TechDigits

Tech news
Friday, Mar 31, 2023

Israeli firm’s spyware linked to attacks on websites in UK and Middle East

Israeli firm’s spyware linked to attacks on websites in UK and Middle East

Canada-based researchers say new evidence suggests Candiru’s software used to target critics of autocratic regimes
Researchers have found new evidence that suggests spyware made by an Israeli company that was recently blacklisted in the US has been used to target critics of Saudi Arabia and other autocratic regimes, including some readers of a London-based news website.

A report by Montreal-based researchers from Slovakian company Eset, an internet security firm, found links between attacks against high-profile websites in the Middle East and UK, and the Israeli company Candiru, which has been called Israel’s “most mysterious cyberwarfare company”.

Candiru and NSO Group, a much more prominent Israeli surveillance company, were both added to a US blacklist this month after the Biden administration took the rare step of accusing the firms of acting against US national security interests.

The Eset report revealed new information about so-called “watering hole attacks”. In such attacks, spyware users launch malware against ordinary websites that are known to attract readers or users who are considered “targets of interest” by the user of the malware.

The sophisticated attacks allow the malware user to identify characteristics about the individuals who have visited the website, including what kind of browser and operating system they are using. In some cases the malware user can then launch an exploit that allows them to take over an individual target’s computer.

Unlike NSO Group’s signature spyware, which is called Pegasus and infects mobile phones, Candiru’s malware is believed by researchers to infect computers. The company appears to be named after a parasitic freshwater catfish that can be found in the Amazon.

The researchers found that the websites that were “known targets” of this kind of attack included Middle East Eye, a London-based news website, and multiple websites associated with government ministries in Iran and Yemen.

Candiru did not respond to the Guardian’s request for comment.

Middle East Eye condemned the attacks. In a statement, its editor-in-chief, David Hearst, said the outlet was no stranger to attempts to take the website down by state and non-state actors.

“Substantial sums of money have been spent trying to take us out. This has not stopped us reporting what is going on in all corners of the region and I am confident that they will not stop us in future,” he said.

Once websites are compromised, researchers at Eset say, they are considered “jumping off sites” that help malware users target individuals. In other words, not every individual who visited one of the compromised websites would have been in danger of being hacked, but users of the malware are believed to have used the websites as a starting point to help identify a much smaller group of individuals who were then targeted.

Matthieu Faou, who uncovered the campaigns, said Eset developed a custom in-house system in 2018 to uncover “watering holes” on high-profile websites. In July 2020, the system notified them that an Iranian embassy website in Abu Dhabi had been tainted with malicious code.

“Our curiosity was aroused by the high-profile nature of the targeted website, and in the following weeks we noticed that other websites with connections to the Middle East were also targeted,” Faou said.

The “threat group” then “went quiet” until it resurfaced in January 2021 and was active until late summer in 2021, when all the websites that were observed to have been victims of attacks were then “cleaned”, Eset said.

Eset said it believed hacking activities ended in late July 2021 after a report by researchers at Citizen Lab, released in conjunction with Microsoft, detailed Candiru’s alleged surveillance activities. That report accused Candiru of selling spyware to governments linked to fake Black Lives Matter and Amnesty International websites that were used to hack targets.

In the July 2021 report, Citizen Lab, a research group affiliated with the University of Toronto, said the Tel Aviv-based Candiru made “untraceable” spyware that could infect computers and phones.

At the time, Candiru declined to comment.

Microsoft said in July that it appeared that Candiru sold the spyware that enabled the hacks, and that the governments generally chose who to target and ran the operations themselves. The company also announced at the time that it had disabled the “cyberweapons” of Candiru and built protections against the malware, including issuing a Windows software update.

There is little public information available about Candiru, which was founded in 2014 and has undergone several name changes. In 2017 the company was selling its malware to clients in the Gulf, western Europe and Asia, according to a lawsuit reported in an Israeli newspaper. Candiru may have deals with Uzbekistan, Saudi Arabia and the UAE, Forbes has reported.

Microsoft reported that it had found victims of the spyware in Israel and Iran. Citizen Lab said it was able to identify a computer that had been hacked by Candiru’s malware, and then used that hard drive to extract a copy of the firm’s Windows spyware. The owner of the computer was a “politically active” individual in western Europe, it said.

This month Candiru made headlines after the Biden administration announced it had added the company to the commerce department’s entity list, a blacklist usually reserved for America’s worst enemies, including Chinese and Russian hackers.

