NSO Group’s latest spyware on par with nation-state abilities, researchers say

When Apple announced Nov. 23 that it filed a lawsuit against Israeli spyware firm NSO Group, it claimed that the firm and its clients “devote the immense resources and capabilities of nation-states to conduct highly targeted cyberattacks.” An independent analysis published Wednesday backs that claim up. Google Project Zero researchers Ian Beer and Samuel Groß took a deep dive into FORCEDENTRY, the malware developed by NSO Group that allowed adversaries to infect targeted Apple devices — without the owner’s knowledge — with NSO Group’s Pegasus spyware. The researchers concluded that it’s “one of the most technically sophisticated exploits” they’ve ever seen, rivaling “those previously thought to be accessible to only a handful of nation states.” Previous iterations of the Pegasus software required the victim to click a link in an SMS message. But FORCEDENTRY was an example of NSO Group’s zero-click exploitation technology, where no interaction from the target was […]

The post NSO Group’s latest spyware on par with nation-state abilities, researchers say appeared first on CyberScoop.

Continue reading NSO Group’s latest spyware on par with nation-state abilities, researchers say

Nation-state hackers aim to exploit Log4j software flaw, Microsoft warns

Hackers associated with the governments of China, Iran, North Korea and Turkey have been trying to find ways to leverage the Apache Log4j vulnerability, Microsoft’s Threat Intelligence Team said Tuesday. The notice came the same day a top U.S. government cyber official said that the Cybersecurity and Infrastructure Security Agency hasn’t seen any U.S. federal agencies targeted with the exploit, but that the government is still fearful of attacks. Hundreds of millions of devices are potentially at risk, an agency official previously said. Microsoft’s notice said its analysts had observed “multiple” known state-associated hacking groups working with the vulnerability, with activity ranging from experimentation to integration in active campaigns to exploitation of targets. The flaw is so severe, computer security specialists have warned, that a successful attack could result in the takeover of an affected system. An Iranian group Microsoft calls “Phosphorus” — known alternatively as “Charming Kitten” — that […]

The post Nation-state hackers aim to exploit Log4j software flaw, Microsoft warns appeared first on CyberScoop.

Continue reading Nation-state hackers aim to exploit Log4j software flaw, Microsoft warns

Suspected espionage campaign targets telecoms, IT service firms in Middle East

Hackers targeted a string of telecommunication operators and IT service organizations in the Middle East and Asia over the last six months, according to research published Tuesday. The suspected espionage activity targeted organizations in Israel, Jordan, Kuwait, Saudi Arabia, the United Arab Emirates, Pakistan, Thailand, and Laos, according to the research from Symantec’s Threat Hunter Team. The “targeting and tactics are consistent with Iranian-sponsored actors,” researchers noted, but stopped short of tying the activity to the Iranian government. Some of the evidence shows a link to Seedworm — otherwise known as MuddyWater — a prolific hacking group with suspected ties to Iran known for concerted espionage efforts dating back to at least 2015. The group previously threatened to kill security researchers who stumbled across one of its command-and-control servers. Its operators have also focused on academia and the tourism industry in multiple countries earlier this year, and governments and other […]

The post Suspected espionage campaign targets telecoms, IT service firms in Middle East appeared first on CyberScoop.

Continue reading Suspected espionage campaign targets telecoms, IT service firms in Middle East

Romanian ransomware suspect arrested in joint Europol, FBI operation

A Romanian man accused of using ransomware to target “high-profile” organizations and companies was arrested Monday as part of a joint operation between the Romanian National Police, the FBI, and Europol. The man — identified only as a 41-year-old living in Craiova, Romania — is accused of compromising an unnamed Romanian IT services company with clients in the retail, energy and utilities sectors, according to a Europol statement posted to the agency’s website. He then used that access to deploy ransomware and steal sensitive data from the IT company’s clients in Romania and abroad, before encrypting the files. The stolen data included financial information, personal information regarding employees and customers and other important documents. The man then asked for a “sizeable ransom payment in cryptocurrency,” the Europol statement read, with the threat of posting the stolen data on cybercrime forums. Allan Liska, the director of threat intelligence at cybersecurity firm […]

The post Romanian ransomware suspect arrested in joint Europol, FBI operation appeared first on CyberScoop.

Continue reading Romanian ransomware suspect arrested in joint Europol, FBI operation

Hack-and-leak group Black Shadow keeps targeting Israeli victims

In October, a little-watched hacking group called Black Shadow went public with data it appeared to have stolen from an Israeli LGBTQ app, doxing users in a way that seemed intended to send a message. The breach was the result of a larger incident at Cyberserve, a web hosting company that also yielded sensitive information from the Machon Mor Medical Institute — which included medical data on roughly 290,000 patients — and other firms that possessed information about Israeli citizens. While the international media sorted through the fallout of the intrusions, security personnel reminded observers that the same hacking group previously breached Shirbit, an Israeli insurance firm, in December 2020, demanding a series of escalating ransom payments that analysts suggested weren’t motivated by money at all. Instead, experts now say, the recent uptick in activity from Black Shadow — a group that’s still shrouded in mystery, though it appears to […]

The post Hack-and-leak group Black Shadow keeps targeting Israeli victims appeared first on CyberScoop.

