Space News from SpaceDaily.com
Spyware campaign targeted journalists, activists: researchers
ADVERTISEMENT

Washington, July 15 (AFP) Jul 15, 2021
A spyware campaign using tools from a secretive Israeli firm was used to attack and impersonate dozens of human rights activists, journalists, dissidents, politicians and others, researchers said Thursday.

Statements from Microsoft security researchers and the University of Toronto's Citizen Lab said powerful "cyberweapons" were being used in precision attacks targeting more than 100 victims around the world.

Microsoft said it patched this week the vulnerability exploited by the group, known by the names Candiru and Sourgum.

Citizen Lab said in a blog post that "Candiru is a secretive Israel-based company that sells spyware exclusively to governments," which can then use it to "infect and monitor iPhones, Androids, Macs, PCs, and cloud accounts."

"We found many domains masquerading as advocacy organizations such as Amnesty International, the Black Lives Matter movement, as well as media companies, and other civil-society themed entities," Citizen Lab said.

Microsoft observed at least 100 victims in the Palestinian territories, Israel, Iran, Lebanon, Yemen, Spain, Britain, Turkey, Armenia and Singapore.

The US tech firm said it moved to thwart the attacks with Windows software updates that prevent Candiru from delivering its malware.

"Microsoft has created and built protections into our products against this unique malware, which we are calling DevilsTongue," a Microsoft statement said.

"We have shared these protections with the security community so that we can collectively address and mitigate this threat."

According to Microsoft, DevilsTongue was able to infiltrate popular websites such as Facebook, Twitter, Gmail, Yahoo and others to collect information, read the victim's messages and retrieve photos.

"DevilsTongue can also send messages as the victim on some of these websites, appearing to any recipient that the victim had sent these messages," said the statement from Microsoft Threat Intelligence Center.

"The capability to send messages could be weaponized to send malicious links to more victims."

Citizen Lab researchers found evidence the spyware can exfiltrate private data from a number of apps and accounts, including Gmail, Skype, Telegram and Facebook.

It can also capture browsing history and passwords, as well as turn on the target's webcam and microphone, according to the findings.

Citizen Lab said the Israeli firm's current name is Saito Tech Ltd, and that it has some of the same investors and principals as NSO Group, another Israeli firm under scrutiny for surveillance software.

rl/sw

FACEBOOK

YAHOO!

Twitter

MICROSOFT


ADVERTISEMENT




Space News from SpaceDaily.com
China's Shenzhou-18 mission docks with space station: Xinhua
NASA and Boeing Prepare for Historic Starliner Launch
Private firm advances with new liquid-fuel rocket development

24/7 Energy News Coverage
Airbus net profit soars 28% in first quarter
Extreme heat scorches Southeast Asia, bringing school closures and warnings
BHP bid for Anglo American spotlights surge in copper demand

Military Space News, Nuclear Weapons, Missile Defense
NATO chief says Ukraine can beat Russia; As exhausted troops await resupply
Ahead of feared Rafah invasion, Palestinians mourn bombardment dead
Poland, Lithuania say can help return military-aged men to Ukraine

24/7 News Coverage
'Extreme' climate blamed for world's worst wine harvest in 62 years
The Indian villagers who lost their homes to the sea
Philippine settlement submerged by dam reappears due to drought


All rights reserved. Copyright Agence France-Presse. Sections of the information displayed on this page (dispatches, photographs, logos) are protected by intellectual property rights owned by Agence France-Presse. As a consequence, you may not copy, reproduce, modify, transmit, publish, display or in any way commercially exploit any of the content of this section without the prior written consent of Agence France-Presse.