Wednesday, October 4, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

Calls Mount for US Gov Clampdown on Mercenary Spyware Merchants

Researcher by Researcher
July 29, 2022
in Cybersecurity
0
High-Severity Flaw in Argo CD is Information Leak Risk
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Cybersecurity professionals from Google’s threat hunting unit and the University of Toronto’s Citizen Lab are upping the pressure on mercenary hacking firms selling high-end surveillance spyware with fresh calls for the U.S. government to urgently clamp down on these businesses.

In prepared remarks during a House Intelligence Committee hearing this week, Google’s Shane Huntley called on Congress to consider a “full ban” on federal procurement of commercial spyware technologies and urged expanded U.S. government sanctions against two notorious vendors — NSO Group and Candiru.

“We welcome recent steps taken by the government in applying sanctions to the NSO Group and Candiru, and we believe other governments should consider expanding these restrictions,” Huntley argued, before urging the U.S. government to consider a full ban on buying these products and the addition of new sanctions “to limit spyware vendors’ ability to operate in the U.S. and receive U.S. investment.”

“The U.S. could also set an example to other governments by reviewing and disclosing its own historical use of these tools,” Huntley told the Permanent Select Committee on Intelligence.

[ WATCH: Fireside Chat with Google Malware Hunter Shane Huntley ]

Huntley, who runs the Google Threat Analysis Group (TAG) and has been closely involved in documenting the use of zero-day exploits, said the rampant abuse of commercial spyware tools and ongoing use of zero-day exploits against widely deployed software have become too dangerous to society.

In fact, according to Huntley, the U.S. Intelligence Community should make it a priority to identify and analyze threats from foreign commercial spyware providers “as being on par with other major advanced threat actors.”

Israel-based NSO Group and Candiru have been outed among a growing list of hack-for-hire companies using zero-days and sophisticated exploit chains to infect the most modern  Windows and iOS/macOS-powered machines.

Earlier this week, Microsoft threat research units warned that an Austrian company called DSIRF was caught exploiting zero-day flaws in Windows and Adobe software products in “limited and targeted attacks.” 

In addition to NSO Group, Candiru and DSIRF, there have been public documentation (.pdf) of several vendors operating in this murky space, a list that includes Cytrox, Cobwebs Technologies, Cognate, Black Cube, Bluehawk CI, BellTroX. Cytrox has been linked to the ‘Predator’ iPhone spyware suite caught on phones belonging to European politicians.

[ READ: Secretive Israeli Exploit Company Behind Wave of Zero-Day Exploits ]

As the exploitation and spyware discoveries mount, Huntley called on the United States to pay close attention to foreign governments who harbor problematic vendors and undertake diplomatic efforts to limit harms caused by the mercenary spyware industry.

“Any one government’s ability to meaningfully impact this market is limited; only through a concerted international effort can this serious risk to online safety be mitigated,” he added.

In separate testimony at the hearing, Citizen Lab senior researcher John Scott-Railton called attention to “pay-to-play government customers” that provide a steady supply of business to the mercenary spyware industry.

“In many cases, the talent pool of mercenary spyware developers draws from veterans of the intelligence services of U.S. allies. This includes countries with whom the U.S. has intelligence-sharing relationships,” Scott-Railton said. “While some pay-to-play customers are situated within governments with a degree of oversight, many are operating without any clear oversight or accountability. Predictably, this ballooning customer list is responsible for many of the abuses that have been uncovered,” he added.

[ READ: Citizen Lab Exposes Cytrox as Vendor Behind ‘Predator’ iPhone Spyware ]

Scott-Railton used the spotlight of the hearing to underscore just how invasive and powerful the commercial spyware products can be, warning the Intelligence Committee that it’s very difficult detect these hacking attacks at scale.

“The mercenary spyware industry knows that expanding espionage capabilities is a core part of their business model. But, it is inconvenient for them to acknowledge, as this quickly leads to the critical question: when does the industry become a threat to the U.S. national security and counterintelligence?” Scott-Railton asked.