In its press release, the commerce department said it had evidence that Candiru developed and supplied spyware to foreign governments that used it to maliciously target government officials, journalists, businesspeople, activists, academics and embassy workers. The tools also helped to enable foreign governments to conduct “transnational repression”, the department said.

Candiru has not commented on its placement on the entity list.
Newsletter

Related Articles

TechDigits
Close
0:00
0:00
China and Brazil have signed a new deal that will allow them to trade in their own currencies, bypassing the US dollar as an intermediary
Elon Musk and Others Call for Pause on A.I., Citing ‘Profound Risks to Society’
U.S. charges FTX's Bankman-Fried with paying $40 million bribe
Fallen 'Crypto King' Who Owes Millions to Investors Was Kidnapped and Tortured
Regulators blame social media for SVB's rapid collapse: 'Complete game changer'
AOC explains why she opposes banning TikTok
Gordon Moore, a co-founder of Intel Corporation, died at 94
Donald Trump arrested – Twitter goes wild with doctored pictures
Credit Suisse's Scandalous History Resulted in an Obvious Collapse - It's time for regulators who fail to do their job to be held accountable and serve as an example by being behind bars.
Russian Hackers Preparing New Cyber Assault Against Ukraine
A brief banking situation report
Elon Musk Is Planning To Build A Town In Texas For His Employees
The Silicon Valley Bank’s collapse effect is spreading around the world, affecting startup companies across the globe
Market Chaos as USDC Loses Peg to USD after $3.3 Billion Reserves Held by Silicon Valley Bank Closed.
Banking regulators close SVB, the largest bank failure since the financial crisis
In a major snub to Downing Street's Silicon Valley dreams, UK chip giant Arm has dealt a serious blow to the government's economic strategy by opting for a US listing
It's the question on everyone's lips: could a four-day workweek be the future of employment?
Corruption and Influence Buying Uncovered in International Mainstream Media: Investigation Reveals Growing Disinformation Mercenaries
Being a Tiktoker might be expensive…
China's top tech firms, including Alibaba, Tencent, Baidu, NetEase, and JD.com, are developing their own versions of Open AI's AI-powered chatbot, ChatGPT
This shocking picture, showing how terrible is the results of the earthquake in Turkey
The desk of King Carlos Alberto of Sardinia has many secret compartments
Charlie Munger, calls for a ban on cryptocurrencies in the US, following China's lead
First generation unopened iPhone set to fetch more than $50,000 at auction.
Almost 30% of professionals say they've tried ChatGPT at work
Interpol seeks woman who ran elaborate exam cheating scam in Singapore
What is ChatGPT?
Tesla reported record profits and record revenues for 2022
Microsoft is finalising plans to become the latest technology giant to reduce its workforce during a global economic slowdown
Tesla slashes prices globally by as much as 20 percent
After Failing To Pay Office Rent, Twitter May Sell User Names
FTX fraud investigators are digging deeper into Sam Bankman-Fried's inner circle – and reportedly have ex-engineer Nishad Singh in their sights
TikTok CEO Plans to Meet European Union Regulators
U.S. Moves to Seize Robinhood Shares, Silvergate Accounts Tied to FTX
Coinbase to Pay $100 Million in Settlement With New York Regulator
FTX assets worth $3.5bn held by Bahamas securities regulator
Former FTX CEO Bankman-Fried finally arrested in Bahamas after U.S. files charges
Corruption works: House Financial Services Chair Waters doesn't plan to subpoena her donor, Sam Bankman-Fried, to testify at hearing on FTX collapse
Yellen hints at ‘national security’ probe into Twitter purchase
Elon Musk reinstates Donald Trump's Twitter account.
George W. Bush and Barack Obama will hold back-to-back disinformation conferences
Solar + Powerwall ensures you never lose power, even if the grid goes down
This man paid for strangers' grocery and it moved them to tears
Meta introduces a new version of Mark Zuckerberg
Virtual Reality on billboards: BMW advertisement on Times Square
Apple CEO Tim Cook says coding should be taught as early as elementary school: 'It's the most important language you can learn'
Apple Executive Resigns After Viral TikTok Shows Him Making Crude Jokes
Huawei is not only better technology, but also protecting users better: Apple Warns Of Security Flaw For Iphones, Ipads And Macs
Mark Zuckerberg warns many teams will ‘shrink’ as Meta revenue drops
Elon Musk reportedly begged for forgiveness after his affair with Google co-founder Sergey Brin's wife
×