Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Wikileaks release CIA's documents for credentials stealing tools called BothanSpy and Gyrfalcon
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit

Wikileaks release CIA's documents for credentials stealing tools called BothanSpy and Gyrfalcon

tech2 News Staff • July 6, 2017, 22:32:36 IST
Whatsapp Facebook Twitter

Wikileaks released three documents from CIA’s Vault 7 for two projects code-named BothanSpy and Gyrfalcon targeting network protocols.

Advertisement
Subscribe Join Us
Choose
Firstpost on Google
Choose
Firstpost on Google
Wikileaks release CIA's documents for credentials stealing tools called BothanSpy and Gyrfalcon

Whistle blowing site Wikileaks released three documents as part of its Vault 7 leaks for two projects code-named BothanSpy and Gyrfalcon targeting network protocols. Both projects are aimed at intercept and extract SSH (Secure Shell) credentials for remote access to a server of a website. SSH is a cryptographic network protocol that secures network services over an unsecured network. Both projects work on different type of operating system and have different attack patterns. BothaSpy affects the SSH credentials for Microsoft Windows and steals them from SSH sessions which are active. Then this stolen data is transferred or exfiltered upon a disk, encrypted with AES, at the user-provided path. BothanSpy only works if Xshell is running on the target, and it has active sessions. Xshell is a powerful terminal emulator that supports SSH, SFTP, TELNETIf the target has a 64-bit Windows then the loader being used must support Wow64 injection. Gyrfalcon is an SSH session “sharing” tool that operates on outbound OpenSSH sessions from the target host on which it is run. It is an implant that targets Linux platforms and can steal the credentials, encrypting the information for later extraction. The tool runs in an automated fashion and is configured in advance, executed on the remote host and is left running. The operator may then come back and “flush” all its collection to an external disk. Gyrfalcon has the ability to track multiple outbound SSH sessions. Recent Vault 7 leaks from Wikileaks include the **Brutal Kangaroo** tool to comrpomise air gapped computers, and the **Cherry Blossom firmware** for compromising wireless routers.

Tags
Wikileaks SSH whistle blowing Vault 7 OpenSSH sessions Secure Shell wireless access points Xshell
  • Home
  • Tech
  • News & Analysis
  • Wikileaks release CIA's documents for credentials stealing tools called BothanSpy and Gyrfalcon
End of Article
Latest News
Find us on YouTube
Subscribe
  • Home
  • Tech
  • News & Analysis
  • Wikileaks release CIA's documents for credentials stealing tools called BothanSpy and Gyrfalcon
End of Article

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Enjoying the news?

Get the latest stories delivered straight to your inbox.

Subscribe
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV