Skip to main content

Vault 7 - Tomato, Surfside and Claymore

A new document released by WikiLeaks identifies three tools that can be utilised alongside Cherry Blossom to access devices.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new document released by WikiLeaks identifies three tools that can be utilised alongside Cherry Blossom to access devices.

Affected platforms

The following platforms are known to be affected:

Threat details

Tomato: is described as a tool that fetches the administrator password from various Broadcom base wireless access points and routers.

Tomato is able to run on Linux or Windows operating systems with the Linux flavour offering a number of bash scripts that are run from the operator’s machine while connected to the targets Wi-Fi network.

Four scripts are offered that perform the following tasks: Fetches administrator passwords from the device, fetches the password and reboots the device, fetches the password and opens a telnet like shell to the device and finally a helper script that offers guidance on using the tool.

The Windows XP version of the tool is presented in the form of a batch .bat files also known as batch files there are separated into the same individual scripts and offer the same functionally as its Linux counterpart.

To achieve these actions, the scripts exploit a vulnerability found within select Broadcom based devices, likely within the UPnP (Universal Plug and Play) service, used by devices to seamlessly discover each other on the network and establish functional network services for data sharing.

The exploit itself will cause the UPnP service to stop functioning and hence the two options of extracting the password also offers a reboot option allowing the operator to decide if the UPnP service being unavailable or a reboot of the devices is the least noticeable indicator of compromise.

Due to the lack of details available, it is unclear if the vulnerabilities found within Broadcom devices are still present in the latest firmware’s available, although, it is common knowledge that with no user prompting router’s and access points, they are often left out-of-date for months or years, leaving many of the devices likely still vulnerable.

Surfside: There currently isn’t a great detail on the Surfside tool and has only been mentioned in name as part of the Cherry Blossom user guides as an exploitation tool comparable to Tomato. It’s speculated that the tool houses exploits for vulnerabilities found in other device firmware.

Claymore: The claymore is described as a flexible tool with a number of modules for surveying, collection and implant operations against wireless devices.

Claymore allows information about potential targets to be collected; this can include the make, model and version of the device. This will allow attackers to determine which vulnerabilities are available to exploit.

The collection function allows wireless traffic to be captured for reconnaissance and data collection operations. The implants function is described as including the exploitation tool to determine administrator passwords, although, the document doesn’t describe any details on this. It is likely to be similar to the exploit tools Tomato and Surfside, as well as any other as yet unrevealed tools which are available to the operator as part of Claymore.

Affected products
A full list of potentially affected Wi-Fi devices was released in the leak. There hasn’t been any confirmation that these devices are effected by the exploits. If these devices are affected by any of the mentioned exploits in the report the exact details have not been released hence we cannot confirm at this time.


Remediation steps

Type Step
  • Ensure all wireless devices are included in patching schedules to ensure any recently patched vulnerabilities.
  • Disable UPnP services where not required.
  • Be on heightened alert where UPnP services are found unexpectedly unavailable.

Last edited: 17 February 2020 11:40 am