Continue reading Hack-and-leak group Black Shadow keeps targeting Israeli victims

SolarWinds hackers kept busy in the year since the seminal hack, Mandiant finds

Hackers associated with the SolarWinds supply chain compromise have been busy in the year since that attack was revealed, compromising multiple cloud solution companies with the goal of stealing data relevant to Russian interests and finding routes to additional victims, new research reveals. Findings published Monday by a team of analysts at Mandiant collate previous observations and analysis — along with the efforts of “hundreds of consultants, analysts and reverse engineers — to paint a picture of potentially distinct groups working alongside or within a more established Russian intelligence hacking group known as Nobelium, a name given to the group by Microsoft. The group is also known as Cozy Bear. The U.S. government formally blamed the Russian government for the hack on SolarWinds, a federal contractor that, when breached as far back as January 2019, provided a path to compromising nine government agencies — including the departments of Treasury, Homeland […]

The post SolarWinds hackers kept busy in the year since the seminal hack, Mandiant finds appeared first on CyberScoop.

Continue reading SolarWinds hackers kept busy in the year since the seminal hack, Mandiant finds

NSO Group tech reportedly used to hack US officials’ iPhones

Nearly a dozen iPhones associated with U.S. State Department employees were hacked using spyware developed by Israel-based NSO Group, Reuters first reported Friday. The attacks were carried out in the last several months by an unknown assailant on U.S. officials either based in Uganda or focused on the country, sources told Reuters. The Washington Post and CNN also confirmed the intrusions. Previous reporting on NSO Group suggested that U.S. officials’ phones may have been targeted using software developed by NSO Group, but Friday’s report is the first to confirm successful breaches. As many as 11 U.S. diplomats received notices from Apple that they may have been targeted with the spyware, the Post reported. Apple began notifying potential targets around the world that they may have been targeted by the NSO Group software on Nov. 23, the same day the tech firm announced a lawsuit against NSO Group for allegedly violating […]

The post NSO Group tech reportedly used to hack US officials’ iPhones appeared first on CyberScoop.

Continue reading NSO Group tech reportedly used to hack US officials’ iPhones

Final defendant in multimillion-dollar SIM hijacking scheme sentenced to prison

The sixth and final defendant in a gang accused of perpetrating a multimillion-dollar SIM hijacking case was sentenced to 10 months in prison and ordered to pay more than $121,000 in restitution, the Department of Justice announced Tuesday. Garrett Endicott, 22, from Missouri, was connected to a hacking group known as “The Community,” which engaged in a string of SIM hijacking incidents targeting individual users’ cryptocurrency exchange accounts in seven states, according to DOJ. SIM hijacking, or SIM swapping, is a technique where an attacker takes control of a target’s phone number, allowing the attackers to receive text messages and other forms of two-factor authentication protocols that are then used to log into accounts. The gang, known as “The Community,” faced charges of conspiracy to commit wire fraud, wire fraud and aggravated identity theft. Three people who worked for mobile phone providers and helped the gang were also charged with […]

The post Final defendant in multimillion-dollar SIM hijacking scheme sentenced to prison appeared first on CyberScoop.

Continue reading Final defendant in multimillion-dollar SIM hijacking scheme sentenced to prison

Apple alerts journalists, activists about state-sponsored hacking attempts after NSO Group suit

On the same day Apple announced a lawsuit against Israeli spyware vendor NSO Group for developing hacking tools to help breach iOS technology, the company was notifying potential targets of those exploits. El Faro, a news organization in San Salvador, El Salvador, reported late Tuesday that 12 of its staff members received notices from the company, which warned that that “Apple believes you are being targeted by state-sponsored attackers who are trying to remotely compromise the iPhone associated with your Apple ID.” The company also sent notices to four others in San Salvador who are “leaders of Civil Society organizations and opposition political parties,” the news organization reported. Notices were also sent to six Thai activists and researchers critical of the government there, Reuters reported. NSO Group develops software designed to allow access to target devices through various bugs in Apple’s technology. A company spokesperson told CyberScoop Tuesday that its […]

The post Apple alerts journalists, activists about state-sponsored hacking attempts after NSO Group suit appeared first on CyberScoop.

Continue reading Apple alerts journalists, activists about state-sponsored hacking attempts after NSO Group suit

Apple sues NSO Group, spyware vendor known for helping governments hack critics

Apple is suing Israeli spyware vendor NSO Group “to hold it accountable for the surveillance and targeting of Apple users,” the company announced Tuesday. The technology company is seeking to permanently ban NSO Group from using any Apple software, services or devices amid reports that the firm sells technology that makes it possible for governments to hack individual devices to spy on journalists, dissidents and human rights activists. As part of those efforts NSO Group has developed exploits capable of subverting Apple’s security controls, requiring “thousands of hours to investigate the attacks, identify the harm, diagnose the extent of the impact and exploitation, and develop and deploy the necessary repairs and patches to ensure that Apple servers,” the suit says.  NSO Group did not immediately respond to a request for comment on Tuesday. “State-sponsored actors like the NSO Group spend millions of dollars on sophisticated surveillance technologies without effective accountability,” […]

The post Apple sues NSO Group, spyware vendor known for helping governments hack critics appeared first on CyberScoop.

Continue reading Apple sues NSO Group, spyware vendor known for helping governments hack critics