TechnologyGoogle Warns of New Spyware Targeting iOS and Android...

Google Warns of New Spyware Targeting iOS and Android Users

In hearings this week, the notorious spyware vendor NSO group told European legislators that at least five EU countries have used its powerful Pegasus surveillance malware. But as ever more comes to light about the reality of how NSO’s products have been abused around the world, researchers are also working to raise awareness that the surveillance-for-hire industry goes far beyond one company. On Thursday, Google’s Threat Analysis Group and Project Zero vulnerability analysis team published findings about the iOS version of a spyware product attributed to the Italian developer RCS Labs.

Google researchers say they detected victims of the spyware in Italy and Kazakhstan on both Android and iOS devices. Last week, the security firm Lookout published findings about the Android version of the spyware, which it calls “Hermit” and also attributes to RCS Labs. Lookout notes that Italian officials used a version of the spyware during a 2019 anti-corruption probe. In addition to victims located in Italy and Kazakhstan, Lookout also found data indicating that an unidentified entity used the spyware for targeting in northeastern Syria.

“Google has been tracking the activities of commercial spyware vendors for years, and in that time we have seen the industry rapidly expand from a few vendors to an entire ecosystem,” TAG security engineer Clement Lecigne tells WIRED. “These vendors are enabling the proliferation of dangerous hacking tools, arming governments that would not be able to develop these capabilities in-house. But there is little or no transparency into this industry, that’s why it’s critical to share information about these vendors and their capabilities.”

TAG says it currently tracks more than 30 spyware makers that offer an array of technical capabilities and levels of sophistication to government-backed clients.

In their analysis of the iOS version, Google researchers found that attackers distributed the iOS spyware using a fake app meant to look like the My Vodafone app from the popular international mobile carrier. In both Android and iOS attacks, attackers may have simply tricked targets into downloading what appeared to be a messaging app by distributing a malicious link for victims to click. But in some particularly dramatic cases of iOS targeting, Google found that attackers may have been working with local ISPs to cut off a specific user’s mobile data connection, send them a malicious download link over SMS, and convince them to install the fake My Vodafone app over Wi-Fi with the promise that this would restore their cell service.

Attackers were able to distribute the malicious app because RCS Labs had registered with Apple’s Enterprise Developer Program, apparently through a shell company called 3-1 Mobile SRL, to obtain a certificate that allows them to sideload apps without going through Apple’s typical AppStore review process.

Apple tells WIRED that all of the known accounts and certificates associated with the spyware campaign have been revoked. 

“Enterprise certificates are meant only for internal use by a company, and are not intended for general app distribution, as they can be used to circumvent App Store and iOS protections,” the company wrote in an October report about sideloading. “Despite the program’s tight controls and limited scale, bad actors have found unauthorized ways of accessing it, for instance by purchasing enterprise certificates on the black market.”

Original Source Link


Please enter your comment!
Please enter your name here

Latest News

Biden signs Inflation Reduction Act into law

The signing caps a spurt of legislative productivity for Biden and Congress, who in three months have approved...

Rep. Liz Cheney Lost A Primary, But Republicans Lost Much More

Harriet Hageman has defeated Rep. Liz Cheney in the Wyoming House Republican primary. Dave Wasserman tweeted: I've seen enough: Harriet...

Glowing snailfish riddled with antifreeze protein discovered off Greenland coast

Scientists drilling deep into an iceberg off Greenland have discovered a fish with glowing green antifreeze coursing through...

Beacon Hill complex sells to partnership for $65.5M

The 139-unit complex, completed last year, is next to the Beacon Hill light rail station. Original Source Link

Australian Scientists Hope To ‘De-Extinct’ Tasmanian Tiger In Next 10 Years

Researchers in Australia hope to see the extinct Tasmania tiger, or thylacine, roaming the wildness sometime in the...

Who Is Jutes? Five Things About Demi Lovato’s New Boyfriend – Hollywood Life

View gallery Demi Lovato, 29, debuted her new beau to the world when she stepped out with him for...

Must Read

GOP’s Nightmare Week Worsens As Inflation Reduction Act Heads To Biden’s Desk

Every single House Democrat voted for the Inflation...

How the Huge New US Climate Bill Will Save You Money

Today President Joe Biden signed the Inflation Reduction...
- Advertisement -

You might also likeRELATED
Recommended to you