consist of "two compiled binaries that should be uploaded to the target platform along with the encrypted configuration file."
You need an attack vector to implant the malware.
The manual says, "Upload the files to the target using whatever means available."
This is something an agent puts on an already-compromised machine.
Nope. Apple installed their own implants except they have round edges.
C'mon... I'd be mad if our intelligence agencies didn't have this. This is just post-exploit kit. They'd be incompetent if they didn't have it. Even more incompetent than they were for letting this material escape the barn.
The thing to get mad about is sabotage of products to maintain backdoors, and keeping bugs secret.
Someone had to do it.