. 24/7 Space News .
CYBER WARS
Apple issues update after cyber weapon captured
By Glenn CHAPMAN
San Francisco (AFP) Aug 26, 2016


Apple iPhone owners on Friday were urged to install a quickly released security update after a sophisticated attack on an Emirati dissident exposed vulnerabilities targeted by cyber arms dealers.

Researchers at Lookout mobile security firm and Citizen Lab at the University of Toronto said they uncovered a fierce, three-pronged cyber attack targeting a dissident's iPhone "that subverts even Apple's strong security environment."

Lookout and Citizen Lab worked with Apple on an iOS patch to defend against what was called "Trident" because of its triad of attack methods, the researchers said in a joint blog post.

"We were made aware of this vulnerability and immediately fixed it with iOS 9.3.5," Apple said in a released statement.

Trident is used in spyware referred to as Pegasus, which a Citizen Lab investigation showed was made by an Israel-based organization called NSO Group.

It was acquired by the US firm Francisco Partners Management six years ago, according to Lookout and Citizen.

Lookout referred to Pegasus as the most sophisticated attack it has seen, sneakily accessing calls, cameras, email, passwords, apps and more on iPhones.

The spyware was detected when used against Ahmed Mansoor, a human rights activist in the United Arab Emirates, who has been repeatedly targeted using spyware.

- Phishing scheme -

After receiving a suspicious text with a link, he reported the matter to Citizen Lab, which worked in conjunction with San Francisco-based Lookout to research the affair.

"The attack sequence, boiled down, is a classic phishing scheme: send text message, open web browser, load page, exploit vulnerabilities, install persistent software to gather information," the joint blog post said.

"This, however, happens invisibly and silently, such that victims do not know they've been compromised."

Mansoor received text messages on August 10 and 11 promising that secrets about detainees being tortured in UAE jails could be accessed by clicking on an enclosed link, researchers said.

Had he fallen for the ruse, the Trident chain of "zero-day exploits" would have broken into his iPhone and installed snooping software.

Once infected, Mansoor's iPhone would have been turned into a "spy in his pocket" capable of tracking his whereabouts and conversations, Citizen Lab said.

Mansoor was targeted five years ago with FinFisher spyware and again the following year with Hacking Team spyware, according to Citizen Lab research.

"The use of such expensive tools against Mansoor shows the lengths that governments are willing to go to target activists," the researchers said.

Although the cyber attack on Mansoor was not linked to a specific government, Citizen Lab said indicators pointed to the UAE.

UAE authorities did not comment on the matter.

Lookout and Citizen believe the spyware has been "in the wild for a significant amount of time."

"It is also being used to attack high-value targets for multiple purposes, including high-level corporate espionage on iOS, Android and Blackberry."

Citizen Lab has also found evidence that "state-sponsored actors" used NSO weapons against a Mexican journalist who reported on high-level corruption in that country and on an unknown target in Kenya.

The NSO tactics included impersonating sites such as the International Committee of the Red Cross, the British government's visa application processing website, and a wide range of news organizations and major technology companies, the researchers said.

- Cyber arms dealers -

Mansoor's decision to enlist Citizen Lab instead of falling into the trap gave researchers a rare chance to expose the work of "shady cyber arms dealers" who command high prices for morally questionable services, Lookout vice president of security research Mike Murray told AFP.

Invoices posted online have shown that hackers can charge tens of thousands of dollars per target hit with their software.

"The smartphone is a valuable target, and breaking into it is a valuable skill set," Murray said.

"People who can do this, and with wiggle room in their moral code, have realized the business opportunity."

NSO Group has been around since 2010 and the capture of one of its weapons was billed as a first.

Studying Trident has helped cyber defenders find ways to spot spyware that had been operating unseen, and they are "actively catching it in the wild now," Murray said.

He declined to reveal anything about other targets, saying that they were people likely to be under surveillance in other ways by local authorities.

Citizen Lab saw the attack on Mansoor as further evidence that "lawful intercept" spyware has significant abuse potential, and that some governments can't resist the temptation to use such tools against political opponents, journalists and human rights defenders.

gc/grf

APPLE INC.

THE NEW YORK TIMES COMPANY

Facebook


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

Previous Report
CYBER WARS
Raytheon debuts Cyber and Electromagnetic Battle Management system
Augusta, Ga. (UPI) Aug 22, 2016
Raytheon has unveiled its Cyber and Electromagnetic Battle Management tool at the U.S. Army's Cyber Quest event, the company announced Monday. The Army event informs cybersecurity requirements and priorities, Raytheon said in a statement. The battle management tool integrates cyber and electromagnetic spectrum awareness capabilities into the service's Electronic Warfare Program M ... read more


CYBER WARS
Space tourists eye $150mln Soyuz lunar flyby

Roscosmos to spend $7.5Mln studying issues of manned lunar missions

Lockheed Martin, NASA Ink Deal for SkyFire Infrared Lunar Discovery Satellite

As dry as the moon

CYBER WARS
Test for damp ground at Mars' seasonal streaks finds none

Fossilized rivers suggest warm, wet ancient Mars

China unveils 2020 Mars rover concept: report

MAVEN Spacecraft Gears Up to Observe Global Dust Storm on Mars

CYBER WARS
Chinese sci-fi prepares to master the universe

China opens longest glass bottom bridge in world

NASA Licenses New Auto-Tracking Mobile Antenna Platform

HERA crew returns paving the way for human research

CYBER WARS
China unveils Mars probe, rover for ambitious 2020 mission

China Ends Preparatory Work on Long March 5 Next-Generation Rocket Engine

China launches hi-res SAR imaging satellite

China launches world first quantum satellite

CYBER WARS
Astronauts Relaxing Before Pair of Spaceships Leave

'New port of call' installed at space station

US astronauts prepare spacewalk to install new docking port

Russia Could Cut Down International Space Station Crew

CYBER WARS
Kourou busy with upcoming Arianespace missions

Ariane 5 is approved for this week's Arianespace launch with two Intelsat payloads

Russian Space Corporation, US Boeing Reach Deal on Dispute Over Sea Launch

Two Intelsat payloads installed on Ariane 5 for next heavy-lift launch

CYBER WARS
A new Goldilocks for habitable planets

Venus-like Exoplanet Might Have Oxygen Atmosphere, but Not Life

Brown dwarfs reveal exoplanets' secrets

Scientists to unveil new Earth-like planet: report

CYBER WARS
A new generation of cheap networked nuclear-radiation detectors

New flexible material can make any window 'smart'

Unraveling the crystal structure of a -70C Celsius superconductor

UNIST to engineer next-generation smart separator membranes









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.