{"id":32459,"date":"2017-07-08T05:45:11","date_gmt":"2017-07-08T09:45:11","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/wikileaks-cia-steals-ssh-credentials-from-windows-and-linux-with-bothanspy-and-gyrfalcon-tools-betanews.php"},"modified":"2017-07-08T05:45:11","modified_gmt":"2017-07-08T09:45:11","slug":"wikileaks-cia-steals-ssh-credentials-from-windows-and-linux-with-bothanspy-and-gyrfalcon-tools-betanews","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/wikileaks\/wikileaks-cia-steals-ssh-credentials-from-windows-and-linux-with-bothanspy-and-gyrfalcon-tools-betanews.php","title":{"rendered":"WikiLeaks: CIA steals SSH credentials from Windows and Linux with BothanSpy and Gyrfalcon tools &#8211; BetaNews"},"content":{"rendered":"<p><p>    The latest addition to WikiLeaks' Vault 7 cache of CIA tools    and documents gives details of tools used by the agency to    attack Windows and Linux computers. The BothanSpy and Gyrfalcon    projects can be used to intercept and exfiltrate SSH (Secure    Shell) credentials.  <\/p>\n<p>    BothanSpy is used to target Windows, while Gyrfalcon is used    for Linux machines, with both working in different ways. A    number of popular distros can be hit by Gyrfalcon, including    CentOS, Debian, RedHat, openSUSE and Ubuntu, and both tools    function as implants that steal credentials before transmitting    them to a CIA server.  <\/p>\n<p>    The leaked documentation for the tools was updated as recently    as March 2015, and the file relating to BothanSpy reveals that    XShell needs to be installed as it itself installs as a    Shellterm extension. There are smatterings of humor throughout    the file, with a warning that: \"It does not destroy the Death    Star, nor does it detect traps laid by The Emperor to destroy    Rebel fleets.\" There is also the introductory quip: \"Many    Bothan spies will die to bring you this information, remember    their sacrifice.\"  <\/p>\n<p>    Writing about the Windows tools, BothanSpy, WikiLeaks says:  <\/p>\n<p>      BothanSpy is an implant that targets the SSH client program      Xshell on the Microsoft Windows platform and steals user      credentials for all active SSH sessions. These credentials      are either username and password in case of      password-authenticated SSH sessions or username, filename of      private SSH key and key password if public key authentication      is used. BothanSpy can exfiltrate the stolen credentials to a      CIA-controlled server (so the implant never touches the disk      on the target system) or save it in an encrypted file for      later exfiltration by other means. BothanSpy is installed as      a Shellterm 3.x extension on the target machine.    <\/p>\n<p>    The Linux tool is different, and the guide warns that anyone    using it must \"obtain a thorough understanding of the    Linux\/UNIX command line interface and shells such as bash, csh,    and sh.\" There is the additional note that: \"Both the library    and application must be installed with root privileges,    however, they do not need root privilege to execute    successfully on the Linux platform. Therefore, the    operator must be confident with their understanding of Linux to    use root privileges and not muck up the Linux platform's    configuration.\"  <\/p>\n<p>    About Gyrfalcon WikiLeaks says:  <\/p>\n<p>      Gyrfalcon is an implant that targets the OpenSSH client on      Linux platforms (centos, debian, rhel, suse, ubuntu). The      implant can not only steal user credentials of active SSH      sessions, but is also capable of collecting full or partial      OpenSSH session traffic. All collected information is stored      in an encrypted file for later exfiltration. It is installed      and configured by using a CIA-developed root kit (JQC\/KitV)      on the target machine.    <\/p>\n<p>    You can read more about BothanSpy and Gyrfalcon over on    WikiLeaks.  <\/p>\n<p>    Image credit: i3alda and Stanislaw Mikulski \/ Shutterstock  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more here:<br \/>\n<a target=\"_blank\" href=\"https:\/\/betanews.com\/2017\/07\/07\/wikileaks-bothanspy-gyrfalcon\/\" title=\"WikiLeaks: CIA steals SSH credentials from Windows and Linux with BothanSpy and Gyrfalcon tools - BetaNews\">WikiLeaks: CIA steals SSH credentials from Windows and Linux with BothanSpy and Gyrfalcon tools - BetaNews<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The latest addition to WikiLeaks' Vault 7 cache of CIA tools and documents gives details of tools used by the agency to attack Windows and Linux computers. The BothanSpy and Gyrfalcon projects can be used to intercept and exfiltrate SSH (Secure Shell) credentials. BothanSpy is used to target Windows, while Gyrfalcon is used for Linux machines, with both working in different ways. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-32459","post","type-post","status-publish","format-standard","hentry","category-wikileaks"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32459"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=32459"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32459\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=32459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=32459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=32459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}