He noted that U.S. government personnel “are not very well protected” from mercenary spyware, pointing to evidence showing at least nine U.S. officials had their phones infected by NSO Group’s Pegasus spying tool.

Scott-Railton said his research team has seen “troubling cases” suggesting that non-state actors may be accessing or directing the use of mercenary spyware, pointing to reports out of Mexico that commercial spyware tools “may be ending up in the hands of cartels.”

More directly, the Citizen Lab security expert called on Congress to direct the U.S. Intelligence Community to identify problematic mercenary spyware companies and use all tools to counter and disrupt their activities.

“Congress should develop legislation ensuring comprehensive U.S. export control and transparency requirements for domestically-developed spyware, including extensive due diligence for national security risks and human rights concerns,” he argued.

Related: Secretive Israeli Exploit Company Behind Wave of Zero-Day Exploits 

Related: Victim of Private Spyware Warns It Can be Used Against US

Related: Microsoft: Austrian Company Exploiting Windows, Adobe Zero-Days

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series.
Ryan is a veteran cybersecurity strategist who has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s past career as a security journalist included bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:





Source link

Related articles

Sentra Raises $30 Million for DSPM Technology

Northern Ireland’s Top Police Officer Apologizes for ‘Industrial Scale’ Data Breach

August 13, 2023
Minimizing Risk Through Proactive Apple Device Management: Addigy

Minimizing Risk Through Proactive Apple Device Management: Addigy

August 12, 2023
Tags: callsClampdownGovMercenarymerchantsMountspyware
Share76Tweet47

Related Posts

Sentra Raises $30 Million for DSPM Technology

Northern Ireland’s Top Police Officer Apologizes for ‘Industrial Scale’ Data Breach

August 13, 2023
0

Northern Ireland’s top police officer apologized Thursday for what he described as an “industrial scale” data breach in which the...

Minimizing Risk Through Proactive Apple Device Management: Addigy

Minimizing Risk Through Proactive Apple Device Management: Addigy

August 12, 2023
0

Enterprise IT teams are struggling to cope with three major forces of change: the evolving regulatory environment, a globally dispersed...

Decipher Podcast: Katelyn Bowden and TC Johnson

Decipher Podcast: Katelyn Bowden and TC Johnson

August 12, 2023
0

Veilid main site: https://veilid.com/ Cult of the Dead Cow site: https://cultdeadcow.com/ Source link

In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack 

In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities

August 12, 2023
0

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under...

Used Correctly, Generative AI is a Boon for Cybersecurity

Used Correctly, Generative AI is a Boon for Cybersecurity

August 12, 2023
0

Adobe stock, by Busra At the Black Hat kickoff keynote on Wednesday, Jeff Moss (AKA Dark Tangent), the founder of...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
Microsoft to Block Macros by Default in Office Apps

Qakbot Email Thread Hijacking Attacks Drop Multiple Payloads

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Browse Safer and Faster Around the World with JellyVPN for just $34.99

Browse Safer and Faster Around the World with JellyVPN for just $34.99

October 3, 2023
Hackers Steal User’s Database From European Institute

Hackers Steal User’s Database From European Institute

October 3, 2023
Hackers Bypass Cloudflare Firewall & DDoS using Cloudflare

Hackers Bypass Cloudflare Firewall & DDoS using Cloudflare

October 2, 2023
AWS Honeypot to Disrupt Threat Actors

AWS Honeypot to Disrupt Threat Actors

October 2, 2023

Recent Posts

Browse Safer and Faster Around the World with JellyVPN for just $34.99

Browse Safer and Faster Around the World with JellyVPN for just $34.99

October 3, 2023
Hackers Steal User’s Database From European Institute

Hackers Steal User’s Database From European Institute

October 3, 2023
Hackers Bypass Cloudflare Firewall & DDoS using Cloudflare

Hackers Bypass Cloudflare Firewall & DDoS using Cloudflare

October 2, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cyber Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches platform Ransomware RoundUp security services Software Stories TFT Threat Top vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved